{"product_id":11299,"v_id":11299,"product_name":"CAE MPIC 3.0.66","certification_status":"Certified","certification_date":"2022-11-23T00:00:00Z","tech_type":"Network Device","vendor_id":{"name":"CAE Inc.","website":"cae.com"},"vendor_poc":"Spiros Kalantzis","vendor_phone":"414-341-2000","vendor_email":"spiros.kalantzis@cae.com","assigned_lab":{"cctl_name":"Lightship Security USA, Inc."},"product_description":"<p class=\"MsoBodyText\"><span style=\"font-size: 11.0pt; font-family: 'Calibri',sans-serif; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin; mso-bidi-theme-font: minor-latin;\">The TOE is a standalone physical network device, used to transmit data from the hardware panels to a software-based flight simulation, processed by one or more Daughter Boards (DB). The simulation data is processed by the DB&rsquo;s and then feedback is transmitted back to the hardware panels via the MPIC. It comes in a range of form factors MPIC, MPIC-PCMIP, MPIC-EMB. The different form factors can be installed in combination or independently to Network data. All form factors provide a basic set of security functions such as, a secure remote management path, identification and authentication services to trusted administrators, and secure auditing of administrator actions. The MPIC-PCMIP form factor differs as it has standard type slot for extensions compared to the custom interface on the MPIC. The MPIC-EMB differs as it is designed to be embedded and not mounted into systems.</span></p>","evaluation_configuration":"<p class=\"MsoBodyText\"><span style=\"font-size: 11.0pt; font-family: 'Calibri',sans-serif; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin; mso-bidi-theme-font: minor-latin;\">The TOE evaluated configuration includes the CAE MPIC running system software version: 3.0.66.</span></p>\r\n<table class=\"TableGrid1\" style=\"margin-left: 5.15pt; border-collapse: collapse; mso-table-layout-alt: fixed; border: none; mso-border-alt: solid windowtext .5pt; mso-yfti-tbllook: 1184; mso-padding-alt: 0in 5.4pt 0in 5.4pt;\" border=\"1\" width=\"626\" cellspacing=\"0\" cellpadding=\"0\">\r\n<thead>\r\n<tr style=\"mso-yfti-irow: 0; mso-yfti-firstrow: yes;\">\r\n<td style=\"width: 93.9pt; border: solid windowtext 1.0pt; mso-border-alt: solid windowtext .5pt; background: #3771C8; padding: 0in 5.4pt 0in 5.4pt;\" width=\"125\">\r\n<p class=\"TableHeading\" style=\"text-align: center;\" align=\"center\"><span style=\"font-size: 11.0pt; font-family: 'Calibri',sans-serif; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin; mso-bidi-theme-font: minor-latin; mso-ansi-language: EN-US; mso-fareast-language: EN-CA;\">Type</span></p>\r\n</td>\r\n<td style=\"width: 93.9pt; border: solid windowtext 1.0pt; border-left: none; mso-border-left-alt: solid windowtext .5pt; mso-border-alt: solid windowtext .5pt; background: #3771C8; padding: 0in 5.4pt 0in 5.4pt;\" valign=\"top\" width=\"125\">\r\n<p class=\"TableHeading\" style=\"text-align: center;\" align=\"center\"><span style=\"font-size: 11.0pt; font-family: 'Calibri',sans-serif; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin; mso-bidi-theme-font: minor-latin; mso-ansi-language: EN-US; mso-fareast-language: EN-CA;\">Model</span></p>\r\n</td>\r\n<td style=\"width: 93.9pt; border: solid windowtext 1.0pt; border-left: none; mso-border-left-alt: solid windowtext .5pt; mso-border-alt: solid windowtext .5pt; background: #3771C8; padding: 0in 5.4pt 0in 5.4pt;\" width=\"125\">\r\n<p class=\"TableHeading\" style=\"text-align: center;\" align=\"center\"><span style=\"font-size: 11.0pt; font-family: 'Calibri',sans-serif; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin; mso-bidi-theme-font: minor-latin; mso-ansi-language: EN-US; mso-fareast-language: EN-CA;\">CPU</span></p>\r\n</td>\r\n<td style=\"width: 81.45pt; border: solid windowtext 1.0pt; border-left: none; mso-border-left-alt: solid windowtext .5pt; mso-border-alt: solid windowtext .5pt; background: #3771C8; padding: 0in 5.4pt 0in 5.4pt;\" width=\"109\">\r\n<p class=\"TableHeading\" style=\"text-align: center;\" align=\"center\"><span style=\"font-size: 11.0pt; font-family: 'Calibri',sans-serif; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin; mso-bidi-theme-font: minor-latin; mso-ansi-language: EN-US; mso-fareast-language: EN-CA;\">Software </span></p>\r\n</td>\r\n<td style=\"width: 106.35pt; border: solid windowtext 1.0pt; border-left: none; mso-border-left-alt: solid windowtext .5pt; mso-border-alt: solid windowtext .5pt; background: #3771C8; padding: 0in 5.4pt 0in 5.4pt;\" width=\"142\">\r\n<p class=\"TableHeading\" style=\"text-align: center;\" align=\"center\"><span style=\"font-size: 11.0pt; font-family: 'Calibri',sans-serif; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin; mso-bidi-theme-font: minor-latin; mso-ansi-language: EN-US; mso-fareast-language: EN-CA;\">Differences</span></p>\r\n</td>\r\n</tr>\r\n</thead>\r\n<tbody>\r\n<tr style=\"mso-yfti-irow: 1;\">\r\n<td style=\"width: 93.9pt; border: solid windowtext 1.0pt; border-top: none; mso-border-top-alt: solid windowtext .5pt; mso-border-alt: solid windowtext .5pt; padding: 0in 5.4pt 0in 5.4pt;\" rowspan=\"3\" valign=\"top\" width=\"125\">\r\n<p class=\"TableText\" style=\"text-align: center;\" align=\"center\"><span lang=\"EN-CA\" style=\"font-size: 11.0pt; font-family: 'Calibri',sans-serif; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin; mso-bidi-theme-font: minor-latin; mso-ansi-language: EN-CA; mso-fareast-language: EN-CA;\">MPIC</span></p>\r\n</td>\r\n<td style=\"width: 93.9pt; border-top: none; border-left: none; border-bottom: solid windowtext 1.0pt; border-right: solid windowtext 1.0pt; mso-border-top-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-alt: solid windowtext .5pt; padding: 0in 5.4pt 0in 5.4pt;\" valign=\"top\" width=\"125\">\r\n<p class=\"TableText\" style=\"text-align: center;\" align=\"center\"><span lang=\"EN-CA\" style=\"font-size: 11.0pt; font-family: 'Calibri',sans-serif; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin; mso-bidi-theme-font: minor-latin; mso-ansi-language: EN-CA; mso-fareast-language: EN-CA;\">MPIC</span></p>\r\n</td>\r\n<td style=\"width: 93.9pt; border-top: none; border-left: none; border-bottom: solid windowtext 1.0pt; border-right: solid windowtext 1.0pt; mso-border-top-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-alt: solid windowtext .5pt; padding: 0in 5.4pt 0in 5.4pt;\" valign=\"top\" width=\"125\">\r\n<p class=\"TableText\" style=\"text-align: center;\" align=\"center\"><span lang=\"EN-CA\" style=\"font-size: 11.0pt; font-family: 'Calibri',sans-serif; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin; mso-bidi-theme-font: minor-latin; mso-ansi-language: EN-CA; mso-fareast-language: EN-CA;\">i.MX6 ARM Cortex-A9 (ARMv7-A) with CAAM</span></p>\r\n</td>\r\n<td style=\"width: 81.45pt; border-top: none; border-left: none; border-bottom: solid windowtext 1.0pt; border-right: solid windowtext 1.0pt; mso-border-top-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-alt: solid windowtext .5pt; padding: 0in 5.4pt 0in 5.4pt;\" rowspan=\"3\" valign=\"top\" width=\"109\">\r\n<p class=\"TableText\" style=\"text-align: center;\" align=\"center\"><span lang=\"EN-CA\" style=\"font-size: 11.0pt; font-family: 'Calibri',sans-serif; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin; mso-bidi-theme-font: minor-latin; mso-ansi-language: EN-CA; mso-fareast-language: EN-CA;\">cae-mx6qmpic-3.0.66<br />MPICLinuxDistributionXR 3.0</span></p>\r\n</td>\r\n<td style=\"width: 106.35pt; border-top: none; border-left: none; border-bottom: solid windowtext 1.0pt; border-right: solid windowtext 1.0pt; mso-border-top-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-alt: solid windowtext .5pt; padding: 0in 5.4pt 0in 5.4pt;\" rowspan=\"3\" valign=\"top\" width=\"142\">\r\n<p class=\"TableText\" style=\"text-align: center;\" align=\"center\"><span lang=\"EN-CA\" style=\"font-size: 11.0pt; font-family: 'Calibri',sans-serif; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin; mso-bidi-theme-font: minor-latin; mso-ansi-language: EN-CA; mso-fareast-language: EN-CA;\">Form Factor</span></p>\r\n</td>\r\n</tr>\r\n<tr style=\"mso-yfti-irow: 2; height: 25.35pt;\">\r\n<td style=\"width: 93.9pt; border-top: none; border-left: none; border-bottom: solid windowtext 1.0pt; border-right: solid windowtext 1.0pt; mso-border-top-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-alt: solid windowtext .5pt; padding: 0in 5.4pt 0in 5.4pt; height: 25.35pt;\" valign=\"top\" width=\"125\">\r\n<p class=\"TableText\" style=\"text-align: center;\" align=\"center\"><span lang=\"EN-CA\" style=\"font-size: 11.0pt; font-family: 'Calibri',sans-serif; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin; mso-bidi-theme-font: minor-latin; mso-ansi-language: EN-CA; mso-fareast-language: EN-CA;\">MPIC-PCMIP</span></p>\r\n</td>\r\n<td style=\"width: 93.9pt; border-top: none; border-left: none; border-bottom: solid windowtext 1.0pt; border-right: solid windowtext 1.0pt; mso-border-top-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-alt: solid windowtext .5pt; padding: 0in 5.4pt 0in 5.4pt; height: 25.35pt;\" valign=\"top\" width=\"125\">\r\n<p class=\"TableText\" style=\"text-align: center;\" align=\"center\"><span lang=\"EN-CA\" style=\"font-size: 11.0pt; font-family: 'Calibri',sans-serif; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin; mso-bidi-theme-font: minor-latin; mso-ansi-language: EN-CA; mso-fareast-language: EN-CA;\">i.MX6 ARM Cortex-A9 (ARMv7-A) with CAAM</span></p>\r\n</td>\r\n</tr>\r\n<tr style=\"mso-yfti-irow: 3; mso-yfti-lastrow: yes;\">\r\n<td style=\"width: 93.9pt; border-top: none; border-left: none; border-bottom: solid windowtext 1.0pt; border-right: solid windowtext 1.0pt; mso-border-top-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-alt: solid windowtext .5pt; padding: 0in 5.4pt 0in 5.4pt;\" valign=\"top\" width=\"125\">\r\n<p class=\"TableText\" style=\"text-align: center;\" align=\"center\"><span lang=\"EN-CA\" style=\"font-size: 11.0pt; font-family: 'Calibri',sans-serif; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin; mso-bidi-theme-font: minor-latin; mso-ansi-language: EN-CA; mso-fareast-language: EN-CA;\">MPIC-EMB</span></p>\r\n</td>\r\n<td style=\"width: 93.9pt; border-top: none; border-left: none; border-bottom: solid windowtext 1.0pt; border-right: solid windowtext 1.0pt; mso-border-top-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-alt: solid windowtext .5pt; padding: 0in 5.4pt 0in 5.4pt;\" valign=\"top\" width=\"125\">\r\n<p class=\"TableText\" style=\"text-align: center;\" align=\"center\"><span lang=\"EN-CA\" style=\"font-size: 11.0pt; font-family: 'Calibri',sans-serif; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin; mso-bidi-theme-font: minor-latin; mso-ansi-language: EN-CA; mso-fareast-language: EN-CA;\">i.MX6 ARM Cortex-A9 (ARMv7-A) with CAAM</span></p>\r\n</td>\r\n</tr>\r\n</tbody>\r\n</table>","security_evaluation_summary":"<p class=\"TableText\"><span style=\"font-size: 11.0pt; font-family: 'Calibri',sans-serif; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin; mso-bidi-theme-font: minor-latin;\">The evaluation was carried out in accordance to the Common Criteria Evaluation and Validation Scheme (CCEVS) process and scheme. The evaluation demonstrated that the product meets the security requirements contained in the Security Target. The criteria against which the CAE MPIC 3.0.66 was judged are described in the Common Criteria for Information Technology Security Evaluation, Version 3.1, Revision 5. The evaluation methodology used by the evaluation team to conduct the evaluation is the Common Methodology for Information Technology Security Evaluation, Version 3.1, Revision 5. Lightship Security USA determined that the product is conformant to requirements for collaborative Protection Profile for Network Devices Version 2.2e.<span style=\"mso-spacerun: yes;\">&nbsp; </span>The product, when configured as identified in the <em>CAE MPIC 3.0.66 Common Criteria Guide</em>, Version 1.1, October 2022, satisfies all of the security functional requirements stated in the <em>CAE MPIC 3.0.66 Security Target</em>, Version 1.1, October 2022. Three validators, on behalf of the CCEVS Validation Body, monitored the evaluation carried out by Lightship Security USA. The evaluation was completed in November 2022. Results of the evaluation can be found in the Common Criteria Evaluation and Validation Scheme Validation Report prepared by CCEVS .</span></p>","environmental_strengths":"<p class=\"MsoNormal\" style=\"margin-bottom: 0in;\"><span style=\"font-size: 11.0pt; font-family: 'Calibri',sans-serif; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin; mso-bidi-theme-font: minor-latin;\">The TOE is comprised of the following security features which are described in more detail in the subsections below.<span style=\"mso-spacerun: yes;\">&nbsp;&nbsp; </span></span></p>\r\n<p class=\"MsoNormal\" style=\"margin-bottom: 0in;\"><span style=\"font-size: 11.0pt; font-family: 'Calibri',sans-serif; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin; mso-bidi-theme-font: minor-latin;\">&nbsp;</span></p>\r\n<p class=\"MsoNormal\"><strong><span style=\"font-size: 11.0pt; font-family: 'Calibri',sans-serif; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin; mso-bidi-theme-font: minor-latin;\">Security Audit</span></strong></p>\r\n<p class=\"MsoNormal\"><span style=\"font-size: 11.0pt; font-family: 'Calibri',sans-serif; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin; mso-bidi-theme-font: minor-latin;\">The TOE is able to generate audit records of security relevant events. The TOE stores audit records locally and can also be configured to send the audit records to an external audit server over a protected communication channel. Log files are transferred in real time via SSH tunnel to the external audit server. Only authorized administrators may view audit records and no capability to modify the audit records is provided.<a name=\"_Toc472011979\"></a><a name=\"_Toc472012137\"></a><a name=\"_Toc472013213\"></a><a name=\"_Toc472013292\"></a><a name=\"_Toc472091622\"></a><a name=\"_Toc472091724\"></a><a name=\"_Toc472348428\"></a></span></p>\r\n<p class=\"MsoNormal\"><strong><span style=\"font-size: 11.0pt; font-family: 'Calibri',sans-serif; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin; mso-bidi-theme-font: minor-latin;\">Cryptographic Support</span></strong></p>\r\n<p class=\"Default\" style=\"text-indent: 0in; mso-list: l0 level2 lfo1; margin: 0in 0in 6.65pt 0in;\"><span style=\"font-size: 11.0pt; font-family: 'Calibri',sans-serif; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin; mso-bidi-theme-font: minor-latin;\">The TOE protects the integrity and confidentiality of communications between itself and the syslog server. The TOE provides the following CAVP-certified cryptographic services: random bit generation; asymmetric cryptographic key pair generation; key establishment; symmetric data encryption and decryption; digital signature generation and verification; cryptographic hashing; and keyed-hash message authentication. When local audit logs reach a maximum size of 8MB, logs are rotated out by removing the oldest log first and creating a new log file.</span></p>\r\n<p class=\"MsoNormal\"><a name=\"_Toc113632643\"></a><strong><span style=\"font-size: 11.0pt; font-family: 'Calibri',sans-serif; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin; mso-bidi-theme-font: minor-latin;\">Identification and Authentication</span></strong></p>\r\n<p class=\"Body\"><span style=\"font-size: 11.0pt; font-family: 'Calibri',sans-serif; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin; mso-bidi-theme-font: minor-latin;\">The TOE requires all users to be successfully identified and authenticated prior to accessing its security management functions and other capabilities. Administrative access to the TOE is facilitated through the local CLI via direct serial connection or SSH. Administrator credentials are the same for each user regardless of which interface is accessed.</span></p>\r\n<p class=\"Body\"><span style=\"font-size: 11.0pt; font-family: 'Calibri',sans-serif; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin; mso-bidi-theme-font: minor-latin;\">The TOE supports the local (i.e., on device) definition of administrators with usernames and passwords. Only after the administrative user presents the correct authentication credentials will they be granted access to the TOE administrative functionality. Passwords can be composed of any combination of upper and lower case letters, numbers, and the following special characters: !; @; #; $; %; ^; &amp;; *; (; and )</span></p>\r\n<p class=\"Default\" style=\"margin-bottom: 6.65pt;\"><span style=\"font-size: 11.0pt; font-family: 'Calibri',sans-serif; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin; mso-bidi-theme-font: minor-latin; color: windowtext;\">The TOE is capable of tracking authentication failures of remote administrators. When a user account has sequentially failed authentication the configured number of times the account will be locked for a Security Administrator defined time period.</span></p>\r\n<p class=\"MsoNormal\"><strong><span style=\"font-size: 11.0pt; font-family: 'Calibri',sans-serif; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin; mso-bidi-theme-font: minor-latin;\">Security Management</span></strong></p>\r\n<p class=\"Default\" style=\"margin-bottom: 6.65pt;\"><strong><span style=\"font-size: 11.0pt; font-family: 'Calibri',sans-serif; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin; mso-bidi-theme-font: minor-latin;\"><span style=\"mso-spacerun: yes;\">&nbsp;</span></span></strong><span style=\"font-size: 11.0pt; font-family: 'Calibri',sans-serif; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin; mso-bidi-theme-font: minor-latin;\">The TOE enables secure management of its security functions, including </span><span style=\"font-size: 11.0pt; font-family: 'Calibri',sans-serif; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin; mso-bidi-theme-font: minor-latin; color: windowtext;\">Administrator authentication with passwords; configurable password policies; Role Based Access Control; access banners; management of critical security functions and data; and protection of cryptographic keys and passwords.</span></p>\r\n<p class=\"MsoNormal\"><strong><span style=\"font-size: 11.0pt; font-family: 'Calibri',sans-serif; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin; mso-bidi-theme-font: minor-latin;\">Protection of the TSF</span></strong></p>\r\n<p class=\"Default\" style=\"margin-bottom: 6.65pt;\"><span style=\"font-size: 11.0pt; font-family: 'Calibri',sans-serif; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin; mso-bidi-theme-font: minor-latin; color: windowtext;\">The TOE protects sensitive data such as stored passwords and cryptographic keys so that they are not accessible even by an administrator.</span></p>\r\n<p class=\"Default\" style=\"margin-bottom: 6.65pt;\"><span style=\"font-size: 11.0pt; font-family: 'Calibri',sans-serif; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin; mso-bidi-theme-font: minor-latin; color: windowtext;\">The TOE provides reliable time stamps for its own use and uses NTP to synchronize its time.</span></p>\r\n<p class=\"Default\" style=\"margin-bottom: 6.65pt;\"><span style=\"font-size: 11.0pt; font-family: 'Calibri',sans-serif; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin; mso-bidi-theme-font: minor-latin; color: windowtext;\">The TOE provides a trusted means for determining the current running version of its firmware and to update its firmware. The TOE verifies the integrity of TOE updates using a hard-coded public key.</span></p>\r\n<p class=\"Default\" style=\"margin-bottom: 6.65pt;\"><span style=\"font-size: 11.0pt; font-family: 'Calibri',sans-serif; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin; mso-bidi-theme-font: minor-latin; color: windowtext;\">The TOE implements various self-tests that execute during the power-on and start up sequence as well as at the administrative user&rsquo;s request, including cryptographic known answer tests that verify the correct operation of the TOE&rsquo;s cryptographic functions.</span></p>\r\n<p class=\"MsoNormal\"><strong><span style=\"font-size: 11.0pt; font-family: 'Calibri',sans-serif; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin; mso-bidi-theme-font: minor-latin;\">TOE Access</span></strong></p>\r\n<p class=\"Default\" style=\"margin-bottom: 6.65pt;\"><span style=\"font-size: 11.0pt; font-family: 'Calibri',sans-serif; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin; mso-bidi-theme-font: minor-latin; color: windowtext;\">The TOE will terminate inactive local and remote interactive sessions after a configurable amount of time. Administrative users may terminate their own sessions at any time using the &ldquo;exit&rdquo; command. The TOE displays an administrator configurable message to users prior to login at the CLI.</span></p>\r\n<p class=\"MsoNormal\"><strong><span style=\"font-size: 11.0pt; font-family: 'Calibri',sans-serif; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin; mso-bidi-theme-font: minor-latin;\">Trusted Path/Channels</span></strong></p>\r\n<p class=\"Default\"><span style=\"font-size: 11.0pt; font-family: 'Calibri',sans-serif; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin; mso-bidi-theme-font: minor-latin; color: windowtext;\">The TOE protects secure communications with an audit server as a client using SSH. The TOE protects connections from remote administrative users as a server using SSH.</span></p>","features":[]}