808bits

SUSE Linux Enterprise NSS Cryptographic Module

FIPS 140-3 certificate #4728 · SUSE LLC · data as of 2026-08-28
Historical. Replaced by certificate #5435. Federal agencies may reference historical validations for existing systems only, not for new procurement.
Caveat: Interim validation. When operated in approved mode and installed, initialized and configured as specified in Section 11 of the Security Policy

Certificate

Certificate number4728
StandardFIPS 140-3
Statushistorical
Overall level1
Module typeSoftware
EmbodimentMulti-Chip Stand Alone
VendorSUSE LLC · website
Software versions3.1

Module description

SUSE Network Security Services (NSS) is a set of libraries designed to support cross-platform development of security-enabled client and server applications. Applications built with NSS can support TLS, PKCS #5, PKCS #7, PKCS #11, PKCS #12, S/MIME, X.509v3 certificates, and other security standards.

Security level exceptions

  • Physical security: N/A
  • Non-invasive security: N/A

Approved algorithms

AlgorithmCAVP certificate
AES-CBCA3575
AES-CBCA3581
AES-CBCA3585
AES-CBC-CS1A3580
AES-CMACA3577
AES-CTRA3575
AES-CTRA3581
AES-ECBA3575
AES-ECBA3581
AES-ECBA3582
AES-ECBA3583
AES-ECBA3585
AES-ECBA3586
AES-ECBA3587
AES-GCMA3575
AES-GCMA3581
AES-GCMA3582
AES-GCMA3583
AES-GCMA3585
AES-GCMA3586
AES-GCMA3587
AES-KWA3576
AES-KWPA3576
DSA SigVer (FIPS186-4)A3575
DSA SigVer (FIPS186-4)A3584
DSA SigVer (FIPS186-4)A3588
ECDSA KeyGen (FIPS186-4)A3575
ECDSA KeyGen (FIPS186-4)A3584
ECDSA KeyGen (FIPS186-4)A3588
ECDSA KeyVer (FIPS186-4)A3575
ECDSA KeyVer (FIPS186-4)A3584
ECDSA KeyVer (FIPS186-4)A3588
ECDSA SigGen (FIPS186-4)A3575
ECDSA SigGen (FIPS186-4)A3584
ECDSA SigGen (FIPS186-4)A3588
ECDSA SigVer (FIPS186-4)A3575
ECDSA SigVer (FIPS186-4)A3584
ECDSA SigVer (FIPS186-4)A3588
Hash DRBGA3575
Hash DRBGA3582
Hash DRBGA3583
Hash DRBGA3584
Hash DRBGA3585
Hash DRBGA3586
Hash DRBGA3587
Hash DRBGA3588
HMAC-SHA-1A3575
HMAC-SHA-1A3588
HMAC-SHA2-224A3575
HMAC-SHA2-224A3584
HMAC-SHA2-224A3588
HMAC-SHA2-256A3575
HMAC-SHA2-256A3584
HMAC-SHA2-256A3588
HMAC-SHA2-384A3575
HMAC-SHA2-512A3575
KAS-ECC-SSC Sp800-56Ar3A3575
KAS-ECC-SSC Sp800-56Ar3A3584
KAS-ECC-SSC Sp800-56Ar3A3588
KAS-FFC-SSC Sp800-56Ar3A3575
KAS-FFC-SSC Sp800-56Ar3A3584
KAS-FFC-SSC Sp800-56Ar3A3588
KDA HKDF Sp800-56Cr1A3574
KDF IKEv1A3579
KDF IKEv2A3579
KDF SP800-108A3578
KDF TLSA3575
KDF TLSA3584
KDF TLSA3588
PBKDFA3575
PBKDFA3584
PBKDFA3588
RSA KeyGen (FIPS186-4)A3575
RSA KeyGen (FIPS186-4)A3584
RSA KeyGen (FIPS186-4)A3588
RSA SigGen (FIPS186-4)A3575
RSA SigGen (FIPS186-4)A3584
RSA SigGen (FIPS186-4)A3588
RSA SigVer (FIPS186-4)A3575
RSA SigVer (FIPS186-4)A3584
RSA SigVer (FIPS186-4)A3588
Safe Primes Key GenerationA3575
Safe Primes Key GenerationA3584
Safe Primes Key GenerationA3588
SHA-1A3575
SHA-1A3588
SHA2-224A3575
SHA2-224A3584
SHA2-224A3588
SHA2-256A3575
SHA2-256A3584
SHA2-256A3588
SHA2-384A3575
SHA2-512A3575
TLS v1.2 KDF RFC7627A3575
TLS v1.2 KDF RFC7627A3584
TLS v1.2 KDF RFC7627A3588

Tested configurations

  • SUSE Linux Enterprise Server 15 SP4 running on GIGABYTE G242-P32-QZ with ARM Ampere(R) Altra(R) Q80-30 processor with PAA
  • SUSE Linux Enterprise Server 15 SP4 running on GIGABYTE G242-P32-QZ with ARM Ampere(R) Altra(R) Q80-30 processor without PAA
  • SUSE Linux Enterprise Server 15 SP4 running on GIGABYTE R181-Z90-00 with AMD EPYC(TM) 7371 processor with PAA
  • SUSE Linux Enterprise Server 15 SP4 running on GIGABYTE R181-Z90-00 with AMD EPYC(TM) 7371 processor without PAA
  • SUSE Linux Enterprise Server 15 SP4 running on IBM z/15 with z15 processor with PAI
  • SUSE Linux Enterprise Server 15 SP4 running on IBM z/15 with z15 processor without PAI
  • SUSE Linux Enterprise Server 15 SP4 running on PowerVM (VIOS 3.1.4.00) running on IBM Power E1080 (9080-HEX) with Power10 processor with PAA
  • SUSE Linux Enterprise Server 15 SP4 running on PowerVM (VIOS 3.1.4.00) running on IBM Power E1080 (9080-HEX) with Power10 processor without PAA
  • SUSE Linux Enterprise Server 15 SP4 running on Supermicro Super Server SYS-6019P-WTR with Intel(R) Xeon(R) Silver 4215R processor with PAA
  • SUSE Linux Enterprise Server 15 SP4 running on Supermicro Super Server SYS-6019P-WTR with Intel(R) Xeon(R) Silver 4215R processor without PAA

Validation history

DateTypeLab
2024-07-17Initialatsec information security corporation

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-08-21: first observed by this tracker, status historical
  • Validation dates on record: 2024-07-17

Source documents