inbuilt iOS VPN FedRamp Support

Replies

Here is the current list of FedRAMP vendors: https://marketplace.fedramp.gov/#!/products?sort=productName At the time of this posting, there are no Apple listings, and one sort-of VPN listed.

  • Thanks Hoffman!

    Does iOS VPN at least support the FedRAMP supported Cipher suite?

    Regards,

Add a Comment

FIPS 140-3 compliance status on current and upcoming macOS appears to be "no" or "not yet".

FedRAMP references FIPS 140-2 and FIPS 140-3 for this, so your question is closer to "Does the iOS, iPadOS, and Mac VPN support include the FIPS 140-2 / 140-3 cipher suite?" or maybe "Can the iOS, iPadOS, and Mac VPN support be restricted to include the FIPS 140-2 / 140-3 cipher suite?"

Some reading:

https://csrc.nist.gov/publications/detail/fips/140/2/final

Which leads to:

https://www.apple.com/mideast/business/docs/a/pdf/shared/macOS_Security_Overview.pdf

and

https://support.apple.com/guide/sccc/security-certifications-for-macos-sccc5eb3dc4fa/web

Which then leads to digging through the validation standards and the vendor review listings. (Which gets to be actual work.)

Have a look at what's posted at the above links and via DDG or other search engines, as you will still need perform that research and that comparison yourself, so that you'll have the details and the links to cite when the inevitable questions and citations arise, as there is an inevitable need to write reports and link to citations in most (all?) contexts involving references to FIPS and FedRAMP reviews.

Complicating all this, it appears there's a transition from FIPS 140-2 to FIPS 140-3 underway, and I don't yet see links to Apple certifications for 140-3 posted, with the last published FIPS 140-2 data was for macOS 10.15 Catalina. Didn't check iOS and iPadOS. Which then visits the "which part of what standard is required for compliance with whatever requirements are involved here" discussion around what you're actually researching and actually seeking compliance with; whether still being FIPS-ish or FIPS-compatible (but not (yet?) certified) is sufficient for your particular requirements, or whether your requirements expect current certifications for the versions intended. (Which looks to be "no" or "not yet" on macOS Big Sur and Monterey, and unknown on whether the features are present and compliant but not (yet?) reviewed, but I stopped digging.)