TD0135: SNMP in NDcPP MACsec EP v1.2
Publication Date
2017.01.25
Protection Profiles
PP_NDCPP_MACSEC_EP_V1.2
Other References
FMT_SNMP_EXT.1.1, FCS_SNMP_EXT.1.1
Issue Description
The end of the FMT_SNMP_EXT.1.1 SFR is confusing as currently written, causing differing interpretations. In addition, the FCS_SNMP_EXT.1.1 SFR is written like an assurance activity instead of a requirement and should be reworded. Resolution
Replace FMT_SNMP_EXT.1.1 as follows: Replace FCS_SNMP_EXT.1.1 and add an assurance activity as follows: FCS_SNMP_EXT.1.1 The TSF shall support SNMP using TLS in accordance with RFC 6353 supporting the following cipher suites [ · Mandatory Cipher suites: o TLS_RSA_WITH_AES_128_CBC_SHA as defined in RFC 5246 · [selection: Optional Cipher suites: o TLS_RSA_WITH_AES_256_CBC_SHA as defined in RFC 5246 o TLS_DHE_RSA_WITH_AES_128_CBC_SHA as defined in RFC 5246 o TLS_DHE_RSA_WITH_AES_256_CBC_SHA as defined in RFC 5246 o TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA as defined in RFC 4492 o TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA as defined in RFC 4492 o TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA as defined in RFC 4492 o TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA as defined in RFC 4492 o TLS_RSA_WITH_AES_128_CBC_SHA256 as defined in RFC 5246 o TLS_RSA_WITH_AES_256_CBC_ SHA256 as defined in RFC 5246 o TLS_DHE_RSA_WITH_AES_128_CBC_ SHA256 as defined in RFC 5246 o TLS_DHE_RSA_WITH_AES_256_CBC_ SHA256 as defined in RFC 5246 o TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA256 as defined in RFC 5289 o TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA384 as defined in RFC 5289 o TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256 as defined in RFC 5289 o TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384 as defined in RFC 5289 o no other cipher suite]].
Justification
Updates made for clarity. |