808bits

Apple OS X CoreCrypto Module, v3.0

FIPS 140-2 certificate #1964 · Apple Inc. · data as of 2026-08-28
Historical. Moved to historical list due to sunsetting. Federal agencies may reference historical validations for existing systems only, not for new procurement.
Caveat: When operated in FIPS mode. The module generates cryptographic keys whose strengths are modified by available entropy

Certificate

Certificate number1964
StandardFIPS 140-2
Statushistorical
Overall level1
Module typeSoftware
EmbodimentMulti-chip standalone
VendorApple Inc. · website
Software versions3.0

Module description

The Apple OS X CoreCrypto Module is a software cryptographic module running on a multi-chip standalone mobile device and provides services intended to protect data in transit and at rest.

Approved algorithms

AlgorithmCAVP certificate
AES2088, 2089, 2090, 2091, 2092, 2093, 2094, 2095, 2103, 2104
DRBG217, 218, 219, 220, 226, 227
ECDSA312, 313
HMAC1267, 1268, 1269, 1270, 1278, 1279
PBKDFvendor affirmed
RSA1078, 1079
SHS1816, 1817, 1818, 1819, 1827, 1828
Triple-DES1339, 1340

Other algorithms

RSA (key wrapping; key establishment methodology provides between 112 and 150 bits of encryption strength; non-compliant less than 112 bits of encryption strength); RSA (non-compliant); Diffie-Hellman (key agreement; key establishment methodology provides between 112 and 150 bits of encryption strength; non-compliant less than 112 bits of encryption strength); EC Diffie-Hellman (key agreement; key establishment methodology provides 128 bits of encryption strength); ECDSA (P-192, P-224 and P-521; non-compliant); DES; MD2; MD4; MD5; CAST5; RIPEMD; Blowfish; BitGen1; BitGen2; BitGen3; RC2; RC4; OMAC (non-compliant)

Tested configurations

  • OS X 10.8 running on iMac with i7 CPU with PAA
  • OS X 10.8 running on iMac with i7 CPU without PAA (single-user mode)
  • OS X 10.8 running on Mac mini with i5 CPU with PAA
  • OS X 10.8 running on Mac mini with i5 CPU without PAA

Validation history

DateTypeLab
2013-06-14Initialatsec information security corporation

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-08-21: first observed by this tracker, status historical
  • Validation dates on record: 2013-06-14

Source documents