{"product_id":11345,"v_id":11345,"product_name":"Aruba Mobility Conductor with ArubaOS 8.10","certification_status":"Certified","certification_date":"2023-06-23T00:00:00Z","tech_type":"Network Device","vendor_id":{"name":"Aruba, a Hewlett Packard Enterprise Company","website":"www.arubanetworks.com"},"vendor_poc":"Kevin Micciche","vendor_phone":"4046480062","vendor_email":"aruba-product-security@hpe.com","assigned_lab":{"cctl_name":"Lightship Security USA, Inc."},"product_description":"<p class=\"MsoNormal\" style=\"text-align: justify;\"><span style=\"mso-bidi-font-weight: bold;\">The Target of Evaluation (TOE) is the<span style=\"mso-spacerun: yes;\">&nbsp; </span>Aruba Mobility Conductor with ArubaOS 8.10.<span style=\"mso-spacerun: yes;\">&nbsp; </span>The Aruba Mobility Conductor simplifies the management of multiple Aruba controllers running ArubaOS 8 or later. Key features include a centralized dashboard to easily see and manage controllers deployed in multiple sites, a hierarchical configuration tool to pre-stage network deployments, and the ability to perform live firmware and feature upgrades during active user sessions. The addition of licensing pools simplifies the transfer of licenses between different controllers to quickly address expanded deployment needs.</span></p>","evaluation_configuration":"<p class=\"MsoNormal\" style=\"text-align: justify;\"><span style=\"mso-bidi-font-weight: bold;\">The TOE is a network device that provides centralized management of multiple Aruba Mobility Controllers. </span>The physical boundary of the TOE includes the appliance models shown in the table below executing ArubaOS 8.10 software.</p>\r\n<p class=\"MsoCaption\" style=\"text-align: center;\" align=\"center\"><a name=\"_Ref287880423\"></a><a name=\"_Toc294793778\"></a><a name=\"_Toc126661826\"></a><a name=\"_Toc126877442\"></a><span style=\"mso-bookmark: _Toc126661826;\"><span style=\"mso-bookmark: _Toc294793778;\"><span style=\"mso-bookmark: _Ref287880423;\">TOE Hardware Models</span></span></span></p>\r\n<table class=\"MsoTableGrid\" style=\"width: 100.0%; border-collapse: collapse; border: none; mso-border-alt: solid windowtext .5pt; mso-yfti-tbllook: 1184; mso-padding-alt: 0in 5.4pt 0in 5.4pt;\" border=\"1\" width=\"100%\" cellspacing=\"0\" cellpadding=\"0\">\r\n<thead>\r\n<tr style=\"mso-yfti-irow: 0; mso-yfti-firstrow: yes;\">\r\n<td style=\"width: 20.62%; border: solid windowtext 1.0pt; mso-border-alt: solid windowtext .5pt; background: #3771C8; padding: 0in 5.4pt 0in 5.4pt;\" width=\"20%\">\r\n<p class=\"TableHeading\"><span style=\"mso-ansi-language: EN-US;\">Model</span></p>\r\n</td>\r\n<td style=\"width: 37.36%; border: solid windowtext 1.0pt; border-left: none; mso-border-left-alt: solid windowtext .5pt; mso-border-alt: solid windowtext .5pt; background: #3771C8; padding: 0in 5.4pt 0in 5.4pt;\" width=\"37%\">\r\n<p class=\"TableHeading\" style=\"text-align: center;\" align=\"center\"><span style=\"mso-ansi-language: EN-US;\">CPU</span></p>\r\n</td>\r\n<td style=\"width: 12.46%; border: solid windowtext 1.0pt; border-left: none; mso-border-left-alt: solid windowtext .5pt; mso-border-alt: solid windowtext .5pt; background: #3771C8; padding: 0in 5.4pt 0in 5.4pt;\" width=\"12%\">\r\n<p class=\"TableHeading\" style=\"text-align: center;\" align=\"center\"><span style=\"mso-ansi-language: EN-US;\">Software</span></p>\r\n</td>\r\n<td style=\"width: 29.58%; border: solid windowtext 1.0pt; border-left: none; mso-border-left-alt: solid windowtext .5pt; mso-border-alt: solid windowtext .5pt; background: #3771C8; padding: 0in 5.4pt 0in 5.4pt;\" width=\"29%\">\r\n<p class=\"TableHeading\" style=\"text-align: center;\" align=\"center\"><span style=\"mso-ansi-language: EN-US;\">Notes on Differences</span></p>\r\n</td>\r\n</tr>\r\n</thead>\r\n<tbody>\r\n<tr style=\"mso-yfti-irow: 1;\">\r\n<td style=\"width: 20.62%; border: solid windowtext 1.0pt; border-top: none; mso-border-top-alt: solid windowtext .5pt; mso-border-alt: solid windowtext .5pt; padding: 0in 5.4pt 0in 5.4pt;\" valign=\"top\" width=\"20%\">\r\n<p class=\"TableText\"><span style=\"mso-ansi-language: EN-US;\">MCR-HW-1K-F1</span></p>\r\n</td>\r\n<td style=\"width: 37.36%; border-top: none; border-left: none; border-bottom: solid windowtext 1.0pt; border-right: solid windowtext 1.0pt; mso-border-top-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-alt: solid windowtext .5pt; padding: 0in 5.4pt 0in 5.4pt;\" valign=\"top\" width=\"37%\">\r\n<p class=\"TableText\" style=\"text-align: center;\" align=\"center\"><span style=\"mso-ansi-language: EN-US;\">Intel Xeon E5-2609v4 (Broadwell)</span></p>\r\n</td>\r\n<td style=\"width: 12.46%; border-top: none; border-left: none; border-bottom: solid windowtext 1.0pt; border-right: solid windowtext 1.0pt; mso-border-top-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-alt: solid windowtext .5pt; padding: 0in 5.4pt 0in 5.4pt;\" rowspan=\"3\" valign=\"top\" width=\"12%\">\r\n<p class=\"TableText\" style=\"text-align: center;\" align=\"center\"><span style=\"mso-ansi-language: EN-US;\">ArubaOS 8.10</span></p>\r\n</td>\r\n<td style=\"width: 29.58%; border-top: none; border-left: none; border-bottom: solid windowtext 1.0pt; border-right: solid windowtext 1.0pt; mso-border-top-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-alt: solid windowtext .5pt; padding: 0in 5.4pt 0in 5.4pt;\" rowspan=\"3\" valign=\"top\" width=\"29%\">\r\n<p class=\"TableText\" style=\"text-align: center;\" align=\"center\"><span style=\"mso-ansi-language: EN-US;\">Difference in the number of managed nodes/ supported devices, clients, and controllers due to the licenses applied.</span></p>\r\n</td>\r\n</tr>\r\n<tr style=\"mso-yfti-irow: 2; height: 25.35pt;\">\r\n<td style=\"width: 20.62%; border: solid windowtext 1.0pt; border-top: none; mso-border-top-alt: solid windowtext .5pt; mso-border-alt: solid windowtext .5pt; padding: 0in 5.4pt 0in 5.4pt; height: 25.35pt;\" valign=\"top\" width=\"20%\">\r\n<p class=\"TableText\"><span style=\"mso-ansi-language: EN-US;\">MCR-HW-5K-F1</span></p>\r\n</td>\r\n<td style=\"width: 37.36%; border-top: none; border-left: none; border-bottom: solid windowtext 1.0pt; border-right: solid windowtext 1.0pt; mso-border-top-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-alt: solid windowtext .5pt; padding: 0in 5.4pt 0in 5.4pt; height: 25.35pt;\" valign=\"top\" width=\"37%\">\r\n<p class=\"TableText\" style=\"text-align: center;\" align=\"center\"><span style=\"mso-ansi-language: EN-US;\">Intel Xeon E5-2620v4 (Broadwell)</span></p>\r\n</td>\r\n</tr>\r\n<tr style=\"mso-yfti-irow: 3; mso-yfti-lastrow: yes;\">\r\n<td style=\"width: 20.62%; border: solid windowtext 1.0pt; border-top: none; mso-border-top-alt: solid windowtext .5pt; mso-border-alt: solid windowtext .5pt; padding: 0in 5.4pt 0in 5.4pt;\" valign=\"top\" width=\"20%\">\r\n<p class=\"TableText\"><span style=\"mso-ansi-language: EN-US;\">MCR-HW-10K-F1</span></p>\r\n</td>\r\n<td style=\"width: 37.36%; border-top: none; border-left: none; border-bottom: solid windowtext 1.0pt; border-right: solid windowtext 1.0pt; mso-border-top-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-alt: solid windowtext .5pt; padding: 0in 5.4pt 0in 5.4pt;\" valign=\"top\" width=\"37%\">\r\n<p class=\"TableText\" style=\"text-align: center;\" align=\"center\"><span style=\"mso-ansi-language: EN-US;\">Intel Xeon E5-2650v4 (Broadwell)</span></p>\r\n</td>\r\n</tr>\r\n</tbody>\r\n</table>","security_evaluation_summary":"<p class=\"MsoNormal\" style=\"text-align: justify;\">The evaluation was carried out in accordance with the Common Criteria Evaluation and Validation Scheme (CCEVS) requirements and guidance.<span style=\"mso-spacerun: yes;\">&nbsp; </span>The criteria against which the TOE was judged are described in the Common Criteria for Information Technology Security Evaluation, Version 3.1, Revision 5, April 2017. The evaluation methodology used by the evaluation team to conduct the evaluation is the Common Methodology for Information Technology Security Evaluation, Evaluation Methodology, Version 3.1, Revision 5, April 2017.<span style=\"mso-spacerun: yes;\">&nbsp; </span>The product, when configured as identified in the <em>ArubaOS 8.10 Supplemental Guidance (Common Criteria Configuration Guidance for Aruba Mobility Conductor with ArubaOS 8.10-FIPS), </em>Version 2.6, June 2023, satisfies all of the security functional requirements stated in the <em>Aruba Mobility Conductor with ArubaOS 8.10 Security Target, </em>Version 1.2, June 2023. The project underwent CCEVS Validator review. The evaluation was completed in June 2023. <span style=\"mso-spacerun: yes;\">&nbsp;&nbsp;</span>Results of the evaluation can be found in the Common Criteria Evaluation and Validation Scheme Validation Report (report number CCEVS-VR-VID11345-2023) prepared by CCEVS.</p>","environmental_strengths":"<p class=\"MsoBodyText\" style=\"margin-top: 6.0pt; mso-pagination: widow-orphan lines-together; page-break-after: avoid;\">The TOE provides the following security functions:</p>\r\n<p class=\"MsoBodyText\" style=\"text-indent: -.25in; mso-list: l0 level1 lfo1; margin: 6.0pt 0in 6.0pt .5in;\"><!-- [if !supportLists]--><span style=\"mso-fareast-font-family: Times; mso-bidi-font-family: Times; mso-bidi-font-weight: bold;\"><span style=\"mso-list: Ignore;\">a)<span style=\"font: 7.0pt 'Times New Roman';\">&nbsp;&nbsp;&nbsp;&nbsp; </span></span></span><!--[endif]--><strong style=\"mso-bidi-font-weight: normal;\">Security Audit: </strong>The TOE generates logs of security relevant events. The TOE stores logs locally and is capable of sending log events to a remote syslog server. Log events are sent in real-time via IPsec.</p>\r\n<p class=\"MsoBodyText\" style=\"text-indent: -.25in; mso-list: l0 level1 lfo1; margin: 6.0pt 0in 6.0pt .5in;\"><!-- [if !supportLists]--><span style=\"mso-fareast-font-family: Times; mso-bidi-font-family: Times; mso-bidi-font-weight: bold;\"><span style=\"mso-list: Ignore;\">b)<span style=\"font: 7.0pt 'Times New Roman';\">&nbsp;&nbsp;&nbsp;&nbsp; </span></span></span><!--[endif]--><strong style=\"mso-bidi-font-weight: normal;\">Cryptographic Support: </strong>The TOE implements a cryptographic module. In the evaluated configuration, the TOE is in FIPS mode to support the cryptographic functionality. The TOE implements cryptographic protocols such as SSH, TLS, HTTPS, and IPsec.</p>\r\n<p class=\"MsoBodyText\" style=\"text-indent: -.25in; mso-list: l0 level1 lfo1; margin: 6.0pt 0in 6.0pt .5in;\"><!-- [if !supportLists]--><span style=\"mso-fareast-font-family: Times; mso-bidi-font-family: Times; mso-bidi-font-weight: bold;\"><span style=\"mso-list: Ignore;\">c)<span style=\"font: 7.0pt 'Times New Roman';\">&nbsp;&nbsp;&nbsp;&nbsp; </span></span></span><!--[endif]--><strong style=\"mso-bidi-font-weight: normal;\">Identification and Authentication:</strong> The TOE requires users who connect to the TOEs administrator interfaces (direct serial connection, remote CLI, and GUI) to authenticate prior to being granted access to any TOE functionality. The TOE supports the use of authentication servers via IPsec.</p>\r\n<p class=\"MsoBodyText\" style=\"text-indent: -.25in; mso-list: l0 level1 lfo1; margin: 6.0pt 0in 6.0pt .5in;\"><!-- [if !supportLists]--><span style=\"mso-fareast-font-family: Times; mso-bidi-font-family: Times; mso-bidi-font-weight: bold;\"><span style=\"mso-list: Ignore;\">d)<span style=\"font: 7.0pt 'Times New Roman';\">&nbsp;&nbsp;&nbsp;&nbsp; </span></span></span><!--[endif]--><strong style=\"mso-bidi-font-weight: normal;\">Secure Management: </strong>The TOE enables secure management of its security functions, including:</p>\r\n<p class=\"MsoBodyText\" style=\"text-indent: -.25in; mso-list: l0 level2 lfo1; margin: 0in 0in 0in 1.0in;\"><!-- [if !supportLists]--><span style=\"font-family: 'Arial',sans-serif; mso-fareast-font-family: Arial;\"><span style=\"mso-list: Ignore;\">i)<span style=\"font: 7.0pt 'Times New Roman';\">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span></span></span><!--[endif]-->Local and remote administration</p>\r\n<p class=\"MsoBodyText\" style=\"text-indent: -.25in; mso-list: l0 level2 lfo1; margin: 0in 0in 0in 1.0in;\"><!-- [if !supportLists]--><span style=\"font-family: 'Arial',sans-serif; mso-fareast-font-family: Arial;\"><span style=\"mso-list: Ignore;\">ii)<span style=\"font: 7.0pt 'Times New Roman';\">&nbsp;&nbsp;&nbsp;&nbsp; </span></span></span><!--[endif]-->Access banners</p>\r\n<p class=\"MsoBodyText\" style=\"text-indent: -.25in; mso-list: l0 level2 lfo1; margin: 0in 0in 0in 1.0in;\"><!-- [if !supportLists]--><span style=\"font-family: 'Arial',sans-serif; mso-fareast-font-family: Arial;\"><span style=\"mso-list: Ignore;\">iii)<span style=\"font: 7.0pt 'Times New Roman';\">&nbsp;&nbsp;&nbsp; </span></span></span><!--[endif]-->Session inactivity and termination</p>\r\n<p class=\"MsoBodyText\" style=\"text-indent: -.25in; mso-list: l0 level2 lfo1; margin: 0in 0in 0in 1.0in;\"><!-- [if !supportLists]--><span style=\"font-family: 'Arial',sans-serif; mso-fareast-font-family: Arial;\"><span style=\"mso-list: Ignore;\">iv)<span style=\"font: 7.0pt 'Times New Roman';\">&nbsp;&nbsp;&nbsp; </span></span></span><!--[endif]-->TOE updates</p>\r\n<p class=\"MsoBodyText\" style=\"text-indent: -.25in; mso-list: l0 level2 lfo1; margin: 0in 0in 0in 1.0in;\"><!-- [if !supportLists]--><span style=\"font-family: 'Arial',sans-serif; mso-fareast-font-family: Arial;\"><span style=\"mso-list: Ignore;\">v)<span style=\"font: 7.0pt 'Times New Roman';\">&nbsp;&nbsp;&nbsp;&nbsp; </span></span></span><!--[endif]-->Management of critical security functions and data</p>\r\n<p class=\"MsoBodyText\" style=\"text-indent: -.25in; mso-list: l0 level2 lfo1; margin: 0in 0in 0in 1.0in;\"><!-- [if !supportLists]--><span style=\"font-family: 'Arial',sans-serif; mso-fareast-font-family: Arial;\"><span style=\"mso-list: Ignore;\">vi)<span style=\"font: 7.0pt 'Times New Roman';\">&nbsp;&nbsp;&nbsp; </span></span></span><!--[endif]-->Protection of cryptographic keys and passwords</p>\r\n<p class=\"MsoBodyText\" style=\"text-indent: -.25in; mso-list: l0 level1 lfo1; margin: 6.0pt 0in 6.0pt .5in;\"><!-- [if !supportLists]--><span style=\"mso-fareast-font-family: Times; mso-bidi-font-family: Times; mso-bidi-font-weight: bold;\"><span style=\"mso-list: Ignore;\">e)<span style=\"font: 7.0pt 'Times New Roman';\">&nbsp;&nbsp;&nbsp;&nbsp; </span></span></span><!--[endif]--><strong style=\"mso-bidi-font-weight: normal;\">Protection of TSF:<span style=\"mso-spacerun: yes;\">&nbsp; </span></strong><span style=\"font-family: 'Times New Roman',serif;\">The TOE prevents reading of private keys and plaintext passwords by any user.<span style=\"mso-spacerun: yes;\">&nbsp; </span>The TOE synchronizes with an external time source.<span style=\"mso-spacerun: yes;\">&nbsp; </span>This date and time are used as a timestamp that is part of each audit record generated by the TOE. <span style=\"mso-spacerun: yes;\">&nbsp;</span></span>The TOE ensures the authenticity and integrity of software updates through digital signatures.<strong style=\"mso-bidi-font-weight: normal;\"><span style=\"mso-spacerun: yes;\">&nbsp; </span></strong>The TOE performs a suite of self-tests to ensure the correct operation and enforcement of its security functions.</p>\r\n<p class=\"MsoBodyText\" style=\"text-indent: -.25in; mso-list: l0 level1 lfo1; margin: 6.0pt 0in 6.0pt .5in;\"><!-- [if !supportLists]--><span style=\"mso-fareast-font-family: Times; mso-bidi-font-family: Times; mso-bidi-font-weight: bold;\"><span style=\"mso-list: Ignore;\">f)<span style=\"font: 7.0pt 'Times New Roman';\">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span></span></span><!--[endif]--><strong style=\"mso-bidi-font-weight: normal;\">TOE Access:<span style=\"mso-spacerun: yes;\">&nbsp; </span></strong>The TOE can terminate inactive sessions after configurable period.<span style=\"mso-spacerun: yes;\">&nbsp; </span>The TOE can also display specified banner on the local and remote CLI interfaces prior to allowing any administrative access to the TOE.<span style=\"mso-spacerun: yes;\">&nbsp; </span>The TOE allows users to manually terminate an established management session with the TOE.</p>\r\n<p class=\"MsoBodyText\" style=\"text-indent: -.25in; mso-list: l0 level1 lfo1; margin: 6.0pt 0in 6.0pt .5in;\"><!-- [if !supportLists]--><span style=\"mso-fareast-font-family: Times; mso-bidi-font-family: Times; mso-bidi-font-weight: bold;\"><span style=\"mso-list: Ignore;\">g)<span style=\"font: 7.0pt 'Times New Roman';\">&nbsp;&nbsp;&nbsp;&nbsp; </span></span></span><!--[endif]--><strong style=\"mso-bidi-font-weight: normal;\">Trusted Path/Channels:</strong> The TOE protects the integrity and confidentiality of communications via the following TOE interfaces: CLI via SSH; Administrative web GUI via HTTPS/TLS; authentication with a remote server via IPsec; external syslog server via IPsec; NTP server via IPsec; and management of Aruba Mobility Controllers via IPsec. <strong style=\"mso-bidi-font-weight: normal;\"><span style=\"mso-spacerun: yes;\">&nbsp;</span></strong></p>","features":[]}