{"product_id":11531,"v_id":11531,"product_name":"IBM MaaS360 Cloud Extender version 3.000.800","certification_status":"Certified","certification_date":"2025-09-02T00:00:00Z","tech_type":"Application Software,Network Encryption","vendor_id":{"name":"IBM Corporation","website":"https://www.ibm.com"},"vendor_poc":"Alex Cherian","vendor_phone":"18004264968","vendor_email":"alex.cherian@ibm.com","assigned_lab":{"cctl_name":"atsec information security corporation"},"product_description":"<div>\r\n<div>\r\n<p>The TOE is the IBM Cloud Extender (CE) application. It consists of four modules enabling communications functionality with various customer-provided services and the IBM MaaS Cloud Extender Configuration Tool, hereafter refers to as Configuration Tool.</p>\r\n<p>The TOE is installed within the customer&rsquo;s network in order to enable services offered by the IBM MaaS360 Enterprise Mobility Management (EMM), a cloud-based multi-tenant platform that provides a mobile device management (MDM) solution. Specifically, the TOE is installed behind the customer firewall with network access to appropriate internal systems. The TOE is available as a small Windows Application.</p>\r\n<p>The four TOE modules covered by the evaluation are the following:</p>\r\n<ul>\r\n<li>Exchange Integration Module: this module interacts with the Exchange Server to automatically discover ActiveSync-connected devices, and uploads that device information to the IBM MaaS360 Cloud.</li>\r\n<li>User Authentication Module: this module interacts with Active Directory or LDAP directories to provide user authentication service for various MaaS360 functions, such as self-service device enrollment with corporate credentials, MaaS360 Portal login, and user management portal.</li>\r\n<li>User Visibility Module: this module uses the corporate directory groups to allow for the assignment and distribution of policies, apps, and content to mobile devices.</li>\r\n<li>Certificate Integration Module: this module facilitates the automatic provisioning, distribution, and renewal of digital identity certificates to managed mobile devices by using existing Microsoft Certificate Authority (CA), Symantec&reg; CA, or Entrust&reg; Admin Services and Identity Guard.</li>\r\n</ul>\r\n</div>\r\n</div>","evaluation_configuration":"<p>The TOE is packaged and delivered in the Windows Application Software (.EXE) running on the following platforms:</p>\r\n<ul>\r\n<li>Operating system: Microsoft Windows Server 2019 Standard version 1809 (x64)</li>\r\n<li>Hardware: Dell PowerEdge R740 with an Intel Xeon Gold 5120 processor (SkyLake microarchitecture)</li>\r\n</ul>","security_evaluation_summary":"<p>The evaluation was carried out in accordance with the Common Criteria Evaluation and Validation Scheme (CCEVS) process. The criteria against which the IBM MaaS360 Cloud Extender version 3.000.800 TOE was judged are described in the Common Criteria for Information Technology Security Evaluation, Version 3.1 R5. The evaluation methodology used by the evaluation team to conduct the evaluation was the Common Methodology for Information Technology Security Evaluation, Version 3.1, R5 supplemented by that found in the Protection Profiles cited&nbsp;below. The product, when delivered and configured as identified in the <em>MaaS360 Cloud Extender Common Criteria Guide</em>, meets the requirements of the following:</p>\r\n<ul>\r\n<li>Protection Profile for Application Software, Version 1.4, 2021-10-07</li>\r\n<li>Functional Package for Transport Layer Security (TLS), Version 1.1, 2019-03-01</li>\r\n</ul>","environmental_strengths":"<h3>Cryptographic Support</h3>\r\n<p>The TOE provides the following cryptographic functions via the Microsoft Cryptography API: Next Generation (CNG) cryptographic library from the underlying Microsoft Windows Server platform on which the TOE runs:</p>\r\n<ul>\r\n<li>TLS v1.2 connections: the TOE communicates with the Exchange Server, Domain Controller, and PKI Certificate Servers.</li>\r\n<li>Protecting data-at-rest using the Encrypted File System (EFS) for directory that contains all configuration and log information.</li>\r\n<li>Encrypting registry entries using Data Protection Application Programming Interface (DPAPI).</li>\r\n</ul>\r\n<p>The TOE also comes with its own OpenSSL cryptographic library, which provides the following cryptographic services:</p>\r\n<ul>\r\n<li>TLS v1.2 connections to the MaaS360 Portal and Simple Certificate Enrollment Protocol (SCEP) certificate servers.</li>\r\n<li>Device and user certificate generation for certificate signing requests to a SCEP server.</li>\r\n</ul>\r\n<h3>User Data Protection</h3>\r\n<p>The TOE provides user data protection services by restricting its access to specific platform-based resources, such as sensitive data repositories, and network communications, that are strictly needed to support the necessary TOE functionality.</p>\r\n<p>Sensitive application data when stored in non-volatile memory is protected using platform-provided EFS services.</p>\r\n<h3>Identification and Authentication</h3>\r\n<p>The TOE supports authentication by X.509 certificates by the TOE and by using the platform API.</p>\r\n<h3>Security Management</h3>\r\n<p>The TOE provides the ability to set a number of its configuration options, which are stored, as recommended by Microsoft, in the Windows Registry and are protected using the Data Protection Application Programming Interface (DPAPI).</p>\r\n<h3>Privacy</h3>\r\n<p>The TOE does not specifically request Personally Identifiable Information (PII).</p>\r\n<h3>Protection of the TSF</h3>\r\n<p>The TOE only uses documented Windows APIs. The TOE does not write user-modifiable files to directories that contain executable files. The TOE implements anti-exploitation capabilities including stack buffer overrun protection and Address Space Layout Randomization (ASLR) techniques.</p>\r\n<p>The TOE is packaged and delivered in the Windows Application Software (.EXE) format signed with Microsoft Authenticode using the Microsoft Sign Tool.</p>\r\n<h3>Trusted Path/Channel</h3>\r\n<p>The TOE protects all transmitted data via trusted channels over TLS 1.2.</p>","features":[{"id":253,"feature_name":"Certificate Authentication"},{"id":252,"feature_name":"Certificate Validation"},{"id":245,"feature_name":"Credential Storage"},{"id":423,"feature_name":"DRBG"},{"id":433,"feature_name":"DTLS 1.0"},{"id":434,"feature_name":"DTLS Server with Mutual Authentication"},{"id":251,"feature_name":"HTTPS Client"},{"id":421,"feature_name":"HTTPS Server with Mutual Authentication"},{"id":418,"feature_name":"PBKDF"},{"id":432,"feature_name":"TLS 1.1"}]}