808bits

Apple OS X CoreCrypto Kernel Module v6.0

FIPS 140-2 certificate #2597 · Apple Inc. · data as of 2026-08-28
Historical. Moved to historical list due to sunsetting. Federal agencies may reference historical validations for existing systems only, not for new procurement.
Caveat: When operated in FIPS mode. The module generates cryptographic keys whose strengths are modified by available entropy

Certificate

Certificate number2597
StandardFIPS 140-2
Statushistorical
Overall level1
Module typeSoftware
EmbodimentMulti-Chip Stand Alone
VendorApple Inc. · website
Software versions6.0

Module description

The Apple OS X CoreCrypto Kernel Module is a software cryptographic module running on a multi-chip standalone mobile device and provides services intended to protect data in transit and at rest.

Security level exceptions

  • Physical Security: N/A

Approved algorithms

AlgorithmCAVP certificate
AES3781, 3782, 3783, 3784, 3785, 3786, 3787, 3788, 3789, 3790, 3791, 3792, 3793, 3794, 3795, 3796
DRBG1047, 1048, 1049, 1050, 1051, 1052, 1053, 1054, 1055, 1056, 1057, 1058
ECDSA816, 817, 818, 819
HMAC2358, 2359, 2360, 2361, 2362, 2363, 2364, 2365, 2366, 2367, 2368, 2369, 2370, 2371, 2372, 2373, 2475, 2476, 2477, 2478
KTS
PBKDFvendor affirmed
RSA1949, 1950, 1951, 1952
SHS3024, 3025, 3026, 3027, 3028, 3029, 3030, 3031, 3032, 3033, 3034, 3035, 3036, 3037, 3038, 3039, 3148, 3149, 3150, 3151
Triple-DES2102, 2103, 2104, 2105

Other algorithms

AES (non-compliant); AES-CMAC (non-compliant); ANSI X9.63 KDF; Blowfish; CAST5; DES; ECDSA (non-compliant); Ed25519; Hash_DRBG (non-compliant); HMAC_DRBG (non-compliant); Integrated Encryption Scheme on elliptic curves; KBKDF (non-compliant); MD2; MD4; MD5; OMAC; RC2; RC4; RFC6637 KDF; RIPEMD; RSA (key wrapping; key establishment methodology provides between 128 and 150 bits of encryption strength; non-compliant less than 112 bits of encryption strength); SP800-56C KDF; Triple-DES (non-compliant)

Tested configurations

  • OS X El Capitan v10.11 running on iMac with i7 CPU with PAA
  • OS X El Capitan v10.11 running on iMac with i7 CPU without PAA
  • OS X El Capitan v10.11 running on Mac mini with i5 CPU with PAA
  • OS X El Capitan v10.11 running on Mac mini with i5 CPU without PAA
  • OS X El Capitan v10.11 running on MacBook with Core M CPU with PAA
  • OS X El Capitan v10.11 running on MacBook with Core M CPU without PAA (single-user mode)
  • OS X El Capitan v10.11 running on MacPro with Xeon CPU with PAA
  • OS X El Capitan v10.11 running on MacPro with Xeon CPU without PAA

Validation history

DateTypeLab
2016-03-29Initialatsec information security corporation
2021-03-11Updateatsec information security corporation

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-08-21: first observed by this tracker, status historical
  • Validation dates on record: 2016-03-29, 2021-03-11

Source documents