808bits

SUSE Linux Enterprise GnuTLS Cryptographic Module

FIPS 140-3 certificate #4742 · SUSE, LLC · data as of 2026-09-15

SUSE Linux Enterprise GnuTLS Cryptographic Module, from SUSE, LLC, holds FIPS 140-3 certificate #4742 at overall level 1. The validation is historical: agencies may keep the module in existing systems but not buy it new. Below are its validation history, algorithm certificates and security policy, drawn from the NIST CMVP entry.

Historical. Replaced by certificate #5419. Federal agencies may reference historical validations for existing systems only, not for new procurement.
Caveat: Interim validation. When operated in approved mode. When installed, initialized and configured as specified in Section 11 of the Security Policy

Certificate

Certificate number4742
StandardFIPS 140-3
Statushistorical
Overall level1
Module typeSoftware
EmbodimentMulti-Chip Stand Alone
VendorSUSE, LLC · website
Software versions1.1

Module description

Quoted from the NIST CMVP entry for this certificate.

GnuTLS is a secure communications library implementing the TLS protocol. It provides a simple C language application programming interface to access the secure communications protocols as well as APIs to parse and write X.509, PKCS#12, and other required structures which is shipped with SUSE Linux Enterprise.

Security level exceptions

  • Physical security: N/A
  • Non-invasive security: N/A
  • Mitigation of other attacks: N/A

Approved algorithms (36)

AlgorithmCAVP certificates
AES-CBCA2984, A2985, A2986, A2987, A2992, A2996, A2997, A3004, A3007
AES-CCMA2984, A2996, A3004, A3007
AES-CFB8A2989, A2990, A2995
AES-CMACA2984, A2987, A2992, A2996, A3004
AES-GCMA2984, A2985, A2986, A2987, A2992, A2996, A2997, A3004, A3007
AES-GMACA2992
AES-XTS Testing Revision 2.0A2993
Counter DRBGA2992
ECDSA KeyGen (FIPS186-4)A2992
ECDSA KeyVer (FIPS186-4)A2992
ECDSA SigGen (FIPS186-4)A2992
ECDSA SigVer (FIPS186-4)A2992
HMAC-SHA-1A2987, A2992, A2998, A3007
HMAC-SHA2-224A2987, A2992, A2998, A3007
HMAC-SHA2-256A2987, A2992, A2998, A3007
HMAC-SHA2-384A2987, A2992, A2998, A3007
HMAC-SHA2-512A2987, A2992, A2998, A3007
KAS-ECC-SSC Sp800-56Ar3A2992
KAS-FFC-SSC Sp800-56Ar3A2992
KDA HKDF Sp800-56Cr1A2991
KDF TLSA2992
PBKDFA2992
RSA KeyGen (FIPS186-4)A2992
RSA SigGen (FIPS186-4)A2992
RSA SigVer (FIPS186-4)A2992
Safe Primes Key GenerationA2992
SHA-1A2987, A2992, A2998, A3007
SHA2-224A2987, A2992, A2998, A3007
SHA2-256A2987, A2992, A2998, A3007
SHA2-384A2987, A2992, A2998, A3007
SHA2-512A2987, A2992, A2998, A3007
SHA3-224A2988, A2994
SHA3-256A2988, A2994
SHA3-384A2988, A2994
SHA3-512A2988, A2994
TLS v1.2 KDF RFC7627A2992

Tested configurations

  • SUSE Linux Enterprise Server 15 SP4 on PowerVM (VIOS 3.1.4.00) running on IBM Power E1080 (9080-HEX) with Power10 with PAA
  • SUSE Linux Enterprise Server 15 SP4 on PowerVM (VIOS 3.1.4.00) running on IBM Power E1080 (9080-HEX) with Power10 without PAA
  • SUSE Linux Enterprise Server 15 SP4 running on GIGABYTE G242-P32-QZ with ARM Ampere(R) Altra(R) Q80-30 with PAA
  • SUSE Linux Enterprise Server 15 SP4 running on GIGABYTE G242-P32-QZ with ARM Ampere(R) Altra(R) Q80-30 without PAA
  • SUSE Linux Enterprise Server 15 SP4 running on GIGABYTE R181-Z90-00 with AMD EPYC(TM) 7371 with PAA
  • SUSE Linux Enterprise Server 15 SP4 running on GIGABYTE R181-Z90-00 with AMD EPYC(TM) 7371 without PAA
  • SUSE Linux Enterprise Server 15 SP4 running on IBM z/15 with z15 with PAI
  • SUSE Linux Enterprise Server 15 SP4 running on IBM z/15 with z15 without PAI
  • SUSE Linux Enterprise Server 15 SP4 running on Supermicro Super Server SYS-6019P-WTR with Intel(R) Xeon(R) Silver 4215R with PAA
  • SUSE Linux Enterprise Server 15 SP4 running on Supermicro Super Server SYS-6019P-WTR with Intel(R) Xeon(R) Silver 4215R without PAA

Validation history

DateTypeLab
2024-07-26Initialatsec information security corporation

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-08-21: first observed by this tracker, status historical
  • Validation dates on record: 2024-07-26

Source documents