{"product_id":10866,"v_id":10866,"product_name":"MMA10G-EXE","certification_status":"Certified","certification_date":"2018-04-25T00:00:00Z","tech_type":"Network Device","vendor_id":{"name":"Evertz Microsystems","website":"https://www.evertz.com"},"vendor_poc":"Naveed Afzal","vendor_phone":"905-335-3700 x3431","vendor_email":"nafzal@evertz.com","assigned_lab":{"cctl_name":"Acumen Security"},"product_description":"<p>&nbsp;</p>\r\n<p style=\"margin: 0in 0in 0pt;\"><span style=\"font-size: 12.0pt; line-height: 106%; font-family: 'Times New Roman',serif;\">The MMA10G-EXE switch is a 10 Gigabit (Gb) Internet Protocol (IP) switch optimized for video-over-IP traffic (compressed or uncompressed).</span></p>\r\n<p>&nbsp;</p>\r\n<p style=\"margin: 0in 0in 0pt;\"><span style=\"font-size: 12.0pt; line-height: 106%; font-family: 'Times New Roman',serif;\">The MMA10G-EXE builds on the capabilities of the existing Evertz line of video routing switches. Video routers receive video signals in various formats, such as Serial Digital Interface (SDI), Serial Data Transport Interface (SDTI), or Asynchronous Serial Interface (ASI), and switch dedicated physical input ports to dedicated physical output ports based on external commands. Video routing networks utilize dedicated physical plant and are highly efficient, sustainable, and secure. The MMA10G-EXE provides the same capability within the context of packet-based networks using shared network infrastructure.</span></p>","evaluation_configuration":"<p>&nbsp;</p>\r\n<p style=\"margin: 0in 0in 0pt;\"><span style=\"font-size: 12.0pt; line-height: 106%; font-family: 'Times New Roman',serif;\">The MMA10G-EXE switch is a 10 Gigabit (Gb) Internet Protocol (IP) switch optimized for video-over-IP traffic (compressed or uncompressed). </span></p>\r\n<p>&nbsp;</p>\r\n<p style=\"margin: 0in 0in 0pt;\"><span style=\"font-size: 12.0pt; line-height: 106%; font-family: 'Times New Roman',serif;\">The MMA10G-EXE builds on the capabilities of the existing Evertz line of video routing switches. Video routers receive video signals in various formats, such as Serial Digital Interface (SDI), Serial Data Transport Interface (SDTI), or Asynchronous Serial Interface (ASI), and switch dedicated physical input ports to dedicated physical output ports based on external commands. Video routing networks utilize dedicated physical plant and are highly efficient, sustainable, and secure. The MMA10G-EXE provides the same capability within the context of packet-based networks using shared network infrastructure.</span></p>","security_evaluation_summary":"<p><span style=\"font-size: 12.0pt; line-height: 106%; font-family: 'Times New Roman',serif; mso-fareast-font-family: Calibri; mso-fareast-theme-font: minor-latin; mso-ansi-language: EN-US; mso-fareast-language: EN-US; mso-bidi-language: AR-SA;\">The evaluation was carried out in accordance with the Common Criteria Evaluation and Validation Scheme (CCEVS) process and scheme. The criteria against which the Evertz MMA10G-EXE was evaluated are described in the Common Criteria for Information Technology Security Evaluation, Version 3.1 rev 4.<span style=\"mso-spacerun: yes;\">&nbsp; </span>The evaluation methodology used by the evaluation team to conduct the evaluation is the Common Methodology for Information Technology Security Evaluation, Version 3.1 rev 4.<span style=\"mso-spacerun: yes;\">&nbsp; </span>Acumen Security determined that the evaluation assurance level (EAL) for the product is EAL 1.<span style=\"mso-spacerun: yes;\">&nbsp; </span>The product, when delivered configured as identified in the MMA10G-EXE Common Criteria Configuration Guide, satisfies all of the security functional requirements stated in the MMA10G-EXE Security Target. The project underwent CCEVS Validator review.<span style=\"mso-spacerun: yes;\">&nbsp; </span>The evaluation was completed in April 2018.<span style=\"mso-spacerun: yes;\">&nbsp; </span>Results of the evaluation can be found in the Common Criteria Evaluation and Validation Scheme Validation Report prepared by CCEVS.</span><u></u></p>","environmental_strengths":"<p>&nbsp;</p>\r\n<p style=\"margin: 0in 0in 8pt;\"><a name=\"_Hlk506127135\"></a><a name=\"_Toc491963981\"></a><span style=\"mso-bookmark: _Hlk506127135;\"><strong style=\"mso-bidi-font-weight: normal;\"><span style=\"font-size: 12.0pt; line-height: 106%; font-family: 'Times New Roman',serif;\">Security Audit</span></strong></span></p>\r\n<p style=\"margin: 0in 0in 8pt;\"><span style=\"mso-bookmark: _Hlk506127135;\"><span style=\"font-size: 12.0pt; line-height: 106%; font-family: 'Times New Roman',serif;\">The TOE&rsquo;s Audit security function supports audit record generation and review.<span style=\"mso-spacerun: yes;\">&nbsp;&nbsp; </span>The TOE provides date and time information that is used in audit timestamps.<span style=\"mso-spacerun: yes;\">&nbsp;&nbsp; </span>Very broadly, the Audit events generated by the TOE include:</span></span></p>\r\n<p style=\"margin: 0in 0in 10pt 0.5in; line-height: 115%; text-indent: -0.25in;\"><span style=\"mso-bookmark: _Hlk506127135;\"><span style=\"mso-bidi-font-size: 12.0pt; line-height: 115%; font-family: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol;\"><span style=\"mso-list: Ignore;\"><span style=\"font-size: medium;\">&middot;</span><span style=\"font: 7.0pt 'Times New Roman';\">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span></span></span><span style=\"mso-bidi-font-size: 12.0pt; line-height: 115%;\"><span style=\"font-family: Times New Roman; font-size: medium;\">Establishment of a Trusted Path or Channel Session</span></span></span></p>\r\n<p style=\"margin: 0in 0in 10pt 0.5in; line-height: 115%; text-indent: -0.25in;\"><span style=\"mso-bookmark: _Hlk506127135;\"><span style=\"mso-bidi-font-size: 12.0pt; line-height: 115%; font-family: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol;\"><span style=\"mso-list: Ignore;\"><span style=\"font-size: medium;\">&middot;</span><span style=\"font: 7.0pt 'Times New Roman';\">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span></span></span><span style=\"mso-bidi-font-size: 12.0pt; line-height: 115%;\"><span style=\"font-family: Times New Roman; font-size: medium;\">Failure to Establish a Trusted Path or Channel Session</span></span></span></p>\r\n<p style=\"margin: 0in 0in 10pt 0.5in; line-height: 115%; text-indent: -0.25in;\"><span style=\"mso-bookmark: _Hlk506127135;\"><span style=\"mso-bidi-font-size: 12.0pt; line-height: 115%; font-family: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol;\"><span style=\"mso-list: Ignore;\"><span style=\"font-size: medium;\">&middot;</span><span style=\"font: 7.0pt 'Times New Roman';\">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span></span></span><span style=\"mso-bidi-font-size: 12.0pt; line-height: 115%;\"><span style=\"font-family: Times New Roman; font-size: medium;\">Termination of a Trusted Path or Channel Session</span></span></span></p>\r\n<p style=\"margin: 0in 0in 10pt 0.5in; line-height: 115%; text-indent: -0.25in;\"><span style=\"mso-bookmark: _Hlk506127135;\"><span style=\"mso-bidi-font-size: 12.0pt; line-height: 115%; font-family: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol;\"><span style=\"mso-list: Ignore;\"><span style=\"font-size: medium;\">&middot;</span><span style=\"font: 7.0pt 'Times New Roman';\">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span></span></span><span style=\"mso-bidi-font-size: 12.0pt; line-height: 115%;\"><span style=\"font-family: Times New Roman; font-size: medium;\">Failure of Trusted Channel Functions</span></span></span></p>\r\n<p style=\"margin: 0in 0in 10pt 0.5in; line-height: 115%; text-indent: -0.25in;\"><span style=\"mso-bookmark: _Hlk506127135;\"><span style=\"mso-bidi-font-size: 12.0pt; line-height: 115%; font-family: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol;\"><span style=\"mso-list: Ignore;\"><span style=\"font-size: medium;\">&middot;</span><span style=\"font: 7.0pt 'Times New Roman';\">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span></span></span><span style=\"mso-bidi-font-size: 12.0pt; line-height: 115%;\"><span style=\"font-family: Times New Roman; font-size: medium;\">Identification and Authentication</span></span></span></p>\r\n<p style=\"margin: 0in 0in 10pt 0.5in; line-height: 115%; text-indent: -0.25in;\"><span style=\"mso-bookmark: _Hlk506127135;\"><span style=\"mso-bidi-font-size: 12.0pt; line-height: 115%; font-family: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol;\"><span style=\"mso-list: Ignore;\"><span style=\"font-size: medium;\">&middot;</span><span style=\"font: 7.0pt 'Times New Roman';\">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span></span></span><span style=\"mso-bidi-font-size: 12.0pt; line-height: 115%;\"><span style=\"font-family: Times New Roman; font-size: medium;\">Unsuccessful attempt to validate a certificate</span></span></span></p>\r\n<p style=\"margin: 0in 0in 10pt 0.5in; line-height: 115%; text-indent: -0.25in;\"><span style=\"mso-bookmark: _Hlk506127135;\"><span style=\"mso-bidi-font-size: 12.0pt; line-height: 115%; font-family: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol;\"><span style=\"mso-list: Ignore;\"><span style=\"font-size: medium;\">&middot;</span><span style=\"font: 7.0pt 'Times New Roman';\">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span></span></span><span style=\"mso-bidi-font-size: 12.0pt; line-height: 115%;\"><span style=\"font-family: Times New Roman; font-size: medium;\">Any update attempt</span></span></span></p>\r\n<p style=\"margin: 0in 0in 10pt 0.5in; line-height: 115%; text-indent: -0.25in;\"><span style=\"mso-bookmark: _Hlk506127135;\"><span style=\"mso-bidi-font-size: 12.0pt; line-height: 115%; font-family: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol;\"><span style=\"mso-list: Ignore;\"><span style=\"font-size: medium;\">&middot;</span><span style=\"font: 7.0pt 'Times New Roman';\">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span></span></span><span style=\"mso-bidi-font-size: 12.0pt; line-height: 115%;\"><span style=\"font-family: Times New Roman; font-size: medium;\">Result of the update attempt</span></span></span></p>\r\n<p style=\"margin: 0in 0in 10pt 0.5in; line-height: 115%; text-indent: -0.25in;\"><span style=\"mso-bookmark: _Hlk506127135;\"><span style=\"mso-bidi-font-size: 12.0pt; line-height: 115%; font-family: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol;\"><span style=\"mso-list: Ignore;\"><span style=\"font-size: medium;\">&middot;</span><span style=\"font: 7.0pt 'Times New Roman';\">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span></span></span><span style=\"mso-bidi-font-size: 12.0pt; line-height: 115%;\"><span style=\"font-family: Times New Roman; font-size: medium;\">Management of TSF data</span></span></span></p>\r\n<p style=\"margin: 0in 0in 10pt 0.5in; line-height: 115%; text-indent: -0.25in;\"><span style=\"mso-bookmark: _Hlk506127135;\"><span style=\"mso-bidi-font-size: 12.0pt; line-height: 115%; font-family: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol;\"><span style=\"mso-list: Ignore;\"><span style=\"font-size: medium;\">&middot;</span><span style=\"font: 7.0pt 'Times New Roman';\">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span></span></span><span style=\"mso-bidi-font-size: 12.0pt; line-height: 115%;\"><span style=\"font-family: Times New Roman; font-size: medium;\">Changes to Time</span></span></span></p>\r\n<p style=\"margin: 0in 0in 8pt;\"><span style=\"mso-bookmark: _Hlk506127135;\"><span style=\"font-size: 12.0pt; line-height: 106%; font-family: 'Times New Roman',serif;\">The TOE can store the generated audit data on itself and it can be configured to send syslog events to a syslog server, using a TLS protected collection method.<span style=\"mso-spacerun: yes;\">&nbsp; </span>Logs are classified into various predefined categories.<span style=\"mso-spacerun: yes;\">&nbsp;&nbsp; </span>The logging categories help describe the content of the messages that they contain.<span style=\"mso-spacerun: yes;\">&nbsp; </span>Access to the logs is restricted to only Security Administrators, who has no access to edit them, only to copy or delete (clear) them.<span style=\"mso-spacerun: yes;\">&nbsp;&nbsp; </span>Audit records are protected from unauthorized modifications and deletions. The previous audit records are overwritten when the allocated space for these records reaches the threshold on a FIFO basis.</span></span></p>\r\n<p style=\"margin: 0in 0in 8pt;\"><span style=\"mso-bookmark: _Hlk506127135;\"><a name=\"_Toc491963982\"></a><strong style=\"mso-bidi-font-weight: normal;\"><span style=\"font-size: 12.0pt; line-height: 106%; font-family: 'Times New Roman',serif;\">Cryptographic Support</span></strong></span></p>\r\n<p style=\"margin: 0in 0in 8pt; line-height: 115%;\"><span style=\"mso-bookmark: _Hlk506127135;\"><span style=\"font-size: 12.0pt; line-height: 115%; font-family: 'Times New Roman',serif;\">The TOE provides cryptography support for secure communications and protection of information.<span style=\"mso-spacerun: yes;\">&nbsp;&nbsp; </span>The<span style=\"mso-spacerun: yes;\">&nbsp; </span>cryptographic<span style=\"mso-spacerun: yes;\">&nbsp; </span>services<span style=\"mso-spacerun: yes;\">&nbsp; </span>provided<span style=\"mso-spacerun: yes;\">&nbsp; </span>by<span style=\"mso-spacerun: yes;\">&nbsp; </span>the<span style=\"mso-spacerun: yes;\">&nbsp; </span>TOE<span style=\"mso-spacerun: yes;\">&nbsp; </span>include:<span style=\"mso-spacerun: yes;\">&nbsp; </span>symmetric<span style=\"mso-spacerun: yes;\">&nbsp; </span>encryption<span style=\"mso-spacerun: yes;\">&nbsp; </span>and<span style=\"mso-spacerun: yes;\">&nbsp; </span>decryption using<span style=\"mso-spacerun: yes;\">&nbsp; </span>AES; asymmetric<span style=\"mso-spacerun: yes;\">&nbsp; </span>key<span style=\"mso-spacerun: yes;\">&nbsp; </span>generation; cryptographic<span style=\"mso-spacerun: yes;\">&nbsp; </span>key<span style=\"mso-spacerun: yes;\">&nbsp; </span>establishment<span style=\"mso-spacerun: yes;\">&nbsp; </span>using DH<span style=\"mso-spacerun: yes;\">&nbsp; </span>key<span style=\"mso-spacerun: yes;\">&nbsp; </span>establishment; digital<span style=\"mso-spacerun: yes;\">&nbsp; </span>signature<span style=\"mso-spacerun: yes;\">&nbsp; </span>using<span style=\"mso-spacerun: yes;\">&nbsp; </span>RSA;<span style=\"mso-spacerun: yes;\">&nbsp; </span>cryptographic hashing using SHA-256; random bit generation using DRBG and keyed-hash message authentication using HMAC-SHA (SHA-256).<span style=\"mso-spacerun: yes;\">&nbsp;&nbsp; </span>The TOE implements the secure protocols TLS/HTTPS on the server side and TLS on the client side.<span style=\"mso-spacerun: yes;\">&nbsp; </span></span></span></p>\r\n<p style=\"margin: 0in 0in 8pt;\"><span style=\"mso-bookmark: _Hlk506127135;\"><a name=\"_Toc491963983\"></a><strong style=\"mso-bidi-font-weight: normal;\"><span style=\"font-size: 12.0pt; line-height: 106%; font-family: 'Times New Roman',serif;\">Identification and Authentication</span></strong></span></p>\r\n<p style=\"margin: 0in 0in 8pt;\"><span style=\"mso-bookmark: _Hlk506127135;\"><span style=\"font-size: 12.0pt; line-height: 106%; font-family: 'Times New Roman',serif;\">All Administrators wanting to use TOE services are identified and authenticated prior to being allowed access to any of the services other than the display of the warning banner.<span style=\"mso-spacerun: yes;\">&nbsp; </span>(&ldquo;Regular&rdquo; MMA10G-EXE users do not access MMA10G-EXE directly; they control IP video switching through the MMA10G-EXE using a switch control system, such as Evertz&rsquo;s Magnum.<span style=\"mso-spacerun: yes;\">&nbsp; </span>The switching of those IP video transport stream is outside the scope of the TOE.)<span style=\"mso-spacerun: yes;\">&nbsp;&nbsp;&nbsp; </span>Once an Administrator attempts to access the management functionality of the TOE, the TOE prompts the Administrator for a user name and password for password-based authentication.<span style=\"mso-spacerun: yes;\">&nbsp; </span>The identification and authentication credentials are confirmed against a local user database. Only after the Administrator presents the correct identification and authentication credentials will access to the TOE functionality be granted.<span style=\"mso-spacerun: yes;\">&nbsp; </span>The TOE uses X.509v3 certificates as defined by RFC 5280 to support authentication for TLS/HTTPS connections.</span></span></p>\r\n<p style=\"margin: 0in 0in 8pt;\"><span style=\"mso-bookmark: _Hlk506127135;\"><span style=\"font-size: 12.0pt; line-height: 106%; font-family: 'Times New Roman',serif;\">The TOE provides the capability to set password minimum length rules.<span style=\"mso-spacerun: yes;\">&nbsp;&nbsp; </span>This is to ensure the use of<span style=\"mso-spacerun: yes;\">&nbsp; </span>strong<span style=\"mso-spacerun: yes;\">&nbsp; </span>passwords<span style=\"mso-spacerun: yes;\">&nbsp; </span>in<span style=\"mso-spacerun: yes;\">&nbsp; </span>attempts<span style=\"mso-spacerun: yes;\">&nbsp; </span>to<span style=\"mso-spacerun: yes;\">&nbsp; </span>protect<span style=\"mso-spacerun: yes;\">&nbsp; </span>against<span style=\"mso-spacerun: yes;\">&nbsp; </span>brute<span style=\"mso-spacerun: yes;\">&nbsp; </span>force<span style=\"mso-spacerun: yes;\">&nbsp; </span>attacks. The TOE also accepts passwords composed of a variety of characters to support complex password composition.<span style=\"mso-spacerun: yes;\">&nbsp; </span>During authentication, no indication is given of the characters composing the password.</span></span></p>\r\n<p style=\"margin: 0in 0in 8pt;\"><span style=\"mso-bookmark: _Hlk506127135;\"><a name=\"_Toc491963984\"></a><strong style=\"mso-bidi-font-weight: normal;\"><span style=\"font-size: 12.0pt; line-height: 106%; font-family: 'Times New Roman',serif;\">Security Management</span></strong></span></p>\r\n<p style=\"margin: 0in 0in 8pt;\"><span style=\"mso-bookmark: _Hlk506127135;\"><span style=\"font-size: 12.0pt; line-height: 106%; font-family: 'Times New Roman',serif;\">The TOE provides secure administrative services for management of general TOE configuration and the security functionality provided by the TOE.<span style=\"mso-spacerun: yes;\">&nbsp;&nbsp; </span>All TOE administration occurs either through a secure session or a local console connection.<span style=\"mso-spacerun: yes;\">&nbsp; </span>The TOE provides the ability to perform the following actions:</span></span></p>\r\n<p style=\"margin: 0in 0in 10pt 0.5in; line-height: 115%; text-indent: -0.25in;\"><span style=\"mso-bookmark: _Hlk506127135;\"><span style=\"mso-bidi-font-size: 12.0pt; line-height: 115%; font-family: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol;\"><span style=\"mso-list: Ignore;\"><span style=\"font-size: medium;\">&middot;</span><span style=\"font: 7.0pt 'Times New Roman';\">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span></span></span><span style=\"mso-bidi-font-size: 12.0pt; line-height: 115%;\"><span style=\"font-family: Times New Roman; font-size: medium;\">Administer the TOE locally and remotely</span></span></span></p>\r\n<p style=\"margin: 0in 0in 10pt 0.5in; line-height: 115%; text-indent: -0.25in;\"><span style=\"mso-bookmark: _Hlk506127135;\"><span style=\"mso-bidi-font-size: 12.0pt; line-height: 115%; font-family: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol;\"><span style=\"mso-list: Ignore;\"><span style=\"font-size: medium;\">&middot;</span><span style=\"font: 7.0pt 'Times New Roman';\">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span></span></span><span style=\"mso-bidi-font-size: 12.0pt; line-height: 115%;\"><span style=\"font-family: Times New Roman; font-size: medium;\">Configure the access banner</span></span></span></p>\r\n<p style=\"margin: 0in 0in 10pt 0.5in; line-height: 115%; text-indent: -0.25in;\"><span style=\"mso-bookmark: _Hlk506127135;\"><span style=\"mso-bidi-font-size: 12.0pt; line-height: 115%; font-family: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol;\"><span style=\"mso-list: Ignore;\"><span style=\"font-size: medium;\">&middot;</span><span style=\"font: 7.0pt 'Times New Roman';\">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span></span></span><span style=\"mso-bidi-font-size: 12.0pt; line-height: 115%;\"><span style=\"font-family: Times New Roman; font-size: medium;\">Configure the cryptographic services</span></span></span></p>\r\n<p style=\"margin: 0in 0in 10pt 0.5in; line-height: 115%; text-indent: -0.25in;\"><span style=\"mso-bookmark: _Hlk506127135;\"><span style=\"mso-bidi-font-size: 12.0pt; line-height: 115%; font-family: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol;\"><span style=\"mso-list: Ignore;\"><span style=\"font-size: medium;\">&middot;</span><span style=\"font: 7.0pt 'Times New Roman';\">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span></span></span><span style=\"mso-bidi-font-size: 12.0pt; line-height: 115%;\"><span style=\"font-family: Times New Roman; font-size: medium;\">Update the TOE and verify the updates using digital signature capability prior to installing those updates</span></span></span></p>\r\n<p style=\"margin: 0in 0in 10pt 0.5in; line-height: 115%; text-indent: -0.25in;\"><span style=\"mso-bookmark: _Hlk506127135;\"><span style=\"mso-bidi-font-size: 12.0pt; line-height: 115%; font-family: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol;\"><span style=\"mso-list: Ignore;\"><span style=\"font-size: medium;\">&middot;</span><span style=\"font: 7.0pt 'Times New Roman';\">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span></span></span><span style=\"mso-bidi-font-size: 12.0pt; line-height: 115%;\"><span style=\"font-family: Times New Roman; font-size: medium;\">Specify the time limits of session inactivity</span></span></span></p>\r\n<p style=\"margin: 0in 0in 8pt;\"><span style=\"mso-bookmark: _Hlk506127135;\"><span style=\"font-size: 12.0pt; line-height: 106%; font-family: 'Times New Roman',serif;\">All of these management functions are restricted to an Administrator, which covers all administrator<span style=\"mso-spacerun: yes;\">&nbsp;&nbsp; </span>roles.<span style=\"mso-spacerun: yes;\">&nbsp; </span>Administrators are individuals who manage specific type of administrative tasks.<span style=\"mso-spacerun: yes;\">&nbsp; </span>In MMA10G-EXE only the admin role exists, since there is no provision for &ldquo;regular&rdquo; users to access MMA10G-EXE <u>directly</u> (as described above), and the portion of MMA10G-EXE they access and control are outside the scope of the TOE. </span></span></p>\r\n<p style=\"margin: 0in 0in 8pt;\"><span style=\"mso-bookmark: _Hlk506127135;\"><span style=\"font-size: 12.0pt; line-height: 106%; font-family: 'Times New Roman',serif;\">Primary management is done using the web-based interface using HTTPS.<span style=\"mso-spacerun: yes;\">&nbsp;&nbsp; </span>This provides a network administration console from which one can manage various identity services.<span style=\"mso-spacerun: yes;\">&nbsp; </span>These services include authentication, authorization and reporting.<span style=\"mso-spacerun: yes;\">&nbsp; </span>All of these services can be managed from the web browser, which uses a menu-driven navigation system.<span style=\"mso-spacerun: yes;\">&nbsp; </span></span></span></p>\r\n<p style=\"margin: 0in 0in 8pt;\"><span style=\"mso-bookmark: _Hlk506127135;\"><span style=\"font-size: 12.0pt; line-height: 106%; font-family: 'Times New Roman',serif;\">There is also a very simple serial-based connection (RS-232) that provides a simple menu interface.<span style=\"mso-spacerun: yes;\">&nbsp;&nbsp; </span>This is used to configure the IP interface (IP address, etc.).<span style=\"mso-spacerun: yes;\">&nbsp; </span>It is password-protected, and is typically only used once, for initial set-up.</span></span></p>\r\n<p style=\"margin: 0in 0in 8pt;\"><span style=\"mso-bookmark: _Hlk506127135;\"><a name=\"_Toc491963985\"></a><strong style=\"mso-bidi-font-weight: normal;\"><span style=\"font-size: 12.0pt; line-height: 106%; font-family: 'Times New Roman',serif;\">Protection of the TSF</span></strong></span></p>\r\n<p style=\"margin: 0in 0in 8pt;\"><span style=\"mso-bookmark: _Hlk506127135;\"><span style=\"font-size: 12.0pt; line-height: 106%; font-family: 'Times New Roman',serif;\">The TOE will terminate inactive sessions after an Administrator-configurable time period.<span style=\"mso-spacerun: yes;\">&nbsp;&nbsp; </span>Once a session has been terminated the TOE requires the user to re-authenticate to establish a new session.<span style=\"mso-spacerun: yes;\">&nbsp;&nbsp; </span>The TOE provides protection of TSF data (authentication data and cryptographic keys).<span style=\"mso-spacerun: yes;\">&nbsp;&nbsp; </span>In addition, the TOE internally maintains the date and time. This date and time is used as the time stamp that is applied to TOE generated audit records. An external NTP server can be used for time updates. The TOE also ensures firmware updates are from a reliable source.<span style=\"mso-spacerun: yes;\">&nbsp;&nbsp; </span>Finally, the TOE performs testing to verify correct operation.</span></span></p>\r\n<p style=\"margin: 0in 0in 8pt;\"><span style=\"mso-bookmark: _Hlk506127135;\"><span style=\"font-size: 12.0pt; line-height: 106%; font-family: 'Times New Roman',serif;\">In<span style=\"mso-spacerun: yes;\">&nbsp; </span>order<span style=\"mso-spacerun: yes;\">&nbsp; </span>for<span style=\"mso-spacerun: yes;\">&nbsp; </span>updates<span style=\"mso-spacerun: yes;\">&nbsp; </span>to<span style=\"mso-spacerun: yes;\">&nbsp; </span>be<span style=\"mso-spacerun: yes;\">&nbsp; </span>installed<span style=\"mso-spacerun: yes;\">&nbsp; </span>on<span style=\"mso-spacerun: yes;\">&nbsp; </span>the<span style=\"mso-spacerun: yes;\">&nbsp; </span>TOE,<span style=\"mso-spacerun: yes;\">&nbsp; </span>an<span style=\"mso-spacerun: yes;\">&nbsp; </span>administrator<span style=\"mso-spacerun: yes;\">&nbsp; </span>initiates the process from the web interface.<span style=\"mso-spacerun: yes;\">&nbsp; </span>MMA10G-EXE automatically uses the RSA digital signature mechanism to confirm the integrity of the product before installing the update.</span></span></p>\r\n<p style=\"margin: 0in 0in 8pt;\"><span style=\"mso-bookmark: _Hlk506127135;\"><a name=\"_Toc491963986\"></a><strong style=\"mso-bidi-font-weight: normal;\"><span style=\"font-size: 12.0pt; line-height: 106%; font-family: 'Times New Roman',serif;\">TOE Access</span></strong></span></p>\r\n<p style=\"margin: 0in 0in 8pt;\"><span style=\"mso-bookmark: _Hlk506127135;\"><span style=\"font-size: 12.0pt; line-height: 106%; font-family: 'Times New Roman',serif;\">Aside from the automatic Administrators session termination due to inactivity describes above, the TOE also allows Administrators to terminate their own interactive session.<span style=\"mso-spacerun: yes;\">&nbsp;&nbsp; </span>Once a session has been terminated the TOE requires the user to re-authenticate to establish a new session.<span style=\"mso-spacerun: yes;\">&nbsp; </span></span></span></p>\r\n<p style=\"margin: 0in 0in 8pt;\"><span style=\"mso-bookmark: _Hlk506127135;\"><span style=\"font-size: 12.0pt; line-height: 106%; font-family: 'Times New Roman',serif;\">The TOE will display an Administrator-specified banner on the web browser management interface prior to allowing any administrative access to the TOE.</span></span></p>\r\n<p style=\"margin: 0in 0in 8pt;\"><span style=\"mso-bookmark: _Hlk506127135;\"><a name=\"_Toc491963987\"></a><strong style=\"mso-bidi-font-weight: normal;\"><span style=\"font-size: 12.0pt; line-height: 106%; font-family: 'Times New Roman',serif;\">Trusted Paths/Channels</span></strong></span></p>\r\n<p style=\"margin: 0in 0in 0pt;\"><span style=\"mso-bookmark: _Hlk506127135;\"><span style=\"font-size: 12.0pt; line-height: 106%; font-family: 'Times New Roman',serif;\">The TOE allows the establishment of a trusted path between a video control system (such as Evertz&rsquo; Magnum) and the MMA10G-EXE.<span style=\"mso-spacerun: yes;\">&nbsp;&nbsp; </span>The TOE also establishes a secure connection for sending syslog data to a syslog server using TLS and other external authentication stores using TLS-protected communications.</span></span></p>","features":[]}