{"product_id":11085,"v_id":11085,"product_name":"Palo Alto Networks GlobalProtect App Version 5.1.5","certification_status":"Certified","certification_date":"2020-08-17T00:00:00Z","tech_type":"Application Software","vendor_id":{"name":"Palo Alto Networks, Inc.","website":"https://www.paloaltonetworks.com"},"vendor_poc":"Jake Bajic","vendor_phone":"408-753-3901","vendor_email":"jbajic@paloaltonetworks.com","assigned_lab":{"cctl_name":"Leidos Common Criteria Testing Laboratory"},"product_description":"<p class=\"MsoNormal\">The TOE is the Palo Alto Networks GlobalProtect App that provides users with the ability to access their company network resources via the Palo Alto Networks GlobalProtect Portals and Gateways that have been deployed.<span style=\"mso-spacerun: yes;\">&nbsp; </span>The TOE also provides several management functions that includes, for examples, allowing the endpoint user to select their desired gateway, and to collect troubleshooting logs from the TOE.<span style=\"mso-spacerun: yes;\">&nbsp; </span>Additional components that interact with the TOE are noted in the TOE Overview.<span style=\"mso-spacerun: yes;\">&nbsp; </span></p>\r\n<p class=\"MsoNormal\">The GlobalProtect app is a software program that runs on the endpoint (desktop/laptop computer) to protect users by using the same security policies that protect the sensitive resources in corporate networks. The GlobalProtect app secures the traffic using TLS and allows users to connect to corporate networks to access company&rsquo;s resources from anywhere in the world (e.g. when users are remote). The TOE runs on either Windows 10 or macOS version 10.14.<span style=\"mso-spacerun: yes;\">&nbsp; </span></p>","evaluation_configuration":"","security_evaluation_summary":"<p class=\"MsoNormal\">The evaluation was carried out in accordance with the Common Criteria Evaluation and Validation Scheme (CCEVS) process and scheme for the <em style=\"mso-bidi-font-style: normal;\">Protection Profile for Application Software</em>, Version 1.3 and the <em style=\"mso-bidi-font-style: normal;\">Functional Package for Transport Layer Security (TLS)</em>, Version 1.1.<span style=\"mso-spacerun: yes;\">&nbsp; </span>The evaluation methodology used by the evaluation team to conduct the evaluation is the Common Methodology for Information Technology Security Evaluation, Version 3.1 release 5. The product, when delivered configured as identified in the guidance document, satisfies all of the security functional requirements stated in the Palo Alto Networks GlobalProtect App Version 5.1.5 Security Target. The evaluation was completed in August 2020.<span style=\"mso-spacerun: yes;\">&nbsp; </span>Results of the evaluation can be found in the Common Criteria Evaluation and Validation Scheme Validation Report prepared by CCEVS.</p>","environmental_strengths":"<p class=\"MsoNormal\"><strong style=\"mso-bidi-font-weight: normal;\"><em style=\"mso-bidi-font-style: normal;\">Cryptographic Support</em></strong></p>\r\n<p class=\"MsoNormal\">The TOE implements NIST validated cryptographic algorithms that provide key management, random bit generation, encryption/decryption, digital signature and cryptographic hashing and keyed-hash message authentication features in support of cryptographic protocols such as TLS.<span style=\"mso-spacerun: yes;\">&nbsp; </span>In order to utilize these features, the TOE must be configured in FIPS-CC mode.<span style=\"mso-spacerun: yes;\">&nbsp; </span></p>\r\n<p class=\"MsoNormal\">GlobalProtect App includes algorithms that are covered by CAVP certificates that are noted in this document. In addition, the TOE also relies on the underlying platforms Windows 10 and macOS.</p>\r\n<p class=\"MsoNormal\"><strong style=\"mso-bidi-font-weight: normal;\"><em style=\"mso-bidi-font-style: normal;\">User Data Protection</em></strong></p>\r\n<p class=\"MsoNormal\">The TOE restricts its access to only using network connectivity when it is needed to communicate to the Palo Alto Networks Gateway or Portal.<span style=\"mso-spacerun: yes;\">&nbsp; </span>Other functionality on the host platform such as its camera, Bluetooth, USB, or microphone are not needed.<span style=\"mso-spacerun: yes;\">&nbsp; </span>The TOE does not store any sensitive data in non-volatile memory.<span style=\"mso-spacerun: yes;\">&nbsp; </span></p>\r\n<p class=\"MsoNormal\"><strong style=\"mso-bidi-font-weight: normal;\"><em style=\"mso-bidi-font-style: normal;\">Identification and Authentication</em></strong></p>\r\n<p class=\"MsoNormal\">The TOE authenticates the X.509 certificate of the Palo Alto Networks GlobalProtect Gateway/Portal as part of establishing a TLS connection.<span style=\"mso-spacerun: yes;\">&nbsp; </span></p>\r\n<p class=\"MsoNormal\"><strong style=\"mso-bidi-font-weight: normal;\"><em style=\"mso-bidi-font-style: normal;\">Security Management</em></strong></p>\r\n<p class=\"MsoNormal\">The TOE provides access to the security management features using an interface on a general-purpose computer.<span style=\"mso-spacerun: yes;\">&nbsp; </span>Security management operations are provided to the user of the TOE.<span style=\"mso-spacerun: yes;\">&nbsp; </span>A user is able to perform security management by configuring necessary items such as assigning the Palo Alto Networks GlobalProtect Portal and Gateway that the TOE will use for its connections.<span style=\"mso-spacerun: yes;\">&nbsp; </span>It also provides the user with the ability to collect troubleshooting logs, configure gateway and portal, check the current version, check for updates, and to enable/disable the transmission of information regarding the system&rsquo;s hardware/software or configuration.<span style=\"mso-spacerun: yes;\">&nbsp; </span>The TOE relies on the OS&rsquo; network ports (i.e. ethernet ports) for communication and management capabilities.<span style=\"mso-spacerun: yes;\">&nbsp; </span></p>\r\n<p class=\"MsoNormal\">In order to install or uninstall the TOE, the user is required to have platform administrator privileges.<span style=\"mso-spacerun: yes;\">&nbsp; </span></p>\r\n<p class=\"MsoNormal\"><strong style=\"mso-bidi-font-weight: normal;\"><em style=\"mso-bidi-font-style: normal;\">Privacy</em></strong></p>\r\n<p class=\"MsoNormal\">The TOE does not transmit PII over a network.</p>\r\n<p class=\"MsoNormal\"><strong style=\"mso-bidi-font-weight: normal;\"><em style=\"mso-bidi-font-style: normal;\">Protection of the TSF</em></strong></p>\r\n<p class=\"MsoNormal\">The TOE implements a variety of functions to ensure that it is protected against corruption.<span style=\"mso-spacerun: yes;\">&nbsp; </span>These include utilizing platform APIs, memory mapping, and stack-based buffer overflow protection.<span style=\"mso-spacerun: yes;\">&nbsp; </span>Palo Alto Networks provides customers with a means of updating their TOE using trusted updates.<span style=\"mso-spacerun: yes;\">&nbsp; </span>These trusted updates are securely delivered and installed using protection mechanisms such as TLS, and by using approved digital signature methods.<span style=\"mso-spacerun: yes;\">&nbsp; </span>All of these updates are properly signed using RSA 2048 with SHA-256.<span style=\"mso-spacerun: yes;\">&nbsp; </span>The trusted update site also provides a checksum of the updates that can be used for additional verification before it is utilized.</p>\r\n<p class=\"MsoNormal\"><strong style=\"mso-bidi-font-weight: normal;\"><em style=\"mso-bidi-font-style: normal;\">Trusted Path/Channels</em></strong></p>\r\n<p class=\"MsoNormal\">The TOE protects communication between itself as the endpoint and other networks using TLS.<span style=\"mso-spacerun: yes;\">&nbsp; </span>TLS 1.2 is utilized to encrypt all data that is passed from the TOE to other components (i.e. Palo Alto Networks GlobalProtect Portals and Gateways).<span style=\"mso-spacerun: yes;\">&nbsp; </span></p>","features":[]}