808bits

Apple OS X CoreCrypto Kernel Module v5.0

FIPS 140-2 certificate #2411 · Apple Inc. · data as of 2026-08-28
Historical. Moved to historical list due to sunsetting. Federal agencies may reference historical validations for existing systems only, not for new procurement.
Caveat: When operated in FIPS mode. The module generates cryptographic keys whose strengths are modified by available entropy

Certificate

Certificate number2411
StandardFIPS 140-2
Statushistorical
Overall level1
Module typeSoftware
EmbodimentMulti-chip standalone
VendorApple Inc. · website
Software versions5.0

Module description

The Apple OS X CoreCrypto Kernel Module is a software cryptographic module running on a multi-chip standalone mobile device and provides services intended to protect data in transit and at rest.

Security level exceptions

  • Physical Security: N/A

Approved algorithms

AlgorithmCAVP certificate
AES3066, 3067, 3068, 3069, 3070, 3071, 3072, 3073, 3102, 3323, 3324, 3325, 3382, 3383, 3384, 3385
DRBG598, 599, 600, 601, 602, 609, 769, 770, 771, 805, 806, 816
ECDSA652, 653, 654, 673
HMAC1927, 1928, 1929, 1930, 1960, 1961, 1962, 1963, 1964, 1965, 1966, 1967, 2114, 2115, 2116, 2155, 2156, 2157, 2158, 2159
PBKDFvendor affirmed
RSA1704, 1705, 1706, 1737
SHS2543, 2544, 2545, 2546, 2579, 2580, 2581, 2582, 2583, 2584, 2585, 2586, 2755, 2756, 2757, 2800, 2801, 2802, 2803, 2804
Triple-DES1895, 1896, 1897, 1921

Other algorithms

AES (non-compliant); AES-CMAC (non-compliant); RSA (key wrapping; key establishment methodology provides between 128 and 150 bits of encryption strength; non-compliant less than 112 bits of encryption strength); ECDSA (non-compliant); DES; Triple-DES (non-compliant); ANSI X9.63 KDF; RFC6637 KDF; KBKDF (non-Compliant); SP800-56C KDF; MD2; MD4; MD5; RIPEMD; ed25519; CAST5; Blowfish; RC2; RC4; OMAC; HMAC-DRBG (non-compliant); Hash-DRBG (non-compliant); Integrated Encryption Scheme on elliptic curves

Tested configurations

  • OS X 10.10 running on iMac with i7 CPU with PAA
  • OS X 10.10 running on iMac with i7 CPU without PAA
  • OS X 10.10 running on Mac mini with i5 CPU with PAA
  • OS X 10.10 running on Mac mini with i5 CPU without PAA
  • OS X 10.10 running on MacBook with Core M CPU with PAA
  • OS X 10.10 running on MacBook with Core M CPU without PAA (single-user mode)
  • OS X 10.10 running on MacPro with Xeon CPU with PAA
  • OS X 10.10 running on MacPro with Xeon CPU without PAA

Validation history

DateTypeLab
2015-07-22Initialatsec information security corporation

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-08-21: first observed by this tracker, status historical
  • Validation dates on record: 2015-07-22

Source documents