{"product_id":11452,"v_id":11452,"product_name":"Axway Validation Authority Server, version 5.2","certification_status":"Certified","certification_date":"2024-07-15T00:00:00Z","tech_type":"Application Software, Network Encryption","vendor_id":{"name":"Axway, Inc.","website":"https://axway.com"},"vendor_poc":"Jeff Allen","vendor_phone":"+1 480 627 1800","vendor_email":"jallen@axway.com","assigned_lab":{"cctl_name":"Gossamer Security Solutions"},"product_description":"<p style=\"margin: 0in 0in 6pt; text-align: justify; line-height: 11pt; font-size: 10pt; font-family: Times, serif;\">The Axway Validation Authority Server (Server) is part of Axway&rsquo;s Validation Authority Suite, which provides a comprehensive, scalable, and reliable framework for real-time validation of digital <span style=\"color: black;\">certifications for the Public Key Infrastructure (PKI). The Axway VA Suite provides a variety of PKI and certificate management functionality to </span>prevent revoked credentials from being used for secure email, smart card login, network access (including wireless), or other sensitive electronic transactions. The administrator can configure the Axway VA Server to act in one of two manners: Repeater or Responder.&nbsp; One can think of the Repeater, conceptually the simpler configuration, as a revocation caching proxy (locally caching CRLs and OCSP responses).&nbsp; While the Responder can locally cache CRLs and generate new OCSP responses (using the certificate statuses within the CRLs) for clients.</p>\r\n<p style=\"margin: 0in 0in 6pt; text-align: justify; line-height: 11pt; font-size: 10pt; font-family: Times, serif;\">The TOE provides the following functionality:</p>\r\n<ul style=\"margin-bottom: 0in; margin-top: 0px;\">\r\n<li style=\"margin: 0in 0in 6pt 0px; text-align: justify; line-height: 11pt; font-size: 10pt; font-family: Times, serif;\">Maintains and processes a store of digital certificate revocation data by obtaining the digital Certificate Revocation List (CRL) from multiple CA or VA sources and performing end-to-end certificate validation if one or more intermediate CAs are used and the validation policy requires a complete certificate chain validation.</li>\r\n<li style=\"margin: 0in 0in 6pt 0px; text-align: justify; line-height: 11pt; font-size: 10pt; font-family: Times, serif;\">Generates and signs OCSP/SCVP responses. Maintains a cache loaded with OCSP responses that are pre-computed or dynamically built up by proxy client requests to a responder.</li>\r\n<li style=\"margin: 0in 0in 6pt 0px; text-align: justify; line-height: 11pt; font-size: 10pt; font-family: Times, serif;\">Allows caching of CRLs and delta CRLs to support non-OCSP clients or clients that want to maintain their own revocation data caches for backup and in low-bandwidth and non real-time environments.</li>\r\n<li style=\"margin: 0in 0in 6pt 0px; text-align: justify; line-height: 11pt; font-size: 10pt; font-family: Times, serif;\">Supports SSL-based communications with clients, digitally signed client requests/responses, and digitally signed XML logs and CRL archives, as well as SSL-based server administration.</li>\r\n<li style=\"margin: 0in 0in 6pt 0px; text-align: justify; line-height: 11pt; font-size: 10pt; font-family: Times, serif;\">Supports software PKCS #11 or CAPI token based hardware signing and encryption products, including hardware security modules from leading vendors that comply with FIPS 140-2 Level 2 or above.<a title=\"\" href=\"#_ftn1\" name=\"_ftnref1\"><span style=\"font-family: 'Times New Roman', serif; vertical-align: super;\"><span style=\"font-family: Times, serif;\"><span style=\"font-family: 'Times New Roman', serif; vertical-align: super;\"><span style=\"font-size: 10.0pt; font-family: Times, serif;\">[1]</span></span></span></span></a></li>\r\n</ul>\r\n<div><br clear=\"all\"><hr align=\"left\" size=\"1\" width=\"33%\">\r\n<div id=\"ftn1\">\r\n<p style=\"margin: 0in; font-size: 10pt; font-family: 'Times New Roman', serif;\"><a title=\"\" href=\"#_ftnref1\" name=\"_ftn1\"><span style=\"font-family: 'Times New Roman', serif; vertical-align: super;\"><span style=\"font-family: 'Times New Roman', serif; vertical-align: super;\"><span style=\"font-size: 10.0pt;\">[1]</span></span></span></a> The use of a Hardware Security Module (HSM) is not included in the evaluated configuration.</p>\r\n<p style=\"margin: 0in; font-size: 10pt; font-family: 'Times New Roman', serif;\">&nbsp;</p>\r\n</div>\r\n</div>","evaluation_configuration":"<p style=\"margin: 0in 0in 6pt; text-align: justify; line-height: 11pt; font-size: 10pt; font-family: Times, serif;\">The Axway Validation Authority Server runs on the following platforms:</p>\r\n<ul style=\"margin-top: 0in; margin-bottom: 0in;\">\r\n<li style=\"margin: 0in 0in 0in 0px; text-align: justify; line-height: 11pt; font-size: 10pt; font-family: Times, serif;\">Microsoft Windows Server 2019 (64 bit) on a 64 bit Intel Xeon processor</li>\r\n<li style=\"margin: 0in 0in 0in 0px; text-align: justify; line-height: 11pt; font-size: 10pt; font-family: Times, serif;\">Microsoft Windows Server 2022 (64 bit) on a 64 bit Intel Xeon processor</li>\r\n<li style=\"margin: 0in 0in 0in 0px; text-align: justify; line-height: 11pt; font-size: 10pt; font-family: Times, serif;\">RHEL 7 (64 bit) on a 64 bit Intel Xeon processor</li>\r\n<li style=\"margin: 0in 0in 0in 0px; text-align: justify; line-height: 11pt; font-size: 10pt; font-family: Times, serif;\">RHEL 8 (64 bit) on a 64 bit Intel Xeon processor</li>\r\n<li style=\"margin: 0in 0in 6pt 0px; text-align: justify; line-height: 11pt; font-size: 10pt; font-family: Times, serif;\">RHEL 9 (64 bit) on a 64 bit Intel Xeon processor</li>\r\n</ul>\r\n<p style=\"margin: 0in 0in 6pt; font-size: 10pt; font-family: Times, serif;\">The Windows and RHEL platforms are part of the operating environment of the TOE.&nbsp; The TOE can execute on any Intel Xeon processor, however the lab tested the TOE on an Intel Xeon E5-2670. The lab also tested the TOE on Windows Server 2022 (64 bit) and RHEL 8 (64 bit) in the evaluated configuration. The TOE binaries remain unchanged for each flavor of operating systems. Thus, the same TOE binaries compiled as Windows executables are used for all claimed Windows operating systems, and the same TOE binaries compiled as 64-bit ELF executables are used for all claimed Red Hat Linux distributions.</p>\r\n<p style=\"margin: 0in 0in 6pt; text-align: justify; line-height: 11pt; font-size: 10pt; font-family: Times, serif;\"><span style=\"color: black;\">The Axway VA Suite is composed of the following applications:</span></p>\r\n<ol style=\"margin-top: 0in; margin-bottom: 6.0pt;\">\r\n<li style=\"margin: 0in 0in 6pt 0px; line-height: 11pt; font-size: 10pt; font-family: Times, serif;\"><u>Validation Authority Server (VA Server)</u> &ndash; the VA Server is comprised of the VA validation server acting as either a Repeater or Responder operating on a Windows or Linux platform, and the Web based administration (Admin UI).&nbsp; The VA Server maintains a store of digital certificate revocation data and ensures the integrity and validity of online transactions by delivering real-time validation of digital certificates.</li>\r\n<li style=\"margin: 0in 0in 6pt 0px; font-size: 10pt; font-family: Times, serif;\"><u>Desktop Validator (DV) - </u>(Standard and Enterprise Editions) - the Desktop Validator is a Microsoft CAPI compliant revocation trust provider that communicates with the Validation Authority Server (VA server) in responder mode to check status of digital certs in real time.&nbsp; DV runs as a service on a 64bit Microsoft Windows platforms and can be invoked to validate standard X.509v3 digital certificates issued by any Certificate Authority (CA).&nbsp; The DV Standard edition provides certificate validation support for client applications, while the DV Enterprise edition provides certificate validation support for both client and server applications.</li>\r\n</ol>\r\n<p style=\"margin: 0in 0in 6pt; font-size: 10pt; font-family: Times, serif;\">The focus of the evaluation is the Validation Authority Server (VA Server).</p>","security_evaluation_summary":"<p style=\"text-align: justify; margin: 0in; font-size: 10pt; font-family: Times, serif;\">The evaluation was carried out in accordance to the Common Criteria Evaluation and Validation Scheme (CCEVS) requirements and guidance.&nbsp; The evaluation demonstrated that the TOE<em> </em>meets the security requirements contained in the Security Target.&nbsp; The criteria against which the TOE was judged are described in the Common Criteria for Information Technology Security Evaluation, Version 3.1, Revision 5, April 2017. The evaluation methodology used by the evaluation team to conduct the evaluation is the Common Methodology for Information Technology Security Evaluation, Evaluation Methodology, Version 3.1, Revision 5, April 2017.&nbsp; The product, when delivered and configured as identified in the Axway Validation Authority Common Criteria Guide, Version 5.2, July 1, 2024 document, satisfies all of the security functional requirements stated in the Axway Validation Authority Server, version 5.2 Security Target, Version .04, July 2, 2024.&nbsp; The project underwent CCEVS Validator review.&nbsp; The evaluation was completed in July 2024.&nbsp; Results of the evaluation can be found in the Common Criteria Evaluation and Validation Scheme Validation Report (report number CCEVS-VR-VID11452-2024) prepared by CCEVS.</p>","environmental_strengths":"<p style=\"text-align: justify; margin: 0in; font-size: 10pt; font-family: Times, serif;\">The logical boundaries of the Axway Validation Authority Server are realized in the security functions that it implements. Each of these security functions is summarized below.</p>\r\n<p style=\"text-align: justify; margin: 0in; font-size: 10pt; font-family: Times, serif;\">&nbsp;</p>\r\n<p style=\"text-align: justify; margin: 0in; font-size: 10pt; font-family: Times, serif;\"><strong>Cryptographic support:</strong></p>\r\n<p style=\"margin: 0in 0in 6pt; text-align: justify; line-height: 11pt; font-size: 10pt; font-family: Times, serif;\">The TOE uses CAVP-validated cryptographic algorithm implementations, provided by the Axway Security Kernel, a cryptographic module built from OpenSSL 3.0.0, to support asymmetric key generation, encryption/decryption, signature generation and verification and establishment of trusted channels to protect data in transit. The TOE provides a web server for TLS/HTTPS to facilitate trusted remote communications and implements functionality to securely store key data related to secure communications.&nbsp; The TOE also relies on the underlying platform to generate entropy that is used as input data for the TOE&rsquo;s deterministic random bit generator (DRBG).</p>\r\n<p style=\"text-align: justify; margin: 0in; font-size: 10pt; font-family: Times, serif;\"><strong>User data protection:</strong></p>\r\n<p style=\"margin: 0in 0in 6pt; text-align: justify; line-height: 11pt; font-size: 10pt; font-family: Times, serif;\"><span style=\"font-family: 'Times New Roman', serif;\">The TOE does not access any hardware resources (other than network connectivity) or sensitive information repositories. The TOE does not store any sensitive data in non-volatile memory.&nbsp; Inbound and outbound network communications are restricted to those that are application initiated.</span></p>\r\n<p style=\"text-align: justify; margin: 0in; font-size: 10pt; font-family: Times, serif;\"><strong>Identification and authentication:</strong></p>\r\n<p style=\"margin: 0in 0in 6pt; text-align: justify; line-height: 11pt; font-size: 10pt; font-family: Times, serif;\"><span style=\"font-family: 'Times New Roman', serif;\">The TOE implements X509 certificate validation to validate the revocation status of certificates using CRL.&nbsp; The TOE uses X509 certificates to support HTTPS/TLS authentication of administrators.</span></p>\r\n<p style=\"text-align: justify; margin: 0in; font-size: 10pt; font-family: Times, serif;\"><strong>Security management:</strong></p>\r\n<p style=\"margin: 0in 0in 6pt; text-align: justify; line-height: 11pt; font-size: 10pt; font-family: Times, serif;\"><span style=\"font-family: 'Times New Roman', serif;\">The TOE provides a Web-based Graphical User Interface (Web GUI) to access and manage the TOE security functions. When configured with default credentials or no credentials, the TOE restricts its functionality and only allows the ability to set new credentials.&nbsp; By default, the TOE is configured with file permissions to protect itself and its data from unauthorized access.</span></p>\r\n<p style=\"text-align: justify; margin: 0in; font-size: 10pt; font-family: Times, serif;\"><strong>Privacy:</strong></p>\r\n<p style=\"margin: 0in 0in 6pt; text-align: justify; line-height: 11pt; font-size: 10pt; font-family: Times, serif;\"><span style=\"font-family: 'Times New Roman', serif;\">The TOE does not transmit personally identifiable information (PII) over any network interfaces.</span></p>\r\n<p style=\"text-align: justify; margin: 0in; font-size: 10pt; font-family: Times, serif;\"><strong>Protection of the TSF:</strong></p>\r\n<p style=\"margin: 0in 0in 6pt; text-align: justify; line-height: 11pt; font-size: 10pt; font-family: Times, serif;\"><span style=\"font-family: 'Times New Roman', serif;\">The TOE protects itself against exploitation by implementing address space layout randomization (ASLR) and by not allocating any memory region for both write and execute permission. The TOE is compiled for both Windows and Linux with stack-based buffer overflow protection and does not allow user-modifiable files to be written to directories that contain executable files. The TOE uses standard platform APIs and includes a number of third party libraries used to perform its functions.</span></p>\r\n<p style=\"margin: 0in 0in 6pt; text-align: justify; line-height: 11pt; font-size: 10pt; font-family: Times, serif;\"><span style=\"font-family: 'Times New Roman', serif;\">The TOE includes mechanisms to check for updates and to query the current version of the application software. TOE software is digitally signed and distributed using the platform-supported package manager (Windows or Linux).&nbsp; The TOE does not update its own binary code in any way and when removed, all traces of the TOE application software are deleted.</span></p>\r\n<p style=\"text-align: justify; margin: 0in; font-size: 10pt; font-family: Times, serif;\"><strong>Trusted path/channels:</strong></p>\r\n<p style=\"margin: 0in 0in 6pt; text-align: justify; line-height: 11pt; font-size: 10pt; font-family: Times, serif;\"><span style=\"font-family: 'Times New Roman', serif;\">The TOE protects communications between itself and remote administrators using HTTPS/TLS.</span></p>","features":[{"id":562,"feature_name":"Certificate Authentication"},{"id":563,"feature_name":"Certificate Validation"},{"id":564,"feature_name":"Credential Storage"},{"id":565,"feature_name":"DRBG"},{"id":566,"feature_name":"DTLS 1.0"},{"id":567,"feature_name":"DTLS Server with Mutual Authentication"},{"id":568,"feature_name":"HTTPS Client"},{"id":569,"feature_name":"HTTPS Server with Mutual Authentication"},{"id":570,"feature_name":"PBKDF"},{"id":571,"feature_name":"TLS 1.1"}]}