{"product_id":11451,"v_id":11451,"product_name":"Axway Desktop Validator, version 5.2","certification_status":"Certified","certification_date":"2024-07-15T00:00:00Z","tech_type":"Application Software","vendor_id":{"name":"Axway, Inc.","website":"https://axway.com"},"vendor_poc":"Jeff Allen","vendor_phone":"+1 480 627 1800","vendor_email":"jallen@axway.com","assigned_lab":{"cctl_name":"Gossamer Security Solutions"},"product_description":"<p style=\"margin: 0in 0in 6pt; text-align: justify; line-height: 11pt; font-size: 10pt; font-family: Times, serif;\">The Axway Desktop Validator (DV) is part of Axway&rsquo;s Validation Authority Suite, which provides a comprehensive, scalable, and reliable framework for real-time validation of digital <span style=\"color: black;\">certifications for the Public Key Infrastructure (PKI). The Axway VA Suite provides a variety of PKI and certificate management functionality to </span>prevent revoked credentials from being used for secure email, smart card login, network access (including wireless), or other sensitive electronic transactions. The Axway DV provides the following functionality:</p>\r\n<ul style=\"margin-bottom: 0in; margin-top: 0px;\">\r\n<li style=\"margin: 0in 0in 6pt 0px; text-align: justify; line-height: 11pt; font-size: 10pt; font-family: Times, serif;\">Maintains and processes a store of digital certificate revocation data by obtaining the digital Certificate Revocation List (CRL) from multiple CA or VA sources and performing end-to-end certificate validation if one or more intermediate CAs are used and the validation policy requires a complete certificate chain validation.</li>\r\n<li style=\"margin: 0in 0in 6pt 0px; text-align: justify; line-height: 11pt; font-size: 10pt; font-family: Times, serif;\">Maintains a cache loaded with OCSP responses that are pre-computed or dynamically built up by proxy client requests to a responder.</li>\r\n<li style=\"margin: 0in 0in 6pt 0px; text-align: justify; line-height: 11pt; font-size: 10pt; font-family: Times, serif;\">Allows caching of CRLs and delta CRLs to support non-OCSP clients or clients that want to maintain their own revocation data caches for backup and in low-bandwidth and non real-time environments.</li>\r\n</ul>","evaluation_configuration":"<p style=\"margin: 0in 0in 6pt; text-align: justify; line-height: 11pt; font-size: 10pt; font-family: Times, serif;\">The Axway Desktop Validator allows installation on Microsoft Windows on one of the following platforms:</p>\r\n<ul style=\"margin-top: 0in; margin-bottom: 0in;\">\r\n<li style=\"margin: 0in 0in 0in 0px; text-align: justify; line-height: 11pt; font-size: 10pt; font-family: Times, serif;\">Microsoft Windows 10/11 (64 bit) on a 64 bit Intel Xeon processor</li>\r\n<li style=\"margin: 0in 0in 0in 0px; text-align: justify; line-height: 11pt; font-size: 10pt; font-family: Times, serif;\">Microsoft Windows Server 2022 (64 bit) on a 64 bit Intel Xeon processor</li>\r\n</ul>\r\n<p style=\"margin: 0in; text-align: justify; line-height: 11pt; font-size: 10pt; font-family: Times, serif;\">&nbsp;</p>\r\n<p style=\"margin: 0in 0in 6pt; text-align: justify; line-height: 11pt; font-size: 10pt; font-family: Times, serif;\">The Windows platform is part of the operating environment of the TOE. The TOE can execute on any Intel Xeon processor, however the lab tested the TOE on an Intel Xeon E5-2670. The lab also tested the TOE on Windows 11 (64 bit) and Windows Server 2022 (64 bit) in the evaluated configuration.</p>\r\n<p style=\"margin: 0in 0in 6pt; text-align: justify; line-height: 11pt; font-size: 10pt; font-family: Times, serif;\"><span style=\"color: black;\">The Axway VA Suite is composed of the following applications:</span></p>\r\n<ol style=\"margin-top: 0in; margin-bottom: 6.0pt;\">\r\n<li style=\"margin: 0in 0in 6pt 0px; line-height: 11pt; font-size: 10pt; font-family: Times, serif;\"><u>Validation Authority Server (VA Server)</u> &ndash; the VA Server is comprised of the VA validation server acting as either a Repeater or Responder operating on a Windows or Linux platform, and the Web based administration (Admin UI).&nbsp; The VA Server maintains a store of digital certificate revocation data and ensures the integrity and validity of online transactions by delivering real-time validation of digital certificates.</li>\r\n<li style=\"margin: 0in 0in 6pt 0px; line-height: 11pt; font-size: 10pt; font-family: Times, serif;\"><u>Desktop Validator (DV) - </u>(Standard and Enterprise Editions) - the Desktop Validator is a Microsoft CAPI compliant revocation trust provider that communicates with the Validation Authority Server (VA server) in responder mode to check status of digital certs in real time.&nbsp; DV runs as a service on a 64bit Microsoft Windows platforms and can be invoked to validate standard X.509v3 digital certificates issued by any Certificate Authority (CA).&nbsp; The DV Standard edition provides certificate validation support for client applications, while the DV Enterprise edition provides certificate validation support for both client and server applications.</li>\r\n</ol>\r\n<p style=\"margin: 0in 0in 6pt; font-size: 10pt; font-family: Times, serif;\">As the focus of this evaluation is on the DV, the lab tested the DV Enterprise edition as the Enterprise edition is a superset that includes the Standard edition&rsquo;s functionality.</p>","security_evaluation_summary":"<p style=\"text-align: justify; margin: 0in; font-size: 10pt; font-family: Times, serif;\">The evaluation was carried out in accordance to the Common Criteria Evaluation and Validation Scheme (CCEVS) requirements and guidance.&nbsp; The evaluation demonstrated that the TOE<em> </em>meets the security requirements contained in the Security Target.&nbsp; The criteria against which the TOE was judged are described in the Common Criteria for Information Technology Security Evaluation, Version 3.1, Revision 5, April 2017. The evaluation methodology used by the evaluation team to conduct the evaluation is the Common Methodology for Information Technology Security Evaluation, Evaluation Methodology, Version 3.1, Revision 5, April 2017.&nbsp; The product, when delivered and configured as identified in the Validation Authority Common Criteria Guide, version 5.2, June 10, 2024 document, satisfies all of the security functional requirements stated in the Axway Desktop Validator, version 5.2 Security Target, Version 0.4, June 11, 20204.&nbsp; The project underwent CCEVS Validator review.&nbsp; The evaluation was completed in July 2024.&nbsp; Results of the evaluation can be found in the Common Criteria Evaluation and Validation Scheme Validation Report (report number CCEVS-VR-VID11451-2024) prepared by CCEVS.</p>","environmental_strengths":"<p style=\"text-align: justify; margin: 0in; font-size: 10pt; font-family: Times, serif;\"><strong>Environmental Strengths</strong>:</p>\r\n<p style=\"text-align: justify; margin: 0in; font-size: 10pt; font-family: Times, serif;\">The logical boundaries of the Axway Desktop Validator are realized in the security functions that it implements. Each of these security functions is summarized below.</p>\r\n<p style=\"margin: 0in; font-size: 10pt; font-family: Times, serif;\">&nbsp;</p>\r\n<p style=\"text-align: justify; margin: 0in; font-size: 10pt; font-family: Times, serif;\"><strong>Cryptographic support:</strong></p>\r\n<p style=\"margin: 0in 0in 6pt; text-align: justify; line-height: 11pt; font-size: 10pt; font-family: Times, serif;\">The TOE does not generate any asymmetric keys.</p>\r\n<p style=\"text-align: justify; margin: 0in; font-size: 10pt; font-family: Times, serif;\"><strong>User data protection:</strong></p>\r\n<p style=\"margin: 0in 0in 6pt; text-align: justify; line-height: 11pt; font-size: 10pt; font-family: Times, serif;\"><span style=\"font-family: 'Times New Roman', serif;\">The TOE does not access any hardware resources (other than network connectivity) or sensitive information repositories. The TOE does not store any sensitive data in non-volatile memory.&nbsp; Inbound and outbound network communications are restricted to those that are application initiated.</span></p>\r\n<p style=\"text-align: justify; margin: 0in; font-size: 10pt; font-family: Times, serif;\"><strong>Security management:</strong></p>\r\n<p style=\"margin: 0in 0in 6pt; text-align: justify; line-height: 11pt; font-size: 10pt; font-family: Times, serif;\"><span style=\"font-family: 'Times New Roman', serif;\">The TOE provides the ability to configure enhanced revocation checking. The TOE also provides the ability to check for TOE updates.</span></p>\r\n<p style=\"text-align: justify; margin: 0in; font-size: 10pt; font-family: Times, serif;\"><strong>Privacy:</strong></p>\r\n<p style=\"margin: 0in 0in 6pt; text-align: justify; line-height: 11pt; font-size: 10pt; font-family: Times, serif;\"><span style=\"font-family: 'Times New Roman', serif;\">The TOE does not transmit personally identifiable information (PII) over any network interfaces.</span></p>\r\n<p style=\"text-align: justify; break-after: avoid; margin: 0in; font-size: 10pt; font-family: Times, serif;\"><strong>Protection of the TSF:</strong></p>\r\n<p style=\"margin: 0in 0in 6pt; text-align: justify; line-height: 11pt; font-size: 10pt; font-family: Times, serif;\"><span style=\"font-family: 'Times New Roman', serif;\">The TOE protects itself against exploitation by implementing address space layout randomization (ASLR) and by not allocating any memory region for both write and execute permission. The TOE is compiled for Windows with stack-based buffer overflow protection and does not allow user-modifiable files to be written to directories that contain executable files.&nbsp; The TOE uses standard platform APIs and includes a number of third party libraries used to perform its functions.</span></p>\r\n<p style=\"margin: 0in 0in 6pt; text-align: justify; line-height: 11pt; font-size: 10pt; font-family: Times, serif;\"><span style=\"font-family: 'Times New Roman', serif;\">The TOE includes mechanisms to check for updates and to query the current version of the application software. TOE software is digitally signed and distributed using the platform-supported package manager (Windows).&nbsp; The TOE does not update its own binary code in any way and when removed, all traces of the TOE application software are deleted.</span></p>\r\n<p style=\"text-align: justify; margin: 0in; font-size: 10pt; font-family: Times, serif;\"><strong>Trusted path/channels:</strong></p>\r\n<p style=\"margin: 0in 0in 6pt; text-align: justify; line-height: 11pt; font-size: 10pt; font-family: Times, serif;\"><span style=\"font-family: 'Times New Roman', serif;\">The TOE does not transmit any sensitive data across the network.</span></p>","features":[{"id":5233,"feature_name":"Application Software"},{"id":5234,"feature_name":"Credential Storage"},{"id":5235,"feature_name":"TLS Client"}]}