NIAP: Assurance Continuity
  NIAP  »»  Product Compliant List  »»  Product Entry  »»  Assurance Continuity  
Assurance Continuity - Aruba Mobility Controller and Access Point Series with ArubaOS version 6.5.X

Date of Maintenance Completion:  2016.10.13

Product Type:    Wireless LAN

Conformance Claim:  Protection Profile Compliant

PP Identifier:    Protection Profile for Wireless Local Area Network (WLAN) Access Systems Version 1.0

Original Evaluated TOE:  2014.10.22 - Aruba Mobility Controllers and Access Points

CC Certificate [PDF] Validation Report [PDF] Assurance Activity [PDF]

Administrative Guide [PDF]

Please note:  The above files are for the Original Evaluated TOE.  Consequently, they do not refer to this maintained version, although they apply to the maintained version. 

Security Target [PDF] * Assurance Continuity Maintenance Report [PDF]

Please note:  This serves as an addendum to the VR for the Original Evaluated TOE. 

* This is the Security Target (ST) associated with this latest Maintenance Release.  To view previous STs for this TOE, click here.

Readers are reminded that the certification of this product (TOE) is the result of maintenance, rather than an actual re-evaluation of the product.  Maintenance only considers the affect of TOE changes on the assurance baseline (i.e. the original evaluated TOE); maintenance is not intended to provide assurance in regard to the resistance of the TOE to new vulnerabilities or attack methods discovered since the date of the initial certificate.  Such assurance can only be gained through re-evaluation. 

Using a security impact analysis of the changes made to the TOE, which was provided by the developer, the CCEVS has determined that the impact of changes on the TOE are considered minor and that independent evaluator analysis was not necessary.  A summary of the results can be found in the Maintenance Report, which is written in relation to the product's original validation report and Security Target.  Readers are therefore reminded to read the Security Target, Validation Report, and the Assurance Maintenance Report to fully understand the meaning of what a maintained certificate represents. 

Product Description

CCEVS reviewed the description of the changes and bug fixes and discussed regression testing with the CCTL.  An analysis of all changes to the product determined that the changes were minor. The CCEVS agrees that the original assurance is maintained for the above-cited version of the product.  Note that the product includes several enhancements that, if implemented, cause the TOE to be outside the evaluated configuration.  The project user is strongly cautioned that the following product enhancements must not be implemented or used in the evaluated configuration:

·         In the updated product, an administrator can initiate a remote telnet or SSH session from the controller to a remote host. Telnet and SSH are not permitted in the TOE.  In the evaluated configuration, IPsec must be used.  Telnet and SSH to a remote host are not included in the TOE and must not be used in the evaluated configuration. 

·         Authentication methods other than those specifically defined within the ST must not be implemented in the evaluated configuration.  Only those authentication methods specifically defined in the Security Target may be used in the evaluated configuration.

Vendor Information

Aruba, a Hewlett Packard Enterprise company
Jon Green
+1 (408)-277-4500
+1 (408)-227-4550
Site Map              Contact Us              Home