{"product_id":10011,"v_id":10011,"product_name":"HP OpenView Operations for UNIX Version A.08.10 with patches","certification_status":"Not Certified","certification_date":"2005-08-19T00:08:00Z","tech_type":"Network Management","vendor_id":{"name":"Hewlett-Packard Company","website":"www.hp.com"},"vendor_poc":"Patrik Batsching, OVO/UNIX R&D Program Manager","vendor_phone":"+49.7031.141688","vendor_email":"patrik.batsching@hp.com","assigned_lab":{"cctl_name":"CygnaCom Solutions, Inc"},"product_description":"<p>HP OpenView Operations for UNIX (OVO/UNIX or just short OVO) is a distributed client-server software solution designed to help system administrators detect, solve, and prevent problems occurring in networks, systems, and applications in any enterprise.&nbsp; The OVO management concept is based on communication between a management server and managed nodes. </p>\r\n<p>OVO/UNIX management server processes, running on a central system, communicate with OVO agent processes running on managed nodes throughout the environment. The OVO agent processes collect and process events on the managed nodes, then forward relevant information in the form of OVO messages to the OVO/UNIX management server. The OVO/UNIX management server responds with actions to prevent or correct problems on the managed nodes. &nbsp;Communication between the managed nodes and the OVO/UNIX management server consists of messages, actions, and configuration changes. Multiple management servers may share management responsibility. </p>\r\n<p>Managed nodes are monitored and controlled by the OVO/UNIX management server.&nbsp; Events are occurrences on the managed nodes.&nbsp; Events trigger messages.&nbsp; The OVO HTTPS agent on the OVO/UNIX management server also serves as the local managed node.&nbsp; </p>\r\n<p>A database serves as the central data repository for all OVO messages and most configuration data on the OVO/UNIX management server.&nbsp; For this evaluation, the database software is installed on and executed on the OVO/UNIX management server and is not considered part of the TOE.&nbsp; There is some configuration data that is stored in the directory structure of the TOE.</p>","evaluation_configuration":null,"security_evaluation_summary":"<p>The OVO/UNIX TOE was evaluated against the <em>Common Criteria for Information Technology Security Evaluation</em>, Version 2.2, by the CygnaCom Solutions Common Criteria Testing Laboratory (CCTL).&nbsp; The evaluation methodology used was the <em>Common Methodology for Information Technology Security Evaluation, </em>Version 2.2.&nbsp; The CCTL concluded that the TOE was <em>Common Criteria</em> Part 2 and Part 3 conformant, and recommended that an EAL2 certificate be issued.&nbsp; The validation was conducted by NIAP&rsquo;s Common Criteria Evaluation and Validation Scheme (CCEVS). The evaluation was completed on August 19, 2005.</p>","environmental_strengths":"<p>The TOE provides the following security features:</p>\r\n<ul>\r\n    <li><strong>Security Audit </strong>- HP OpenView Operations for UNIX provides its own auditing capabilities separate from those of the Operating System.&nbsp; HP OVO relies on the operating system to supply the UNIX User Identification of the TOE user. HP OVO uses the UNIX user&rsquo;s identification, such as the user &lsquo;root&rsquo;, to supplement its own audit information to further delineate the subject that causes an auditable event. Audit logs are stored within a relational database, which is not part of the TOE. </li>\r\n    <li><strong>Access Control </strong>- HP OpenView Operations for UNIX provides its own access control, separate from the Operating System, for the user login attempts into the OVO Motif Admin GUI and OVO Java GUI.&nbsp; This is covered by the HP OpenView Operations Access Control Policy.&nbsp; HP OVO/UNIX relies on the underling OS to enforce the operating system&rsquo;s access control policy to restrict execution of the OVO CLIs to the UNIX user <em>root </em>(Windows user <em>administrator</em>). </li>\r\n    <li><strong>User Identification and Authentication </strong>- HP OpenView Operations for UNIX provides user identification and authentication of the OVO Motif Admin GUI and OVO Java GUI through the use of user accounts and the enforcement of password policies using the Pluggable Authentication Module (PAM) interfaces. PAM is outside of the TOE boundary.&nbsp; HP OVO/UNIX relies on the underling OS, which was not part of this evaluation, to require identification and authentication prior to allowing access to the OVO CLIs to the UNIX user <em>root </em>(Windows user <em>administrator</em>). &nbsp;&nbsp; </li>\r\n    <li><strong>System Identification and Authentication </strong>- HP OpenView Operations for UNIX uses certificates for the OVO/UNIX management server and HTTPS agents to identify and authorize appropriate activities - such as configuration deployment from the OVO/UNIX management server to the OVO HTTPS agent, remote action execution, application launches, etc. </li>\r\n    <li><strong>Security Management </strong>- HP OpenView Operations for UNIX provides security management through the use of the OVO Motif Admin GUI and CLIs.&nbsp; The enforcement of the OVO/UNIX ACP, restricts the ability to manage various security attributes and TSF data to the OVO Administrator using the administrator interface.&nbsp; On the OVO/UNIX management server, normally a dedicated system to just run the OpenView suite, the Operating System user &quot;<em>root</em>&quot; is a privileged user able to perform OVO administrative management tasks, such as policy configuration, certificate management, and start/stop OVO, via CLIs.&nbsp; On the OVO/UNIX agent the Operating System user &quot;<em>administrator</em>&quot; is a privileged user able to perform OVO administrative tasks, such as stop/start OVO agent, via CLIs.&nbsp; </li>\r\n    <li><strong>Partial Protection of TSF </strong>- HP OpenView Operations for UNIX protects its programs and data from unauthorized access through its own interfaces.&nbsp;&nbsp; For example, the local HTTPS agent configuration has a digital signature, OVO messages sent from the OVO HTTPS agent to the OVO/UNIX management server are encrypted, actions are signed, etc. (Note: The encryption utilized is outside the TOE Boundary and has not been FIPS certified nor has it been analyzed or tested to conform to cryptographic standards during this evaluation). </li>\r\n</ul>\r\n<p>For this evaluation, it was appropriate for the Security Target to claim compliance with the external standards Triple-DES, Blowfish, RSA, and SHA-1 for the definition of the encryption algorithm. There are many ways of determining compliance with a standard.&nbsp;OVO/UNIX has chosen to make a developer claim of compliance. This means that there has been no independent verification (by either the evaluators or a third party standards body, such as a FIPS laboratory) that the implementation of the cryptographic algorithms actually meets the claimed standards. Potential users of this product should confirm that the cryptographic capabilities are suitable to meet the user's requirements.</p>","features":[]}