808bits

IBM® Crypto for C

FIPS 140-3 certificate #4755 · IBM Corporation · data as of 2026-09-03

IBM® Crypto for C, from IBM Corporation, holds FIPS 140-3 certificate #4755 at overall level 1. The validation is historical: agencies may keep the module in existing systems but not buy it new. Below are its validation history, algorithm certificates and security policy, drawn from the NIST CMVP entry.

Historical. Replaced by certificate #5486. Federal agencies may reference historical validations for existing systems only, not for new procurement.
Caveat: Interim validation. When operated in the approved mode. When installed, initialized and configured as specified in sections 11.1 and 11.2 of the Security Policy

Certificate

Certificate number4755
StandardFIPS 140-3
Statushistorical
Overall level1
Module typeSoftware
EmbodimentMulti-Chip Stand Alone
VendorIBM Corporation · website
Software versions8.8.1.0

Module description

Quoted from the NIST CMVP entry for this certificate.

The IBM Crypto for C version 8.8.1.0 (ICC) cryptographic module is implemented in the C programming language. It is packaged as dynamic (shared) libraries usable by applications written in a language that supports C language linking conventions (e.g. C, C++, Java, Assembler, etc.) for use on commercially available operating systems. The ICC allows these applications to access cryptographic functions using an Application Programming Interface (API) provided through an ICC import library and based on the API defined by the OpenSSL group.

Security level exceptions

  • Physical security: N/A
  • Non-invasive security: N/A
  • Mitigation of other attacks: N/A

Approved algorithms (45)

AlgorithmCAVP certificates
AES-CBCA2619, A2620
AES-CCMA2619, A2620
AES-CFB1A2619, A2620
AES-CFB128A2619, A2620
AES-CFB8A2619, A2620
AES-CMACA2619, A2620
AES-CTRA2619, A2620
AES-ECBA2619, A2620
AES-GCMA2619, A2620
AES-KWA2619, A2620
AES-KWPA2619, A2620
AES-OFBA2619, A2620
AES-XTS Testing Revision 2.0A2619, A2620
Counter DRBGA2619, A2620
DSA SigVer (FIPS186-4)A2619, A2620
ECDSA KeyGen (FIPS186-4)A2619, A2620
ECDSA KeyVer (FIPS186-4)A2619, A2620
ECDSA SigGen (FIPS186-4)A2619, A2620
ECDSA SigVer (FIPS186-4)A2619, A2620
Hash DRBGA2619, A2620
HMAC DRBGA2619, A2620
HMAC-SHA2-224A2619, A2620
HMAC-SHA2-256A2619, A2620
HMAC-SHA2-384A2619, A2620
HMAC-SHA2-512A2619, A2620
HMAC-SHA3-224A2619, A2620
HMAC-SHA3-256A2619, A2620
HMAC-SHA3-384A2619, A2620
HMAC-SHA3-512A2619, A2620
KAS-ECC-SSC Sp800-56Ar3A2619, A2620
KAS-FFC-SSC Sp800-56Ar3A2619, A2620
KDA HKDF Sp800-56Cr1A2619, A2620
PBKDFA2619, A2620
RSA KeyGen (FIPS186-4)A2619, A2620
RSA SigGen (FIPS186-4)A2619, A2620
RSA SigVer (FIPS186-4)A2619, A2620
Safe Primes Key GenerationA2619, A2620
SHA2-224A2619, A2620
SHA2-256A2619, A2620
SHA2-384A2619, A2620
SHA2-512A2619, A2620
SHA3-224A2619, A2620
SHA3-256A2619, A2620
SHA3-384A2619, A2620
SHA3-512A2619, A2620

Tested configurations

  • IBM AIX 7.2 64-bit (Big Endian) on IBM PowerVM 3.1 running on IBM Power System S914 (9009-41A) with IBM POWER9 with PAA
  • IBM AIX 7.2 64-bit (Big Endian) on IBM PowerVM 3.1 running on IBM Power System S914 (9009-41A) with IBM POWER9 without PAA
  • IBM z/OS 2.3 on IBM z/VM 7.2 running on IBM z15 (8561 T01) with IBM z15 with PAI
  • IBM z/OS 2.3 on IBM z/VM 7.2 running on IBM z15 (8561 T01) with IBM z15 without PAI
  • Microsoft Windows Server 2019 64-bit on Lenovo ThinkSystem SR630 with Intel Xeon® Gold 5217 with PAA
  • Microsoft Windows Server 2019 64-bit on Lenovo ThinkSystem SR630 with Intel Xeon® Gold 5217 without PAA
  • Red Hat Linux Enterprise Server 7.9 64-bit (Big Endian) on IBM PowerVM 3.1 running on IBM Power System S914 (9009-41A) with IBM POWER9 with PAA
  • Red Hat Linux Enterprise Server 7.9 64-bit (Big Endian) on IBM PowerVM 3.1 running on IBM Power System S914 (9009-41A) with IBM POWER9 without PAA
  • Red Hat Linux Enterprise Server 8.4 64-bit (Little Endian) on IBM PowerVM 3.1 running on IBM Power System S914 (9009-41A) with IBM POWER9 with PAA
  • Red Hat Linux Enterprise Server 8.4 64-bit (Little Endian) on IBM PowerVM 3.1 running on IBM Power System S914 (9009-41A) with IBM POWER9 without PAA
  • Red Hat Linux Enterprise Server 8.4 64-bit (Little Endian) on Lenovo ThinkSystem SR630 with Intel Xeon® Gold 5217 with PAA
  • Red Hat Linux Enterprise Server 8.4 64-bit (Little Endian) on Lenovo ThinkSystem SR630 with Intel Xeon® Gold 5217 without PAA
  • zLinux Red Hat Linux Enterprise Server 8.6 64-bit (Big Endian) on IBM z/VM 7.2 running on IBM z15 (8561 T01) with IBM z15 with PAI
  • zLinux Red Hat Linux Enterprise Server 8.6 64-bit (Big Endian) on IBM z/VM 7.2 running on IBM z15 (8561 T01) with IBM z15 without PAI

Validation history

DateTypeLab
2024-08-09Initialatsec information security corporation

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-08-21: first observed by this tracker, status historical
  • Validation dates on record: 2024-08-09

Source documents