{"product_id":11402,"v_id":11402,"product_name":"Palo Alto Networks GlobalProtect App 6","certification_status":"Certified","certification_date":"2023-10-20T00:00:00Z","tech_type":"Application Software, Network Encryption","vendor_id":{"name":"Palo Alto Networks, Inc.","website":"https://www.paloaltonetworks.com"},"vendor_poc":"Jake Bajic","vendor_phone":"408-753-3901","vendor_email":"jbajic@paloaltonetworks.com","assigned_lab":{"cctl_name":"Leidos Common Criteria Testing Laboratory"},"product_description":"<p class=\"Body\"><span style=\"font-family: 'Calibri',sans-serif; mso-ascii-theme-font: minor-latin; mso-fareast-font-family: Calibri; mso-fareast-theme-font: minor-latin; mso-hansi-theme-font: minor-latin; mso-bidi-theme-font: minor-latin;\">Palo Alto Networks GlobalProtect App 6 provides users with the ability to access their company network resources via the Palo Alto Networks GlobalProtect Portals and Gateways. The TOE also provides several management functions that include, for example, allowing the endpoint user to select their desired gateway, and to collect troubleshooting logs from the TOE.</span></p>","evaluation_configuration":"<p class=\"MsoNormal\" style=\"margin-bottom: 3.0pt;\"><span style=\"font-size: 11.0pt; line-height: 115%; font-family: 'Calibri',sans-serif; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin; mso-bidi-theme-font: minor-latin;\">The evaluated configuration consists of GlobalProtect App 6, supported and tested on the following operating systems<a style=\"mso-footnote-id: ftn1;\" title=\"\" href=\"file:///C:/Users/HeatherNye(CTR)/AppData/Local/Temp/Temp8f6fadcf-3a05-4bce-8868-422065bed259_Final_Package_-_Public_Forms.zip/VID11402%20Final%20Package/Public/VID11402_PCL.docx#_ftn1\" name=\"_ftnref1\"><span class=\"MsoFootnoteReference\"><span style=\"mso-special-character: footnote;\"><!-- [if !supportFootnotes]--><span class=\"MsoFootnoteReference\"><span style=\"font-size: 11.0pt; line-height: 115%; font-family: 'Calibri',sans-serif; mso-ascii-theme-font: minor-latin; mso-fareast-font-family: Calibri; mso-fareast-theme-font: minor-latin; mso-hansi-theme-font: minor-latin; mso-bidi-theme-font: minor-latin; mso-ansi-language: EN-US; mso-fareast-language: EN-US; mso-bidi-language: AR-SA;\">[1]</span></span><!--[endif]--></span></span></a></span><span style=\"font-size: 11.0pt; line-height: 115%; font-family: 'Calibri',sans-serif; mso-ascii-theme-font: minor-latin; mso-fareast-font-family: Calibri; mso-hansi-theme-font: minor-latin;\">:</span></p>\r\n<ul style=\"margin-top: 0in;\" type=\"disc\">\r\n<li class=\"MsoNormal\" style=\"margin-bottom: 0in; margin-top: 0in; mso-margin-bottom-alt: 10.0pt; mso-margin-top-alt: 0in; mso-add-space: auto; text-align: left; line-height: 107%; mso-list: l0 level1 lfo1;\"><span style=\"font-size: 11.0pt; line-height: 107%; font-family: 'Calibri',sans-serif; mso-fareast-font-family: Calibri;\">Windows 11</span></li>\r\n<li class=\"MsoNormal\" style=\"margin-bottom: 0in; margin-top: 0in; mso-margin-bottom-alt: 10.0pt; mso-margin-top-alt: 0in; mso-add-space: auto; text-align: left; line-height: 107%; mso-list: l0 level1 lfo1;\"><span style=\"font-size: 11.0pt; line-height: 107%; font-family: 'Calibri',sans-serif; mso-fareast-font-family: Calibri;\">macOS 12</span></li>\r\n<li class=\"MsoNormal\" style=\"margin-bottom: 0in; margin-top: 0in; mso-margin-bottom-alt: 10.0pt; mso-margin-top-alt: 0in; mso-add-space: auto; text-align: left; line-height: 107%; mso-list: l0 level1 lfo1;\"><span style=\"font-size: 11.0pt; line-height: 107%; font-family: 'Calibri',sans-serif; mso-fareast-font-family: Calibri;\">Android 12</span></li>\r\n<li class=\"MsoNormal\" style=\"margin-bottom: 0in; margin-top: 0in; mso-margin-bottom-alt: 10.0pt; mso-margin-top-alt: 0in; mso-add-space: auto; text-align: left; line-height: 107%; mso-list: l0 level1 lfo1;\"><span style=\"font-size: 11.0pt; line-height: 107%; font-family: 'Calibri',sans-serif; mso-fareast-font-family: Calibri;\">iOS 16</span></li>\r\n<li class=\"MsoNormal\" style=\"margin-bottom: 10.0pt; mso-margin-bottom-alt: 10.0pt; mso-margin-top-alt: 0in; mso-add-space: auto; text-align: left; line-height: 107%; mso-list: l0 level1 lfo1;\"><span style=\"font-size: 11.0pt; line-height: 107%; font-family: 'Calibri',sans-serif; mso-fareast-font-family: Calibri;\">Linux Ubuntu 20.04</span></li>\r\n</ul>\r\n<p class=\"Body\"><span style=\"font-family: 'Calibri',sans-serif; mso-ascii-theme-font: minor-latin; mso-fareast-font-family: Calibri; mso-fareast-theme-font: minor-latin; mso-hansi-theme-font: minor-latin; mso-bidi-theme-font: minor-latin;\">Palo Alto Networks GlobalProtect App 6 provides users with the ability to access their company network resources via the Palo Alto Networks GlobalProtect Portals and Gateways. The TOE also provides several management functions that include, for example, allowing the endpoint user to select their desired gateway, and to collect troubleshooting logs from the TOE.</span></p>\r\n<div style=\"mso-element: footnote-list;\"><!-- [if !supportFootnotes]--><br clear=\"all\" /><hr align=\"left\" size=\"1\" width=\"33%\" /><!--[endif]-->\r\n<div id=\"ftn1\" style=\"mso-element: footnote;\">\r\n<p class=\"MsoFootnoteText\"><a style=\"mso-footnote-id: ftn1;\" title=\"\" href=\"file:///C:/Users/HeatherNye(CTR)/AppData/Local/Temp/Temp8f6fadcf-3a05-4bce-8868-422065bed259_Final_Package_-_Public_Forms.zip/VID11402%20Final%20Package/Public/VID11402_PCL.docx#_ftnref1\" name=\"_ftn1\"><span class=\"MsoFootnoteReference\"><span style=\"mso-special-character: footnote;\"><!-- [if !supportFootnotes]--><span class=\"MsoFootnoteReference\"><span style=\"font-size: 10.0pt; line-height: 115%; font-family: 'Times New Roman',serif; mso-fareast-font-family: 'Times New Roman'; mso-ansi-language: EN-US; mso-fareast-language: EN-US; mso-bidi-language: AR-SA;\">[1]</span></span><!--[endif]--></span></span></a> <span style=\"color: black;\">While the TOE was tested on these operating systems, the TOE is compatible with later versions of the operating systems identified here. This is vendor affirmed.</span></p>\r\n</div>\r\n</div>","security_evaluation_summary":"<p class=\"Default\" style=\"margin-left: 1.0in; text-align: justify; text-indent: -1.0in; line-height: 115%;\"><span style=\"font-size: 11.0pt; line-height: 115%; font-family: 'Calibri',sans-serif; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin; mso-bidi-theme-font: minor-latin;\">The evaluation was carried out in accordance with the Common Criteria Evaluation and Validation Scheme (CCEVS) process and scheme for the </span></p>\r\n<p class=\"Default\" style=\"text-align: justify; line-height: 115%;\"><em style=\"mso-bidi-font-style: normal;\"><span style=\"font-size: 11.0pt; line-height: 115%; font-family: 'Calibri',sans-serif; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin; mso-bidi-theme-font: minor-latin; mso-bidi-font-weight: bold;\"><span style=\"mso-spacerun: yes;\">&nbsp;</span>Protection Profile for Application Software</span></em><span style=\"font-size: 11.0pt; line-height: 115%; font-family: 'Calibri',sans-serif; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin; mso-bidi-theme-font: minor-latin; mso-bidi-font-weight: bold;\">, Version 1.4, 7 October 2021</span></p>\r\n<p class=\"Default\" style=\"text-align: justify;\"><span style=\"font-size: 11.0pt; font-family: 'Calibri',sans-serif; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin; mso-bidi-theme-font: minor-latin;\">The evaluation methodology used by the evaluation team to conduct the evaluation is the Common Methodology for Information Technology Security Evaluation, Version 3.1 release 5. The product, when delivered configured as identified in the guidance document, satisfies all of the security functional requirements stated in the Palo Alto Networks GlobalProtect App 6 Security Target. The evaluation was completed in July 2023. Results of the evaluation can be found in the Common Criteria Evaluation and Validation Scheme Validation Report prepared by CCEVS.</span></p>","environmental_strengths":"<p class=\"MsoNormal\" style=\"margin-bottom: 0in; page-break-after: avoid; mso-layout-grid-align: none; text-autospace: none;\"><strong style=\"mso-bidi-font-weight: normal;\"><em style=\"mso-bidi-font-style: normal;\"><span style=\"font-size: 11.0pt; line-height: 115%; font-family: 'Calibri',sans-serif; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin; mso-bidi-theme-font: minor-latin;\">Cryptographic Support</span></em></strong></p>\r\n<p class=\"Body\"><span style=\"font-family: 'Calibri',sans-serif; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin; mso-bidi-theme-font: minor-latin;\">The TOE implements NIST validated cryptographic algorithms that provide key management, random bit generation, encryption/decryption, digital signature and cryptographic hashing and keyed-hash message authentication features in support of cryptographic protocols such as TLS. In order to utilize these features, the TOE must be configured in FIPS-CC mode.<span style=\"mso-spacerun: yes;\">&nbsp; </span></span><span style=\"font-family: 'Calibri',sans-serif; mso-ascii-theme-font: minor-latin; mso-fareast-font-family: Lato; mso-hansi-theme-font: minor-latin; mso-bidi-theme-font: minor-latin; color: black;\">GlobalProtect App includes algorithms that are covered by CAVP certificates and the TOE also relies on the underlying platforms.</span></p>\r\n<p class=\"MsoNormal\" style=\"margin-bottom: 0in; page-break-after: avoid; mso-layout-grid-align: none; text-autospace: none;\"><strong style=\"mso-bidi-font-weight: normal;\"><em style=\"mso-bidi-font-style: normal;\"><span style=\"font-size: 11.0pt; line-height: 115%; font-family: 'Calibri',sans-serif; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin; mso-bidi-theme-font: minor-latin;\">User Data Protection</span></em></strong></p>\r\n<p class=\"Body\"><span style=\"font-family: 'Calibri',sans-serif; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin; mso-bidi-theme-font: minor-latin;\">The TOE restricts its access to only using network connectivity when it is needed to communicate to the Palo Alto Networks Gateway or Portal.<span style=\"mso-spacerun: yes;\">&nbsp; </span>Other functionality on the host platform such as its camera, Bluetooth, USB, or microphone are not needed.<span style=\"mso-spacerun: yes;\">&nbsp; </span>The TOE does not store any sensitive data in non-volatile memory.<span style=\"mso-spacerun: yes;\">&nbsp; </span></span></p>\r\n<p class=\"MsoNormal\" style=\"margin-bottom: 0in; page-break-after: avoid; mso-layout-grid-align: none; text-autospace: none;\"><strong style=\"mso-bidi-font-weight: normal;\"><em style=\"mso-bidi-font-style: normal;\"><span style=\"font-size: 11.0pt; line-height: 115%; font-family: 'Calibri',sans-serif; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin; mso-bidi-theme-font: minor-latin;\">Identification and Authentication</span></em></strong></p>\r\n<p class=\"Body\"><span style=\"font-family: 'Calibri',sans-serif; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin; mso-bidi-theme-font: minor-latin;\">The TOE authenticates the X.509 certificate of the Palo Alto Networks GlobalProtect Gateway/Portal as part of establishing a TLS connection.</span></p>\r\n<p class=\"MsoNormal\" style=\"margin-bottom: 0in; page-break-after: avoid; mso-layout-grid-align: none; text-autospace: none;\"><strong style=\"mso-bidi-font-weight: normal;\"><em style=\"mso-bidi-font-style: normal;\"><span style=\"font-size: 11.0pt; line-height: 115%; font-family: 'Calibri',sans-serif; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin; mso-bidi-theme-font: minor-latin;\">Security Management</span></em></strong></p>\r\n<p class=\"Body\"><span style=\"font-family: 'Calibri',sans-serif; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin; mso-bidi-theme-font: minor-latin;\">The TOE provides access to the security management features using an interface on a general-purpose computer.<span style=\"mso-spacerun: yes;\">&nbsp; </span>Security management operations are provided to the user of the TOE.<span style=\"mso-spacerun: yes;\">&nbsp; </span>A user is able to perform security management by configuring necessary items such as assigning the Palo Alto Networks GlobalProtect Portal and Gateway that the TOE will use for its connections.<span style=\"mso-spacerun: yes;\">&nbsp; </span>It also provides the user with the ability to collect troubleshooting logs, configure gateway and portal, check the current version, check for updates, and to enable/disable the transmission of information regarding the system&rsquo;s hardware/software or configuration. The TOE relies on the OS&rsquo; network ports (i.e. ethernet ports) for communication and management capabilities.<span style=\"mso-spacerun: yes;\">&nbsp; </span></span></p>\r\n<p class=\"Body\"><span style=\"font-family: 'Calibri',sans-serif; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin; mso-bidi-theme-font: minor-latin;\">In order to install or uninstall the TOE, the user is required to have platform administrator privileges.</span></p>\r\n<p class=\"MsoNormal\" style=\"margin-bottom: 0in; page-break-after: avoid; mso-layout-grid-align: none; text-autospace: none;\"><strong style=\"mso-bidi-font-weight: normal;\"><em style=\"mso-bidi-font-style: normal;\"><span style=\"font-size: 11.0pt; line-height: 115%; font-family: 'Calibri',sans-serif; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin; mso-bidi-theme-font: minor-latin;\">Privacy</span></em></strong></p>\r\n<p class=\"Body\"><span style=\"font-family: 'Calibri',sans-serif; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin; mso-bidi-theme-font: minor-latin;\">The TOE does not transmit PII over the network.</span></p>\r\n<p class=\"MsoNormal\" style=\"margin-bottom: 0in; page-break-after: avoid; mso-layout-grid-align: none; text-autospace: none;\"><strong style=\"mso-bidi-font-weight: normal;\"><em style=\"mso-bidi-font-style: normal;\"><span style=\"font-size: 11.0pt; line-height: 115%; font-family: 'Calibri',sans-serif; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin; mso-bidi-theme-font: minor-latin;\">Protection of the TSF</span></em></strong></p>\r\n<p class=\"Body\"><span style=\"font-family: 'Calibri',sans-serif; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin; mso-bidi-theme-font: minor-latin;\">The TOE implements a variety of functions to ensure that it is protected against corruption.<span style=\"mso-spacerun: yes;\">&nbsp; </span>These include utilizing platform APIs, memory mapping, and stack-based buffer overflow protection.<span style=\"mso-spacerun: yes;\">&nbsp; </span>Palo Alto Networks provides customers with a means of updating the TOE using trusted updates.<span style=\"mso-spacerun: yes;\">&nbsp; </span>These trusted updates are securely delivered and installed using protection mechanisms such as TLS, and by using approved digital signature methods. Palo Alto Networks signs all updates using RSA 2048 with SHA-256. The trusted update site also provides a checksum of the updates that can be used for additional verification before it is utilized.</span></p>\r\n<p class=\"MsoNormal\" style=\"margin-bottom: 0in; page-break-after: avoid; mso-layout-grid-align: none; text-autospace: none;\"><strong style=\"mso-bidi-font-weight: normal;\"><em style=\"mso-bidi-font-style: normal;\"><span style=\"font-size: 11.0pt; line-height: 115%; font-family: 'Calibri',sans-serif; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin; mso-bidi-theme-font: minor-latin;\">Trusted Path/Channels</span></em></strong></p>\r\n<p class=\"Body\"><span style=\"font-family: 'Calibri',sans-serif; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin; mso-bidi-theme-font: minor-latin; color: black; mso-bidi-font-weight: bold;\">The TOE protects communication between itself as the endpoint and other networks using TLS. The TOE uses TLS 1.2 to encrypt all data that it transmits to external IT entities (i.e., Palo Alto Networks GlobalProtect Portals and Gateways).</span></p>\r\n<p class=\"Body\"><span style=\"font-family: 'Calibri',sans-serif; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin; mso-bidi-theme-font: minor-latin; color: black; mso-bidi-font-weight: bold;\">&nbsp;</span></p>","features":[{"id":1749,"feature_name":"Certificate Authentication"},{"id":1751,"feature_name":"Certificate Validation"},{"id":1753,"feature_name":"Credential Storage"},{"id":1754,"feature_name":"DRBG"},{"id":1755,"feature_name":"DTLS 1.0"},{"id":1756,"feature_name":"DTLS Client"},{"id":1757,"feature_name":"DTLS Server with Mutual Authentication"},{"id":1758,"feature_name":"PBKDF"},{"id":1759,"feature_name":"TLS 1.1"}]}