SUSE Linux Enterprise Libica Cryptographic Module
Caveat: Interim validation. When operated in approved mode with module SUSE Linux Enterprise OpenSSL Cryptographic Module validated to FIPS 140-3 under Cert. #4725 operating in approved mode. When installed, initialized and configured as specified in Section 11 of the Security Policy
Certificate
| Certificate number | 4822 |
|---|---|
| Standard | FIPS 140-3 |
| Status | active |
| Sunset date | 2029-10-06 |
| Overall level | 1 |
| Module type | Software-hybrid |
| Embodiment | Multi-Chip Stand Alone |
| Vendor | SUSE, LLC · website |
| Software versions | 1.1 |
| Hardware versions | IBM z15 |
Module description
The SUSE Linux Enterprise Server Libica Cryptographic Module is a software-hybrid module that provides general purpose cryptographic algorithms to applications running in the user space of the underlying operating system through a C language application program interface (API). The module is composed by a software library, which provides the API and a subset of the cryptographic algorithms, and the Central Processor Assist for Cryptographic Functions (CPACF), which is part of the z15 processor and provides cryptographic algorithms implemented in firmware and hardware.
Security level exceptions
- Non-invasive security: N/A
- Mitigation of other attacks: N/A
Approved algorithms
| Algorithm | CAVP certificate |
|---|---|
| AES-CBC | A3378 |
| AES-CBC-CS1 | A3378 |
| AES-CBC-CS2 | A3378 |
| AES-CBC-CS3 | A3378 |
| AES-CCM | A3378 |
| AES-CFB128 | A3378 |
| AES-CFB8 | A3378 |
| AES-CMAC | A3378 |
| AES-CTR | A3378 |
| AES-ECB | A3378 |
| AES-GCM | A3377 |
| AES-GCM | A3378 |
| AES-GMAC | A3377 |
| AES-GMAC | A3378 |
| AES-OFB | A3378 |
| AES-XTS Testing Revision 2.0 | A3378 |
| Counter DRBG | A3150 |
| ECDSA KeyGen (FIPS186-4) | A3147 |
| ECDSA SigGen (FIPS186-4) | A3378 |
| ECDSA SigVer (FIPS186-4) | A3378 |
| HMAC-SHA2-256 | A3147 |
| KAS-ECC-SSC Sp800-56Ar3 | A3378 |
| RSA KeyGen (FIPS186-4) | A3147 |
| SHA-1 | A3378 |
| SHA2-224 | A3378 |
| SHA2-256 | A3147 |
| SHA2-256 | A3378 |
| SHA2-384 | A3378 |
| SHA2-512 | A3378 |
| SHA2-512/224 | A3378 |
| SHA2-512/256 | A3378 |
| SHA3-224 | A3378 |
| SHA3-256 | A3378 |
| SHA3-384 | A3378 |
| SHA3-512 | A3378 |
| SHAKE-128 | A3378 |
| SHAKE-256 | A3378 |
Tested configurations
- SUSE Linux Enterprise Server 15 SP4 running on IBM z/15 with FC3863 with z15 with PAI
Validation history
| Date | Type | Lab |
|---|---|---|
| 2024-10-07 | Initial | atsec information security corporation |
Status timeline
As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.
- 2026-08-21: first observed by this tracker, status active
- Validation dates on record: 2024-10-07