{"product_id":11441,"v_id":11441,"product_name":"VMware Workspace ONE Boxer Email Client Version 23.11","certification_status":"Certified","certification_date":"2024-05-06T00:00:00Z","tech_type":"Application Software, Email Client","vendor_id":{"name":"VMware, LLC","website":"www.vmware.com"},"vendor_poc":"Vann Nguyen","vendor_phone":"1 (877) 486-9273","vendor_email":"vannn@vmware.com","assigned_lab":{"cctl_name":"Booz Allen Hamilton Common Criteria Testing Laboratory"},"product_description":"<p class=\"MsoNormal\"><span style=\"font-size: 11.0pt; font-family: 'Times New Roman',serif;\">The TOE is the VMware Workspace ONE Boxer Email Client Version 23.11 application which is an enterprise email client for iOS, iPadOS and Android mobile devices. The Boxer application provides S/MIME email services and containerizes enterprise data from personal data that resides on the user&rsquo;s mobile device. </span></p>","evaluation_configuration":"<p class=\"MsoNormal\"><span style=\"font-size: 11.0pt; font-family: 'Times New Roman',serif;\">In the evaluated configuration, the TOE is installed on either a mobile device running iOS 16 (VID11349), iPadOS 16 (VID11350), or Android 13 (VID11342). The mobile devices must be enrolled and managed by the VMware Workspace ONE Unified Endpoint Management (UEM) at the device level. When the TOE application is installed on the mobile device it is then enrolled as a managed application in UEM in order to obtain its configuration information. </span></p>\r\n<p class=\"MsoNormal\"><span style=\"font-size: 11.0pt; font-family: 'Times New Roman',serif;\">Additionally, the TOE is configured to use ActiveSync to communicate with the Microsoft Exchange server over a TLS v1.2 trusted channel. The Exchange server resides in the operational environment and is for sending and receiving enterprise data such as email, calendar information and appointment data. Whether installed on an Android or iOS/iPadOS device, the application validates the certificates using OCSP. The OCSP responder is also considered part of the operational environment.</span></p>\r\n<p class=\"MsoNormal\"><span style=\"font-size: 11.0pt; font-family: 'Times New Roman',serif; mso-bidi-font-weight: bold;\">The following list identifies the components and applications in the environment that the TOE relies upon in order to function properly:</span></p>\r\n<table class=\"ST-TABLE11\" style=\"width: 422.5pt; margin-left: .5pt; border-collapse: collapse; border: none; mso-border-alt: solid #7BA0CD 1.0pt; mso-yfti-tbllook: 1184; mso-padding-alt: 0in 5.75pt 0in 5.75pt;\" border=\"1\" width=\"563\" cellspacing=\"0\" cellpadding=\"0\">\r\n<tbody>\r\n<tr style=\"mso-yfti-irow: -1; mso-yfti-firstrow: yes; mso-yfti-lastfirstrow: yes; height: 18.4pt;\">\r\n<td style=\"width: 175.0pt; border: solid windowtext 1.0pt; mso-border-alt: solid windowtext .5pt; background: black; padding: 0in 5.75pt 0in 5.75pt; height: 18.4pt;\" width=\"233\">\r\n<p class=\"MsoNormal\" style=\"line-height: 115%; mso-pagination: none; mso-yfti-cnfc: 5; margin: 6.0pt 0in 6.0pt 0in;\"><a name=\"_Hlk31795038\"></a><strong><span style=\"font-size: 11.0pt; line-height: 115%; font-family: 'Times New Roman',serif; mso-fareast-font-family: Calibri; color: white;\">Component</span></strong></p>\r\n</td>\r\n<td style=\"width: 247.5pt; border: solid windowtext 1.0pt; border-left: none; mso-border-left-alt: solid windowtext .5pt; mso-border-alt: solid windowtext .5pt; background: black; padding: 0in 5.75pt 0in 5.75pt; height: 18.4pt;\" width=\"330\">\r\n<p class=\"MsoNormal\" style=\"line-height: 115%; mso-pagination: none; mso-yfti-cnfc: 1; margin: 6.0pt 0in 6.0pt 0in;\"><span style=\"mso-bookmark: _Hlk31795038;\"><strong><span style=\"font-size: 11.0pt; line-height: 115%; font-family: 'Times New Roman',serif; mso-fareast-font-family: Calibri; color: white;\">Definition</span></strong></span></p>\r\n</td>\r\n</tr>\r\n<tr style=\"mso-yfti-irow: 0;\">\r\n<td style=\"width: 175.0pt; border: solid windowtext 1.0pt; border-top: none; mso-border-top-alt: solid windowtext .5pt; mso-border-alt: solid windowtext .5pt; background: #D9D9D9; padding: 0in 5.75pt 0in 5.75pt;\" width=\"233\">\r\n<p class=\"MsoNormal\" style=\"line-height: 115%; mso-pagination: none; mso-yfti-cnfc: 68; margin: 6.0pt 0in 6.0pt 0in;\"><span style=\"mso-bookmark: _Hlk31795038;\"><a name=\"_Hlk67045027\"></a><strong><span style=\"font-size: 11.0pt; line-height: 115%; font-family: 'Times New Roman',serif; mso-fareast-font-family: Calibri;\">OCSP Responder</span></strong></span></p>\r\n</td>\r\n<td style=\"width: 247.5pt; border-top: none; border-left: none; border-bottom: solid windowtext 1.0pt; border-right: solid windowtext 1.0pt; mso-border-top-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-alt: solid windowtext .5pt; background: #D9D9D9; padding: 0in 5.75pt 0in 5.75pt;\" width=\"330\">\r\n<p class=\"MsoNormal\" style=\"line-height: 115%; mso-pagination: none; mso-yfti-cnfc: 64; margin: 6.0pt 0in 6.0pt 0in;\"><span style=\"mso-bookmark: _Hlk31795038;\"><span style=\"mso-bookmark: _Hlk67045027;\"><span style=\"font-size: 11.0pt; line-height: 115%; font-family: 'Times New Roman',serif; mso-fareast-font-family: Calibri;\">A server deployed within the Operational Environment which confirms the validity and revocation status of certificates.</span></span></span></p>\r\n</td>\r\n</tr>\r\n<tr style=\"mso-yfti-irow: 1;\">\r\n<td style=\"width: 175.0pt; border: solid windowtext 1.0pt; border-top: none; mso-border-top-alt: solid windowtext .5pt; mso-border-alt: solid windowtext .5pt; padding: 0in 5.75pt 0in 5.75pt;\" width=\"233\">\r\n<p class=\"MsoNormal\" style=\"line-height: 115%; mso-pagination: none; mso-yfti-cnfc: 132; margin: 6.0pt 0in 6.0pt 0in;\"><span style=\"mso-bookmark: _Hlk31795038;\"><span style=\"mso-bookmark: _Hlk67045027;\"><strong><span style=\"font-size: 11.0pt; line-height: 115%; font-family: 'Times New Roman',serif; mso-fareast-font-family: Calibri;\">VMware Workspace ONE Unified Endpoint Management (UEM) Server</span></strong></span></span></p>\r\n</td>\r\n<td style=\"width: 247.5pt; border-top: none; border-left: none; border-bottom: solid windowtext 1.0pt; border-right: solid windowtext 1.0pt; mso-border-top-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-alt: solid windowtext .5pt; padding: 0in 5.75pt 0in 5.75pt;\" width=\"330\">\r\n<p class=\"MsoNormal\" style=\"line-height: 115%; mso-pagination: none; mso-yfti-cnfc: 128; margin: 6.0pt 0in 6.0pt 0in;\"><span style=\"mso-bookmark: _Hlk31795038;\"><span style=\"mso-bookmark: _Hlk67045027;\"><span style=\"font-size: 11.0pt; line-height: 115%; font-family: 'Times New Roman',serif; mso-fareast-font-family: Calibri;\">The VMware Workspace ONE UEM server is used to manage the Boxer app (TOE) and its host mobile device. The UEM Server provides administrative access through its UEM Console.</span></span></span></p>\r\n</td>\r\n</tr>\r\n<tr style=\"mso-yfti-irow: 2;\">\r\n<td style=\"width: 175.0pt; border: solid windowtext 1.0pt; border-top: none; mso-border-top-alt: solid windowtext .5pt; mso-border-alt: solid windowtext .5pt; background: #D9D9D9; padding: 0in 5.75pt 0in 5.75pt;\" width=\"233\">\r\n<p class=\"MsoNormal\" style=\"line-height: 115%; mso-pagination: none; mso-yfti-cnfc: 68; margin: 6.0pt 0in 6.0pt 0in;\"><span style=\"mso-bookmark: _Hlk31795038;\"><span style=\"mso-bookmark: _Hlk67045027;\"><strong><span style=\"font-size: 11.0pt; line-height: 115%; font-family: 'Times New Roman',serif; mso-fareast-font-family: Calibri;\">Microsoft Exchange Server 2019</span></strong></span></span></p>\r\n</td>\r\n<td style=\"width: 247.5pt; border-top: none; border-left: none; border-bottom: solid windowtext 1.0pt; border-right: solid windowtext 1.0pt; mso-border-top-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-alt: solid windowtext .5pt; background: #D9D9D9; padding: 0in 5.75pt 0in 5.75pt;\" width=\"330\">\r\n<p class=\"MsoNormal\" style=\"line-height: 115%; mso-pagination: none; mso-yfti-cnfc: 64; margin: 6.0pt 0in 6.0pt 0in;\"><span style=\"mso-bookmark: _Hlk31795038;\"><span style=\"mso-bookmark: _Hlk67045027;\"><span style=\"font-size: 11.0pt; line-height: 115%; font-family: 'Times New Roman',serif; mso-fareast-font-family: Calibri;\">Exchange server for sending and receiving emails to and from the Operational Environment configured to use ActiveSync to communicate.</span></span></span></p>\r\n</td>\r\n</tr>\r\n<tr style=\"mso-yfti-irow: 3; mso-yfti-lastrow: yes;\">\r\n<td style=\"width: 175.0pt; border: solid windowtext 1.0pt; border-top: none; mso-border-top-alt: solid windowtext .5pt; mso-border-alt: solid windowtext .5pt; padding: 0in 5.75pt 0in 5.75pt;\" width=\"233\">\r\n<p class=\"MsoNormalCxSpMiddle\" style=\"mso-add-space: auto; line-height: 115%; mso-pagination: none; mso-yfti-cnfc: 132; margin: 6.0pt 0in 6.0pt 0in;\"><span style=\"mso-bookmark: _Hlk31795038;\"><span style=\"mso-bookmark: _Hlk67045027;\"><strong><span style=\"font-size: 11.0pt; line-height: 115%; font-family: 'Times New Roman',serif; mso-fareast-font-family: Calibri;\">Mobile Device</span></strong></span></span></p>\r\n</td>\r\n<td style=\"width: 247.5pt; border-top: none; border-left: none; border-bottom: solid windowtext 1.0pt; border-right: solid windowtext 1.0pt; mso-border-top-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-alt: solid windowtext .5pt; padding: 0in 5.75pt 0in 5.75pt;\" width=\"330\">\r\n<p class=\"MsoNormalCxSpMiddle\" style=\"line-height: 115%; mso-yfti-cnfc: 128;\"><span style=\"mso-bookmark: _Hlk31795038;\"><span style=\"mso-bookmark: _Hlk67045027;\"><span style=\"font-size: 11.0pt; line-height: 115%; font-family: 'Times New Roman',serif; mso-fareast-font-family: Calibri;\">The hardware that runs the OS in which the application is installed on.</span></span></span></p>\r\n<p class=\"MsoNormalCxSpMiddle\" style=\"line-height: 115%; mso-yfti-cnfc: 128;\"><span style=\"mso-bookmark: _Hlk31795038;\"><span style=\"mso-bookmark: _Hlk67045027;\"><span style=\"font-size: 11.0pt; line-height: 115%; font-family: 'Times New Roman',serif; mso-fareast-font-family: Calibri;\">&nbsp;</span></span></span></p>\r\n<p class=\"MsoNormalCxSpMiddle\" style=\"line-height: 115%; mso-yfti-cnfc: 128;\"><span style=\"mso-bookmark: _Hlk31795038;\"><span style=\"mso-bookmark: _Hlk67045027;\"><span style=\"font-size: 11.0pt; line-height: 115%; font-family: 'Times New Roman',serif; mso-fareast-font-family: Calibri;\">The TOE was installed on a certified iOS 16 (VID11349) device, iPadOS 16 (VID11350), and certified Android 13 (VID11342) device. For testing, this evaluation used a Samsung Galaxy XCover6 Pro (Android), iPad Air 4th generation (Apple), and an iPhone 12 Pro (Apple).</span></span></span></p>\r\n</td>\r\n</tr>\r\n</tbody>\r\n</table>","security_evaluation_summary":"<p class=\"MsoNormal\"><span style=\"font-size: 11.0pt; font-family: 'Times New Roman',serif;\">The evaluation was carried out in accordance with the Common Criteria Evaluation and Validation Scheme (CCEVS) processes and procedures. VMware Workspace ONE Boxer Email Client Version 23.11 was evaluated against the criteria contained in the Common Criteria for Information Technology Security Evaluation, Version 3.1 Revision 5. The evaluation methodology used by the evaluation team to conduct the evaluation is the Common Methodology for Information Technology Security Evaluation, Version 3.1 Revision 5. The product, when installed and configured per the instructions provided in the preparative guidance, satisfies all of the security functional requirements stated in the <a name=\"_Hlk78216061\"></a><em style=\"mso-bidi-font-style: normal;\">VMware Workspace ONE Boxer Email Client Version 23.11 Security Target</em><em style=\"mso-bidi-font-style: normal;\"> V1.0, </em><span style=\"mso-bidi-font-style: italic;\">dated March 4, 2024.</span> The evaluation underwent CCEVS Validator review. The evaluation was completed in May 2024. Results of the evaluation can be found in the Common Criteria Evaluation and Validation Scheme Validation Report, CCEVS-VR-</span> <span style=\"font-size: 11.0pt; font-family: 'Times New Roman',serif;\">VID11441-2024 prepared by CCEVS.</span></p>","environmental_strengths":"<p class=\"MsoNormal\" style=\"mso-pagination: widow-orphan lines-together; page-break-after: avoid; mso-outline-level: 3; margin: 10.0pt 0in 6.0pt 0in;\"><a name=\"_Hlk78216955\"></a><a name=\"_Hlk512945721\"></a><a name=\"_Toc61639519\"></a><a name=\"_Toc41726772\"></a><span style=\"mso-bookmark: _Toc61639519;\"><span style=\"mso-bookmark: _Hlk512945721;\"><span style=\"mso-bookmark: _Hlk78216955;\"><strong><span style=\"font-size: 11.0pt; font-family: 'Times New Roman',serif;\">Cryptographic Support</span></strong></span></span></span></p>\r\n<p class=\"MsoNormal\"><span style=\"mso-bookmark: _Hlk512945721;\"><span style=\"mso-bookmark: _Hlk78216955;\"><span style=\"font-size: 11.0pt; font-family: 'Times New Roman',serif;\">Depending on which OS the application is installed on, the TOE either invokes the underlying platform or implements its own cryptographic module to perform cryptographic services. All cryptographic mechanisms, whether platform or application provided, use DRBG functionality to support cryptographic operations. Cryptographic functionality includes encryption/decryption services, credential/key storage, key establishment, key destruction, hashing services, signature services, key-hashed message authentication, and key chaining using a password-based derivation function.</span></span></span></p>\r\n<p class=\"MsoNormal\"><span style=\"mso-bookmark: _Hlk512945721;\"><span style=\"mso-bookmark: _Hlk78216955;\"><span style=\"font-size: 11.0pt; font-family: 'Times New Roman',serif;\">Cryptographic services for the application&rsquo;s S/MIME functionality and TLS communications are provided by the underlying platform when the application is installed on a device running iOS/iPadOS. When installed on a device running the Android OS, the TOE invokes the underlying platform cryptographic libraries for TLS communications and implements an OpenSSL cryptographic module to perform the cryptographic functionality required to support S/MIME (CAVP certificate #A5072).</span></span></span></p>\r\n<p class=\"MsoNormal\" style=\"text-indent: -.5in; mso-pagination: widow-orphan lines-together; page-break-after: avoid; mso-outline-level: 3; margin: 10.0pt 0in 6.0pt .5in;\"><span style=\"mso-bookmark: _Hlk512945721;\"><span style=\"mso-bookmark: _Hlk78216955;\"><a name=\"_Hlk23340457\"></a><a name=\"_Hlk41727608\"></a><a name=\"_Toc61639520\"></a><a name=\"_Toc41726773\"></a><span style=\"mso-bookmark: _Toc61639520;\"><span style=\"mso-bookmark: _Hlk41727608;\"><span style=\"mso-bookmark: _Hlk23340457;\"><strong><span style=\"font-size: 11.0pt; font-family: 'Times New Roman',serif;\">User Data Protection</span></strong></span></span></span></span></span></p>\r\n<p class=\"MsoNormal\" style=\"margin: 6.0pt 0in 6.0pt 0in;\"><span style=\"mso-bookmark: _Hlk512945721;\"><span style=\"mso-bookmark: _Hlk78216955;\"><span style=\"mso-bookmark: _Hlk41727608;\"><span style=\"mso-bookmark: _Hlk23340457;\"><a name=\"_Hlk41727714\"></a><a name=\"_Hlk34737419\"></a><span style=\"mso-bookmark: _Hlk41727714;\"><span style=\"font-size: 11.0pt; font-family: 'Times New Roman',serif; mso-fareast-font-family: Calibri;\">The TOE uses S/MIME to digitally sign, verify, decrypt, and encrypt email messages. The TOE stores all application data in an encrypted Boxer database which is created on the mobile device during installation. The TOE&rsquo;s host platforms (iOS, iPadOS, and Android) implement file-based encryption to securely store the data. The TOE restricts its network access and provides user awareness when it attempts to access hardware resources and sensitive data stored on the host platform. The TOE displays notification icons that show S/MIME status. Each status is shown as a different color so that the user can quickly identify any issues.</span></span></span></span></span></span></p>\r\n<p class=\"MsoNormal\" style=\"text-indent: -.5in; mso-pagination: widow-orphan lines-together; page-break-after: avoid; mso-outline-level: 3; margin: 10.0pt 0in 6.0pt .5in;\"><span style=\"mso-bookmark: _Hlk512945721;\"><span style=\"mso-bookmark: _Hlk78216955;\"><span style=\"mso-bookmark: _Hlk41727608;\"><span style=\"mso-bookmark: _Hlk23340457;\"><a name=\"_Toc61639521\"></a><a name=\"_Toc41726774\"></a><span style=\"mso-bookmark: _Toc61639521;\"><strong><span style=\"font-size: 11.0pt; font-family: 'Times New Roman',serif;\">Identification and Authentication</span></strong></span></span></span></span></span></p>\r\n<p class=\"MsoNormal\"><span style=\"mso-bookmark: _Hlk512945721;\"><span style=\"mso-bookmark: _Hlk78216955;\"><span style=\"mso-bookmark: _Hlk41727608;\"><span style=\"mso-bookmark: _Hlk23340457;\"><span style=\"mso-bookmark: _Toc41726774;\"><span style=\"mso-bookmark: _Toc61639521;\"><span style=\"font-size: 11.0pt; font-family: 'Times New Roman',serif;\">The TOE relies on the OS to validate X.509.3 certificates for TLS communication. The TOE validates X.509v3 certificates for signing and encrypting emails for S/MIME.</span></span></span></span></span></span></span></p>\r\n<p class=\"MsoNormal\" style=\"text-indent: -.5in; mso-pagination: widow-orphan lines-together; page-break-after: avoid; mso-outline-level: 3; margin: 10.0pt 0in 6.0pt .5in;\"><span style=\"mso-bookmark: _Hlk512945721;\"><span style=\"mso-bookmark: _Hlk78216955;\"><span style=\"mso-bookmark: _Hlk41727608;\"><span style=\"mso-bookmark: _Hlk23340457;\"><span style=\"mso-bookmark: _Toc41726774;\"><span style=\"mso-bookmark: _Toc61639521;\"><strong><span style=\"font-size: 11.0pt; font-family: 'Times New Roman',serif;\">Security Management</span></strong></span></span></span></span></span></span></p>\r\n<p class=\"MsoNormal\" style=\"margin: 6.0pt 0in 6.0pt 0in;\"><span style=\"mso-bookmark: _Hlk512945721;\"><span style=\"mso-bookmark: _Hlk78216955;\"><span style=\"mso-bookmark: _Hlk41727608;\"><span style=\"mso-bookmark: _Hlk23340457;\"><a name=\"_Hlk41727687\"></a><span style=\"font-size: 11.0pt; font-family: 'Times New Roman',serif; mso-fareast-font-family: Calibri;\">The TOE enforces the application&rsquo;s enterprise policy set by the UEM administrator pushed out to the managed TOE device. The TOE does not use default passwords, and automatically installs and configures the application to protect itself and its data from unauthorized access while also implementing the recommended platform security mechanisms. Changing one&rsquo;s own password from the application is the only management function that can be performed by the owner/user of the mobile device with the TOE installed.</span></span></span></span></span></p>\r\n<p class=\"MsoNormal\" style=\"text-indent: -.5in; mso-pagination: widow-orphan lines-together; page-break-after: avoid; mso-outline-level: 3; margin: 10.0pt 0in 6.0pt .5in;\"><span style=\"mso-bookmark: _Hlk512945721;\"><span style=\"mso-bookmark: _Hlk78216955;\"><span style=\"mso-bookmark: _Hlk41727608;\"><span style=\"mso-bookmark: _Hlk23340457;\"><a name=\"_Toc61639522\"></a><a name=\"_Toc41726775\"></a><span style=\"mso-bookmark: _Toc61639522;\"><strong><span style=\"font-size: 11.0pt; font-family: 'Times New Roman',serif;\">Privacy</span></strong></span></span></span></span></span></p>\r\n<p class=\"MsoNormal\" style=\"margin: 6.0pt 0in 6.0pt 0in;\"><span style=\"mso-bookmark: _Hlk512945721;\"><span style=\"mso-bookmark: _Hlk78216955;\"><span style=\"mso-bookmark: _Hlk41727608;\"><span style=\"mso-bookmark: _Hlk23340457;\"><span style=\"font-size: 11.0pt; font-family: 'Times New Roman',serif;\">The TOE does not transmit any personally identifiable information (PII) over the network unless voluntarily sent via free text email</span></span></span></span></span><span style=\"mso-bookmark: _Hlk512945721;\"><span style=\"mso-bookmark: _Hlk78216955;\"><span style=\"mso-bookmark: _Hlk41727608;\"><span style=\"mso-bookmark: _Hlk23340457;\"><span style=\"font-size: 11.0pt; font-family: 'Times New Roman',serif; mso-fareast-font-family: Calibri;\">.</span></span></span></span></span></p>\r\n<p class=\"MsoNormal\" style=\"text-indent: -.5in; mso-pagination: widow-orphan lines-together; page-break-after: avoid; mso-outline-level: 3; margin: 10.0pt 0in 6.0pt .5in;\"><span style=\"mso-bookmark: _Hlk512945721;\"><span style=\"mso-bookmark: _Hlk78216955;\"><span style=\"mso-bookmark: _Hlk41727608;\"><span style=\"mso-bookmark: _Hlk23340457;\"><a name=\"_Toc61639523\"></a><a name=\"_Toc41726776\"></a><span style=\"mso-bookmark: _Toc61639523;\"><strong><span style=\"font-size: 11.0pt; font-family: 'Times New Roman',serif;\">Protection of the TSF</span></strong></span></span></span></span></span></p>\r\n<p class=\"MsoNormal\" style=\"margin: 6.0pt 0in 6.0pt 0in;\"><span style=\"mso-bookmark: _Hlk512945721;\"><span style=\"mso-bookmark: _Hlk78216955;\"><span style=\"mso-bookmark: _Hlk41727608;\"><span style=\"mso-bookmark: _Hlk23340457;\"><a name=\"_Hlk41727667\"></a><span style=\"font-size: 11.0pt; font-family: 'Times New Roman',serif; mso-fareast-font-family: Calibri;\">The TOE does not support the installation of trusted or untrusted add-ons. The user is able to navigate the platform to check the version of the TOE and also check for updates to the application. All updates come from the Google Play Store (Android) or Apple App Store (iOS and iPadOS). The digital signature of the updates is verified by the mobile device platform prior to being installed. The TOE does not replace or modify its own binaries without user interaction. The TOE implements anti-exploitation features, such as stack-based overflow protection, is compatible with security features provided by the OS, and will only use documented APIs and libraries.<span style=\"mso-spacerun: yes;\">&nbsp; </span></span></span></span></span></span></p>\r\n<p class=\"MsoNormal\" style=\"text-indent: -.5in; mso-pagination: widow-orphan lines-together; page-break-after: avoid; mso-outline-level: 3; margin: 10.0pt 0in 6.0pt .5in;\"><span style=\"mso-bookmark: _Hlk512945721;\"><span style=\"mso-bookmark: _Hlk78216955;\"><span style=\"mso-bookmark: _Hlk41727608;\"><span style=\"mso-bookmark: _Hlk23340457;\"><a name=\"_Toc61639524\"></a><a name=\"_Toc41726777\"></a><span style=\"mso-bookmark: _Toc61639524;\"><strong><span style=\"font-size: 11.0pt; font-family: 'Times New Roman',serif;\">Trusted Path/Channels</span></strong></span></span></span></span></span></p>\r\n<p class=\"MsoNormalCxSpMiddle\"><span style=\"mso-bookmark: _Hlk78216955;\"><span style=\"font-size: 11.0pt; font-family: 'Times New Roman',serif; mso-fareast-font-family: Calibri;\">The TOE invokes the platform to provide the trusted communication channel between the TOE and the Exchange server. Communications are protected with TLS v1.2. Communication to the Exchange server uses ActiveSync to send and receive emails.</span></span></p>","features":[{"id":1515,"feature_name":"Application Software"},{"id":1523,"feature_name":"Asymmetric Key Generation"},{"id":1539,"feature_name":"Certificate Authentication"},{"id":1538,"feature_name":"Certificate Validation"},{"id":1532,"feature_name":"Cryptographic Hashing"},{"id":1531,"feature_name":"Cryptographic Key Establishment"},{"id":1534,"feature_name":"Cryptographic Signature Generation"},{"id":1535,"feature_name":"Cryptographic Signature Verification"},{"id":1537,"feature_name":"DRBG"},{"id":1540,"feature_name":"Email Client"},{"id":1514,"feature_name":"Key Destruction"},{"id":1533,"feature_name":"Keyed-hash message authentication"},{"id":1524,"feature_name":"TLS"}]}