808bits

Apple OS X CoreCrypto Module, v4.0

FIPS 140-2 certificate #2015 · Apple Inc. · data as of 2026-08-28
Historical. Moved to historical list due to sunsetting. Federal agencies may reference historical validations for existing systems only, not for new procurement.
Caveat: When operated in FIPS mode. The module generates cryptographic keys whose strengths are modified by available entropy

Certificate

Certificate number2015
StandardFIPS 140-2
Statushistorical
Overall level1
Module typeSoftware
EmbodimentMulti-chip standalone
VendorApple Inc.
Software versions4.0

Module description

The Apple OS X CoreCrypto Module is a software cryptographic module running on a multi-chip standalone mobile device and provides services intended to protect data in transit and at rest.

Approved algorithms

AlgorithmCAVP certificate
AES2519, 2520, 2521, 2523, 2524, 2027, 2528, 2529, 2530, 2531, 2532, 2533, 2534, 2535, 2536, 2537, 2538, 2539, 2540, 2541
DRBG364, 365, 366, 367, 368, 369, 370, 371, 372, 373, 374, 375
ECDSA432, 433, 434, 435
HMAC1552, 1553, 1554, 1555, 1556, 1557, 1558, 1559, 1560, 1561, 1562, 1563
PBKDFvendor affirmed
RSA1293, 1294, 1295, 1296
SHS2130, 2131, 2132, 2133, 2134, 2135, 2136, 2137, 2138, 2139, 2140, 2141
Triple-DES1534, 1535, 1536, 1537

Other algorithms

RSA (key wrapping; key establishment methodology provides between 112 and 150 bits of encryption strength; non-compliant less than 112 bits of encryption strength); Diffie-Hellman (key agreement; key establishment methodology provides between 112 and 150 bits of encryption strength; non-compliant less than 112 bits of encryption strength); EC Diffie-Hellman (key agreement; key establishment methodology provides 128 or 160 bits of encryption strength); ECDSA (P-192, P-224 and P-521; non-compliant); RSA (non-compliant); DES; MD2; MD4; MD5; CAST5; RIPEMD; Blowfish; BitGen1; BitGen2; BitGen3; RC2; RC4; OMAC

Tested configurations

  • OS X 10.9 running on iMac with i7 CPU with PAA
  • OS X 10.9 running on iMac with i7 CPU without PAA (single-user mode)
  • OS X 10.9 running on Mac mini with i5 CPU with PAA
  • OS X 10.9 running on Mac mini with i5 CPU without PAA

Validation history

DateTypeLab
2013-11-07Initialatsec information security corporation

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-08-21: first observed by this tracker, status historical
  • Validation dates on record: 2013-11-07

Source documents