IBM® z/OS® Version 2 Release 1 Security Server RACF® Signature Verification Module [1], IBM® z/OS® Version 2 Release 2 Security Server RACF® Signature Verification Module [2], IBM® z/OS® Version 2 Release 3 Security Server RACF® Signature Verification Module [3] and IBM® z/OS® Version 2 Release 4 Security Server RACF® Signature Verification Module [4][5]

Certificate #2691

Webpage information

Status active
Validation dates 28.07.2016 , 25.04.2017 , 09.05.2017 , 01.06.2017 , 31.10.2017 , 07.02.2019 , 19.02.2019 , 22.04.2020 , 08.09.2020 , 13.08.2021
Sunset date 12-08-2026
Standard FIPS 140-2
Security level 1
Type Software-Hybrid
Embodiment Multi-Chip Stand Alone
Caveat None
Exceptions
  • Mitigation of Other Attacks: N/A
Description The z/OS RACF Program Signature Verification package consists of the core module (IRRPVERS) that is utilized when verifying signed code as it is loaded as well as an auxiliary module responsible for driving the initialization of IRRPVERS. The RACF Program Signature Verification module consists of software-based cryptographic algorithms, as well as hashing algorithms provided by the CP Assist for Cryptographic Function (CPACF).
Version (Hardware) FC 3863 EC N98775 Drv 22H [1], FC 3863 EC P00339 Drv D27I [2], FC 3863 EC P42601 Drv D32L [3], FC 3863 EC P42601 Drv D32L [4] and FC 3863 EC P46601 D41C [5]
Tested configurations
  • IBM z/OS Version 2 Release 1 running on an IBM z13 [1]
  • IBM z/OS Version 2 Release 2 running on an IBM z13 [2]
  • IBM z/OS Version 2 Release 3 running on an IBM z14 [3]
  • IBM z/OS Version 2 Release 4 running on an IBM z14 [4]
  • IBM z/OS Version 2 Release 4 running on an IBM z15 [5] (single-user mode)
Vendor IBM® Corporation
References

This certificate's webpage directly references 0 certificates, transitively this expands into 0 certificates.

Security policy

Symmetric Algorithms
AES, DES
Asymmetric Algorithms
RSA 2048
Hash functions
SHA-256, SHA256

Security level
Level 1

Standards
FIPS 140-2, FIPS 180-4, PKCS #1

File metadata

Title IRRPVERS-FIPS-1.8-Security-Policy
Author Dick Sikkema
Creation date D:20210325175315Z00'00'
Modification date D:20210325175315Z00'00'
Pages 18
Creator Word
Producer macOS Version 10.14.6 (Build 18G8012) Quartz PDFContext

References

Incoming
  • 3919 - historical - IBM® z/OS® Version 2 Release 4 System SSL Cryptographic Module
  • 3924 - historical - IBM® z/OS® Version 2 Release 4 ICSF PKCS #11 Cryptographic Module
  • 2829 - historical - IBM® z/OS® Version 2 Release 1 System SSL Cryptographic Module
  • 3909 - historical - IBM® z/OS® Version 2 Release 4 ICSF PKCS #11 Cryptographic Module
  • 2763 - historical - IBM® z/OS® Version 2 Release 1 ICSF PKCS #11 Cryptographic Module
  • 3555 - historical - IBM® z/OS® Version 2 Release 3 ICSF PKCS #11 Cryptographic Module
  • 3557 - historical - IBM® z/OS® Version 2 Release 3 System SSL Cryptographic Module
  • 3057 - historical - IBM® z/OS® Version 2 Release 2 System SSL Cryptographic Module
  • 3019 - historical - IBM® z/OS® Version 2 Release 2 ICSF PKCS #11 Cryptographic Module
  • 4591 - active - IBM® z/OS® Version 2 Release 4 ICSF PKCS #11 Cryptographic Module
  • 4618 - active - IBM® z/OS® Version 2 Release 4 System SSL Cryptographic Module
  • 3937 - historical - IBM® z/OS® Version 2 Release 4 System SSL Cryptographic Module

Heuristics

No heuristics are available for this certificate.

References

Loading...

Updates Feed

  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate was first processed.

Raw data

{
  "_type": "sec_certs.sample.fips.FIPSCertificate",
  "cert_id": 2691,
  "dgst": "e2a424edff99af60",
  "heuristics": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.Heuristics",
    "algorithms": {
      "_type": "Set",
      "elements": [
        "SHS#3196",
        "RSA#C1634",
        "SHS#A389",
        "RSA#2283",
        "RSA#C219",
        "RSA#1979",
        "RSA#C1766",
        "SHS#C79",
        "SHS#3661"
      ]
    },
    "cpe_matches": null,
    "direct_transitive_cves": null,
    "extracted_versions": {
      "_type": "Set",
      "elements": [
        "1",
        "3",
        "3863",
        "5",
        "4",
        "2"
      ]
    },
    "indirect_transitive_cves": null,
    "module_processed_references": {
      "_type": "sec_certs.sample.certificate.References",
      "directly_referenced_by": {
        "_type": "Set",
        "elements": [
          "2763",
          "3919",
          "4591",
          "3909",
          "3937",
          "3019",
          "4618",
          "3555",
          "3557",
          "3057",
          "3924",
          "2829"
        ]
      },
      "directly_referencing": null,
      "indirectly_referenced_by": {
        "_type": "Set",
        "elements": [
          "2763",
          "3919",
          "4591",
          "3937",
          "3909",
          "3019",
          "4618",
          "3555",
          "3557",
          "3057",
          "3924",
          "2829"
        ]
      },
      "indirectly_referencing": null
    },
    "module_prunned_references": {
      "_type": "Set",
      "elements": []
    },
    "policy_processed_references": {
      "_type": "sec_certs.sample.certificate.References",
      "directly_referenced_by": {
        "_type": "Set",
        "elements": [
          "2763",
          "3919",
          "4591",
          "3909",
          "3937",
          "3019",
          "4618",
          "3555",
          "3557",
          "3057",
          "3924",
          "2829"
        ]
      },
      "directly_referencing": null,
      "indirectly_referenced_by": {
        "_type": "Set",
        "elements": [
          "2763",
          "3919",
          "4591",
          "3937",
          "3909",
          "3019",
          "4618",
          "3555",
          "3557",
          "3057",
          "3924",
          "2829"
        ]
      },
      "indirectly_referencing": null
    },
    "policy_prunned_references": {
      "_type": "Set",
      "elements": []
    },
    "related_cves": null,
    "verified_cpe_matches": null
  },
  "pdf_data": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.PdfData",
    "keywords": {
      "asymmetric_crypto": {
        "RSA": {
          "RSA 2048": 1
        }
      },
      "certification_process": {},
      "cipher_mode": {},
      "cplc_data": {},
      "crypto_engine": {},
      "crypto_library": {},
      "crypto_protocol": {},
      "crypto_scheme": {},
      "device_model": {},
      "ecc_curve": {},
      "eval_facility": {},
      "fips_cert_id": {
        "Cert": {
          "# 1": 2,
          "#1": 2,
          "#1979": 1,
          "#2283": 1,
          "#3196": 1,
          "#3661": 1
        }
      },
      "fips_certlike": {
        "Certlike": {
          "# C79": 1,
          "PKCS #1": 4,
          "RSA 2048": 1,
          "SHA- 256": 1,
          "SHA-256": 4,
          "SHA256": 1
        }
      },
      "fips_security_level": {
        "Level": {
          "Level 1": 2
        }
      },
      "hash_function": {
        "SHA": {
          "SHA2": {
            "SHA-256": 4,
            "SHA256": 1
          }
        }
      },
      "ic_data_group": {},
      "javacard_api_const": {},
      "javacard_packages": {},
      "javacard_version": {},
      "os_name": {},
      "pq_crypto": {},
      "randomness": {},
      "side_channel_analysis": {},
      "standard_id": {
        "FIPS": {
          "FIPS 140-2": 9,
          "FIPS 180-4": 1
        },
        "PKCS": {
          "PKCS #1": 2
        }
      },
      "symmetric_crypto": {
        "AES_competition": {
          "AES": {
            "AES": 1
          }
        },
        "DES": {
          "DES": {
            "DES": 1
          }
        }
      },
      "tee_name": {},
      "tls_cipher_suite": {},
      "vendor": {},
      "vulnerability": {}
    },
    "policy_metadata": {
      "/AAPL:Keywords": "[]",
      "/Author": "Dick Sikkema",
      "/CreationDate": "D:20210325175315Z00\u002700\u0027",
      "/Creator": "Word",
      "/Keywords": "",
      "/ModDate": "D:20210325175315Z00\u002700\u0027",
      "/Producer": "macOS Version 10.14.6 (Build 18G8012) Quartz PDFContext",
      "/Subject": "",
      "/Title": "IRRPVERS-FIPS-1.8-Security-Policy",
      "pdf_file_size_bytes": 1556351,
      "pdf_hyperlinks": {
        "_type": "Set",
        "elements": []
      },
      "pdf_is_encrypted": false,
      "pdf_number_of_pages": 18
    }
  },
  "state": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.InternalState",
    "module_download_ok": true,
    "module_extract_ok": true,
    "policy_convert_ok": true,
    "policy_download_ok": true,
    "policy_extract_ok": true,
    "policy_json_hash": null,
    "policy_pdf_hash": "0a431abd04c29235c2aeac24369e75ae0c1a8bbedee4aadc817ace96b9246599",
    "policy_txt_hash": "d98fccb39cc14ec33afe2bff3eac22f6bb2df286a6d22970581d8d55ddf1cbb8"
  },
  "web_data": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.WebData",
    "caveat": "None",
    "certificate_pdf_url": "https://csrc.nist.gov/CSRC/media/projects/cryptographic-module-validation-program/documents/certificates/FIPS140ConsolidatedCertJuly2016.pdf",
    "date_sunset": "2026-08-12",
    "description": "The z/OS RACF Program Signature Verification package consists of the core module (IRRPVERS) that is utilized when verifying signed code as it is loaded as well as an auxiliary module responsible for driving the initialization of IRRPVERS. The RACF Program Signature Verification module consists of software-based cryptographic algorithms, as well as hashing algorithms provided by the CP Assist for Cryptographic Function (CPACF).",
    "embodiment": "Multi-Chip Stand Alone",
    "exceptions": [
      "Mitigation of Other Attacks: N/A"
    ],
    "fw_versions": null,
    "historical_reason": null,
    "hw_versions": "FC 3863 EC N98775 Drv 22H [1], FC 3863 EC P00339 Drv D27I [2], FC 3863 EC P42601 Drv D32L [3], FC 3863 EC P42601 Drv D32L [4] and FC 3863 EC P46601 D41C [5]",
    "level": 1,
    "mentioned_certs": {},
    "module_name": "IBM\u00ae z/OS\u00ae Version 2 Release 1 Security Server RACF\u00ae Signature Verification Module [1], IBM\u00ae z/OS\u00ae Version 2 Release 2 Security Server RACF\u00ae Signature Verification Module [2], IBM\u00ae z/OS\u00ae Version 2 Release 3 Security Server RACF\u00ae Signature Verification Module [3] and IBM\u00ae z/OS\u00ae Version 2 Release 4 Security Server RACF\u00ae Signature Verification Module [4][5]",
    "module_type": "Software-Hybrid",
    "revoked_link": null,
    "revoked_reason": null,
    "standard": "FIPS 140-2",
    "status": "active",
    "sw_versions": "RACF level HRF7790 [1], RACF level HRF77A0 [2], RACF level HRF77B0 [3] and RACF level HRF77C0 [4][5]",
    "tested_conf": [
      "IBM z/OS Version 2 Release 1 running on an IBM z13 [1]",
      "IBM z/OS Version 2 Release 2 running on an IBM z13 [2]",
      "IBM z/OS Version 2 Release 3 running on an IBM z14 [3]",
      "IBM z/OS Version 2 Release 4 running on an IBM z14 [4]",
      "IBM z/OS Version 2 Release 4 running on an IBM z15 [5] (single-user mode)"
    ],
    "validation_history": [
      {
        "_type": "sec_certs.sample.fips.FIPSCertificate.ValidationHistoryEntry",
        "date": "2016-07-28",
        "lab": "atsec information security corporation",
        "validation_type": "Initial"
      },
      {
        "_type": "sec_certs.sample.fips.FIPSCertificate.ValidationHistoryEntry",
        "date": "2017-04-25",
        "lab": "atsec information security corporation",
        "validation_type": "Update"
      },
      {
        "_type": "sec_certs.sample.fips.FIPSCertificate.ValidationHistoryEntry",
        "date": "2017-05-09",
        "lab": "atsec information security corporation",
        "validation_type": "Update"
      },
      {
        "_type": "sec_certs.sample.fips.FIPSCertificate.ValidationHistoryEntry",
        "date": "2017-06-01",
        "lab": "atsec information security corporation",
        "validation_type": "Update"
      },
      {
        "_type": "sec_certs.sample.fips.FIPSCertificate.ValidationHistoryEntry",
        "date": "2017-10-31",
        "lab": "atsec information security corporation",
        "validation_type": "Update"
      },
      {
        "_type": "sec_certs.sample.fips.FIPSCertificate.ValidationHistoryEntry",
        "date": "2019-02-07",
        "lab": "atsec information security corporation",
        "validation_type": "Update"
      },
      {
        "_type": "sec_certs.sample.fips.FIPSCertificate.ValidationHistoryEntry",
        "date": "2019-02-19",
        "lab": "atsec information security corporation",
        "validation_type": "Update"
      },
      {
        "_type": "sec_certs.sample.fips.FIPSCertificate.ValidationHistoryEntry",
        "date": "2020-04-22",
        "lab": "atsec information security corporation",
        "validation_type": "Update"
      },
      {
        "_type": "sec_certs.sample.fips.FIPSCertificate.ValidationHistoryEntry",
        "date": "2020-09-08",
        "lab": "atsec information security corporation",
        "validation_type": "Update"
      },
      {
        "_type": "sec_certs.sample.fips.FIPSCertificate.ValidationHistoryEntry",
        "date": "2021-08-13",
        "lab": "atsec information security corporation",
        "validation_type": "Update"
      }
    ],
    "vendor": "IBM\u00ae Corporation",
    "vendor_url": "http://www.ibm.com"
  }
}