Apple corecrypto Module v12 [Intel, Kernel, Software]

Certificate details

Certificate ID #4956
Status active
Validation dates 30.01.2025
Sunset date 29-01-2027
Standard FIPS 140-3
Security level 1
Type Software
Embodiment Multi-Chip Stand Alone
Caveat Interim validation. When operated in approved mode. No assurance of minimum security of SSPs (e.g., keys, bit strings) that are externally loaded, or of SSPs established with externally loaded SSPs.
Exceptions
  • Physical security: N/A
  • Non-invasive security: N/A
  • Mitigation of other attacks: N/A
Description The Apple corecrypto Kernel module is a software cryptographic module running on a multi-chip standalone hardware device and provides services intended to protect data in transit and at rest.
Tested configurations
  • macOS Monterey 12 running on iMac Pro with Xeon W (Sky Lake) with PAA
  • macOS Monterey 12 running on iMac Pro with Xeon W (Sky Lake) without PAA
  • macOS Monterey 12 running on iMac with an Intel i5 (Comet Lake) with PAA
  • macOS Monterey 12 running on iMac with an Intel i5 (Comet Lake) without PAA
  • macOS Monterey 12 running on iMac with an Intel i7 (Comet Lake) with PAA
  • macOS Monterey 12 running on iMac with an Intel i7 (Comet Lake) without PAA
  • macOS Monterey 12 running on Mac Pro with Xeon W (Cascade Lake) with PAA
  • macOS Monterey 12 running on Mac Pro with Xeon W (Cascade Lake) without PAA (single-user mode)
  • macOS Monterey 12 running on MacBook Air with an Intel i5 (Amber Lake) with PAA
  • macOS Monterey 12 running on MacBook Air with an Intel i5 (Amber Lake) without PAA
  • macOS Monterey 12 running on MacBook Air with an Intel i7 (Ice Lake) with PAA
  • macOS Monterey 12 running on MacBook Air with an Intel i7 (Ice Lake) without PAA
  • macOS Monterey 12 running on MacBook Pro with an Intel i7 (Coffee Lake) with PAA
  • macOS Monterey 12 running on MacBook Pro with an Intel i7 (Coffee Lake) without PAA
  • macOS Monterey 12 running on MacBook Pro with an Intel i9 (Coffee Lake) with PAA
  • macOS Monterey 12 running on MacBook Pro with an Intel i9 (Coffee Lake) without PAA
Vendor Apple, Inc. http://www.apple.com
Lab Acumen Security
Algorithms
  • AES-CBCA2853
  • AES-CCMA2859
  • AES-CFB128A2853
  • AES-CFB8A2853
  • AES-CTRA2859
  • AES-ECBA2859
  • AES-GCMA2859
  • AES-KWA2853
  • AES-OFBA2853
  • AES-XTS Testing Revision 2.0A2851
  • Counter DRBGA2859
  • ECDSA KeyGen (FIPS186-4)A2856
  • ECDSA KeyVer (FIPS186-4)A2856
  • ECDSA SigGen (FIPS186-4)A2856
  • ECDSA SigVer (FIPS186-4)A2856
  • HMAC DRBGA2856
  • HMAC-SHA-1A2860
  • HMAC-SHA2-224A2860
  • HMAC-SHA2-256A2860
  • HMAC-SHA2-384A2860
  • HMAC-SHA2-512/256A2856
  • HMAC-SHA2-512A2860
  • KDF SP800-108A2856
  • RSA KeyGen (FIPS186-4)A2856
  • RSA SigGen (FIPS186-4)A2856
  • RSA SigVer (FIPS186-4)A2856
  • SHA-1A2860
  • SHA2-224A2860
  • SHA2-256A2860
  • SHA2-384A2860
  • SHA2-512/256A2856
  • SHA2-512A2860
References

This certificate's webpage directly references 0 certificates, transitively this expands into 0 certificates.

Security policy

Extracted keywords

Symmetric Algorithms
AES-128, AES-256, AES, CAST5, CAST, RC4, RC2, DES, Triple-DES, Blowfish, HMAC
Asymmetric Algorithms
RSA 2048, ECDSA, ECIES
Hash functions
SHA-1, MD4, MD5, RIPEMD
Schemes
MAC, Key Agreement
Protocols
TLS, IKE, IPsec
Randomness
DRBG
Elliptic Curves
P-224, P-256, P-521, Curve P-192, curve P-192, P-384, P-512, P-192, Ed25519
Block cipher modes
ECB, CBC, CTR, OFB, GCM, CCM, XTS

Security level
Level 1, level 1

Automated analysis

Automated inference - use with caution

All attributes shown in this section (e.g., links between certificates, products, vendors, and known CVEs) are generated by automated heuristics and have not been reviewed by humans. These methods can produce false positives or false negatives and should not be treated as definitive without independent verification. This applies equally to the Cross-references section below. If you want to know more about how this data is computed and how reliable it is, see our documentation on automated analysis. If you believe any information here is inaccurate or harmful, please submit feedback.

No automatically derived data are available in this section.

Cross-references

No references are available for this certificate.

Processing updates

Feed
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate was first processed.

Raw data

{
  "_type": "sec_certs.sample.fips.FIPSCertificate",
  "cert_id": 4956,
  "dgst": "2e18e12a751bac81",
  "heuristics": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.Heuristics",
    "algorithms": {
      "_type": "Set",
      "elements": [
        "HMAC-SHA2-224A2860",
        "AES-XTS Testing Revision 2.0A2851",
        "HMAC-SHA2-512A2860",
        "#A2854",
        "HMAC DRBGA2856",
        "HMAC-SHA2-512/256A2856",
        "SHA2-512A2860",
        "#A2853",
        "#A2850",
        "Counter DRBGA2859",
        "#A2858",
        "SHA2-256A2860",
        "RSA SigVer (FIPS186-4)A2856",
        "ECDSA SigVer (FIPS186-4)A2856",
        "AES-CTRA2859",
        "#A2851",
        "#A2855",
        "AES-CFB128A2853",
        "SHA2-384A2860",
        "ECDSA SigGen (FIPS186-4)A2856",
        "AES-OFBA2853",
        "ECDSA KeyGen (FIPS186-4)A2856",
        "SHA2-512/256A2856",
        "AES-CFB8A2853",
        "#A2852",
        "ECDSA KeyVer (FIPS186-4)A2856",
        "KDF SP800-108A2856",
        "HMAC-SHA-1A2860",
        "#A2856",
        "#A2860",
        "AES-GCMA2859",
        "HMAC-SHA2-384A2860",
        "SHA-1A2860",
        "AES-KWA2853",
        "SHA2-224A2860",
        "AES-ECBA2859",
        "#A2859",
        "AES-CCMA2859",
        "RSA SigGen (FIPS186-4)A2856",
        "HMAC-SHA2-256A2860",
        "AES-CBCA2853",
        "RSA KeyGen (FIPS186-4)A2856"
      ]
    },
    "cpe_matches": null,
    "direct_transitive_cves": null,
    "extracted_versions": {
      "_type": "Set",
      "elements": [
        "-"
      ]
    },
    "indirect_transitive_cves": null,
    "module_processed_references": {
      "_type": "sec_certs.sample.certificate.References",
      "directly_referenced_by": null,
      "directly_referencing": null,
      "indirectly_referenced_by": null,
      "indirectly_referencing": null
    },
    "module_prunned_references": {
      "_type": "Set",
      "elements": []
    },
    "policy_processed_references": {
      "_type": "sec_certs.sample.certificate.References",
      "directly_referenced_by": null,
      "directly_referencing": null,
      "indirectly_referenced_by": null,
      "indirectly_referencing": null
    },
    "policy_prunned_references": {
      "_type": "Set",
      "elements": []
    },
    "related_cves": null,
    "verified_cpe_matches": null
  },
  "pdf_data": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.PdfData",
    "br1_deviations": 32,
    "br1_tables": null,
    "is_br1_format": false,
    "keywords": {
      "asymmetric_crypto": {
        "ECC": {
          "ECDSA": {
            "ECDSA": 25
          },
          "ECIES": {
            "ECIES": 4
          }
        },
        "RSA": {
          "RSA 2048": 2
        }
      },
      "certification_process": {},
      "cipher_mode": {
        "CBC": {
          "CBC": 8
        },
        "CCM": {
          "CCM": 4
        },
        "CTR": {
          "CTR": 3
        },
        "ECB": {
          "ECB": 7
        },
        "GCM": {
          "GCM": 7
        },
        "OFB": {
          "OFB": 1
        },
        "XTS": {
          "XTS": 5
        }
      },
      "cplc_data": {},
      "crypto_engine": {},
      "crypto_library": {},
      "crypto_protocol": {
        "IKE": {
          "IKE": 1
        },
        "IPsec": {
          "IPsec": 2
        },
        "TLS": {
          "TLS": {
            "TLS": 1
          }
        }
      },
      "crypto_scheme": {
        "KA": {
          "Key Agreement": 2
        },
        "MAC": {
          "MAC": 6
        }
      },
      "device_model": {},
      "ecc_curve": {
        "Edwards": {
          "Ed25519": 7
        },
        "NIST": {
          "Curve P-192": 4,
          "P-192": 5,
          "P-224": 12,
          "P-256": 8,
          "P-384": 2,
          "P-512": 2,
          "P-521": 4,
          "curve P-192": 1
        }
      },
      "eval_facility": {
        "Acumen": {
          "Acumen Security": 1
        }
      },
      "fips_cert_id": {},
      "fips_certlike": {
        "Certlike": {
          "# A2854": 4,
          "AES CBC 128": 2,
          "AES GCM 128": 2,
          "AES-128": 2,
          "AES-256": 3,
          "HMAC- SHA-1": 1,
          "HMAC-SHA-1": 8,
          "PKCS#1": 14,
          "RSA 2048": 2,
          "SHA-1": 15,
          "SHA2- 224": 2,
          "SHA2- 256": 4,
          "SHA2- 284": 6,
          "SHA2- 512": 1,
          "SHA2-224": 15,
          "SHA2-256": 19,
          "SHA2-284": 1,
          "SHA2-384": 10,
          "SHA2-512": 16
        }
      },
      "fips_security_level": {
        "Level": {
          "Level 1": 2,
          "level 1": 2
        }
      },
      "hash_function": {
        "MD": {
          "MD4": {
            "MD4": 2
          },
          "MD5": {
            "MD5": 1
          }
        },
        "RIPEMD": {
          "RIPEMD": 2
        },
        "SHA": {
          "SHA1": {
            "SHA-1": 15
          }
        }
      },
      "ic_data_group": {},
      "javacard_api_const": {},
      "javacard_packages": {},
      "javacard_version": {},
      "os_name": {},
      "pq_crypto": {},
      "randomness": {
        "PRNG": {
          "DRBG": 17
        }
      },
      "side_channel_analysis": {},
      "standard_id": {
        "FIPS": {
          "FIPS 140-3": 13,
          "FIPS 180-4": 1,
          "FIPS 186-4": 2,
          "FIPS 198": 1,
          "FIPS PUB 140-3": 1,
          "FIPS186-4": 2
        },
        "ISO": {
          "ISO/IEC 19790": 4,
          "ISO/IEC 24759": 2
        },
        "NIST": {
          "NIST SP 800-140B": 2,
          "NIST SP 800-140F": 1,
          "NIST SP 800-90B": 2,
          "SP 800-38D": 1,
          "SP 800-90B": 1
        },
        "PKCS": {
          "PKCS#1": 7
        },
        "RFC": {
          "RFC 4106": 1,
          "RFC6637": 2
        }
      },
      "symmetric_crypto": {
        "AES_competition": {
          "AES": {
            "AES": 24,
            "AES-128": 2,
            "AES-256": 3
          },
          "CAST": {
            "CAST": 3,
            "CAST5": 2
          },
          "RC": {
            "RC2": 2,
            "RC4": 2
          }
        },
        "DES": {
          "3DES": {
            "Triple-DES": 4
          },
          "DES": {
            "DES": 3
          }
        },
        "constructions": {
          "MAC": {
            "HMAC": 12
          }
        },
        "miscellaneous": {
          "Blowfish": {
            "Blowfish": 2
          }
        }
      },
      "tee_name": {},
      "tls_cipher_suite": {},
      "vendor": {},
      "vulnerability": {}
    },
    "module_algorithms": {
      "_type": "Set",
      "elements": [
        "HMAC-SHA2-224A2860",
        "AES-XTS Testing Revision 2.0A2851",
        "HMAC-SHA2-512A2860",
        "HMAC DRBGA2856",
        "HMAC-SHA2-512/256A2856",
        "SHA2-512A2860",
        "Counter DRBGA2859",
        "SHA2-256A2860",
        "RSA SigVer (FIPS186-4)A2856",
        "ECDSA SigVer (FIPS186-4)A2856",
        "AES-CTRA2859",
        "AES-CFB128A2853",
        "SHA2-384A2860",
        "ECDSA SigGen (FIPS186-4)A2856",
        "AES-OFBA2853",
        "ECDSA KeyGen (FIPS186-4)A2856",
        "SHA2-512/256A2856",
        "AES-CFB8A2853",
        "ECDSA KeyVer (FIPS186-4)A2856",
        "KDF SP800-108A2856",
        "HMAC-SHA-1A2860",
        "AES-GCMA2859",
        "HMAC-SHA2-384A2860",
        "SHA-1A2860",
        "AES-KWA2853",
        "SHA2-224A2860",
        "AES-ECBA2859",
        "AES-CCMA2859",
        "RSA SigGen (FIPS186-4)A2856",
        "HMAC-SHA2-256A2860",
        "AES-CBCA2853",
        "RSA KeyGen (FIPS186-4)A2856"
      ]
    },
    "policy_algorithms": {
      "_type": "Set",
      "elements": [
        "#A2858",
        "#A2852",
        "#A2854",
        "#A2851",
        "#A2855",
        "#A2859",
        "#A2856",
        "#A2860",
        "#A2853",
        "#A2850"
      ]
    },
    "policy_metadata": {
      "/Author": "Aniket Ingle  Intertek",
      "/ClassificationContentMarkingFooterFontProps": "#000000,7,Calibri",
      "/ClassificationContentMarkingFooterShapeIds": "2,4,5",
      "/ClassificationContentMarkingFooterText": "Juniper Business Use Only",
      "/Comments": "",
      "/Company": "",
      "/ContentTypeId": "0x0101005FC48ADBEA28F14BA352723A969D8CBC",
      "/CreationDate": "D:20250115171742+05\u002730\u0027",
      "/Creator": "Acrobat PDFMaker 24 for Word",
      "/Keywords": "",
      "/MSIP_Label_0633b888-ae0d-4341-a75f-06e04137d755_ActionId": "10f4ee9b-e3a9-4cc7-88d2-2f42364a5831",
      "/MSIP_Label_0633b888-ae0d-4341-a75f-06e04137d755_ContentBits": "2",
      "/MSIP_Label_0633b888-ae0d-4341-a75f-06e04137d755_Enabled": "true",
      "/MSIP_Label_0633b888-ae0d-4341-a75f-06e04137d755_Method": "Standard",
      "/MSIP_Label_0633b888-ae0d-4341-a75f-06e04137d755_Name": "0633b888-ae0d-4341-a75f-06e04137d755",
      "/MSIP_Label_0633b888-ae0d-4341-a75f-06e04137d755_SetDate": "2022-11-30T05:04:04Z",
      "/MSIP_Label_0633b888-ae0d-4341-a75f-06e04137d755_SiteId": "bea78b3c-4cdb-4130-854a-1d193232e5f4",
      "/ModDate": "D:20250115171810+05\u002730\u0027",
      "/Producer": "Adobe PDF Library 24.4.48",
      "/SourceModified": "D:20250115101912",
      "/Subject": "",
      "/Title": "",
      "/_DocHome": "318573247",
      "pdf_file_size_bytes": 688847,
      "pdf_hyperlinks": {
        "_type": "Set",
        "elements": [
          "http://www.apple.com/legal/intellectual-",
          "https://www.acumensecurity.net/"
        ]
      },
      "pdf_is_encrypted": false,
      "pdf_number_of_pages": 40
    }
  },
  "state": {
    "_type": "sec_certs.sample.fips.InternalState",
    "module": {
      "_type": "sec_certs.sample.document_state.DocumentState",
      "convert_ok": true,
      "download_ok": true,
      "extract_ok": true,
      "json_hash": null,
      "source_hash": null,
      "txt_hash": null
    },
    "policy": {
      "_type": "sec_certs.sample.document_state.DocumentState",
      "convert_ok": true,
      "download_ok": true,
      "extract_ok": true,
      "json_hash": "b0a4c6c767b6e4d22c76b87ddfb4bbb9c3bcef55832d28124ad8df7a0182c642",
      "source_hash": "ed9eb3a86b86831834e632fd6b6071da20ea217f2513f54fcba0a34f1ae83ccc",
      "txt_hash": "db865dffd0e5f729fbbdbe943ac03bbd841c026ed8b5ffc8150f7cba6676680e"
    }
  },
  "web_data": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.WebData",
    "caveat": "Interim validation. When operated in approved mode. No assurance of minimum security of SSPs (e.g., keys, bit strings) that are externally loaded, or of SSPs established with externally loaded SSPs.",
    "certificate_pdf_url": "https://csrc.nist.gov/CSRC/media/projects/cryptographic-module-validation-program/documents/certificates/January 2025-signed.pdf",
    "date_sunset": "2027-01-29",
    "description": "The Apple corecrypto Kernel module is a software cryptographic module running on a multi-chip standalone hardware device and provides services intended to protect data in transit and at rest.",
    "embodiment": "Multi-Chip Stand Alone",
    "exceptions": [
      "Physical security: N/A",
      "Non-invasive security: N/A",
      "Mitigation of other attacks: N/A"
    ],
    "fw_versions": null,
    "historical_reason": null,
    "hw_versions": null,
    "level": 1,
    "mentioned_certs": {},
    "module_name": "Apple corecrypto Module v12 [Intel, Kernel, Software]",
    "module_type": "Software",
    "revoked_link": null,
    "revoked_reason": null,
    "standard": "FIPS 140-3",
    "status": "active",
    "sw_versions": "12",
    "tested_conf": [
      "macOS Monterey 12 running on iMac Pro with Xeon W (Sky Lake) with PAA",
      "macOS Monterey 12 running on iMac Pro with Xeon W (Sky Lake) without PAA",
      "macOS Monterey 12 running on iMac with an Intel i5 (Comet Lake) with PAA",
      "macOS Monterey 12 running on iMac with an Intel i5 (Comet Lake) without PAA",
      "macOS Monterey 12 running on iMac with an Intel i7 (Comet Lake) with PAA",
      "macOS Monterey 12 running on iMac with an Intel i7 (Comet Lake) without PAA",
      "macOS Monterey 12 running on Mac Pro with Xeon W (Cascade Lake) with PAA",
      "macOS Monterey 12 running on Mac Pro with Xeon W (Cascade Lake) without PAA (single-user mode)",
      "macOS Monterey 12 running on MacBook Air with an Intel i5 (Amber Lake) with PAA",
      "macOS Monterey 12 running on MacBook Air with an Intel i5 (Amber Lake) without PAA",
      "macOS Monterey 12 running on MacBook Air with an Intel i7 (Ice Lake) with PAA",
      "macOS Monterey 12 running on MacBook Air with an Intel i7 (Ice Lake) without PAA",
      "macOS Monterey 12 running on MacBook Pro with an Intel i7 (Coffee Lake) with PAA",
      "macOS Monterey 12 running on MacBook Pro with an Intel i7 (Coffee Lake) without PAA",
      "macOS Monterey 12 running on MacBook Pro with an Intel i9 (Coffee Lake) with PAA",
      "macOS Monterey 12 running on MacBook Pro with an Intel i9 (Coffee Lake) without PAA"
    ],
    "validation_history": [
      {
        "_type": "sec_certs.sample.fips.FIPSCertificate.ValidationHistoryEntry",
        "date": "2025-01-30",
        "lab": "Acumen Security",
        "validation_type": "Initial"
      }
    ],
    "vendor": "Apple, Inc.",
    "vendor_url": "http://www.apple.com"
  }
}