Validated Product - IBM WebSphere Application Server for z/OS V6.1.0.2Certificate Date: 16 March 2007 Validation Report Number: CCEVS-VR-07-0014 Product Type: Miscellaneous Conformance Claim: EAL4 Augmented with ALC_FLR.1 PP Identifiers: None CC Testing Lab: SAIC Common Criteria Testing Laboratory
PRODUCT DESCRIPTIONWebSphere Application Server for z/OS V6.1, service level 6.1.0.2. Requires fix to APAR AK30720. TOE Identification: WebSphere Application Server for z/OS configured according to WebSphere Application Server EAL4 AGD – Guidance document (version 16). The WebSphere Application Server for z/OS TOE is a subset of the WebSphere Application Server for z/OS product. The WebSphere Application Server for z/OS TOE consists of the following WebSphere Application Server for z/OS product components:
Other WebSphere Application Server for z/OS product components that are not part of the TOE do not implement the primary purpose of the product and are not required to facilitate the product management functions. TOE Environment: WebSphere Application Server for z/OS relies upon the environment to perform cryptographic key generation, cryptographic key destruction, cryptographic operations (digital signature generation/verification, encryption/decryption), maintenance of security attributes associated with users (user ID, Group ID, Password or Certificate), audit , TOE security protection and authentication. The following Operating System (OS) is supported but outside the scope of this evaluation:
TOE Description: The WebSphere Application Server for z/OS TOE is a Java 2 Enterprise Edition (J2EE) 1.4 compliant run-time environment. The primary purpose of the product is to provide an environment for running and managing user-supplied enterprise applications and their components of. J2EE is a comprehensive set of specifications for designing, developing and deploying multi-tier, server-based applications. The WebSphere Application Server for z/OS TOE supports the following security functions: Identification, Access Control, and Security Management. The TOE identifies a client before performing any other TSF mediated action for the client with the exception of access to a method or static web content that is not configured with a security constraint or specifically allows access to “Everyone”. The environment is depended upon to authenticate and maintain security attributes associated with users. The TOE provides access control functions that allow only authorized remote callers access to the sensitive resources. The TOE permits a client to access a protected resource only if a user or group ID of the user is mapped to a role that has permission to access the resource. The resources protected by the TOE are:
The authorized role can use the TOE to map user and group IDs to roles which are the attributes used by the access control function. SECURITY EVALUATION SUMMARYThe evaluation was carried out in accordance to the Common Criteria Evaluation and Validation Scheme (CCEVS) process and scheme. The evaluation demonstrated that the WebSphere Application Server for z/OS TOEmeets the security requirements contained in the Security Target. The criteria against which the WebSphere Application Server for z/OS TOE was judged are described in the Common Criteria for Information Technology Security Evaluation, Version 2.2. The evaluation methodology used by the evaluation team to conduct the evaluation is the Common Methodology for Information Technology Security Evaluation, Version 2.2. Science Application International Corporation (SAIC) determined that the evaluation assurance level (EAL) for the WebSphere Application Server for z/OS TOE is EAL 4 augmented with ALC_FLR.1. The TOE, configured as specified in the installation guide, satisfies all of the security functional requirements stated in the Security Target. Several validators on behalf of the CCEVS Validation Body monitored the evaluation carried out by SAIC. The evaluation was completed in January 2007. Results of the evaluation can be found in the Common Criteria Evaluation and Validation Scheme Validation Report for WebSphere Application Serverfor z/OS prepared by CCEVS. The WebSphere Application Server for z/OS EAL4+ Security Target makes a claim that the TOE can be supported on z/OS operating systems platforms and is considered to be outside the scope of the TOE. ENVIRONMENTAL STRENGTHSThe WebSphere Application Server for z/OS TOE is a commercial product that provides identification, access control and the management of access control to protective resources. Additionally, the TOE provides a mechanism for requiring requests from remote callers to be encrypted using SSL (note that SSL is outside the scope of the TOE). The WebSphere Application Server for z/OS TOE provides a level of protection that is appropriate for IT environments where the WebSphere Application Server for z/OS TOE and the platform upon which it is installed can be appropriately protected from physical attacks. |