{"product_id":10317,"v_id":10317,"product_name":"CA Siteminder Web Access Manager r12 SP1-CR3","certification_status":"Not Certified","certification_date":"2009-06-12T00:06:00Z","tech_type":"Network Access Control, System Access Control","vendor_id":{"name":"CA Technologies","website":"www.ca.com"},"vendor_poc":"William F. Clark","vendor_phone":"703-708-3501","vendor_email":"william.clark@ca.com","assigned_lab":{"cctl_name":"Booz Allen Hamilton Common Criteria Testing Laboratory"},"product_description":"<p class=\"MsoNormal\" style=\"margin: 0in 0in 0pt; line-height: 12pt; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto;\"><span style=\"font-size: 10pt; color: #333333; font-family: \">CA </span><span style=\"font-size: 10pt; font-family: \">SiteMinder Web Access Manager r12<span style=\"color: #333333;\"> SP1-CR3 </span>provides an enterprise-scale Web access management system that enables you to control access to Web applications and portals for employees, customers and business partners&mdash;both securely and efficiently.</span></p>","evaluation_configuration":"<p class=\"MsoNormal\" style=\"margin: 0in 0in 0pt; line-height: 12pt; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto;\"><span style=\"font-size: 10pt; color: #333333; font-family: \">The TOE was evaluated on the following platforms:</span></p>\r\n<p class=\"MsoNormal\" style=\"margin: 0in 0in 0pt;\"><span style=\"font-size: 10pt; font-family: \">Windows Server 2003 SP2:</span></p>\r\n<ul style=\"margin-top: 0in;\" type=\"disc\">\r\n<li class=\"MsoNormal\" style=\"margin: 0in 0in 0pt; mso-list: l0 level1 lfo1; tab-stops: list .5in;\"><span style=\"font-size: 10pt; font-family: \">CPU:<span style=\"mso-tab-count: 2;\">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span>Intel Xeon 5130 2.00GHz</span></li>\r\n<li class=\"MsoNormal\" style=\"margin: 0in 0in 0pt; mso-list: l0 level1 lfo1; tab-stops: list .5in;\"><span style=\"font-size: 10pt; font-family: \">Memory:<span style=\"mso-tab-count: 1;\">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span>2 GB system RAM</span></li>\r\n<li class=\"MsoNormal\" style=\"margin: 0in 0in 0pt; mso-list: l0 level1 lfo1; tab-stops: list .5in;\"><span style=\"font-size: 10pt; font-family: \">Disk Space: <span style=\"mso-tab-count: 1;\">&nbsp;&nbsp;&nbsp;&nbsp; </span>60 GB</span></li>\r\n<li class=\"MsoNormal\" style=\"margin: 0in 0in 0pt; mso-list: l0 level1 lfo1; tab-stops: list .5in;\"><span style=\"font-size: 10pt; font-family: \">Temp Space:<span style=\"mso-tab-count: 1;\">&nbsp;&nbsp;&nbsp; </span>60 GB</span></li>\r\n<li class=\"MsoNormal\" style=\"margin: 0in 0in 0pt; mso-list: l0 level1 lfo1; tab-stops: list .5in;\"><span style=\"font-size: 10pt; font-family: \">Active Directory Win2k3</span></li>\r\n<li class=\"MsoNormal\" style=\"margin: 0in 0in 0pt; mso-list: l0 level1 lfo1; tab-stops: list .5in;\"><span style=\"font-size: 10pt; font-family: \">Oracle 10g R2</span></li>\r\n<li class=\"MsoNormal\" style=\"margin: 0in 0in 0pt; mso-list: l0 level1 lfo1; tab-stops: list .5in;\"><span style=\"font-size: 10pt; font-family: \">Jboss 4.0.5</span></li>\r\n<li class=\"MsoNormal\" style=\"margin: 0in 0in 0pt; mso-list: l0 level1 lfo1; tab-stops: list .5in;\"><span style=\"font-size: 10pt; font-family: \">IIS 6.0, ASF Apache 2.2</span></li>\r\n</ul>\r\n<p class=\"MsoNormal\" style=\"margin: 0in 0in 0pt;\"><span style=\"font-size: 10pt; font-family: \">&nbsp;</span></p>\r\n<p class=\"MsoNormal\" style=\"margin: 0in 0in 0pt;\"><span style=\"font-size: 10pt; font-family: \">&nbsp;</span></p>\r\n<p class=\"MsoNormal\" style=\"margin: 0in 0in 0pt;\"><span style=\"font-size: 10pt; font-family: \">Red Hat Advanced Server 4.0:</span></p>\r\n<ul style=\"margin-top: 0in;\" type=\"disc\">\r\n<li class=\"MsoNormal\" style=\"margin: 0in 0in 0pt; mso-list: l1 level1 lfo2; tab-stops: list .5in;\"><span style=\"font-size: 10pt; font-family: \">CPU:<span style=\"mso-tab-count: 2;\">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span>Intel Pentium 4 2.66GHz</span></li>\r\n<li class=\"MsoNormal\" style=\"margin: 0in 0in 0pt; mso-list: l1 level1 lfo2; tab-stops: list .5in;\"><span style=\"font-size: 10pt; font-family: \">Memory:<span style=\"mso-tab-count: 1;\">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span>1 GB system RAM</span></li>\r\n<li class=\"MsoNormal\" style=\"margin: 0in 0in 0pt; mso-list: l1 level1 lfo2; tab-stops: list .5in;\"><span style=\"font-size: 10pt; font-family: \">Disk Space:<span style=\"mso-tab-count: 1;\">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span>45 GB</span></li>\r\n<li class=\"MsoNormal\" style=\"margin: 0in 0in 0pt; mso-list: l1 level1 lfo2; tab-stops: list .5in;\"><span style=\"font-size: 10pt; font-family: \">Temp Space:<span style=\"mso-tab-count: 1;\">&nbsp;&nbsp;&nbsp; </span>1.9 GB</span></li>\r\n<li class=\"MsoNormal\" style=\"margin: 0in 0in 0pt; mso-list: l1 level1 lfo2; tab-stops: list .5in;\"><span style=\"font-size: 10pt; font-family: \">iPlanet 5.2</span></li>\r\n<li class=\"MsoNormal\" style=\"margin: 0in 0in 0pt; mso-list: l1 level1 lfo2; tab-stops: list .5in;\"><span style=\"font-size: 10pt; font-family: \">Oracle 10g R2</span></li>\r\n<li class=\"MsoNormal\" style=\"margin: 0in 0in 0pt; mso-list: l1 level1 lfo2; tab-stops: list .5in;\"><span style=\"font-size: 10pt; font-family: \">Jboss 4.0.5</span></li>\r\n<li class=\"MsoNormal\" style=\"margin: 0in 0in 0pt; mso-list: l1 level1 lfo2; tab-stops: list .5in;\"><span style=\"font-size: 10pt; font-family: \">ASF Apache 2.2, Sunone 6.1 SP2</span></li>\r\n</ul>\r\n<p class=\"MsoNormal\" style=\"margin: 0in 0in 0pt;\"><span style=\"font-size: 10pt; font-family: \">&nbsp;</span></p>\r\n<p class=\"MsoNormal\" style=\"margin: 0in 0in 0pt;\"><span style=\"font-size: 10pt; font-family: \">Solaris 10:</span></p>\r\n<ul style=\"margin-top: 0in;\" type=\"disc\">\r\n<li class=\"MsoNormal\" style=\"margin: 0in 0in 0pt; mso-list: l2 level1 lfo3; tab-stops: list .5in;\"><span style=\"font-size: 10pt; font-family: \">CPU:<span style=\"mso-tab-count: 2;\">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span>Sparc 1336MHz</span></li>\r\n<li class=\"MsoNormal\" style=\"margin: 0in 0in 0pt; mso-list: l2 level1 lfo3; tab-stops: list .5in;\"><span style=\"font-size: 10pt; font-family: \">Memory:<span style=\"mso-tab-count: 1;\">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span>1 GB system RAM</span></li>\r\n<li class=\"MsoNormal\" style=\"margin: 0in 0in 0pt; mso-list: l2 level1 lfo3; tab-stops: list .5in;\"><span style=\"font-size: 10pt; font-family: \">Disk Space:<span style=\"mso-tab-count: 1;\">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span>2 GB</span></li>\r\n<li class=\"MsoNormal\" style=\"margin: 0in 0in 0pt; mso-list: l2 level1 lfo3; tab-stops: list .5in;\"><span style=\"font-size: 10pt; font-family: \">Temp Space:<span style=\"mso-tab-count: 1;\">&nbsp;&nbsp;&nbsp; </span>680 MB</span></li>\r\n<li class=\"MsoNormal\" style=\"margin: 0in 0in 0pt; mso-list: l2 level1 lfo3; tab-stops: list .5in;\"><span style=\"font-size: 10pt; font-family: \">iPlanet 5.2</span></li>\r\n<li class=\"MsoNormal\" style=\"margin: 0in 0in 0pt; mso-list: l2 level1 lfo3; tab-stops: list .5in;\"><span style=\"font-size: 10pt; font-family: \">Oracle 10g R2</span></li>\r\n<li class=\"MsoNormal\" style=\"margin: 0in 0in 0pt; mso-list: l2 level1 lfo3; tab-stops: list .5in;\"><span style=\"font-size: 10pt; font-family: \">WebLogic 9.2</span></li>\r\n<li class=\"MsoNormal\" style=\"margin: 0in 0in 0pt; mso-list: l2 level1 lfo3; tab-stops: list .5in;\"><span style=\"font-size: 10pt; font-family: \">Sunone 6.1 SP2, ASF Apache 2.2</span></li>\r\n</ul>\r\n<p class=\"MsoNormal\" style=\"margin: 0in 0in 0pt;\"><span style=\"mso-tab-count: 1;\"><span style=\"font-family: Book Antiqua;\">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span></span></p>","security_evaluation_summary":"<p class=\"MsoNormal\" style=\"margin: 0in 0in 0pt; line-height: 12pt; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto;\"><span style=\"font-size: 10pt; color: #333333; font-family: \">The evaluation was carried out in accordance with the Common Criteria Evaluation and Validation Scheme (CCEVS) processes and procedures. CA SiteMinder Web Access Manager r12 SP1 CR3 software was evaluated against the criteria contained in the Common Criteria for Information Technology Security Evaluation, Version 3.1.Revision 2 The evaluation methodology used by the evaluation team to conduct the evaluation is the Common Methodology for Information Technology Security Evaluation, Version 3.1 Revision2. It has been determined that the product meets the security criteria in the Security Target, which specifies an assurance level of EAL3 augmented with ALC_FLR.1 and ASE_TSS.2. Validators, on behalf of the CCEVS Validation Body, monitored the evaluation. The evaluation was completed in May 2009.</span></p>","environmental_strengths":"<p><span style=\"font-size: 15pt; color: #333333; font-family: \">\r\n<p class=\"MsoNormal\" style=\"margin: 0in 0in 0pt; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-line-height-alt: 14.4pt; mso-outline-level: 2;\"><span style=\"font-size: 15pt; color: #333333; font-family: &quot;Arial&quot;,&quot;sans-serif&quot;;\"><strong><em>Authentication</em></strong></span></p>\r\n<p class=\"MsoNormal\" style=\"margin: 0in 0in 0pt; line-height: 12pt; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto;\"><span style=\"font-size: 10pt; color: #333333; font-family: &quot;Arial&quot;,&quot;sans-serif&quot;;\">CA SiteMinder supports a broad range of authentication methods including passwords, Integrated Windows Authentication, and X.509 certificates. Authentication methods can also be combined for stronger authentication, for example, a certificate can be required in addition to a password.<span style=\"mso-spacerun: yes;\">&nbsp; </span>SiteMinder administrators can also define password policies, and web resource policies based on realms and domains.</span></p>\r\n<p class=\"MsoNormal\" style=\"margin: 0in 0in 0pt; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-line-height-alt: 12.0pt;\"><span style=\"font-size: 15pt; color: #333333; font-family: &quot;Arial&quot;,&quot;sans-serif&quot;;\"><strong><em>Authorization</em></strong></span></p>\r\n<p class=\"MsoNormal\" style=\"margin: 0in 0in 0pt; line-height: 12pt; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto;\"><span style=\"font-size: 10pt; color: #333333; font-family: &quot;Arial&quot;,&quot;sans-serif&quot;;\">SiteMinder authorization protects the server resources from unauthorized access. Administrators define policies, rules, and responses to handle the HTTP operations of end users and allow, deny, or redirect the operations accordingly.</span></p>\r\n<p class=\"MsoNormal\" style=\"margin: 0in 0in 0pt; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-line-height-alt: 14.4pt; mso-outline-level: 2;\"><span style=\"font-size: 15pt; color: #333333; font-family: &quot;Arial&quot;,&quot;sans-serif&quot;;\"><strong><em>Audit</em></strong></span></p>\r\n<p class=\"MsoNormal\" style=\"margin: 0in 0in 0pt; line-height: 12pt; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto;\"><span style=\"font-size: 10pt; color: #333333; font-family: &quot;Arial&quot;,&quot;sans-serif&quot;;\">The TOE generates audit records for selected security events. Events are tracked based on occurrence and who triggered them. Audit data is written to local files on the machine to which SiteMinder has been installed. Anyone who wishes to review the audit data must have Administrator (or root) privileges on that machine. SiteMinder can also audit to a central RDBMS and tools are available to bulk load audit files into the RDBMS audit store.</span></p>\r\n<p class=\"MsoNormal\" style=\"margin: 0in 0in 0pt; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-line-height-alt: 14.4pt; mso-outline-level: 2;\"><span style=\"font-size: 15pt; color: #333333; font-family: &quot;Arial&quot;,&quot;sans-serif&quot;;\"><strong><em>Data Protection</em></strong></span></p>\r\n<p class=\"MsoNormal\" style=\"margin: 0in 0in 0pt; line-height: 12pt; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto;\"><span style=\"font-size: 10pt; color: #333333; font-family: &quot;Arial&quot;,&quot;sans-serif&quot;;\">The access control features of the underlying operating system, LDAP user store, and Oracle database protect all the TOE data. Local access is not permitted by any user other than an authorized IT environment administrator that has an account on the local machine. Administrators manage the TOE remotely using the web-based WAM Admin UI.</span></p>\r\n<p class=\"MsoNormal\" style=\"margin: 0in 0in 0pt; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-line-height-alt: 14.4pt; mso-outline-level: 2;\"><span style=\"font-size: 15pt; color: #333333; font-family: &quot;Arial&quot;,&quot;sans-serif&quot;;\"><strong><em>Protected Data Transmission</em></strong></span></p>\r\n<p class=\"MsoNormal\" style=\"margin: 0in 0in 0pt; line-height: 12pt; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto;\"><span style=\"font-size: 10pt; color: #333333; font-family: &quot;Arial&quot;,&quot;sans-serif&quot;;\">The TOE uses an encryption scheme known as the TLI handshake protocol that utilizes vendor-asserted AES, AES Key Wrap, and HMAC-SHA256 algorithms to protect data transmitted between the networked components of the TOE.</span></p>\r\n<p class=\"MsoNormal\" style=\"margin: 0in 0in 0pt; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-line-height-alt: 14.4pt; mso-outline-level: 2;\"><span style=\"font-size: 15pt; color: #333333; font-family: &quot;Arial&quot;,&quot;sans-serif&quot;;\"><strong><em>Security Management</em></strong></span></p>\r\n<p class=\"MsoNormal\" style=\"margin: 0in 0in 0pt; line-height: 12pt; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto;\"><span style=\"font-size: 10pt; color: #333333; font-family: &quot;Arial&quot;,&quot;sans-serif&quot;;\">Security Management is handled by a remote administrator using the web-based WAM Admin UI. The local machine onto which SiteMinder is installed contains a Policy Server Management Console, but this is only used for initial configuration of the TOE.</span></p>\r\n<p class=\"MsoNormal\" style=\"margin: 0in 0in 0pt; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-line-height-alt: 14.4pt; mso-outline-level: 2;\"><span style=\"font-size: 15pt; color: #333333; font-family: &quot;Arial&quot;,&quot;sans-serif&quot;;\"><strong><em>Resource Utilization</em></strong></span></p>\r\n<p class=\"MsoNormal\" style=\"margin: 0in 0in 0pt;\"><span style=\"font-size: 10pt; color: #333333; font-family: &quot;Arial&quot;,&quot;sans-serif&quot;;\">A SiteMinder Web Agent can specify multiple clustered Policy Servers to connect to in order to ensure continued access control to protected resources if there is a failure in any of the clustered Policy Servers.</span></p>\r\n<p class=\"MsoNormal\" style=\"margin: 0in 0in 0pt;\"><span style=\"font-size: 10pt; color: #333333; font-family: &quot;Arial&quot;,&quot;sans-serif&quot;;\">&nbsp;</span></p>\r\n<p class=\"MsoNormal\" style=\"margin: 0in 0in 0pt;\"><span style=\"font-size: 10pt; color: #333333; font-family: &quot;Arial&quot;,&quot;sans-serif&quot;;\">For more information on CA SiteMinder, refer to the technology brief <a href=\"http://ca.com/files/TechnologyBriefs/siteminder-web-access-manager.pdf\"><span style=\"color: #3333aa;\">http://ca.com/files/TechnologyBriefs/siteminder-web-access-manager.pdf</span></a></span></p>\r\n<p class=\"MsoNormal\" style=\"margin: 0in 0in 0pt; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-line-height-alt: 14.4pt; mso-outline-level: 2;\">&nbsp;</p>\r\n</span></p>\r\n<p class=\"MsoNormal\" style=\"margin: 0in 0in 0pt; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-line-height-alt: 14.4pt; mso-outline-level: 2;\">&nbsp;</p>","features":[]}