{"product_id":11157,"v_id":11157,"product_name":"VMware Workspace ONE Boxer Email Client Version 21.05","certification_status":"Certified","certification_date":"2021-10-05T00:00:00Z","tech_type":"Application Software, Email Client","vendor_id":{"name":"VMware, LLC","website":"www.vmware.com"},"vendor_poc":"Vann Nguyen","vendor_phone":"650-427-5000","vendor_email":"vannn@vmware.com","assigned_lab":{"cctl_name":"Booz Allen Hamilton Common Criteria Testing Laboratory"},"product_description":"<p>The TOE is the VMware Workspace ONE Boxer Email Client Version 21.05 application which is an enterprise email client for iOS and Android mobile devices. The Boxer application provides S/MIME email services and containerizes enterprise data from personal data that resides on the user&rsquo;s mobile device.</p>","evaluation_configuration":"<p>In the evaluated configuration, the TOE is installed on a mobile device running iOS 13 (VID11036) as well as a mobile device host running Android 10 (VID11042). The mobile devices must be enrolled and managed by the VMware Workspace ONE Unified Endpoint Management (UEM) at the device level. When the TOE application is installed on the mobile device it is then enrolled as a managed application in UEM in order to obtain its configuration information.</p>\r\n<p>Additionally, the TOE is configured to use ActiveSync to communicate with the Microsoft Exchange server over a TLS v1.2 trusted channel. The Exchange server resides in the operational environment and is for sending and receiving enterprise data such as email, calendar information and appointment data. Whether installed on an Android or iOS device, the application validates the certificates using OCSP. The OCSP responder is also considered part of the operational environment.</p>\r\n<p>The following list identifies the components and applications in the environment that the TOE relies upon in order to function properly:</p>\r\n<p>&nbsp;</p>\r\n<table class=\"ST-TABLE11\" style=\"width: 422.5pt; margin-left: .5pt; border-collapse: collapse; border: none; mso-border-alt: solid #7BA0CD 1.0pt; mso-yfti-tbllook: 1184; mso-padding-alt: 0in 5.75pt 0in 5.75pt;\" border=\"1\" width=\"563\" cellspacing=\"0\" cellpadding=\"0\">\r\n<tbody>\r\n<tr style=\"mso-yfti-irow: -1; mso-yfti-firstrow: yes; mso-yfti-lastfirstrow: yes; height: 18.4pt;\">\r\n<td style=\"width: 175.0pt; border: solid windowtext 1.0pt; mso-border-alt: solid windowtext .5pt; background: black; padding: 0in 5.75pt 0in 5.75pt; height: 18.4pt;\" width=\"233\">\r\n<p class=\"MsoNormal\" style=\"line-height: 115%; mso-pagination: none; mso-yfti-cnfc: 5; margin: 6.0pt 0in 6.0pt 0in;\"><a name=\"_Hlk31795038\"></a><strong><span style=\"font-size: 11.0pt; line-height: 115%; font-family: 'Times New Roman',serif; mso-fareast-font-family: Calibri; color: white;\">Component</span></strong></p>\r\n</td>\r\n<td style=\"width: 247.5pt; border: solid windowtext 1.0pt; border-left: none; mso-border-left-alt: solid windowtext .5pt; mso-border-alt: solid windowtext .5pt; background: black; padding: 0in 5.75pt 0in 5.75pt; height: 18.4pt;\" width=\"330\">\r\n<p class=\"MsoNormal\" style=\"line-height: 115%; mso-pagination: none; mso-yfti-cnfc: 1; margin: 6.0pt 0in 6.0pt 0in;\"><span style=\"mso-bookmark: _Hlk31795038;\"><strong><span style=\"font-size: 11.0pt; line-height: 115%; font-family: 'Times New Roman',serif; mso-fareast-font-family: Calibri; color: white;\">Definition</span></strong></span></p>\r\n</td>\r\n</tr>\r\n<tr style=\"mso-yfti-irow: 0;\">\r\n<td style=\"width: 175.0pt; border: solid windowtext 1.0pt; border-top: none; mso-border-top-alt: solid windowtext .5pt; mso-border-alt: solid windowtext .5pt; background: #D9D9D9; padding: 0in 5.75pt 0in 5.75pt;\" width=\"233\">\r\n<p class=\"MsoNormal\" style=\"line-height: 115%; mso-pagination: none; mso-yfti-cnfc: 68; margin: 6.0pt 0in 6.0pt 0in;\"><strong><a name=\"_Hlk67045027\"></a>OCSP Responder</strong></p>\r\n</td>\r\n<td style=\"width: 247.5pt; border-top: none; border-left: none; border-bottom: solid windowtext 1.0pt; border-right: solid windowtext 1.0pt; mso-border-top-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-alt: solid windowtext .5pt; background: #D9D9D9; padding: 0in 5.75pt 0in 5.75pt;\" width=\"330\">\r\n<p class=\"MsoNormal\" style=\"line-height: 115%; mso-pagination: none; mso-yfti-cnfc: 64; margin: 6.0pt 0in 6.0pt 0in;\">A server deployed within the Operational Environment which confirms the validity and revocation status of certificates.</p>\r\n</td>\r\n</tr>\r\n<tr style=\"mso-yfti-irow: 1;\">\r\n<td style=\"width: 175.0pt; border: solid windowtext 1.0pt; border-top: none; mso-border-top-alt: solid windowtext .5pt; mso-border-alt: solid windowtext .5pt; padding: 0in 5.75pt 0in 5.75pt;\" width=\"233\">\r\n<p class=\"MsoNormal\" style=\"line-height: 115%; mso-pagination: none; mso-yfti-cnfc: 132; margin: 6.0pt 0in 6.0pt 0in;\"><strong>VMware Workspace ONE Unified Endpoint Management (UEM) Server</strong></p>\r\n</td>\r\n<td style=\"width: 247.5pt; border-top: none; border-left: none; border-bottom: solid windowtext 1.0pt; border-right: solid windowtext 1.0pt; mso-border-top-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-alt: solid windowtext .5pt; padding: 0in 5.75pt 0in 5.75pt;\" width=\"330\">\r\n<p class=\"MsoNormal\" style=\"line-height: 115%; mso-pagination: none; mso-yfti-cnfc: 128; margin: 6.0pt 0in 6.0pt 0in;\">The VMware Workspace ONE UEM server is used to manage the VMware Boxer app (TOE) and its host mobile device. The UEM Server provides administrative access through its UEM Console.</p>\r\n</td>\r\n</tr>\r\n<tr style=\"mso-yfti-irow: 2;\">\r\n<td style=\"width: 175.0pt; border: solid windowtext 1.0pt; border-top: none; mso-border-top-alt: solid windowtext .5pt; mso-border-alt: solid windowtext .5pt; background: #D9D9D9; padding: 0in 5.75pt 0in 5.75pt;\" width=\"233\">\r\n<p class=\"MsoNormal\" style=\"line-height: 115%; mso-pagination: none; mso-yfti-cnfc: 68; margin: 6.0pt 0in 6.0pt 0in;\"><strong>Microsoft Exchange Server 2019</strong></p>\r\n</td>\r\n<td style=\"width: 247.5pt; border-top: none; border-left: none; border-bottom: solid windowtext 1.0pt; border-right: solid windowtext 1.0pt; mso-border-top-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-alt: solid windowtext .5pt; background: #D9D9D9; padding: 0in 5.75pt 0in 5.75pt;\" width=\"330\">\r\n<p class=\"MsoNormal\" style=\"line-height: 115%; mso-pagination: none; mso-yfti-cnfc: 64; margin: 6.0pt 0in 6.0pt 0in;\">Exchange server for sending and receiving emails to and from the Operational Environment configured to use ActiveSync to communicate.</p>\r\n</td>\r\n</tr>\r\n<tr style=\"mso-yfti-irow: 3; mso-yfti-lastrow: yes;\">\r\n<td style=\"width: 175.0pt; border: solid windowtext 1.0pt; border-top: none; mso-border-top-alt: solid windowtext .5pt; mso-border-alt: solid windowtext .5pt; padding: 0in 5.75pt 0in 5.75pt;\" width=\"233\">\r\n<p class=\"MsoNormalCxSpMiddle\" style=\"mso-add-space: auto; line-height: 115%; mso-pagination: none; mso-yfti-cnfc: 132; margin: 6.0pt 0in 6.0pt 0in;\"><strong>Mobile Device</strong></p>\r\n</td>\r\n<td style=\"width: 247.5pt; border-top: none; border-left: none; border-bottom: solid windowtext 1.0pt; border-right: solid windowtext 1.0pt; mso-border-top-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-alt: solid windowtext .5pt; padding: 0in 5.75pt 0in 5.75pt;\" width=\"330\">\r\n<p class=\"MsoNormalCxSpMiddle\" style=\"line-height: 115%; mso-yfti-cnfc: 128;\">The hardware that runs the OS in which the application is installed on.</p>\r\n<p class=\"MsoNormalCxSpMiddle\" style=\"line-height: 115%; mso-yfti-cnfc: 128;\"><span style=\"mso-bookmark: _Hlk31795038;\"><span style=\"mso-bookmark: _Hlk67045027;\"><span style=\"font-size: 11.0pt; line-height: 115%; font-family: 'Times New Roman',serif; mso-fareast-font-family: Calibri;\">&nbsp;</span></span></span></p>\r\n<p class=\"MsoNormalCxSpMiddle\" style=\"line-height: 115%; mso-yfti-cnfc: 128;\">The TOE was installed on a certified iOS 13 (VID11036)device and certified Android 10 (VID11042) device. For testing, this evaluation used a Samsung Galaxy S10+ (Android) and on an iPhone Xs (Apple).</p>\r\n</td>\r\n</tr>\r\n</tbody>\r\n</table>","security_evaluation_summary":"<p class=\"MsoNormal\">The evaluation was carried out in accordance with the Common Criteria Evaluation and Validation Scheme (CCEVS) processes and procedures. VMware Workspace ONE Boxer Email Client Version 21.05 was evaluated against the criteria contained in the Common Criteria for Information Technology Security Evaluation, Version 3.1 Revision 5. The evaluation methodology used by the evaluation team to conduct the evaluation is the Common Methodology for Information Technology Security Evaluation, Version 3.1 Revision 5. The product, when installed and configured per the instructions provided in the preparative guidance, satisfies all of the security functional requirements stated in the <em><a name=\"_Hlk78216061\"></a>VMware Workspace ONE Boxer Email Client Version 21.05 Security Target V1.5, </em>dated September 21, 2021. The evaluation underwent CCEVS Validator review. The evaluation was completed in October 2021. Results of the evaluation can be found in the Common Criteria Evaluation and Validation Scheme Validation Report, CCEVS-VR-VID11157-2021 prepared by CCEVS.</p>","environmental_strengths":"<p class=\"MsoNormal\" style=\"mso-pagination: widow-orphan lines-together; page-break-after: avoid; mso-outline-level: 3; margin: 10.0pt 0in 6.0pt 0in;\"><a name=\"_Hlk78216955\"></a><a name=\"_Hlk512945721\"></a><a name=\"_Toc41726772\"></a><strong><a name=\"_Toc61639519\"></a>Cryptographic Support</strong></p>\r\n<p>Depending on which OS the application is installed on, the TOE either invokes the underlying platform or implements its own cryptographic module to perform cryptographic services. All cryptographic mechanisms, whether platform or application provided, use DRBG functionality to support cryptographic operations. Cryptographic functionality includes encryption/decryption services, credential/key storage, key establishment, key destruction, hashing services, signature services, key-hashed message authentication, and key chaining using a password-based derivation function.</p>\r\n<p>Cryptographic services for the application&rsquo;s S/MIME functionality and TLS communications are provided by the underlying platform when the application is installed on a device running iOS. When installed on a device running the Android OS, the TOE invokes the underlying platform cryptographic libraries for TLS communications and implements an OpenSSL cryptographic module to perform the cryptographic functionality required to support S/MIME (CAVP certificate #A1297).</p>\r\n<p><a name=\"_Hlk41727608\"></a><a name=\"_Hlk23340457\"></a><a name=\"_Toc41726773\"></a><strong><a name=\"_Toc61639520\"></a>User Data Protection</strong></p>\r\n<p><a name=\"_Hlk41727714\"></a><a name=\"_Hlk34737419\"></a>The TOE uses S/MIME to digitally sign, verify, decrypt, and encrypt email messages. The TOE stores all application data in an encrypted Boxer database which is created on the mobile device during installation. The TOE requires that the host platform have full disk encryption enabled to securely store the data. The TOE restricts its network access and provides user awareness when it attempts to access hardware resources and sensitive data stored on the host platform. The TOE displays notification icons that show S/MIME status. Each status is shown as a different color so that the user can quickly identify any issues.</p>\r\n<p><a name=\"_Toc41726774\"></a><a name=\"_Toc61639521\"></a><strong>Identification and Authentication</strong></p>\r\n<p>The TOE relies on the OS to validate X.509.3 certificates for TLS communication. The TOE validates X.509v3 certificates for signing and encrypting emails for S/MIME.</p>\r\n<p><strong>Security Management</strong></p>\r\n<p><a name=\"_Hlk41727687\"></a>The TOE enforces the application&rsquo;s enterprise policy set by the UEM administrator pushed out to the managed TOE device. The TOE does not use default passwords, and automatically installs and configures the application to protect itself and its data from unauthorized access while also implementing the recommended platform security mechanisms. Changing one&rsquo;s own password from the application is the only management function that can be performed by the owner/user of the mobile device with the TOE installed.</p>\r\n<p><a name=\"_Toc41726775\"></a><strong><a name=\"_Toc61639522\"></a>Privacy</strong></p>\r\n<p>The TOE does not transmit any personally identifiable information (PII) over the network unless voluntarily sent via free text email.</p>\r\n<p><a name=\"_Toc41726776\"></a><strong><a name=\"_Toc61639523\"></a>Protection of the TSF</strong></p>\r\n<p><a name=\"_Hlk41727667\"></a>The TOE does not support the installation of trusted or untrusted add-ons. The user is able to navigate the platform to check the version of the TOE and also check for updates to the application. All updates come from the Google Play Store (Android) or Apple App Store (iOS). The digital signature of the updates is verified by the mobile device platform prior to being installed. The TOE does not replace or modify its own binaries without user interaction. The TOE implements anti-exploitation features, such as stack-based overflow protection, is compatible with security features provided by the OS, and will only use documented APIs and libraries.&nbsp;</p>\r\n<p><a name=\"_Toc41726777\"></a><strong><a name=\"_Toc61639524\"></a>Trusted Path/Channels</strong></p>\r\n<p>The TOE invokes the platform to provide the trusted communication channel between the TOE and the Exchange server. Communications are protected with TLS v1.2. Communication to the Exchange server uses ActiveSync to send and receive emails.</p>","features":[]}