SUSE Certifications and Features

JUMP TO...

NIST Cryptographic Module Validation Program

The National Institute of Standards and Technology (NIST) developed the Federal Information Processing Standards (FIPS) FIPS 140-2, and now FIPS 140-3, that outlines the security requirements that must be satisfied by cryptographic modules, providing four increasing, qualitative levels intended to cover a wide range of potential applications and environments.

Many other industry standards like Defense Counterintelligence Security Agency (DCSA) and the Defense Information Systems Agency (DISA) Security Requirements Guides (SRGs) and Security Technical Implementation Guides (STIG) depend on FIPS 140-2 and FIPS 140-3 certified cryptography modules. The tests and requirements of FIPS 140-2 and FIPS 140-3 assure that the cryptographic modules that are validated comply with the latest standards, utilize the appropriate key lengths, and create correct cipher text and keys. The validation process confirms that the modules behave as defined.

The following modules are validated:

Tested Configuration FIPS 140-2 Modules Certificate Validation Date Sunset Date

SUSE Linux Enterprise Server 12 SP4

Kernel Crypto API

#4069

11/15/2021

09/21/2026

OpenSSL

#4070

11/15/2021

09/21/2026

SUSE Linux Enterprise Server 12 SP5

Kernel Crypto API

#4069

11/15/2021

09/21/2026

SUSE Linux Enterprise Server 15 SP2

Kernel Crypto API

#3962

06/30/2021 11/28/2021

06/29/2026

OpenSSL

#3991

07/22/2021 11/28/2021

07/21/2026

Libgcrypt

#3992

07/22/2021 11/28/2021

07/21/2026

Libica

#4055

10/27/2021 11/28/2021

10/26/2026 09/21/2026

Tested Configuration FIPS 140-3 Modules Certificate Validation Date Sunset Date

SUSE Linux Enterprise Server 15 SP4

Libgcrypt

#5420

07/07/2026

07/10/2029

OpenSSL

#5436

07/26/2026

07/11/2029

Kernel Crypto API

#4727

07/15/2024

07/14/2029

Mozilla-NSS

#5435

07/26/2026

07/16/2029

GnuTLS

#5419

07/09/2026

07/25/2029

Libica

#4822

10/07/2024

10/06/2029

SUSE Linux Enterprise Server 15 SP6

OpenSSL 3

#5096

11/26/2025

11/26/2030

Kernel Crypto API

#5112

12/18/2025

12/17/2030

Libcrypt

#5248

04/27/2026

04/26/2031

OpenSSL 1

#5238

04/10/2026

04/09/2031

GnuTLS

#5355

06/25/2026

06/24/2031

Validations may also be viewed at the NIST CMVP Validated Modules Page.

NIST CMVP Process for FIPS Validation and Updates, Patches, and CVEs

NIST has updated their site outlining the process for handling updates, patches, and CVEs for certified modules. You can read their statement at: https://csrc.nist.gov/Projects/cryptographic-module-validation-program/cmvp-flow in the section entitled "FIPS Validation and Updates, Patches, and CVEs".

NIST Cryptographic Module Validation Program - Modules In Process List

The following modules are in progress:

Module Name Standard Status

SUSE Linux Enterprise GnuTLS Cryptographic Module

FIPS 140-3

Comment Resolution - Lab (1/20/2026)

SUSE Linux Enterprise Kernel Crypto API Cryptographic Module

FIPS 140-3

Pending Review (5/26/2026)

SUSE Linux Enterprise Libica Cryptographic Module

FIPS 140-3

Comment Resolution - Lab (3/16/2026)

SUSE Linux Enterprise NSS Cryptographic Module

FIPS 140-3

Review (5/27/2026)

SUSE Linux Enterprise NSS Cryptographic Module

FIPS 140-3

Comment Resolution - Lab (1/26/2026)

SUSE Linux Enterprise GnuTLS Cryptographic Module

FIPS 140-3

Comment Resolution - Lab (6/12/2026)

SUSE Linux Enterprise Libgcrypt Cryptographic Module

FIPS 140-3

Comment Resolution - Lab (6/12/2026)

SUSE Linux Enterprise Libica Cryptographic Module

FIPS 140-3

Comment Resolution - Lab (6/16/2026)

SUSE Linux Enterprise OpenSSL Cryptographic Module

FIPS 140-3

Review (6/12/2026)

Modules in progress can also be viewed at the NIST CMVP Modules-In-Process Page.

NIST Cryptographic Algorithm Validation Program

The NIST Cryptographic Algorithm Validation Program (CAVP) provides validation testing of approved cryptographic algorithms and their various components. Cryptographic algorithm validation is a prerequisite of the NIST Cyptographic Module Validation Program.

The following algorithms are validated:

Tested Configuration Algorithm Certificate Validation Date

SUSE Linux Enterprise Server 15 SP4

Libica (Generic C)

1111

03/08/2023

L ibica (CPACF)

A3378

03/08/2023

NSS (64 bit) (TLSv1.3)

A3574

04/25/2023

NSS (64 bit)(Generic C)

A3575

04/25/2023

NSS (64 bit)(Generic C AES KW)

A3576

04/25/2023

NSS (64 bit)(Generic C AES CMAC)

A3577

04/25/2023

NSS (64 bit) (Generic C KBKDF)

A3578

04/25/2023

NSS (64 bit) (IKE_KDF)

A3579

04/25/2023

NSS (64 bit) (Generic C AES CTS)

A3580

04/25/2023

NSS (64 bit) (AESNI_AES)

A3581

04/25/2023

NSS (64 bit) (AESNI_AES_C_GHASH)

A3582

04/25/2023

NSS (64 bit) (C_AES_CLMUL_GHASH)

A3583

04/25/2023

NSS (64 bit) (AESNI_SHA)

A3584

04/25/2023

NSS (64 bit) (CE_AES)

A3585

04/25/2023

NSS (64 bit) (CE_AES_C_GHASH)

A3586

04/25/2023

NSS (64 bit) (C_AES_PLMUL_GHASH)

A3587

04/25/2023

NSS (64 bit) (CE_SHA)

A3588

04/25/2023

SUSE Linux Enterprise Server 15 SP6

GnuTLS (64 bit) (AESNI)

A6360

12/12/2024

GnuTLS (64 bit) (AESNI_PCLMUL)

A6361

12/12/2024

GnuTLS (64 bit) (AESNI_PCLMUL_AVX)

A6362

12/12/2024

GnuTLS (64 bit) (SSSE3)

A6363

12/12/2024

GnuTLS (64 bit) (SSSE3_SHA3)

A6364

12/12/2024

GnuTLS (64 bit) (SSSE3_CFB8_CMAC)

A6365

12/12/2024

GnuTLS (64 bit) (AESNI_CFB8_CMAC)

A6366

12/12/2024

GnuTLS (64 bit) (TLS v1.3)

A6367

12/12/2024

GnuTLS (64 bit) (Generic C)

A6368

12/12/2024

GnuTLS (64 bit) (Generic C XTS)

A6369

12/12/2024

GnuTLS (64 bit) (C_SHA3)

A6370

12/12/2024

GnuTLS (64 bit) (C_CFB8)

A6371

12/12/2024

GnuTLS (64 bit) (CE)

A6372

12/12/2024

GnuTLS (64 bit) (Generic C)

A6373

12/12/2024

GnuTLS (64 bit) (CPACF_AES)

A6374

12/12/2024

GnuTLS (64 bit) (CPACF_AES_C_GHASH)

A6375

12/12/2024

GnuTLS (64 bit) (CPACF_SHA)

A6376

12/12/2024

Libica (Generic C)

A6659

03/07/2025

Libica (CPACF)

A6660

03/07/2025

Libica (Generic C)

A6711

03/14/2025

Libica (CPACF)

A6712

03/14/2025

SUSE Linux Enterprise - Libgcrypt Cryptographic Module (AESNI AVX)

A6821

04/22/2025

SUSE Linux Enterprise - Libgcrypt Cryptographic Module (SSSE3)

A6822

04/22/2025

SUSE Linux Enterprise - Libgcrypt Cryptographic Module (SHLD)

A6823

04/22/2025

SUSE Linux Enterprise - Libgcrypt Cryptographic Module (Full Acceleration)

A6824

04/22/2025

SUSE Linux Enterprise - Libgcrypt Cryptographic Module (No Acceleration)

A6825

04/22/2025

SUSE Linux Enterprise - Libgcrypt Cryptographic Module (AESNI BMI2)

A6826

04/22/2025

SUSE Linux Enterprise - Libgcrypt Cryptographic Module (NEON)

A6827

04/22/2025

SUSE Rancher

SUSE Rancher Kubernetes Cryptographic Library

A6389

12/17/2024

More information on the NIST CAVP can be viewed at: https://csrc.nist.gov/projects/cryptographic-algorithm-validation-program.

Cloud Provider Packages

Amazon

suse-sles-15-sp2-chost-byos-v20201208-hvm-ssd-x86_64

Microsoft/Azure

suse-sles-15-sp2-chost-byos-v20201208-gen2

Google

sles-15-sp2-chost-byos-v20201208

Alibaba

sles-15-sp2-chost-byos-v20201208