{"product_id":11454,"v_id":11454,"product_name":"FortiMail 7.4","certification_status":"Certified","certification_date":"2024-07-26T00:00:00Z","tech_type":"Network Device","vendor_id":{"name":"Fortinet, Inc.","website":"https://www.fortinet.com"},"vendor_poc":"Marc Boire","vendor_phone":"613-225-9381","vendor_email":"mboire@fortinet.com","assigned_lab":{"cctl_name":"Leidos Common Criteria Testing Laboratory"},"product_description":"<p style=\"margin: 0in 0in 6pt; text-align: justify; font-size: 11pt; font-family: Calibri, sans-serif;\">Fortinet FortiMail is a specialized email security system that provides multi-layered protection against blended threats consisting of spam, viruses, worms and spyware. FortiMail&rsquo;s inbound filtering engine blocks spam and malware before it can clog networks and affect users. FortiMail&rsquo;s dynamic and static user-blocking provides granular control over all email policies and users. Secure content delivery is enforced with FortiMail&rsquo;s Identity-Based Encryption (IBE), S/MIME, or TLS email encryption options. FortiMail&rsquo;s predefined or customized dictionaries prevent accidental and intentional loss of confidential data.</p>\r\n<p style=\"margin: 0in 0in 6pt; text-align: justify; font-size: 11pt; font-family: Calibri, sans-serif;\">For this evaluation, the Target of Evaluation (TOE) is FortiMail evaluated as a network device. The TOE claims exact conformance to the NDcPP. As such, the security-relevant functionality of the product is limited to the claimed requirements in this PP.</p>\r\n<p style=\"margin: 0in 0in 6pt; line-height: normal; text-align: justify; font-size: 10pt; font-family: 'Times New Roman', serif;\"><span style=\"font-size: 11.0pt; font-family: Calibri, sans-serif;\">The TOE consists of the following appliances running FortiMail firmware v7.4:</span></p>\r\n<ul style=\"margin-bottom: 6pt; margin-top: 0px;\">\r\n<li style=\"margin: 0in 0in 6pt 0px; line-height: normal; text-align: justify; font-size: 10pt; font-family: 'Times New Roman', serif;\"><span style=\"font-size: 11.0pt; font-family: Calibri, sans-serif;\">FortiMail 200F (FML-200F)</span></li>\r\n<li style=\"margin: 0in 0in 6pt 0px; line-height: normal; text-align: justify; font-size: 10pt; font-family: 'Times New Roman', serif;\"><span style=\"font-size: 11.0pt; font-family: Calibri, sans-serif;\">FortiMail 400F (FML-400F)</span></li>\r\n<li style=\"margin: 0in 0in 6pt 0px; line-height: normal; text-align: justify; font-size: 10pt; font-family: 'Times New Roman', serif;\"><span style=\"font-size: 11.0pt; font-family: Calibri, sans-serif;\">FortiMail 900F (FML-900F)</span></li>\r\n<li style=\"margin: 0in 0in 6pt 0px; line-height: normal; text-align: justify; font-size: 10pt; font-family: 'Times New Roman', serif;\"><span style=\"font-size: 11.0pt; font-family: Calibri, sans-serif;\">FortiMail (FML-2000F)</span></li>\r\n<li style=\"margin: 0in 0in 6pt 0px; line-height: normal; text-align: justify; font-size: 10pt; font-family: 'Times New Roman', serif;\"><span style=\"font-size: 11.0pt; font-family: Calibri, sans-serif;\">FortiMail (FML-3000F)</span></li>\r\n<li style=\"margin: 0in 0in 6pt 0px; line-height: normal; text-align: justify; font-size: 10pt; font-family: 'Times New Roman', serif;\"><span style=\"font-size: 11.0pt; font-family: Calibri, sans-serif;\"><span style=\"font-size: 11pt; line-height: 115%; font-family: Calibri, sans-serif;\">FortiMail VM Virtual Machine (VM)</span></span></li>\r\n</ul>\r\n<p>&nbsp;</p>","evaluation_configuration":"<h2 style=\"margin: 6pt 0in 8pt; text-indent: 0in; break-after: avoid; font-size: 13pt; font-family: 'Calibri Light', sans-serif; color: rgb(46, 116, 181); font-weight: normal;\"><a name=\"_Toc134616175\"></a>1.1<span style=\"font: 7.0pt 'Times New Roman';\">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span>Evaluated Configuration</h2>\r\n<p style=\"margin: 0in 0in 8pt; line-height: 107%; font-size: 11pt; font-family: Calibri, sans-serif;\">The Target of Evaluation (TOE) is Fortinet FortiMail version 7.4. The specific tested firmware version is &ldquo;7.4.2&rdquo;.</p>\r\n<p style=\"margin: 0in; line-height: 107%; font-size: 11pt; font-family: Calibri, sans-serif;\">All functional testing was performed on the following devices:</p>\r\n<ul style=\"margin-bottom: 0in; margin-top: 0px;\">\r\n<li style=\"margin: 0in 0in 0in 0px; line-height: 107%; font-size: 11pt; font-family: Calibri, sans-serif;\">Physical device: FML-900F</li>\r\n<li style=\"margin: 0in 0in 8pt 0px; line-height: 107%; font-size: 11pt; font-family: Calibri, sans-serif;\">Virtual device: virtualized on VMware ESXi 8.0, Intel Xeon E5-2620v4 processor</li>\r\n</ul>\r\n<p style=\"margin: 0in; line-height: 107%; font-size: 11pt; font-family: Calibri, sans-serif;\">Additionally, to ensure full coverage of all processor microarchitectures and substrates, cryptographic algorithm validation was performed on both models listed above as well as the FML-200F, FML-400F, and FML-2000F.</p>\r\n<h2 style=\"margin: 6pt 0in 8pt; text-indent: 0in; break-after: avoid; font-size: 13pt; font-family: 'Calibri Light', sans-serif; color: rgb(46, 116, 181); font-weight: normal;\"><a name=\"_Toc134616176\"></a>1.2<span style=\"font: 7.0pt 'Times New Roman';\">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span>Excluded Functionality</h2>\r\n<p><span style=\"font-size: 11.0pt; line-height: 107%; font-family: Calibri, sans-serif;\">The product is designed to function as a network security appliance that filters emails and associated executable content to prevent compromise of end user systems. No NIAP PP or PP-Module exists for this functionality, so the TOE conforms to the NDcPP for its implementation of general security mechanisms. As such, the security-relevant functionality of the product is limited to the claimed requirements in this standard. The security-relevant functionality is described in [ST] sections 2.3 and 2.4. The product overview in section 2.2 is intended to provide the reader with an overall summary of the entire product so that its intended usage is clear. The subset of the product functionality that is within the evaluation scope is subsequently described in the sections of the [ST] that follow it.</span></p>","security_evaluation_summary":"<p><span style=\"font-size: 11.0pt; line-height: 115%; font-family: Calibri, sans-serif;\">The evaluation was carried out in accordance with the Common Criteria Evaluation and Validation Scheme (CCEVS) process and scheme for the&nbsp;<em>collaborative Protection Profile for Network Devices, </em>Version 2.2e. The evaluation methodology used by the evaluation team to conduct the evaluation is the Common Methodology for Information Technology Security Evaluation, Version 3.1 release 5. The product, when delivered and configured as identified in the guidance documentation, satisfies all of the security functional requirements stated in the Fortinet FortiMail Version 7.4 Security Target. The evaluation was completed in <span style=\"background-image: initial; background-position: initial; background-size: initial; background-repeat: initial; background-attachment: initial; background-origin: initial; background-clip: initial;\">July 2024</span></span><span style=\"font-size: 11.0pt; line-height: 115%; font-family: Calibri, sans-serif;\">. Results of the evaluation can be found in the Common Criteria Evaluation and Validation Scheme Validation Report prepared by CCEVS.</span></p>","environmental_strengths":"<p style=\"margin: 0in; break-after: avoid; text-align: justify; line-height: 115%; font-size: 10pt; font-family: 'Times New Roman', serif;\"><strong><em><span style=\"font-size: 11.0pt; line-height: 115%; font-family: Calibri, sans-serif;\">Security Audit</span></em></strong></p>\r\n<p style=\"margin: 0in 0in 6pt; line-height: normal; break-after: avoid; text-align: justify; font-size: 10pt; font-family: 'Times New Roman', serif;\"><span style=\"font-size: 11.0pt; font-family: Calibri, sans-serif;\">The TOE generates audit records of security-relevant activity. Audit data is stored locally and the TOE also has the ability to export all audit records to an external audit server over a TLS protected channel. The TOE manages the audit storage by overwriting previous audit records when the local storage space for audit data is full in order to capture new events.</span></p>\r\n<p style=\"margin: 0in; break-after: avoid; text-align: justify; line-height: 115%; font-size: 10pt; font-family: 'Times New Roman', serif;\"><strong><em><span style=\"font-size: 11.0pt; line-height: 115%; font-family: Calibri, sans-serif;\">Cryptographic Support</span></em></strong></p>\r\n<p style=\"margin: 0in 0in 6pt; text-align: justify; font-size: 11pt; font-family: Calibri, sans-serif;\">The TOE implements cryptographic functions in support of trusted communications, key pair generation for X.509 certificate requests, and self-testing. For trusted communications, the TOE implements TLS as a server with HTTPS, and TLS as a client without HTTPS. The TOE&rsquo;s TLS client supports mutual authentication. The TOE relies on platform hardware to generate entropy that is used to seed its DRBG to ensure that generated keys have the advertised security strength.</p>\r\n<p style=\"margin: 0in; break-after: avoid; text-align: justify; line-height: 115%; font-size: 10pt; font-family: 'Times New Roman', serif;\"><strong><em><span style=\"font-size: 11.0pt; line-height: 115%; font-family: Calibri, sans-serif;\">Identification and Authentication</span></em></strong></p>\r\n<p style=\"margin: 0in 0in 6pt; line-height: normal; break-after: avoid; text-align: justify; font-size: 10pt; font-family: 'Times New Roman', serif;\"><span style=\"font-size: 11.0pt; font-family: Calibri, sans-serif;\">The TOE uses a local password-based mechanism and additionally for SSH, an SSH public key-based mechanism for administrator authentication. The TOE enforces restrictions on the length and character composition of administrator passwords. Excessive failed authentication attempts on a remote administrative interface will cause a lockout that is resolved by a waiting period. The TOE also uses X.509 certificates for authentication of TLS connections. The TOE has a mechanism by which a certificate signing request can be generated so that it may obtain a certificate for its own use from a trusted CA.</span></p>\r\n<p style=\"margin: 0in; break-after: avoid; text-align: justify; line-height: 115%; font-size: 10pt; font-family: 'Times New Roman', serif;\"><strong><em><span style=\"font-size: 11.0pt; line-height: 115%; font-family: Calibri, sans-serif;\">Security Management</span></em></strong></p>\r\n<p style=\"margin: 0in 0in 6pt; text-align: justify; font-size: 11pt; font-family: Calibri, sans-serif;\">The TOE has a web-based remote management interface as well as a local/remote console. Most functionality can be administered over both interfaces. The TOE uses a single Security Administrator role to authorize the use of management functions.</p>\r\n<p style=\"margin: 0in; break-after: avoid; text-align: justify; line-height: 115%; font-size: 10pt; font-family: 'Times New Roman', serif;\"><strong><em><span style=\"font-size: 11.0pt; line-height: 115%; font-family: Calibri, sans-serif;\">Protection of the TSF</span></em></strong></p>\r\n<p style=\"margin: 0in 0in 6pt; text-align: justify; font-size: 11pt; font-family: Calibri, sans-serif;\">The TOE protects sensitive data from unauthorized access. It enforces integrity of its own contents through the use of self-tests to ensure that the TSF has not been modified. Firmware updates are obtained through the operational environment (e.g. downloaded from the vendor&rsquo;s support site); updates have a digital signature that is verified prior to application.</p>\r\n<p style=\"margin: 0in; break-after: avoid; text-align: justify; line-height: 115%; font-size: 10pt; font-family: 'Times New Roman', serif;\"><strong><em><span style=\"font-size: 11.0pt; line-height: 115%; font-family: Calibri, sans-serif;\">TOE Access</span></em></strong></p>\r\n<p style=\"margin: 0in 0in 6pt; line-height: normal; break-after: avoid; text-align: justify; font-size: 10pt; font-family: 'Times New Roman', serif;\"><span style=\"font-size: 11.0pt; font-family: Calibri, sans-serif;\">The TOE controls access through enforcement of idle session timeout on its management interfaces. These interfaces also display a configurable pre-authentication warning banner that advises against unauthorized use of the TOE.</span></p>\r\n<p style=\"margin: 0in; break-after: avoid; text-align: justify; line-height: 115%; font-size: 10pt; font-family: 'Times New Roman', serif;\"><strong><em><span style=\"font-size: 11.0pt; line-height: 115%; font-family: Calibri, sans-serif;\">Trusted Path/Channels<br></span></em></strong><span style=\"font-family: helvetica, arial, sans-serif;\">The TOE implements a TLS trusted channel between itself and trusted external audit servers. The TOE also implements SSH and TLS/HTTPS trusted paths for secure remote administration.</span></p>","features":[{"id":3127,"feature_name":"Asymmetric Key Generation"},{"id":3122,"feature_name":"Auditing"},{"id":415,"feature_name":"Certificate Authentication"},{"id":413,"feature_name":"Certificate Validation"},{"id":3129,"feature_name":"Cryptographic Hashing"},{"id":407,"feature_name":"Cryptographic Key Establishment"},{"id":3128,"feature_name":"Cryptographic Signature Verification"},{"id":411,"feature_name":"DRBG"},{"id":408,"feature_name":"HTTPS Client"},{"id":410,"feature_name":"HTTPS Server without Mutual Authentication"},{"id":3125,"feature_name":"Key Destruction"},{"id":3130,"feature_name":"Keyed-hash message authentication"},{"id":3133,"feature_name":"SSH Server"},{"id":3134,"feature_name":"TLS 1.1"},{"id":3135,"feature_name":"TLS 1.2"},{"id":3131,"feature_name":"TLS Client"},{"id":3132,"feature_name":"TLS Server without Mutual Authentication"},{"id":3126,"feature_name":"Virtual Network Device"}]}