808bits

SUSE Linux Enterprise Libica Cryptographic Module

FIPS 140-3 certificate #4822 · SUSE, LLC · data as of 2026-08-28
Active. Sunset date 2029-10-06, 1134 days away.
Caveat: Interim validation. When operated in approved mode with module SUSE Linux Enterprise OpenSSL Cryptographic Module validated to FIPS 140-3 under Cert. #4725 operating in approved mode. When installed, initialized and configured as specified in Section 11 of the Security Policy

Certificate

Certificate number4822
StandardFIPS 140-3
Statusactive
Sunset date2029-10-06
Overall level1
Module typeSoftware-hybrid
EmbodimentMulti-Chip Stand Alone
VendorSUSE, LLC · website
Software versions1.1
Hardware versionsIBM z15

Module description

The SUSE Linux Enterprise Server Libica Cryptographic Module is a software-hybrid module that provides general purpose cryptographic algorithms to applications running in the user space of the underlying operating system through a C language application program interface (API). The module is composed by a software library, which provides the API and a subset of the cryptographic algorithms, and the Central Processor Assist for Cryptographic Functions (CPACF), which is part of the z15 processor and provides cryptographic algorithms implemented in firmware and hardware.

Security level exceptions

  • Non-invasive security: N/A
  • Mitigation of other attacks: N/A

Approved algorithms

AlgorithmCAVP certificate
AES-CBCA3378
AES-CBC-CS1A3378
AES-CBC-CS2A3378
AES-CBC-CS3A3378
AES-CCMA3378
AES-CFB128A3378
AES-CFB8A3378
AES-CMACA3378
AES-CTRA3378
AES-ECBA3378
AES-GCMA3377
AES-GCMA3378
AES-GMACA3377
AES-GMACA3378
AES-OFBA3378
AES-XTS Testing Revision 2.0A3378
Counter DRBGA3150
ECDSA KeyGen (FIPS186-4)A3147
ECDSA SigGen (FIPS186-4)A3378
ECDSA SigVer (FIPS186-4)A3378
HMAC-SHA2-256A3147
KAS-ECC-SSC Sp800-56Ar3A3378
RSA KeyGen (FIPS186-4)A3147
SHA-1A3378
SHA2-224A3378
SHA2-256A3147
SHA2-256A3378
SHA2-384A3378
SHA2-512A3378
SHA2-512/224A3378
SHA2-512/256A3378
SHA3-224A3378
SHA3-256A3378
SHA3-384A3378
SHA3-512A3378
SHAKE-128A3378
SHAKE-256A3378

Tested configurations

  • SUSE Linux Enterprise Server 15 SP4 running on IBM z/15 with FC3863 with z15 with PAI

Validation history

DateTypeLab
2024-10-07Initialatsec information security corporation

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-08-21: first observed by this tracker, status active
  • Validation dates on record: 2024-10-07

Source documents