Validated Product - Sun Java System Identity Manager

Certificate Date: 24 August 2005

Validation Report Number: CCEVS-VR-05-0117

Product Type: IDS/IPS

Conformance Claim: EAL2

PP Identifiers: None

CC Testing Lab: CygnaCom Solutions, Inc


PRODUCT DESCRIPTION

The TOE is Sun Java™ System Identity Manager, which is a server application that provides password management, automated user provisioning, and identity data synchronization capabilities in a single, converged solution. Identity Manager allows system administrators to leverage a consistent interface for updating user accounts and configuration information across many target systems, including all of the leading operating systems, databases, directories, enterprise business applications, security managers, and access management systems. With role and rule based provisioning, this solution automates the activities associated with granting, managing, and revoking user access privileges.

The main security service provided by Sun Java™ System Identity Manager is to manage user identities.  The Identity Manager server maintains information on users and the resources they can access using the Virtual Identity Manager (VIM). This enables the collection of key information on managed accounts, without duplicating the entire account back to a private, centralized repository. The data-sparse model helps ensure the security of the identity management process by lessening the requirement for data synchronization as the data stays in the native format.

The Identity Manager Administrator Interface provides a single web-based interface for authorized administrators to grant, manage, and revoke user access privileges.

Sun Java™ System Identity Manager provides the following security functions:

  • Security Audit – Identity Manager provides the ability to audit the following events: generated accounts, approved requests, failed access attempts, password changes and resets, self provisioning activities, and administration of configuration data. Identity Manager provides a utility for searching, sorting, ordering, and viewing audit records. 
  • User Data Protection/Access Control – Identity Manager provides access control through the enforcement of the Sun Java™ System Identity Manager Access Control Policy. The IDM Access Control Policy is based on user roles also described as user capabilities in the Administrator’s Guide. This functionality is specified using security attributes in user records in the IDM Data Store.
  • User Identification and Authentication – Identity Manager provides user identification and authentication through the use of user accounts and the enforcement of password policies. In addition, IDM provides the capability to automatically generate passwords that meet the rules of the password policy.
  • Security Management – Identity Manager provides security management through the use of the Administrator Interface and User Interface.

The evaluated configuration includes the following: 

  • Sun Java™ System Identity Manager V5.0 running on Microsoft Windows 2000
  • Sun Java™ System Identity Manager Administrator/User Interface running on the same machine.

The TOE includes the Identity Manager Server and the Administrator/User Interface.

SECURITY EVALUATION SUMMARY

The evaluation was carried out in accordance with the Common Criteria Evaluation and Validation Scheme (CCEVS) processes and procedures. Sun Java™ System Identity Manager was evaluated against the criteria contained in the Common Criteria for Information Technology Security Evaluation, Version 2.2. The evaluation methodology used by the evaluation team to conduct the evaluation is the Common Methodology for Information Technology Security Evaluation, Version 2.2. CygnaCom Solutions has determined that the product meets the security criteria in the Security Target, which specifies an assurance level of EAL2. A validator, on behalf of the CCEVS Validation Body, monitored the evaluation. The evaluation was completed in August 2005.

ENVIRONMENTAL STRENGTHS

Sun Java™ System Identity Manager (IDM) is an identity management system that enables authorized administrators to securely and efficiently manage access to accounts and resources. Identity Manager is a server application that provides a consistent interface for system administrators to update user account and other configuration information in many target systems of various kinds.

Vendor Information


Sun Microsystems, Inc.
Hilda Cox
512.401.4024
hilda.cox@sun.com

http://www.sun.com

--->