Apple OS X CoreCrypto Module, v4.0

Certificate details

Certificate ID #2015
Status historical
Historical reason Moved to historical list due to sunsetting
Validation dates 07.11.2013
Standard FIPS 140-2
Security level 1
Type Software
Embodiment Multi-Chip Stand Alone
Caveat When operated in FIPS mode. The module generates cryptographic keys whose strengths are modified by available entropy
Description The Apple OS X CoreCrypto Module is a software cryptographic module running on a multi-chip standalone mobile device and provides services intended to protect data in transit and at rest.
Tested configurations
  • OS X 10.9 running on iMac with i7 CPU with PAA
  • OS X 10.9 running on iMac with i7 CPU without PAA (single-user mode)
  • OS X 10.9 running on Mac mini with i5 CPU with PAA
  • OS X 10.9 running on Mac mini with i5 CPU without PAA
Vendor [email protected]
References

This certificate's webpage directly references 0 certificates, transitively this expands into 0 certificates.

Security policy

Extracted keywords

Symmetric Algorithms
AES, AES-128, AES-192, AES-256, CAST5, RC4, RC2, DES, Triple-DES, Blowfish, HMAC, HMAC-SHA-224, HMAC-SHA-384, HMAC-SHA-256, HMAC-SHA-512
Asymmetric Algorithms
ECDSA, ECC, Diffie-Hellman, DH, DSA
Hash functions
SHA-1, SHA-224, SHA-384, SHA-512, SHA-256, SHA-2, MD4, MD5, RIPEMD, PBKDF
Schemes
MAC, Key Agreement, Key agreement
Protocols
TLS
Randomness
TRNG, DRBG, RNG
Elliptic Curves
P-256, P-384, P-192, P-224, P-521, curve P-384
Block cipher modes
ECB, CBC, CTR, CFB, OFB, GCM, XTS

Security level
level 1, Level 2

Cross-references

Incoming
  • 2471 - historical - SUSE Linux Enterprise Server 12 - OpenSSH Server Module
  • 2484 - historical - SUSE Linux Enterprise Server 12 - StrongSwan Cryptographic Module
  • 2472 - historical - SUSE Linux Enterprise Server 12 - OpenSSH Client Module

Automated analysis

Automated inference - use with caution

All attributes shown in this section (e.g., links between certificates, products, vendors, and known CVEs) are generated by automated heuristics and have not been reviewed by humans. These methods can produce false positives or false negatives and should not be treated as definitive without independent verification. This applies equally to the Cross-references section below. If you want to know more about how this data is computed and how reliable it is, see our documentation on automated analysis. If you believe any information here is inaccurate or harmful, please submit feedback.

No automatically derived data are available in this section.

Cross-references

Loading...

Processing updates

Feed
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate was first processed.

Raw data

{
  "_type": "sec_certs.sample.fips.FIPSCertificate",
  "cert_id": 2015,
  "dgst": "a85e9db4851f7cd3",
  "heuristics": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.Heuristics",
    "algorithms": {
      "_type": "Set",
      "elements": [
        "AES#2520",
        "HMAC#1560",
        "RSA#1293",
        "HMAC#1557",
        "HMAC#1556",
        "DRBG#365",
        "HMAC#1558",
        "RSA#1294",
        "AES#2027",
        "AES#2541",
        "HMAC#1555",
        "SHS#2136",
        "AES#2532",
        "Triple-DES#1535",
        "DRBG#368",
        "AES#2539",
        "SHS#2134",
        "HMAC#1561",
        "SHS#2130",
        "Triple-DES#1534",
        "DRBG#374",
        "ECDSA#433",
        "HMAC#1552",
        "SHS#2131",
        "AES#2523",
        "HMAC#1563",
        "AES#2536",
        "HMAC#1559",
        "DRBG#373",
        "SHS#2141",
        "DRBG#367",
        "DRBG#369",
        "HMAC#1554",
        "HMAC#1553",
        "SHS#2139",
        "Triple-DES#1536",
        "ECDSA#435",
        "DRBG#366",
        "SHS#2135",
        "AES#2519",
        "SHS#2132",
        "SHS#2138",
        "AES#2535",
        "AES#2540",
        "AES#2538",
        "SHS#2137",
        "DRBG#370",
        "AES#2521",
        "AES#2530",
        "RSA#1295",
        "AES#2524",
        "AES#2537",
        "AES#2529",
        "Triple-DES#1537",
        "RSA#1296",
        "ECDSA#434",
        "AES#2534",
        "DRBG#371",
        "DRBG#372",
        "DRBG#375",
        "DRBG#364",
        "AES#2528",
        "ECDSA#432",
        "AES#2533",
        "SHS#2140",
        "HMAC#1562",
        "SHS#2133",
        "AES#2531"
      ]
    },
    "cpe_matches": null,
    "direct_transitive_cves": null,
    "extracted_versions": {
      "_type": "Set",
      "elements": [
        "4.0"
      ]
    },
    "indirect_transitive_cves": null,
    "module_processed_references": {
      "_type": "sec_certs.sample.certificate.References",
      "directly_referenced_by": null,
      "directly_referencing": null,
      "indirectly_referenced_by": null,
      "indirectly_referencing": null
    },
    "module_prunned_references": {
      "_type": "Set",
      "elements": []
    },
    "policy_processed_references": {
      "_type": "sec_certs.sample.certificate.References",
      "directly_referenced_by": {
        "_type": "Set",
        "elements": [
          "2484",
          "2472",
          "2471"
        ]
      },
      "directly_referencing": null,
      "indirectly_referenced_by": {
        "_type": "Set",
        "elements": [
          "2472",
          "2471",
          "3099",
          "2484",
          "2549"
        ]
      },
      "indirectly_referencing": null
    },
    "policy_prunned_references": {
      "_type": "Set",
      "elements": []
    },
    "related_cves": null,
    "verified_cpe_matches": null
  },
  "pdf_data": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.PdfData",
    "keywords": {
      "asymmetric_crypto": {
        "ECC": {
          "ECC": {
            "ECC": 4
          },
          "ECDSA": {
            "ECDSA": 9
          }
        },
        "FF": {
          "DH": {
            "DH": 1,
            "Diffie-Hellman": 9
          },
          "DSA": {
            "DSA": 1
          }
        }
      },
      "certification_process": {},
      "cipher_mode": {
        "CBC": {
          "CBC": 10
        },
        "CFB": {
          "CFB": 1
        },
        "CTR": {
          "CTR": 5
        },
        "ECB": {
          "ECB": 6
        },
        "GCM": {
          "GCM": 5
        },
        "OFB": {
          "OFB": 5
        },
        "XTS": {
          "XTS": 5
        }
      },
      "cplc_data": {},
      "crypto_engine": {},
      "crypto_library": {},
      "crypto_protocol": {
        "TLS": {
          "TLS": {
            "TLS": 2
          }
        }
      },
      "crypto_scheme": {
        "KA": {
          "Key Agreement": 1,
          "Key agreement": 4
        },
        "MAC": {
          "MAC": 3
        }
      },
      "device_model": {},
      "ecc_curve": {
        "NIST": {
          "P-192": 8,
          "P-224": 8,
          "P-256": 12,
          "P-384": 15,
          "P-521": 8,
          "curve P-384": 1
        }
      },
      "eval_facility": {
        "atsec": {
          "atsec": 2
        }
      },
      "fips_cert_id": {},
      "fips_certlike": {
        "Certlike": {
          "AES-128": 2,
          "AES-192": 1,
          "AES-256": 1,
          "HMAC-SHA-1": 8,
          "HMAC-SHA-224": 2,
          "HMAC-SHA-256": 4,
          "HMAC-SHA-256 32": 4,
          "HMAC-SHA-384": 2,
          "HMAC-SHA-512": 2,
          "HMAC-SHA-512 1552": 2,
          "HMAC-SHA256": 2,
          "PKCS#1": 4,
          "PKCS1-v1_5": 1,
          "PKCS3": 2,
          "PKCS7": 2,
          "SHA- 256": 1,
          "SHA-1": 7,
          "SHA-2": 1,
          "SHA-224": 6,
          "SHA-256": 5,
          "SHA-384": 4,
          "SHA-512": 3,
          "SHA-512 32": 1
        }
      },
      "fips_security_level": {
        "Level": {
          "Level 2": 1,
          "level 1": 3
        }
      },
      "hash_function": {
        "MD": {
          "MD4": {
            "MD4": 1
          },
          "MD5": {
            "MD5": 1
          }
        },
        "PBKDF": {
          "PBKDF": 3
        },
        "RIPEMD": {
          "RIPEMD": 1
        },
        "SHA": {
          "SHA1": {
            "SHA-1": 7
          },
          "SHA2": {
            "SHA-2": 1,
            "SHA-224": 6,
            "SHA-256": 5,
            "SHA-384": 4,
            "SHA-512": 4
          }
        }
      },
      "ic_data_group": {},
      "javacard_api_const": {},
      "javacard_packages": {},
      "javacard_version": {},
      "os_name": {},
      "pq_crypto": {},
      "randomness": {
        "PRNG": {
          "DRBG": 8
        },
        "RNG": {
          "RNG": 3
        },
        "TRNG": {
          "TRNG": 2
        }
      },
      "side_channel_analysis": {},
      "standard_id": {
        "FIPS": {
          "FIPS 140-2": 20,
          "FIPS 180-3": 2,
          "FIPS 186-2": 1,
          "FIPS 197": 2,
          "FIPS 198": 1,
          "FIPS 46-3": 1,
          "FIPS PUB 140-2": 1
        },
        "NIST": {
          "NIST SP 800-90A": 1,
          "SP 800-132": 1,
          "SP 800-38": 3,
          "SP 800-38D": 1,
          "SP 800-56A": 2,
          "SP 800-67": 1,
          "SP 800-90A": 5
        },
        "PKCS": {
          "PKCS#1": 2,
          "PKCS3": 1,
          "PKCS7": 1
        }
      },
      "symmetric_crypto": {
        "AES_competition": {
          "AES": {
            "AES": 14,
            "AES-128": 2,
            "AES-192": 1,
            "AES-256": 1
          },
          "CAST": {
            "CAST5": 1
          },
          "RC": {
            "RC2": 1,
            "RC4": 1
          }
        },
        "DES": {
          "3DES": {
            "Triple-DES": 8
          },
          "DES": {
            "DES": 2
          }
        },
        "constructions": {
          "MAC": {
            "HMAC": 10,
            "HMAC-SHA-224": 4,
            "HMAC-SHA-256": 1,
            "HMAC-SHA-384": 2,
            "HMAC-SHA-512": 1
          }
        },
        "miscellaneous": {
          "Blowfish": {
            "Blowfish": 1
          }
        }
      },
      "tee_name": {},
      "tls_cipher_suite": {},
      "vendor": {},
      "vulnerability": {}
    },
    "policy_metadata": {
      "/Author": "Isabell Fouquet",
      "/CreationDate": "D:20131031164458-05\u002700\u0027",
      "/Creator": "Microsoft\u00ae Word 2010",
      "/Keywords": "FIPS 140-2, FSM",
      "/ModDate": "D:20131031164458-05\u002700\u0027",
      "/Producer": "Microsoft\u00ae Word 2010",
      "/Title": "FIPS 140-2 Non-Proprietary Security Policy",
      "pdf_file_size_bytes": 444402,
      "pdf_hyperlinks": {
        "_type": "Set",
        "elements": [
          "http://www.rsa.com/rsalabs/node.asp?id=2126",
          "http://www.rsa.com/rsalabs/node.asp?id=2129",
          "http://csrc.nist.gov/groups/STM/cmvp/standards.html",
          "http://csrc.nist.gov/groups/STM/cavp/index.html",
          "http://www.apple.com/",
          "http://csrc.nist.gov/groups/STM/cmvp/index.html"
        ]
      },
      "pdf_is_encrypted": false,
      "pdf_number_of_pages": 26
    }
  },
  "state": {
    "_type": "sec_certs.sample.fips.InternalState",
    "module": {
      "_type": "sec_certs.sample.document_state.DocumentState",
      "convert_ok": true,
      "download_ok": true,
      "extract_ok": true,
      "json_hash": null,
      "source_hash": null,
      "txt_hash": null
    },
    "policy": {
      "_type": "sec_certs.sample.document_state.DocumentState",
      "convert_ok": true,
      "download_ok": true,
      "extract_ok": true,
      "json_hash": null,
      "source_hash": "4feba101dc95bc6663fa73b74165a782d2cd886d098a844561854de6a6ae3dce",
      "txt_hash": "26484c64a0ff50923226e3b09929d23a24baa0e40d9d893d80a7bfc4e36fb72c"
    }
  },
  "web_data": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.WebData",
    "caveat": "When operated in FIPS mode. The module generates cryptographic keys whose strengths are modified by available entropy",
    "certificate_pdf_url": "https://csrc.nist.gov/CSRC/media/projects/cryptographic-module-validation-program/documents/certificates/FIPS140ConsolidatedCertList0035.pdf",
    "date_sunset": null,
    "description": "The Apple OS X CoreCrypto Module is a software cryptographic module running on a multi-chip standalone mobile device and provides services intended to protect data in transit and at rest.",
    "embodiment": "Multi-Chip Stand Alone",
    "exceptions": null,
    "fw_versions": null,
    "historical_reason": "Moved to historical list due to sunsetting",
    "hw_versions": null,
    "level": 1,
    "mentioned_certs": {},
    "module_name": "Apple OS X CoreCrypto Module, v4.0",
    "module_type": "Software",
    "revoked_link": null,
    "revoked_reason": null,
    "standard": "FIPS 140-2",
    "status": "historical",
    "sw_versions": "4.0",
    "tested_conf": [
      "OS X 10.9  running on iMac with i7 CPU with PAA",
      "OS X 10.9  running on iMac with i7 CPU without PAA (single-user mode)",
      "OS X 10.9  running on Mac mini with i5 CPU with PAA",
      "OS X 10.9  running on Mac mini with i5 CPU without PAA"
    ],
    "validation_history": [
      {
        "_type": "sec_certs.sample.fips.FIPSCertificate.ValidationHistoryEntry",
        "date": "2013-11-07",
        "lab": "atsec information security corporation",
        "validation_type": "Initial"
      }
    ],
    "vendor": "[email\u00a0protected]",
    "vendor_url": "/cdn-cgi/l/email-protection"
  }
}