{"product_id":10495,"v_id":10495,"product_name":"HP StoreOnce Backup System","certification_status":"Not Certified","certification_date":"2014-02-27T00:02:00Z","tech_type":"Miscellaneous","vendor_id":{"name":"Hewlett-Packard Company","website":"www.hp.com"},"vendor_poc":"Noel Rodrigues","vendor_phone":"+44 (0)-117-312-9467","vendor_email":"noel.rodrigues@hp.com","assigned_lab":{"cctl_name":"Leidos Common Criteria Testing Laboratory"},"product_description":"<p>HP StoreOnce Backup System, Generation 3 Version 3.6.6</p>\r\n<p><span style=\"text-decoration: underline;\">Hardware Models</span></p>\r\n<table border=\"1\" cellspacing=\"0\" cellpadding=\"0\">\r\n<tbody>\r\n<tr>\r\n<td width=\"265\">\r\n<p class=\"Body\"><strong>Single Node   Appliances</strong></p>\r\n</td>\r\n<td width=\"255\">\r\n<p class=\"Body\"><strong>Multi-Node   Appliances</strong></p>\r\n</td>\r\n</tr>\r\n<tr>\r\n<td width=\"265\" valign=\"top\">\r\n<p class=\"Body\">HP StoreOnce 2610   iSCSI Backup</p>\r\n<p class=\"Body\">HP StoreOnce 2620   iSCSI Backup</p>\r\n<p class=\"Body\">HP StoreOnce 4210   iSCSI Backup</p>\r\n<p class=\"Body\">HP StoreOnce 4210   FC Backup</p>\r\n<p class=\"Body\">HP StoreOnce 4220   Backup</p>\r\n<p class=\"Body\">HP StoreOnce 4420   Backup</p>\r\n<p class=\"Body\">HP StoreOnce 4430   Backup</p>\r\n</td>\r\n<td width=\"255\" valign=\"top\">\r\n<p class=\"Body\">HP StoreOnce B6200 Backup   System</p>\r\n</td>\r\n</tr>\r\n</tbody>\r\n</table>\r\n<p>&nbsp;Henceforth, the above referenced software on the above referenced hardware is referred to as the TOE or StoreOnce.</p>\r\n<p class=\"Body\">The Target of Evaluation (TOE) is an HP StoreOnce Backup System with one or more hardware appliances.&nbsp; The TOE models that offer either a single-node or multi-node system and are running Generation 3 Version 3.6.6 software are the target of evaluation.&nbsp; The following appliances allow the TOE to provide varying types of fault-tolerance and are the hardware platform for the TOE.&nbsp;</p>\r\n<ul>\r\n<li>HP StoreOnce B6200</li>\r\n<li>HP StoreOnce 2610 iSCSI Backup</li>\r\n<li>HP StoreOnce 2620 iSCSI Backup</li>\r\n<li>HP StoreOnce 4210 iSCSI Backup</li>\r\n<li>HP StoreOnce 4210 FC Backup</li>\r\n<li>HP StoreOnce 4220 Backup</li>\r\n<li>HP StoreOnce 4420 Backup</li>\r\n</ul>\r\n<p class=\"Body\">HP StoreOnce Single-node appliances operate as standalone devices and do not operate as part of a cluster.&nbsp;</p>\r\n<p class=\"Body\">Multi-node appliances operate as a cluster.&nbsp; A cluster is composed of from 1 to 4 couplets, each couplet having two nodes.&nbsp; A cluster is the scope of administrative control, with the configuration of the cluster defining the behavior of all nodes within the cluster.&nbsp;</p>\r\n<p>The B6200 appliance is a multi-node appliance.&nbsp; The number of nodes in a model B6200 is determined by the customer.&nbsp; The B6200 can be ordered as a single couplet (2 nodes), a 2 couplet (4 node) cluster, a 3 couplet (6 node) cluster or a 4 couplet (8 node) cluster.&nbsp; A customer can buy a cluster of one couplet and then buy additional couplets to expand the cluster up to a maximum of 4 couplets.</p>","evaluation_configuration":null,"security_evaluation_summary":"<p>The evaluation was carried out in accordance to the Common Criteria Evaluation and Validation Scheme (CCEVS) process and scheme. The evaluation demonstrated that the&nbsp;&nbsp; TOE<em> </em>meets the security requirements contained in the Security Target.&nbsp; The criteria against which the&nbsp;&nbsp; TOE was judged are described in the Common Criteria for Information Technology Security Evaluation, Version 3.1 Revision 3. The evaluation methodology used by the evaluation team to conduct the evaluation is the Common Methodology for Information Technology Security Evaluation, Version 3.1 Revision 3.&nbsp; Leidos determined that the evaluation assurance level (EAL) for the TOE is EAL 2 augmented with ALC_FLR.3.&nbsp; The TOE, configured as specified in the installation guide, satisfies all of the security functional requirements stated in the Security Target.&nbsp; Several validators on behalf of the CCEVS Validation Body monitored the evaluation carried out by Leidos.&nbsp;</p>\r\n<p>It must be noted that the TOE assumes that it is in a relatively benign security environment; the client hosts are presumed to be within the same physical area as the TOE, are accorded the same physical protections as the TOE, and are trusted to present their host identifiers (e.g., IP address, Fibre Channel port number) accurately. Accordingly, the TOE accepts the identifier presented and does not authenticate the identity of the host. This is reflected in the assumption A.HOST_IDENTITY, defined in the Security Target (ST) Thus, if the TOE environment does not satisfy the security assumption of trusted client hosts, then some authentication method must be provided.</p>","environmental_strengths":"<p>The HP StoreOnce Backup System is a disk-based storage appliance for backing up host network servers or PCs to target devices on the appliance. These devices are configured as either Network-Attached Storage (NAS) or Virtual Tape Library (VTL) or StoreOnce Catalyst targets for backup applications.</p>\r\n<p class=\"Body\">The HP StoreOnce Backup System products are hardware appliances that offer network accessible administration interfaces in the form of an HTTPS based Graphical User Interface or SSH protected Command Line Interface.</p>\r\n<p>A single node appliance or a couplet provides network access using a number of network distinct ports.&nbsp; There are four (4) physical 1GB ports and two (2) physical 10GB ports for Ethernet connections.&nbsp; Another two (2) 10GB network connections are used for the internal network (internal to the cluster only) and are not accessible to client-hosts.&nbsp; Fibre Channel connections (available on some appliances) are only used to present VTL devices that have been configured on the nodes in a couplet.</p>\r\n<p class=\"Body\">Remote administration sessions occurring through the management network are protected using cryptography (SSH and HTTPS).&nbsp; Network traffic between the product and NTP or LDAP servers occurs utilizing only protections inherent in the NTP and LDAP protocols.&nbsp; The HP StoreOnce Backup System allows a site to choose to combine the data and management networks.&nbsp; In single-node configurations, the data and management network must be combined.&nbsp; Both single-node and multi-node configurations utilize an Internal network for communication with storage devices.&nbsp;</p>\r\n<p>The HP StoreOnce Backup Systems provides Ethernet network connections for use as a management network (i.e., used for all management traffic).&nbsp; All Ethernet-based networks support only IPv4 networking functionality.&nbsp; IPSec and IPv6 security features are not available, though some protection is supported for administrator network communications (e.g., SSH and HTTPS).&nbsp; The data network can be either Ethernet or Fibre Channel.&nbsp; The internal network will be Ethernet.</p>","features":[]}