{"product_id":10233,"v_id":10233,"product_name":"Brocade Director Models: 48000 and DCX; Brocade Switch Models: 200E, 300, 4100, 4900, 5000, 5100, 5300, 7500 and 7500E; Director Blade Models: FC2-16, FC4-16, FC4-32, FC4-46, FC4-18, FC4-32, FC4-48, FR4-18I, FC8-16, FC8-32, FC8-48, CP4, CP8, CR8; Embedded Blades: 4012, 4016, 4018, 4020, and 4024","certification_status":"Not Certified","certification_date":"2009-03-31T00:03:00Z","tech_type":"Sensitive Data Protection, System Access Control","vendor_id":{"name":"Brocade Communications Systems LLC A Broadcom Inc. Company","website":"www.broadcom.com"},"vendor_poc":"Greg Farris","vendor_phone":"408-333-7315","vendor_email":"gfarris@brocade.com","assigned_lab":{"cctl_name":"Leidos Common Criteria Testing Laboratory"},"product_description":"<p class=\"Body\" style=\"margin: 0in 0in auto;\"><span style=\"font-size: x-small; font-family: Times New Roman;\">The Target of Evaluation (TOE) is the Brocade Directors and Switches hardware appliance with all TOE models running FabricOS version 6.1.1.</span></p>\r\n<p class=\"Body\" style=\"margin: 0in 0in auto;\"><span style=\"font-size: x-small; font-family: Times New Roman;\">Brocade Directors and Switches are hardware appliances that implement what is called a &ldquo;Storage Area Network&rdquo; or &ldquo;SAN&rdquo;. SANs provide physical connections between machines in the environment containing a type of network card called a Host Bus Adapter (HBA) that are located in the environment and storage devices such as disk storage systems and tape libraries that are also located in the environment.<span style=\"mso-spacerun: yes;\">&nbsp; </span>SANs are optimized to transfer large blocks of data between HBAs and storage devices.<span style=\"mso-spacerun: yes;\">&nbsp; </span>SANs can be used to replace or supplement server-attached storage solutions, for example. </span></p>\r\n<p class=\"Body\" style=\"margin: 0in 0in auto;\"><span style=\"font-size: x-small; font-family: Times New Roman;\">HBAs communicate with the TOE using Fibre Channel (FC) or FC over IP (FCIP) protocols. Storage devices in turn are physically connected to the TOE using FC/FCIP interfaces. When more than one instance of the TOE is interconnected (i.e. installed and configured to work together), they are referred to collectively as a &ldquo;SAN fabric&rdquo; or simply a &ldquo;fabric.&rdquo; A zone is a specified group of fabric-connected devices (called zone members) that have access to one another.</span></p>\r\n<p class=\"Body\" style=\"margin: 0in 0in auto;\"><span style=\"font-size: x-small; font-family: Times New Roman;\">The TOE provides the ability to centralize the location of storage devices in a network in the environment. Instead of attaching disks or tapes to individual hosts in the environment, or for example attaching a disk or tape directly to the network, storage devices can be physically attached to the TOE, which can then be physically attached to host bus adapters in the environment. Host bus adapters that are connected to the TOE can then read from and write to storage devices that are attached to the TOE according to TOE configuration. Storage devices in the environment appear to the operating system running on the machine that the host bus adapter is installed in as local (i.e. directly-attached) devices. </span></p>\r\n<p class=\"Body\" style=\"margin: 0in 0in auto;\"><span style=\"font-size: x-small; font-family: Times New Roman;\">More than one host bus adapter can share one or more storage devices that are attached to the TOE according to TOE configuration. Scalability is achieved by interconnecting multiple instances of TOE directors and switches to form a fabric that supports different numbers of host bus adapters and storage devices.</span></p>\r\n<p class=\"Body\" style=\"margin: 0in 0in auto;\"><span style=\"font-size: x-small; font-family: Times New Roman;\">The Brocade Directors and Switches hardware appliances can operate in one of two modes: a fabric switch mode or an &ldquo;Access Gateway&rdquo; mode.<span style=\"mso-spacerun: yes;\">&nbsp; </span>The evaluated configuration supports only interconnected TOE instances operated in a fabric switch mode, which is the default mode and user guidance specifically warns the user that Access Gateway mode is not allowed in the CC evaluated configuration.</span></p>\r\n<p class=\"Body\" style=\"margin: 0in 0in auto;\"><span style=\"font-size: x-small; font-family: Times New Roman;\">Directors and switches both can be used by host bus adapters to access storage devices using the TOE. Switch appliances provide a fixed number of physical interfaces to hosts and storage devices in the environment.<span style=\"mso-spacerun: yes;\">&nbsp; </span>Directors provide a configurable number of physical interfaces using a chassis architecture that supports the use of blades that can be installed in and removed from the director chassis according to administrator configuration.</span></p>\r\n<p class=\"Body\" style=\"margin: 0in 0in auto;\"><span style=\"font-size: x-small; font-family: Times New Roman;\">There are administrative interfaces to manage TOE services that can be accessed using an Ethernet network, as well as interfaces that can be accessed using a directly-attached console as follows:</span></p>\r\n<p class=\"Body\" style=\"margin: 0in 0in auto 0.5in; text-indent: -0.25in; mso-list: l0 level1 lfo1; tab-stops: list .5in;\"><span style=\"font-family: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol;\"><span style=\"mso-list: Ignore;\"><span style=\"font-size: x-small;\">&middot;</span><span style=\"font: 7pt &quot;Times New Roman&quot;;\">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span></span></span><span style=\"font-size: x-small; font-family: Times New Roman;\">Ethernet network-based web-based administrator console interfaces &ndash;Provides web-based administrator console interfaces called the &ldquo;Brocade Advanced Web Tools.&rdquo;</span></p>\r\n<p class=\"Body\" style=\"margin: 0in 0in auto 0.5in; text-indent: -0.25in; mso-list: l0 level1 lfo1; tab-stops: list .5in;\"><span style=\"font-family: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol;\"><span style=\"mso-list: Ignore;\"><span style=\"font-size: x-small;\">&middot;</span><span style=\"font: 7pt &quot;Times New Roman&quot;;\">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span></span></span><span style=\"font-size: x-small; font-family: Times New Roman;\">Ethernet network-based command-line administrator console interfaces &ndash; Provides command-line administrator console interfaces called the &ldquo;FabricOS Command Line Interface.&rdquo;</span></p>\r\n<p class=\"Body\" style=\"margin: 0in 0in auto 0.5in; text-indent: -0.25in; mso-list: l0 level1 lfo1; tab-stops: list .5in;\"><span style=\"font-family: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol;\"><span style=\"mso-list: Ignore;\"><span style=\"font-size: x-small;\">&middot;</span><span style=\"font: 7pt &quot;Times New Roman&quot;;\">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span></span></span><span style=\"font-size: x-small; font-family: Times New Roman;\">Serial terminal-based command-line administrator console interfaces &ndash; Provides command-line administrator console interfaces called the &ldquo;FabricOS Command Line Interface.&rdquo;</span></p>\r\n<p class=\"Body\" style=\"margin: 0in 0in auto;\"><span style=\"font-size: x-small; font-family: Times New Roman;\">There also exists administrative Ethernet network-based programmatic API interfaces, however these interfaces are disabled during initial installation and configuration in the evaluated configuration. Similarly, there exists a modem hardware component that is optional to the product that can be used in a similar manner as a serial console port, but it is disabled by virtue of not being physically installed during initial installation and configuration in the evaluated configuration.</span></p>\r\n<p class=\"Body\" style=\"margin: 0in 0in auto;\"><span style=\"font-size: x-small;\"><span style=\"font-family: Times New Roman;\"><span style=\"mso-spacerun: yes;\">&nbsp;</span>The Brocade Advanced Web Tools login interface distinguishes between the correct entry of a userID and password.<span style=\"mso-spacerun: yes;\">&nbsp; </span>This feedback would allow an attacker to systematically guess userIDs until a correct userID is found and then switch to guessing passwords. The vendor plans to remove this feedback in the next release.<span style=\"mso-spacerun: yes;\">&nbsp; </span>If this is a concern for the target environment, then only the Command Line Interface should be used.</span></span></p>\r\n<p class=\"Body\" style=\"margin: 0in 0in auto;\"><span style=\"font-size: x-small; font-family: Times New Roman;\">The OS \"root\" account is required for installation of the Brocade and Switches appliance, and the \"root\" account allows direct command line access to the Fabric OS.<span style=\"mso-spacerun: yes;\">&nbsp; </span>The Brocade Fabric OS v6.1.1 Release Notes v4.0 strongly cautions the system administrator to disable the \"root\" account after installation and configuration of the appliance to ensure that access to the OS is not allowed.</span></p>","evaluation_configuration":null,"security_evaluation_summary":"<p><span style=\"font-size: 11pt; line-height: 115%; font-family: &quot;Calibri&quot;,&quot;sans-serif&quot;; mso-fareast-font-family: Calibri; mso-bidi-font-family: 'Times New Roman'; mso-ansi-language: EN-US; mso-fareast-language: EN-US; mso-bidi-language: AR-SA;\">The evaluation was carried out in accordance to the Common Criteria Evaluation and Validation Scheme (CCEVS) process and scheme. The evaluation demonstrated that <span style=\"mso-bidi-font-style: italic;\">the <span style=\"mso-spacerun: yes;\">&nbsp;</span><span style=\"mso-spacerun: yes;\">&nbsp;</span>TOE<em> </em></span>meets the security requirements contained in the Security Target.<span style=\"mso-spacerun: yes;\">&nbsp; </span>The criteria against which the <span style=\"mso-spacerun: yes;\">&nbsp;</span><span style=\"mso-spacerun: yes;\">&nbsp;</span>TOE was judged are described in the Common Criteria for Information Technology Security Evaluation, Version 3.1. The evaluation methodology used by the evaluation team to conduct the evaluation is the Common Methodology for Information Technology Security Evaluation, Version 3.1.<span style=\"mso-spacerun: yes;\">&nbsp; </span>Science Application International Corporation (SAIC) determined that the evaluation assurance level (EAL) for the TOE is EAL 3 augmented with ALC_FLR.2.<span style=\"mso-spacerun: yes;\">&nbsp; </span>The TOE, configured as specified in the installation guide, satisfies all of the security functional requirements stated in the Security Target.<span style=\"mso-spacerun: yes;\">&nbsp; </span>The CCEVS Validation Body provided oversight of the evaluation conducted by the SAIC CCTL. <span style=\"mso-spacerun: yes;\">&nbsp;&nbsp;</span>The evaluation was completed in March 2009.<span style=\"mso-spacerun: yes;\">&nbsp; </span>Results of the evaluation can be found in the Common Criteria Evaluation and Validation Scheme Validation Report<em> </em><span style=\"mso-bidi-font-style: italic;\">Brocade Directors and Switches </span>prepared by CCEVS.</span></p>","environmental_strengths":"<p><span style=\"font-size: 10pt; line-height: 115%; font-family: &quot;Times New Roman&quot;,&quot;serif&quot;; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-size: 12.0pt; mso-ansi-language: EN-US; mso-fareast-language: EN-US; mso-bidi-language: AR-SA;\">The TOE protects itself from attempts to bypass its security mechanisms. The TOE performs user data protection of the data stored outside the TOE that is routed to and from users through the TOE within a defined zone.<span style=\"mso-spacerun: yes;\">&nbsp; </span>The TOE performs identification and authentication of all administrative users and provides security management functionality to manage the TOE appliances.</span></p>","features":[]}