808bits

IBM® z/OS® Version 2 Release 4 ICSF PKCS #11 Cryptographic Module

FIPS 140-2 certificate #4591 · IBM Corporation · data as of 2026-09-08

IBM® z/OS® Version 2 Release 4 ICSF PKCS #11 Cryptographic Module, from IBM Corporation, holds FIPS 140-2 certificate #4591 at overall level 1. The validation is historical: agencies may keep the module in existing systems but not buy it new. Below are its validation history, algorithm certificates and security policy, drawn from the NIST CMVP entry.

Historical. Moved to historical list due to sunsetting. Federal agencies may reference historical validations for existing systems only, not for new procurement.
Caveat: When operated in FIPS mode with module IBM(R) z/OS(R) Version 2 Release 4 Security Server RACF(R) Signature Verification Module validated to FIPS 140-2 under Cert. #2691 operating in FIPS mode

Certificate

Certificate number4591
StandardFIPS 140-2
Statushistorical
Overall level1
Module typeSoftware-Hybrid
EmbodimentMulti-Chip Stand Alone
VendorIBM Corporation · website
Software versionsICSF level HCR77D0 with APAR OA63132
Hardware versionsCOP chips integrated within processor unit [1] and COP chips integrated within processor unit and P/N 02WN654-N37880 (Low Power) [2]
Firmware versionsFeature 3863 (aka FC3863) with System Driver Level 41C [1], and Feature 3863 (aka FC3863) with System Driver Level 41C and CCA 7.0.68z [2]

Module description

Quoted from the NIST CMVP entry for this certificate.

ICSF is a software element of z/OS that works with hardware cryptographic features and the Security Server (RACF) to provide secure, high-speed cryptographic services in the z/OS environment. ICSF, which runs as a started task, provides the application programming interfaces by which applications request the cryptographic services.

Security level exceptions

  • Mitigation of Other Attacks: N/A

Approved algorithms (11)

AlgorithmCAVP certificates
AESA389, C1772
CKGvendor affirmed
DRBGC1763, C1772
DSAC1772
ECDSAC1772
HMACC1772
KAS-SSCA2666, A2667
KTS
RSAC1766, C1772, C1799
SHSA389, C1772
Triple-DESA389

Allowed algorithms

AES (Cert. #A389, key unwrapping; key establishment methodology provides between 128 and 256 bits of encryption strength); MD5; NDRNG; RSA (key wrapping; key establishment methodology provides between 112 and 149 bits of encryption strength); Triple-DES (Cert. #A389, key unwrapping; key establishment methodology provides 112 bits of encryption strength)

Tested configurations

  • IBM z/OS Version 2 Release 4 running on an IBM z15 with CP Assist for Cryptographic Functions [1]
  • IBM z/OS Version 2 Release 4 running on an IBM z15 with CP Assist for Cryptographic Functions with CEX7A [2] (single-user mode)

Validation history

DateTypeLab
2023-09-11Initialatsec information security corporation

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-08-21: first observed by this tracker, status historical
  • Validation dates on record: 2023-09-11

Source documents