SUSE Linux Enterprise Server Libica Cryptographic Module

Certificate #4055

Webpage information

Status active
Validation dates 27.10.2021 , 28.11.2021
Sunset date 21-09-2026
Standard FIPS 140-2
Security level 1
Type Software-Hybrid
Embodiment Multi-Chip Stand Alone
Caveat When operated in FIPS mode and installed, initialized and configured as specified in Section 9.1 of the Security Policy with module SUSE Linux Enterprise Server OpenSSL Cryptographic Module validated to FIPS 140-2 under Cert. #3991 operating in FIPS mode
Exceptions
  • Mitigation of Other Attacks: N/A
Description The SUSE Linux Enterprise Server Libica Cryptographic Module contains the interface library routines used by IBM modules to interface with OpenSSL and the IBM Central Processor Assist for Cryptographic Functions (CPACF).
Version (Hardware) IBM z15
Version (Firmware) Feature Code 3863 (FC3863)
Tested configurations
  • SUSE Linux Enterprise Server 15 SP2 running on IBM System Z/15 with IBM z15 (single-user mode)
Vendor SUSE, LLC
References

This certificate's webpage directly references 1 certificates, transitively this expands into 1 certificates.

Security policy

Symmetric Algorithms
AES, DES, Triple-DES, TDES, TDEA, HMAC, HMAC-SHA-256, CMAC
Asymmetric Algorithms
ECDSA, ECC
Hash functions
SHA-1, SHA-224, SHA-256, SHA-384, SHA-512, SHA-2, SHA-3, SHA3-224, SHA3-256, SHA3-384, SHA3-512
Schemes
MAC, Key Exchange, Key Agreement
Protocols
SSH, TLS, IKE
Randomness
TRNG, DRBG, RNG
Libraries
OpenSSL
Elliptic Curves
P-192, P-256, P-384, P-521, P-224
Block cipher modes
ECB, CBC, CTR, CFB, OFB, GCM, CCM, XEX, XTS

Trusted Execution Environments
SSC

Security level
level 1, Level 1

Standards
FIPS 140-2, FIPS197, FIPS202, FIPS180-4, FIPS186-4, FIPS198-1, FIPS PUB 140-2, PKCS#1, RFC5246, RFC4253, RFC7296

File metadata

Title FIPS 140-2 Non-Proprietary Security Policy
Keywords FIPS 140-2
Author Traci Porter
Creation date D:20211123133539-06'00'
Pages 28
Creator Writer
Producer OpenOffice 4.1.10

References

Outgoing
  • 3991 - active - SUSE Linux Enterprise Server OpenSSL Cryptographic Module

Heuristics

No heuristics are available for this certificate.

References

Loading...

Updates Feed

  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate was first processed.

Raw data

{
  "_type": "sec_certs.sample.fips.FIPSCertificate",
  "cert_id": 4055,
  "dgst": "959d6171b513d014",
  "heuristics": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.Heuristics",
    "algorithms": {
      "_type": "Set",
      "elements": [
        "AES#A806",
        "RSA#A360",
        "HMAC#A360",
        "AES#A389",
        "DRBG#A491",
        "SHS#A389",
        "SHS#A491",
        "SHA-3#A389",
        "ECDSA#A360",
        "Triple-DES#A389",
        "KAS-SSC#A684"
      ]
    },
    "cpe_matches": null,
    "direct_transitive_cves": null,
    "extracted_versions": {
      "_type": "Set",
      "elements": [
        "3863"
      ]
    },
    "indirect_transitive_cves": null,
    "module_processed_references": {
      "_type": "sec_certs.sample.certificate.References",
      "directly_referenced_by": null,
      "directly_referencing": {
        "_type": "Set",
        "elements": [
          "3991"
        ]
      },
      "indirectly_referenced_by": null,
      "indirectly_referencing": {
        "_type": "Set",
        "elements": [
          "3991"
        ]
      }
    },
    "module_prunned_references": {
      "_type": "Set",
      "elements": [
        "3991"
      ]
    },
    "policy_processed_references": {
      "_type": "sec_certs.sample.certificate.References",
      "directly_referenced_by": null,
      "directly_referencing": {
        "_type": "Set",
        "elements": [
          "3991"
        ]
      },
      "indirectly_referenced_by": null,
      "indirectly_referencing": {
        "_type": "Set",
        "elements": [
          "3991"
        ]
      }
    },
    "policy_prunned_references": {
      "_type": "Set",
      "elements": [
        "3991"
      ]
    },
    "related_cves": null,
    "verified_cpe_matches": null
  },
  "pdf_data": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.PdfData",
    "keywords": {
      "asymmetric_crypto": {
        "ECC": {
          "ECC": {
            "ECC": 3
          },
          "ECDSA": {
            "ECDSA": 21
          }
        }
      },
      "certification_process": {},
      "cipher_mode": {
        "CBC": {
          "CBC": 5
        },
        "CCM": {
          "CCM": 5
        },
        "CFB": {
          "CFB": 2
        },
        "CTR": {
          "CTR": 7
        },
        "ECB": {
          "ECB": 5
        },
        "GCM": {
          "GCM": 4
        },
        "OFB": {
          "OFB": 4
        },
        "XEX": {
          "XEX": 1
        },
        "XTS": {
          "XTS": 8
        }
      },
      "cplc_data": {},
      "crypto_engine": {},
      "crypto_library": {
        "OpenSSL": {
          "OpenSSL": 23
        }
      },
      "crypto_protocol": {
        "IKE": {
          "IKE": 1
        },
        "SSH": {
          "SSH": 1
        },
        "TLS": {
          "TLS": {
            "TLS": 1
          }
        }
      },
      "crypto_scheme": {
        "KA": {
          "Key Agreement": 2
        },
        "KEX": {
          "Key Exchange": 1
        },
        "MAC": {
          "MAC": 7
        }
      },
      "device_model": {},
      "ecc_curve": {
        "NIST": {
          "P-192": 8,
          "P-224": 8,
          "P-256": 8,
          "P-384": 8,
          "P-521": 8
        }
      },
      "eval_facility": {
        "atsec": {
          "atsec": 30
        }
      },
      "fips_cert_id": {
        "Cert": {
          "#3991": 1
        }
      },
      "fips_certlike": {
        "Certlike": {
          "HMAC SHA-256 112": 1,
          "HMAC-SHA-256": 4,
          "PKCS#1": 2,
          "SHA- 512": 1,
          "SHA-1": 6,
          "SHA-2": 1,
          "SHA-224": 5,
          "SHA-256": 6,
          "SHA-3": 6,
          "SHA-384": 5,
          "SHA-512": 7,
          "SHA3-224": 2,
          "SHA3-256": 3,
          "SHA3-384": 3,
          "SHA3-512": 3
        }
      },
      "fips_security_level": {
        "Level": {
          "Level 1": 2,
          "level 1": 3
        }
      },
      "hash_function": {
        "SHA": {
          "SHA1": {
            "SHA-1": 6
          },
          "SHA2": {
            "SHA-2": 1,
            "SHA-224": 5,
            "SHA-256": 6,
            "SHA-384": 5,
            "SHA-512": 7
          },
          "SHA3": {
            "SHA-3": 6,
            "SHA3-224": 2,
            "SHA3-256": 3,
            "SHA3-384": 3,
            "SHA3-512": 3
          }
        }
      },
      "ic_data_group": {},
      "javacard_api_const": {},
      "javacard_packages": {},
      "javacard_version": {},
      "os_name": {},
      "pq_crypto": {},
      "randomness": {
        "PRNG": {
          "DRBG": 17
        },
        "RNG": {
          "RNG": 1
        },
        "TRNG": {
          "TRNG": 2
        }
      },
      "side_channel_analysis": {},
      "standard_id": {
        "FIPS": {
          "FIPS 140-2": 40,
          "FIPS PUB 140-2": 1,
          "FIPS180-4": 3,
          "FIPS186-4": 3,
          "FIPS197": 3,
          "FIPS198-1": 2,
          "FIPS202": 2
        },
        "PKCS": {
          "PKCS#1": 1
        },
        "RFC": {
          "RFC4253": 1,
          "RFC5246": 1,
          "RFC7296": 1
        }
      },
      "symmetric_crypto": {
        "AES_competition": {
          "AES": {
            "AES": 32
          }
        },
        "DES": {
          "3DES": {
            "TDEA": 1,
            "TDES": 1,
            "Triple-DES": 25
          },
          "DES": {
            "DES": 2
          }
        },
        "constructions": {
          "MAC": {
            "CMAC": 9,
            "HMAC": 9,
            "HMAC-SHA-256": 2
          }
        }
      },
      "tee_name": {
        "IBM": {
          "SSC": 1
        }
      },
      "tls_cipher_suite": {},
      "vendor": {},
      "vulnerability": {}
    },
    "policy_metadata": {
      "/Author": "Traci Porter",
      "/CreationDate": "D:20211123133539-06\u002700\u0027",
      "/Creator": "Writer",
      "/Keywords": "FIPS 140-2",
      "/Producer": "OpenOffice 4.1.10",
      "/Title": "FIPS 140-2 Non-Proprietary Security Policy",
      "pdf_file_size_bytes": 411862,
      "pdf_hyperlinks": {
        "_type": "Set",
        "elements": [
          "http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-38b.pdf",
          "https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-132.pdf",
          "http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-90Ar1.pdf",
          "http://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-38c.pdf",
          "http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-38F.pdf",
          "http://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.186-4.pdf",
          "http://csrc.nist.gov/groups/STM/cmvp/documents/fips140-2/FIPS1402IG.pdf",
          "http://csrc.nist.gov/publications/fips/fips140-2/fips1402.pdf",
          "https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.202.pdf",
          "http://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-67r1.pdf",
          "http://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-38a.pdf",
          "http://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-38e.pdf",
          "http://www.ietf.org/rfc/rfc3447.txt",
          "http://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-38d.pdf",
          "https://csrc.nist.gov/CSRC/media/projects/cryptographic-module-validation-program/documents/security-policies/140sp3991.pdf",
          "http://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.180-4.pdf",
          "http://csrc.nist.gov/publications/fips/fips197/fips-197.pdf",
          "http://csrc.nist.gov/publications/fips/fips198-1/FIPS-198-1_final.pdf",
          "http://csrc.nist.gov/",
          "https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-56Ar3.pdf"
        ]
      },
      "pdf_is_encrypted": false,
      "pdf_number_of_pages": 28
    }
  },
  "state": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.InternalState",
    "module_download_ok": true,
    "module_extract_ok": true,
    "policy_convert_ok": true,
    "policy_download_ok": true,
    "policy_extract_ok": true,
    "policy_json_hash": null,
    "policy_pdf_hash": "bcd16b04deb31cd0e65c9c1852986bf80d9da3084ab09c2114be9294c832b7a6",
    "policy_txt_hash": "a440e15d661b7979548d9281cc16e3bc455a45e55e7ba7a995f18ba73e2339da"
  },
  "web_data": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.WebData",
    "caveat": "When operated in FIPS mode and installed, initialized and configured as specified in Section 9.1 of the Security Policy with module SUSE Linux Enterprise Server OpenSSL Cryptographic Module validated to FIPS 140-2 under Cert. #3991 operating in FIPS mode",
    "certificate_pdf_url": "https://csrc.nist.gov/CSRC/media/projects/cryptographic-module-validation-program/documents/certificates/October 2021_011121_0730_signed.pdf",
    "date_sunset": "2026-09-21",
    "description": "The SUSE Linux Enterprise Server Libica Cryptographic Module contains the interface library routines used by IBM modules to interface with OpenSSL and the IBM Central Processor Assist for Cryptographic Functions (CPACF).",
    "embodiment": "Multi-Chip Stand Alone",
    "exceptions": [
      "Mitigation of Other Attacks: N/A"
    ],
    "fw_versions": "Feature Code 3863 (FC3863)",
    "historical_reason": null,
    "hw_versions": "IBM z15",
    "level": 1,
    "mentioned_certs": {
      "3991": 1
    },
    "module_name": "SUSE Linux Enterprise Server Libica Cryptographic Module",
    "module_type": "Software-Hybrid",
    "revoked_link": null,
    "revoked_reason": null,
    "standard": "FIPS 140-2",
    "status": "active",
    "sw_versions": "1.0",
    "tested_conf": [
      "SUSE Linux Enterprise Server 15 SP2 running on IBM System Z/15 with IBM z15 (single-user mode)"
    ],
    "validation_history": [
      {
        "_type": "sec_certs.sample.fips.FIPSCertificate.ValidationHistoryEntry",
        "date": "2021-10-27",
        "lab": "atsec information security corporation",
        "validation_type": "Initial"
      },
      {
        "_type": "sec_certs.sample.fips.FIPSCertificate.ValidationHistoryEntry",
        "date": "2021-11-28",
        "lab": "atsec information security corporation",
        "validation_type": "Update"
      }
    ],
    "vendor": "SUSE, LLC",
    "vendor_url": "http://www.suse.com"
  }
}