{"product_id":10359,"v_id":10359,"product_name":"Red Hat Certificate System 8","certification_status":"Not Certified","certification_date":"2012-03-08T00:03:00Z","tech_type":"Certificate Authority","vendor_id":{"name":"Red Hat, Inc.","website":"http://www.redhat.com"},"vendor_poc":"Ellen Newlands","vendor_phone":"978-392-3929","vendor_email":"enewland@redhat.com","assigned_lab":{"cctl_name":"Leidos Common Criteria Testing Laboratory"},"product_description":"<p class=\"Body\">Red Hat Certificate System 8.1 (RHCS 8.1) provides a security framework to guarantee the identity of users and ensure privacy of communications. RHCS 8.1 issues and manages X.509v3 certificates needed to handle strong authentication, single sign-on and secure communications. RHCS 8.1 handles all the major functions around the certificate lifecycle simplifying enterprise-wide deployment and adoption. Customizable registration allows RHCS 8.1 to adapt to virtually any enterprise security policy</p>\r\n<p class=\"Body\">RHCS 8.1 provides integrity controls to ensure data is not modified. RHCS 8.1,includes protections to protect against someone with physical access to the components and includes assurance requirements to ensure the CIMC is functioning securely.</p>\r\n<p class=\"Body\">RHCS 8.1 provides protection against malicious authorized users by requiring at least three distinct roles. At a minimum, one role will be responsible for account administration, key generation, and audit configuration; a second role will be responsible for issuing and revoking certificates; and a third role responsible for maintaining the audit logs. RHCS 8.1 provides two-party control of private key export and additional auditing of import and export of secret and private keys and requests for information. Cryptographic modules responsible for long-term private key protection or for signing certificates or certificate status information must be validated to FIPS 140-2 Level 3. Finally, there is increased public key protection and digital signatures are required on all messages.</p>","evaluation_configuration":null,"security_evaluation_summary":"<p>The evaluation was carried out in accordance with the Common Criteria Evaluation and Validation Scheme (CCEVS) process and scheme. The criteria against which the Red Hat Certificate System 8.1 TOE was judged are described in the Common Criteria for Information Technology Security Evaluation, Version 3.1 rev 3.&nbsp; The evaluation methodology used by the evaluation team to conduct the evaluation is the Common Methodology for Information Technology Security Evaluation, Version 3.1 rev 3.&nbsp; Science Applications International Corporation (SAIC) determined that the evaluation assurance level (EAL) for the product is EAL 4 augmented with ALC_FLR.2.&nbsp; The product, when delivered configured as identified in <strong>Implementing a Common Criteria Environment and Common Criteria Environment: A Walkthrough of the Preparation, Installation, and Configuration for a Certified PKI </strong>documents found on the Red Hat website at http://docs.redhat.com/docs/en-US/Red_Hat_Certificate_System_Common_Criteria_Certification/index.html, satisfies all of the security functional requirements stated in the Red Hat Certificate System 8.1 Security Target (Version 1.0). The project underwent Validation Oversight Review (VOR) panel reviews.&nbsp; The evaluation was completed in March 2012.&nbsp; Results of the evaluation can be found in the Common Criteria Evaluation and Validation Scheme Validation Report, (report number CCEVS-VR-10359-2012, dated March 8, 2012) prepared by CCEVS.</p>","environmental_strengths":"<p>The logical boundaries of RHCS 8.1 TOE are realized in the security functions that it implements. These security functions are realized at the network interfaces that service clients and via the administrator commands. Each of these security functions is summarized below.</p>\r\n<p><strong>Identification &amp; Authentication - </strong>RHCS 8.1 ensures that users are identified and authenticated before they can access any other security relevant services.</p>\r\n<p><strong>Access Control - </strong>RHCS 8.1 provides the ability to define an access control list for each service it provides. These access control lists are used to ensure that users can only access services they have been authorized to use.</p>\r\n<p><strong>Security Management - </strong>RHCS 8.1 uses the access control functions to control the actions of administrative personnel. In order to accomplish this, predefined access control lists are assigned to the applicable services.</p>\r\n<p><strong>Security Audit - </strong>RHCS 8.1 has the capability to audit security relevant events.&nbsp; Audit records are generated when audit events occur, including the responsible user, date, time, and other details. Audit records are collected into audit buffers that are signed, to protect against possible tampering of the audit records, and then copied into non-volatile audit logs.</p>\r\n<p><strong>Remote Data Entry &amp; Export - </strong>RHCS 8.1 protects data import and export operations using SSL sessions and secure channels in the case of TMS.</p>\r\n<p><strong>Key Management - </strong>RHCS 8.1 includes a number of key management functions. In particular, RHCS 8.1 protects security critical keys and other information by either encrypting it or storing it within a hardware cryptographic module. RHCS 8.1 also uses digital signatures when appropriate to ensure the integrity of key management related information.</p>\r\n<p><strong>Certificate Management - </strong>RHCS 8.1 includes a number of certificate management functions. In particular, RHCS 8.1 allows administrators to control, limit, or mandate values in certificates, certificate revocation lists (CRLs), and online certificate status protocol (OCSP) responses that are generated.</p>\r\n<p><strong>Strength of Functions - </strong>RHCS 8.1 is designed to make appropriate use of a FIPS 140-2 certified Hardware Security Module (HSM) for critical cryptographic operations</p>","features":[]}