Apple OS X CoreCrypto Kernel Module v5.0
Certificate
| Certificate number | 2411 |
|---|---|
| Standard | FIPS 140-2 |
| Status | historical |
| Overall level | 1 |
| Module type | Software |
| Embodiment | Multi-chip standalone |
| Vendor | Apple Inc. · website |
| Software versions | 5.0 |
Module description
The Apple OS X CoreCrypto Kernel Module is a software cryptographic module running on a multi-chip standalone mobile device and provides services intended to protect data in transit and at rest.
Security level exceptions
- Physical Security: N/A
Approved algorithms
| Algorithm | CAVP certificate |
|---|---|
| AES | 3066, 3067, 3068, 3069, 3070, 3071, 3072, 3073, 3102, 3323, 3324, 3325, 3382, 3383, 3384, 3385 |
| DRBG | 598, 599, 600, 601, 602, 609, 769, 770, 771, 805, 806, 816 |
| ECDSA | 652, 653, 654, 673 |
| HMAC | 1927, 1928, 1929, 1930, 1960, 1961, 1962, 1963, 1964, 1965, 1966, 1967, 2114, 2115, 2116, 2155, 2156, 2157, 2158, 2159 |
| PBKDF | vendor affirmed |
| RSA | 1704, 1705, 1706, 1737 |
| SHS | 2543, 2544, 2545, 2546, 2579, 2580, 2581, 2582, 2583, 2584, 2585, 2586, 2755, 2756, 2757, 2800, 2801, 2802, 2803, 2804 |
| Triple-DES | 1895, 1896, 1897, 1921 |
Other algorithms
AES (non-compliant); AES-CMAC (non-compliant); RSA (key wrapping; key establishment methodology provides between 128 and 150 bits of encryption strength; non-compliant less than 112 bits of encryption strength); ECDSA (non-compliant); DES; Triple-DES (non-compliant); ANSI X9.63 KDF; RFC6637 KDF; KBKDF (non-Compliant); SP800-56C KDF; MD2; MD4; MD5; RIPEMD; ed25519; CAST5; Blowfish; RC2; RC4; OMAC; HMAC-DRBG (non-compliant); Hash-DRBG (non-compliant); Integrated Encryption Scheme on elliptic curves
Tested configurations
- OS X 10.10 running on iMac with i7 CPU with PAA
- OS X 10.10 running on iMac with i7 CPU without PAA
- OS X 10.10 running on Mac mini with i5 CPU with PAA
- OS X 10.10 running on Mac mini with i5 CPU without PAA
- OS X 10.10 running on MacBook with Core M CPU with PAA
- OS X 10.10 running on MacBook with Core M CPU without PAA (single-user mode)
- OS X 10.10 running on MacPro with Xeon CPU with PAA
- OS X 10.10 running on MacPro with Xeon CPU without PAA
Validation history
| Date | Type | Lab |
|---|---|---|
| 2015-07-22 | Initial | atsec information security corporation |
Status timeline
As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.
- 2026-08-21: first observed by this tracker, status historical
- Validation dates on record: 2015-07-22