Apple macOS 11 Big Sur: Contacts Common Criteria Configuration Guide

VID: 11243

Document Version: 1.0

Date: January 2022

Prepared for:
Apple
One Apple Park Way
Cupertino, CA 95014

Prepared by:
Intertek Acumen Security
2400 Research Blvd
Suite 395
Rockville, MD 20850

Revision History

VersionDateChanges
1.0January 2022Released for Check-Out

Trademarks

Apple's trademarks applicable to this document are listed in https://www.apple.com/legal/intellectual-property/trademark/appletmlist.html

Other company, product, and service names may be trademarks or service marks of others.

Introduction

This guide provides instructions to configure and operate Apple macOS 11 Big Sur: Contacts in the Common Criteria evaluated configuration.

Target of Evaluation

The evaluated application is the Apple macOS 11 Big Sur: Contacts application, hereafter referred to as "Contacts". Contacts is bundled with the Apple macOS 11 Big Sur operating system. Contacts provides access and management of user contact information. Contacts was evaluated on the following physical devices:

Model NameMarketing NameModel IdentifierProcessorSecurity Chip
MacBook Air (Retina, 13-inch, 2018)A1932MacBookAir8,1Intel Core i5 8210YApple T2
MacBook Air (Retina, 13-inch, Mid 2019)A1932MacBookAir8,2Intel Core i5 8210YApple T2
MacBook Air (Retina, 13-inch, 2020)A2179MacBookAir9,1Intel Core i5 1030NG7
Intel Core i7 1060NG7
Apple T2
MacBook AirA2337MacBookAir10,1Apple M1
MacBook Pro (15-inch, 2018)A1990MacBookPro15,1Intel Core i7 8750H
Intel Core i7 8850H
Intel Core i9 8950HK
Apple T2
MacBook Pro (15-inch, 2019)A1990MacBookPro15,1Intel Core i7 9750H
Intel Core i7 9880H
Intel Core i9 9980HK
Apple T2
MacBook Pro (13-inch, 2018, Four Thunderbolt 3 Ports)A1989MacBookPro15,2Intel Core i5 8259U
Intel Core i7 8559U
Apple T2
MacBook Pro (13-inch, 2019, Four Thunderbolt 3 Ports)A1989MacBookPro15,2Intel Core i5 8279U
Intel Core i7 8569U
Apple T2
MacBook Pro (15-inch, 2018) +Vega graphicsA1990MacBookPro15,3Intel Core i7 8750H
Intel Core i7 8850H
Intel Core i9 8950HK
Apple T2
MacBook Pro (15-inch, 2019) +Vega graphicsA1990MacBookPro15,3Intel Core i7 9750H
Intel Core i7 9880H
Intel Core i9 9980HK
Apple T2
MacBook Pro (13-inch, 2019, 2-port)A2159MacBookPro15,4Intel Core i5 8257U
Intel Core i7 8557U
Apple T2
MacBook Pro (16-inch, 2019)A2141MacBookPro16,1Intel Core i7 9750H
Intel Core i9 9880H
Intel Core i9 9980HK
Apple T2
MacBook Pro (13-inch, 2020 Four Thunderbolt 3 ports)A2251MacBookPro16,2Intel Core i5 1038NG7
Intel Core i7 1068NG7
Apple T2
MacBook Pro (13-inch, 2020 Two Thunderbolt 3 ports)A2289MacBookPro16,3Intel Core i5 8257U
Intel Core i7 8557U
Apple T2
MacBook Pro (16-inch, 2019) 5600MA2141MacBookPro16,4Intel Core i7 9750H
Intel Core i9 9880H
Intel Core i9 9980HK
Apple T2
MacBook Pro (13-Inch, M1, 2020)A2338MacBookPro17,1Apple M1
Model NameMarketing NameModel IdentifierProcessorSecurity Chip
Mac mini (Late 2018)A1993Macmini8,1Intel Core i5 8500B
Intel Core i7 8700B
Apple T2
Mac miniA2348Macmini9,1Apple M1
iMac (Retina 5K, 27-inch, 2019)A2115iMac19,1Intel Core i5 8500
Intel Core i5 8600
Intel Core i5 9600K
Intel Core i9 9900K
Apple T2
iMac (Retina 4K, 21.5-inch, 2019)A2116iMac19,2Intel Core i5 8500
Intel Core i7 8700
Apple T2
iMac 27-inch (5K,2020) 5700 XT / Navi10)A2115iMac20,1Intel Core i5 10500
Intel Core i5 10600
Intel Core i7 10700K
Intel Core i9 10910
Apple T2
iMac 27-inch (5K,2020; 5700 XT / Navi10)A2115iMac20,2Intel Core i7 10700K
Intel Core i9 10910
Apple T2
iMac Pro (2017)A1862iMacPro1,1Intel Xeon W-2140B
Intel Xeon W-2150B
Intel Xeon W-2170B
Intel Xeon W-2190B
Apple T2
Mac Pro (2019)A1991MacPro7,1Intel Xeon W-3223
Intel Xeon W-3235
Intel Xeon W-3245
Intel Xeon W-3265M
Intel Xeon W-3275M
Apple T2
Mac Pro (2019 Rack)A2304MacPro7,1Intel Xeon W-3223
Intel Xeon W-3235
Intel Xeon W-3245
Intel Xeon W-3265M
Intel Xeon W-3275M
Apple T2

Contacts was tested on version 11.4 of Apple macOS 11 Big Sur.

Document Purpose and Scope

This document describes the installation and Common Criteria evaluation related usage of Apple macOS 11 Big Sur: Contacts on MacBook Air, MacBook Pro, Mac mini, iMac, iMac Pro, and Mac Pro devices. Contacts and the underlying platform must be configured as described in this document to satisfy the requirements of Protection Profile for Application Software, Version 1.3.

Installation/Update

Contacts is loaded by default on macOS 11 Big Sur. Contacts cannot be deleted.

Checking the Version

The version of Contacts can be verified using the following steps:

  1. Open Contacts
  2. Choose Contacts menu > About Contacts

An example of this version verification can be found in Figure 1. Note that the Version field indicates version 13.0.

Figure 1 - Contacts Version Verification: A screenshot of the macOS Contacts application's 'About Contacts' window, displaying 'Version 13.0 (2452.7)' and copyright information.

Software Identification

The software identity of Contacts can be verified by inspecting the Info.plist file in Contacts (i.e., Contacts.app/Content/Info.plist) and verifying the following:

Installing Updates

Updates to Contacts are distributed with updates to macOS. Updates can be checked for and installed using the following steps:

  1. Choose Apple menu > About This Mac
  2. Click Software Update...
  3. MacOS will display "Checking for updates..."
  4. If any updates are available, macOS will list the updates and provide an Install Now or Upgrade Now option.

Reinstall macOS

You can use macOS Recovery, the built-in recovery system on your Mac, to reinstall macOS. macOS Recovery keeps your files and user settings intact when reinstalling.

  1. Start up your computer in macOS Recovery:
    • On a Mac with Apple silicon: Choose Apple menu > Shut Down, press and hold the power button until "Loading startup options" appears, select Options, click Continue, then follow the onscreen instructions.
    • On an Intel-based Mac: Choose Apple menu > Restart, then immediately press and hold one of these key combinations, depending on what you want to do:
      • Install the latest version of macOS compatible with your computer: Option-Command-R.
      • Reinstall your computer's original version of macOS (including available updates): Option-Shift-Command-R.
      • Reinstall your current version of macOS: Command-R.
  2. In the Recovery app window, select Reinstall for your macOS release, then click Continue.
  3. Follow the onscreen instructions. In the pane where you select a volume, select your current macOS volume (in most cases, it's the only one available).

Enabling Data Encryption

Encryption of Contacts data in non-volatile memory is provided by FileVault. FileVault is the disk encryption solution provided by macOS. FileVault must be enabled using the following steps:

  1. Open System Preferences
  2. Navigate to Security & Privacy
  3. Click Turn On FileVault... and follow the onscreen instructions.
  4. The status will change to “FileVault is turned on for the disk..."

Figure 2 - Verification of FileVault: A screenshot of the macOS Security & Privacy settings showing the FileVault tab. It indicates 'FileVault secures the data on your disk by encrypting its contents automatically.' and displays 'FileVault is turned on for the disk "Macintosh HD - Data".' A warning about needing a password or recovery key is also visible.

Other Assumptions

The administrator of the underlying platform and application software must not be careless, willfully negligent, or hostile.

The user of the application software is not willfully negligent or hostile. The user also uses the software in compliance with the applied enterprise security policy.

Managing Accounts

Contacts stores contact information locally with no user intervention. Contacts can be configured to synchronize contact information with an Apple iCloud server or other server. All account management is performed by choosing Contacts menu > Preferences..., then clicking Accounts.

Figure 3: Accounts Preferences: A screenshot of the macOS Contacts application's Preferences window, showing the Accounts tab. The left pane lists 'iCloud' and 'CardDAV'. The right pane displays account information for iCloud, with options to 'Enable this account', set a Description, User Name, and Fetch settings.

Adding Accounts

Click the Add button [add] and follow the onscreen instructions. Secure communication using HTTPS/TLS are automatically configured (see Section 4.1 for additional details).

Note: Contacts automatically stores credentials in the login Keychain.

Deleting Accounts

Select the account you wish to delete and then click the Remove button [remove].

Enabling Accounts

Select the account you wish to enable or disable. Check "Enable this account" to enable the account or uncheck to disable the account. When an account is disabled, the contact information and account details are saved; however, Contacts does not synchronize with the server.

Secure Communications

TLS Configuration

Contacts supports secure communications with Apple servers or other user-configured servers via HTTPS/TLS. When communicating with Apple servers, Contacts leverages preconfigured reference identifiers. When connecting to non-Apple servers, the platform automatically creates the reference identifiers from the DNS name or IP address used to specify the server.

All configuration of TLS parameters is handled exclusively by the underlying platform (Apple macOS). No additional configuration is required to ensure proper usage.

Digital Certificates

Contacts leverages “Trusted” CA certificates that are preinstalled in the macOS Trust Store to verify the authenticity of server certificates. No configuration is necessary to facilitate the use of these certificates. Additional information regarding the default Trust Store can be found at https://support.apple.com/HT212140. Additional trust anchors may be added by performing the following steps:

  1. Open Keychain Access
  2. Select the Keychain you wish to add the trust anchor to:
    • The System Keychain applies to all users and can only be updated by an Administrator
    • The login Keychain only applies to the current user
  3. Choose File > Import Items...
  4. Select the CA certificate to add as a trust anchor and click Open
  5. Select the imported certificate. Note: You may have to click “All Items” or “Certificates" to display the certificate
  6. Choose File > Get Info
  7. Expand the Trust section
  8. Change the "Secure Sockets Layer (SSL)" selection to “Always Trust"
  9. Close the window to save the change

Resource Usage

Contacts uses the following resources:

Acronyms

AcronymDefinition
DNSDomain Name System
HTTPSHypertext Transfer Protocol Secure
IPInternet Protocol
OSOperating System
TLSTransport Layer Security

PDF preview unavailable. Download the PDF instead.

Apple macOS 11 Big Sur 联系人通用标准配置指南 macOS Version 11.5 (Build 20G71) Quartz PDFContext Word

Related Documents

Preview Apple Korea RoHS Declarations Compliance Statement
This document provides compliance declarations for various Apple products regarding the restriction of hazardous substances in Korea, commonly known as Korea RoHS.
Preview Apple macOS 13 Ventura FileVault Common Criteria Configuration Guide
This guide from Apple Inc. provides administrators with detailed instructions for configuring and operating FileVault on macOS 13 Ventura within a Common Criteria evaluated environment, covering installation, updates, recovery, user management, and security settings.
Preview Apple Education Institution Hardware and Software Price List - January 2023
Comprehensive price list for Apple hardware and software, including iMac, Mac mini, Mac Studio, MacBook Air, MacBook Pro, and iPad models with AppleCare+ options, specifically for US Education Institutions, valid as of January 2023.
Preview Apple Mac Employee Starter Guide: Mastering macOS for Business
A comprehensive guide for employees on using Apple Mac computers with macOS for business. Learn about basic setup, productivity features, Apple Intelligence, and seamless integration with other Apple devices for enhanced workflow.
Preview Apple macOS 11 Big Sur Contacts Security Target: Common Criteria Evaluation
This document details the security target for the Apple macOS 11 Big Sur Contacts application, outlining its conformance to Common Criteria standards, security objectives, requirements, and assurance measures.
Preview MacBook Pro 13-inch Touch Bar 2018 Teardown Guide
A detailed teardown guide of the 2018 Apple MacBook Pro 13-inch with Touch Bar, covering its internal components, specifications, and disassembly steps.
Preview Employee Starter Guide to Mac Basics with macOS Ventura
A comprehensive guide for employees on using Mac computers with macOS Ventura, covering hardware, software, essential features, and tips for productivity and customization.
Preview MacBook Pro 16" 2019 Teardown: A Detailed Look Inside
Explore the internal components and design of the 2019 MacBook Pro 16-inch with this comprehensive teardown guide from iFixit. Learn about its new keyboard, speakers, and thermal system.