{"product_id":11639,"v_id":11639,"product_name":"MAGNUM-SC-CC2","certification_status":"Certified","certification_date":"2025-12-18T00:00:00Z","tech_type":"Network Device,Remote Access","vendor_id":{"name":"Evertz Microsystems","website":"https://www.evertz.com"},"vendor_poc":"Jason Fagg","vendor_phone":"+19053353700","vendor_email":"jfagg@evertz.com","assigned_lab":{"cctl_name":"Acumen Security"},"product_description":"<p style=\"margin: 0in 0in 10pt; line-height: 115%; font-size: 11pt; font-family: Calibri, sans-serif;\"><a name=\"_Hlk126914590\"></a><span style=\"line-height: 115%;\">The TOE is classified as a network device (a generic infrastructure device that can be connected to a<strong> </strong>network). The TOE hardware device is the Evertz MAGNUM-SC-CC2 which includes the MAGNUM-SC-CC2 (1 RU) with</span> an <span style=\"font-family: 'Source Sans Pro', sans-serif; color: #1b1b1b; background: white;\">AMD</span> EPYC 7313P (16C/32T) in a Gigabyte E152-ZE1, running MAGNUM-OS<strong> </strong>firmware v24.11.8<span style=\"line-height: 115%;\">. </span>The MAGNUM-OS firmware is based on Ubuntu version 24.04 LTS (Noble). The MAGNUM-OS serves as the primary user and network interface device for the MAGNUM control application.</p>\r\n<p style=\"margin: 0in 0in 6pt; font-size: 11pt; font-family: Calibri, sans-serif;\">Evertz MAGNUM software (v24.11.8) is a custom-developed application written primarily in python. MAGNUM-SC-CC2 operates as a combination of an application layer and as part of the integrated Linux platform stack, using a customized Ubuntu operating system. The TOE version of MAGNUM (MAGNUM-SC-CC2) is only operable on Evertz provided platforms and hardware.</p>\r\n<p style=\"margin: 0in 0in 6pt; font-size: 11pt; font-family: Calibri, sans-serif;\">The TOE is an infrastructure network device that provides secure remote management, auditing, and updating capabilities. The TOE provides secure remote management using an HTTPS/TLS web interface and an SSH command line interface. The TOE generates audit logs and transmits the audit logs to a remote syslog server over a mutually authenticated Syslog over TLS channel. The TOE verifies the authenticity of software updates by verifying the digital signature prior to installing any update.</p>\r\n<p style=\"margin: 0in 0in 6pt; font-size: 11pt; font-family: Calibri, sans-serif;\">The scope of the evaluated functionality includes the following,</p>\r\n<ol style=\"margin-bottom: 6pt; margin-top: 0px;\">\r\n<li style=\"list-style: none; margin: 0in 0in 6pt 0px; font-size: 11pt; font-family: Calibri, sans-serif;\">\r\n<ul style=\"margin-bottom: 6pt; margin-top: 0px;\">\r\n<li style=\"margin: 0in 0in 6pt 0px; font-size: 11pt; font-family: Calibri, sans-serif;\">Secure remote administration of the TOE via TLS and SSH</li>\r\n<li style=\"margin: 0in 0in 6pt 0px; font-size: 11pt; font-family: Calibri, sans-serif;\">Secure Local administration of the TOE</li>\r\n<li style=\"margin: 0in 0in 6pt 0px; font-size: 11pt; font-family: Calibri, sans-serif;\">Secure connectivity with remote audit servers</li>\r\n<li style=\"margin: 0in 0in 6pt 0px; font-size: 11pt; font-family: Calibri, sans-serif;\">Secure access to the management functionality of the TOE</li>\r\n<li style=\"margin: 0in 0in 6pt 0px; font-size: 11pt; font-family: Calibri, sans-serif;\">Identification and authentication of the administrator of the TOE</li>\r\n</ul>\r\n</li>\r\n</ol>\r\n<p style=\"margin: 0in; font-size: 11pt; font-family: Calibri, sans-serif;\">The IT Testing Environment Components used to test the TOE are shown in Table 2 in the security target document. No other functionality is included within the scope of this evaluation.</p>","evaluation_configuration":"<p style=\"margin: 0in; font-size: 11pt; font-family: Calibri, sans-serif;\">The IT Testing Environment Components used to test the TOE are shown in Table below:</p>\r\n<table class=\"MsoTableGrid\" style=\"width: 472.3pt; border-collapse: collapse; border: none;\" border=\"1\" cellspacing=\"0\" cellpadding=\"0\">\r\n<thead>\r\n<tr style=\"page-break-inside: avoid;\">\r\n<td style=\"width: 116.25pt; border: solid windowtext 1.0pt; background: #FFC000; padding: 0in 5.4pt 0in 5.4pt;\" valign=\"top\">\r\n<p style=\"text-align: left; break-after: avoid; margin: 0in; font-size: 10pt; font-family: Calibri, sans-serif; font-weight: bold;\"><a name=\"_Hlk176815209\"></a><span style=\"color: black;\">Component</span></p>\r\n</td>\r\n<td style=\"width: 108.8pt; border: solid windowtext 1.0pt; border-left: none; background: #FFC000; padding: 0in 5.4pt 0in 5.4pt;\" valign=\"top\">\r\n<p style=\"text-align: left; margin: 0in; font-size: 10pt; font-family: Calibri, sans-serif; font-weight: bold;\"><span style=\"color: black;\">Required</span></p>\r\n</td>\r\n<td style=\"width: 247.25pt; border: solid windowtext 1.0pt; border-left: none; background: #FFC000; padding: 0in 5.4pt 0in 5.4pt;\" valign=\"top\">\r\n<p style=\"text-align: left; margin: 0in; font-size: 10pt; font-family: Calibri, sans-serif; font-weight: bold;\"><span style=\"color: black;\">Purpose/Description</span></p>\r\n</td>\r\n</tr>\r\n</thead>\r\n<tbody>\r\n<tr>\r\n<td style=\"width: 116.25pt; border: solid windowtext 1.0pt; border-top: none; padding: 0in 5.4pt 0in 5.4pt;\" valign=\"top\">\r\n<p style=\"margin: 1pt 0.05in 3pt 0in; font-size: 10pt; font-family: Calibri, sans-serif;\"><span style=\"color: black;\">Syslog server</span></p>\r\n</td>\r\n<td style=\"width: 108.8pt; border-top: none; border-left: none; border-bottom: solid windowtext 1.0pt; border-right: solid windowtext 1.0pt; padding: 0in 5.4pt 0in 5.4pt;\" valign=\"top\">\r\n<p style=\"margin: 0in; font-size: 11pt; font-family: Calibri, sans-serif;\"><span style=\"font-size: 10.0pt; color: black;\">Yes </span></p>\r\n<p style=\"margin: 1pt 0.05in 3pt 0in; font-size: 10pt; font-family: Calibri, sans-serif;\">&nbsp;</p>\r\n</td>\r\n<td style=\"width: 247.25pt; border-top: none; border-left: none; border-bottom: solid windowtext 1.0pt; border-right: solid windowtext 1.0pt; padding: 0in 5.4pt 0in 5.4pt;\" valign=\"top\">\r\n<ul style=\"margin-bottom: 0in; margin-top: 1.33333px;\">\r\n<li style=\"margin: 1pt 0.05in 3pt 0px; font-size: 10pt; font-family: Calibri, sans-serif;\"><span style=\"color: black;\">Conformant with RFC 5424 (Syslog Protocol)</span></li>\r\n<li style=\"margin: 1pt 0.05in 3pt 0px; font-size: 10pt; font-family: Calibri, sans-serif;\"><span style=\"color: black;\">Supporting Syslog over TLS (RFC 5425)</span></li>\r\n<li style=\"margin: 1pt 0.05in 3pt 0px; font-size: 10pt; font-family: Calibri, sans-serif;\"><span style=\"color: black;\">Acting as a TLSv1.2 server</span></li>\r\n<li style=\"margin: 1pt 0.05in 3pt 0px; font-size: 10pt; font-family: Calibri, sans-serif;\"><span style=\"color: black;\">Supporting Client Certificate authentication</span></li>\r\n<li style=\"margin: 1pt 0.05in 3pt 0px; font-size: 10pt; font-family: Calibri, sans-serif;\"><span style=\"color: black;\">Supporting at least one of the following cipher suites:</span></li>\r\n</ul>\r\n<ul style=\"list-style-type: circle; margin-bottom: 0in; margin-top: 1.33333px;\">\r\n<li style=\"margin: 1pt 0.05in 3pt 0px; font-size: 10pt; font-family: Calibri, sans-serif;\"><span style=\"color: black;\">TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256</span></li>\r\n<li style=\"margin: 1pt 0.05in 3pt 0px; font-size: 10pt; font-family: Calibri, sans-serif;\"><span style=\"color: black;\">TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384</span></li>\r\n</ul>\r\n</td>\r\n</tr>\r\n<tr>\r\n<td style=\"width: 116.25pt; border: solid windowtext 1.0pt; border-top: none; padding: 0in 5.4pt 0in 5.4pt;\" valign=\"top\">\r\n<p style=\"margin: 1pt 0.05in 3pt 0in; font-size: 10pt; font-family: Calibri, sans-serif;\"><span style=\"color: black;\">IPX Video Switch </span></p>\r\n</td>\r\n<td style=\"width: 108.8pt; border-top: none; border-left: none; border-bottom: solid windowtext 1.0pt; border-right: solid windowtext 1.0pt; padding: 0in 5.4pt 0in 5.4pt;\" valign=\"top\">\r\n<p style=\"margin: 0in; font-size: 11pt; font-family: Calibri, sans-serif;\"><span style=\"font-size: 10.0pt; color: black;\">Yes</span></p>\r\n</td>\r\n<td style=\"width: 247.25pt; border-top: none; border-left: none; border-bottom: solid windowtext 1.0pt; border-right: solid windowtext 1.0pt; padding: 0in 5.4pt 0in 5.4pt;\" valign=\"top\">\r\n<ul style=\"margin-bottom: 0in; margin-top: 1.33333px;\">\r\n<li style=\"margin: 1pt 0.05in 3pt 0px; font-size: 10pt; font-family: Calibri, sans-serif;\"><span style=\"color: black;\">Provides switching of video signals</span></li>\r\n<li style=\"margin: 1pt 0.05in 3pt 0px; font-size: 10pt; font-family: Calibri, sans-serif;\"><span style=\"color: black;\">Acting as a TLSv1.2 server</span></li>\r\n<li style=\"margin: 1pt 0.05in 3pt 0px; font-size: 10pt; font-family: Calibri, sans-serif;\"><span style=\"color: black;\">Supporting Client Certificate authentication</span></li>\r\n<li style=\"margin: 1pt 0.05in 3pt 0px; font-size: 10pt; font-family: Calibri, sans-serif;\"><span style=\"color: black;\">Supporting at least one of the following cipher suites:</span></li>\r\n</ul>\r\n<ul style=\"list-style-type: circle; margin-bottom: 0in; margin-top: 1.33333px;\">\r\n<li style=\"margin: 1pt 0.05in 3pt 0px; font-size: 10pt; font-family: Calibri, sans-serif;\"><span style=\"color: black;\">TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256</span></li>\r\n<li style=\"margin: 1pt 0.05in 3pt 0px; font-size: 10pt; font-family: Calibri, sans-serif;\"><span style=\"color: black;\">TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384</span></li>\r\n</ul>\r\n</td>\r\n</tr>\r\n<tr>\r\n<td style=\"width: 116.25pt; border: solid windowtext 1.0pt; border-top: none; padding: 0in 5.4pt 0in 5.4pt;\" valign=\"top\">\r\n<p style=\"margin: 1pt 0.05in 3pt 0in; font-size: 10pt; font-family: Calibri, sans-serif;\"><span style=\"color: black;\">Management workstation with web browser </span></p>\r\n</td>\r\n<td style=\"width: 108.8pt; border-top: none; border-left: none; border-bottom: solid windowtext 1.0pt; border-right: solid windowtext 1.0pt; padding: 0in 5.4pt 0in 5.4pt;\" valign=\"top\">\r\n<p style=\"margin: 0in; font-size: 11pt; font-family: Calibri, sans-serif;\"><span style=\"font-size: 10.0pt; color: black;\">Yes</span></p>\r\n</td>\r\n<td style=\"width: 247.25pt; border-top: none; border-left: none; border-bottom: solid windowtext 1.0pt; border-right: solid windowtext 1.0pt; padding: 0in 5.4pt 0in 5.4pt;\" valign=\"top\">\r\n<ul style=\"margin-bottom: 0in; margin-top: 1.33333px;\">\r\n<li style=\"margin: 1pt 0.05in 3pt 0px; font-size: 10pt; font-family: Calibri, sans-serif;\"><span style=\"color: black;\">Supported browser: Chrome or Safari</span></li>\r\n<li style=\"margin: 1pt 0.05in 3pt 0px; font-size: 10pt; font-family: Calibri, sans-serif;\"><span style=\"color: black;\">Supporting TLSv1.2</span></li>\r\n<li style=\"margin: 1pt 0.05in 3pt 0px; font-size: 10pt; font-family: Calibri, sans-serif;\"><span style=\"color: black;\">Supporting at least one of the following ciphersuites:</span></li>\r\n</ul>\r\n<ul style=\"list-style-type: circle; margin-bottom: 0in; margin-top: 1.33333px;\">\r\n<li style=\"margin: 1pt 0.05in 3pt 0px; font-size: 10pt; font-family: Calibri, sans-serif;\"><span style=\"color: black;\">TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256</span></li>\r\n<li style=\"margin: 0in 0in 0in 0px; font-size: 11pt; font-family: Calibri, sans-serif;\"><span style=\"font-size: 10.0pt; color: black;\">TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384</span></li>\r\n</ul>\r\n</td>\r\n</tr>\r\n<tr>\r\n<td style=\"width: 116.25pt; border: solid windowtext 1.0pt; border-top: none; padding: 0in 5.4pt 0in 5.4pt;\" valign=\"top\">\r\n<p style=\"margin: 1pt 0.05in 3pt 0in; font-size: 10pt; font-family: Calibri, sans-serif;\"><span style=\"color: black;\">Management workstation with </span><span style=\"color: black;\">remote CLI</span><span style=\"color: black;\"> </span></p>\r\n</td>\r\n<td style=\"width: 108.8pt; border-top: none; border-left: none; border-bottom: solid windowtext 1.0pt; border-right: solid windowtext 1.0pt; padding: 0in 5.4pt 0in 5.4pt;\" valign=\"top\">\r\n<p style=\"margin: 0in; font-size: 11pt; font-family: Calibri, sans-serif;\"><span style=\"font-size: 10.0pt; color: black;\">Yes</span></p>\r\n</td>\r\n<td style=\"width: 247.25pt; border-top: none; border-left: none; border-bottom: solid windowtext 1.0pt; border-right: solid windowtext 1.0pt; padding: 0in 5.4pt 0in 5.4pt;\" valign=\"top\">\r\n<ul style=\"margin-bottom: 0in; margin-top: 1.33333px;\">\r\n<li style=\"margin: 1pt 0.05in 3pt 0px; font-size: 10pt; font-family: Calibri, sans-serif;\"><span style=\"color: black;\">Supported SSH version: SSHv2 </span></li>\r\n<li style=\"margin: 1pt 0.05in 3pt 0px; font-size: 10pt; font-family: Calibri, sans-serif;\"><span style=\"color: black;\">Conformant with RFCs 4251-4254, 5647, 5656, </span>8308 and 8332</li>\r\n</ul>\r\n</td>\r\n</tr>\r\n<tr>\r\n<td style=\"width: 116.25pt; border: solid windowtext 1.0pt; border-top: none; padding: 0in 5.4pt 0in 5.4pt;\" valign=\"top\">\r\n<p style=\"margin: 1pt 0.05in 3pt 0in; font-size: 10pt; font-family: Calibri, sans-serif;\"><span style=\"color: black;\">Local Management Workstation</span></p>\r\n</td>\r\n<td style=\"width: 108.8pt; border-top: none; border-left: none; border-bottom: solid windowtext 1.0pt; border-right: solid windowtext 1.0pt; padding: 0in 5.4pt 0in 5.4pt;\" valign=\"top\">\r\n<p style=\"margin: 0in; font-size: 11pt; font-family: Calibri, sans-serif;\"><span style=\"font-size: 10.0pt; color: black;\">Yes</span></p>\r\n</td>\r\n<td style=\"width: 247.25pt; border-top: none; border-left: none; border-bottom: solid windowtext 1.0pt; border-right: solid windowtext 1.0pt; padding: 0in 5.4pt 0in 5.4pt;\" valign=\"top\">\r\n<ul style=\"margin-bottom: 0in; margin-top: 1.33333px;\">\r\n<li style=\"margin: 1pt 0.05in 3pt 0px; font-size: 10pt; font-family: Calibri, sans-serif;\"><span style=\"color: black;\">Computer with terminal emulation software to access the console interface (CLI)</span></li>\r\n</ul>\r\n</td>\r\n</tr>\r\n<tr>\r\n<td style=\"width: 116.25pt; border: solid windowtext 1.0pt; border-top: none; padding: 0in 5.4pt 0in 5.4pt;\" valign=\"top\">\r\n<p style=\"margin: 1pt 0.05in 3pt 0in; font-size: 10pt; font-family: Calibri, sans-serif;\"><span style=\"color: black;\">CRL Server</span></p>\r\n</td>\r\n<td style=\"width: 108.8pt; border-top: none; border-left: none; border-bottom: solid windowtext 1.0pt; border-right: solid windowtext 1.0pt; padding: 0in 5.4pt 0in 5.4pt;\" valign=\"top\">\r\n<p style=\"margin: 0in; font-size: 11pt; font-family: Calibri, sans-serif;\"><span style=\"font-size: 10.0pt; color: black;\">Yes</span></p>\r\n</td>\r\n<td style=\"width: 247.25pt; border-top: none; border-left: none; border-bottom: solid windowtext 1.0pt; border-right: solid windowtext 1.0pt; padding: 0in 5.4pt 0in 5.4pt;\" valign=\"top\">\r\n<ul style=\"margin-bottom: 0in; margin-top: 1.33333px;\">\r\n<li style=\"margin: 1pt 0.05in 3pt 0px; font-size: 10pt; font-family: Calibri, sans-serif;\"><span style=\"color: black;\">Conformant with RFC 5280</span></li>\r\n<li style=\"margin: 1pt 0.05in 3pt 0px; font-size: 10pt; font-family: Calibri, sans-serif;\"><span style=\"color: black;\">Provides a list of revoked certificates.</span></li>\r\n<li style=\"margin: 1pt 0.05in 3pt 0px; font-size: 10pt; font-family: Calibri, sans-serif;\"><span style=\"color: black;\">TOE uses the CRL server to check the revocation status of a server&rsquo;s presented certificate.</span></li>\r\n<li style=\"margin: 1pt 0.05in 3pt 0px; font-size: 10pt; font-family: Calibri, sans-serif;\"><span style=\"color: black;\">Communication between the TOE and the CRL server occurs over HTTP.</span></li>\r\n</ul>\r\n</td>\r\n</tr>\r\n<tr>\r\n<td style=\"width: 116.25pt; border: solid windowtext 1.0pt; border-top: none; padding: 0in 5.4pt 0in 5.4pt;\" valign=\"top\">\r\n<p style=\"margin: 1pt 0.05in 3pt 0in; font-size: 10pt; font-family: Calibri, sans-serif;\"><span style=\"color: black;\">DNS Server</span></p>\r\n</td>\r\n<td style=\"width: 108.8pt; border-top: none; border-left: none; border-bottom: solid windowtext 1.0pt; border-right: solid windowtext 1.0pt; padding: 0in 5.4pt 0in 5.4pt;\" valign=\"top\">\r\n<p style=\"margin: 0in; font-size: 11pt; font-family: Calibri, sans-serif;\"><span style=\"font-size: 10.0pt; color: black;\">Yes</span></p>\r\n</td>\r\n<td style=\"width: 247.25pt; border-top: none; border-left: none; border-bottom: solid windowtext 1.0pt; border-right: solid windowtext 1.0pt; padding: 0in 5.4pt 0in 5.4pt;\" valign=\"top\">\r\n<ul style=\"margin-bottom: 0in; margin-top: 1.33333px;\">\r\n<li style=\"margin: 1pt 0.05in 3pt 0px; font-size: 10pt; font-family: Calibri, sans-serif;\"><span style=\"color: black;\">Conformant with RFC 1035</span></li>\r\n<li style=\"margin: 1pt 0.05in 3pt 0px; font-size: 10pt; font-family: Calibri, sans-serif;\"><span style=\"color: black;\">Communication between the TOE and the DNS server occurs over TCP.</span></li>\r\n</ul>\r\n</td>\r\n</tr>\r\n</tbody>\r\n</table>","security_evaluation_summary":"<p><span style=\"font-size: 11.0pt; line-height: 106%; font-family: Calibri, sans-serif;\">The evaluation was carried out in accordance with the Common Criteria Evaluation and Validation Scheme (CCEVS) process and scheme. The criteria against which the </span><strong><span style=\"font-size: 11.0pt; line-height: 106%; font-family: Calibri, sans-serif;\">MAGNUM-SC-CC2</span></strong><strong><span style=\"font-size: 11.0pt; line-height: 106%; font-family: Calibri, sans-serif;\"> V24.11.8</span></strong><span style=\"font-size: 11.0pt; line-height: 106%; font-family: Calibri, sans-serif;\"> was evaluated is described in the Common Criteria for Information Technology Security Evaluation, Version 3.1 rev 5.&nbsp; The evaluation methodology used by the evaluation team to conduct the evaluation is the Common Methodology for Information Technology Security Evaluation, Version 3.1 rev 5.&nbsp; The product, when delivered and configured as identified in the Common Criteria Administrator Guidance, satisfies all of the security functional requirements stated in the MAGNUM-SC-CC2 v24.11.8 Security Target. The project underwent CCEVS Validator review.&nbsp; The evaluation was completed in December 2025.&nbsp; Results of the evaluation can be found in the Common Criteria Evaluation and Validation Scheme Validation Report prepared by CCEVS</span></p>","environmental_strengths":"<p style=\"margin: 0in; font-size: 11pt; font-family: Calibri, sans-serif;\">The TOE provides the security functions required by the Collaborative Protection Profile for Network Devices, hereafter referred to as NDcPP v3.0e or NDcPP and Functional Package for SSH, Version 1.0, hereafter referred to as PKG_SSH_v1.0.</p>\r\n<p style=\"margin: 0in; font-size: 11pt; font-family: Calibri, sans-serif;\"><em><span style=\"color: red;\">&nbsp;</span></em></p>\r\n<h4 style=\"margin: 12pt 0in 0in 1.1in; text-indent: -0.6in; break-after: avoid; font-size: 11pt; font-family: Cambria, serif; color: rgb(33, 182, 215); font-weight: normal;\">1.1.1.1<span style=\"font: 7.0pt 'Times New Roman';\">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span>Security Audit</h4>\r\n<p style=\"margin: 0in; font-size: 11pt; font-family: Calibri, sans-serif;\">The TOE generates audit records for security relevant events. Audit data are stored internally and are only accessible to privileged administrators. The TOE supports access to TSF using administrator accounts for authentication and authorization to management and security functions.</p>\r\n<p style=\"margin: 0in; font-size: 11pt; font-family: Calibri, sans-serif;\">&nbsp;</p>\r\n<p style=\"margin: 0in; font-size: 11pt; font-family: Calibri, sans-serif;\">The TOE also supports sending audit records to a remote Syslog server. Audit records sent to the remote server are protected by a TLS connection. Each audit record includes identity (username, IP address, or process), date and time of the event, type of event, and the outcome of the event.</p>\r\n<h4 style=\"margin: 12pt 0in 0in 1.1in; text-indent: -0.6in; break-after: avoid; font-size: 11pt; font-family: Cambria, serif; color: rgb(33, 182, 215); font-weight: normal;\">1.1.1.2<span style=\"font: 7.0pt 'Times New Roman';\">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span>Cryptographic Support</h4>\r\n<p style=\"margin: 0in; font-size: 11pt; font-family: Calibri, sans-serif;\">The TOE includes an OpenSSL library (openssl version 3.0.13-0ubuntu3.5, openssl_fips version 3.0.9et2 and linux-image-generic_6.8.0.71) that implements CAVP validated cryptographic algorithms for random bit generation, encryption/decryption, authentication, and integrity protection/verification. These algorithms are used to provide security for the TLS, HTTPs, and SSH connections for secure management and secure connections to a syslog and authentication servers. TLS and HTTPs are also used to verify firmware updates. The cryptographic services provided by the TOE are described below:</p>\r\n<p style=\"margin: 0in; font-size: 11pt; font-family: Calibri, sans-serif;\">&nbsp;</p>\r\n<p style=\"text-align: left; margin: 0in; break-after: avoid; font-size: 9pt; font-family: Cambria, serif; font-weight: bold;\">&nbsp;</p>\r\n<table class=\"MsoNormalTable\" style=\"width: 624px; border-collapse: collapse; border: none; height: 513.455px;\" border=\"1\" cellspacing=\"0\" cellpadding=\"0\">\r\n<tbody>\r\n<tr style=\"height: 20.5382px;\">\r\n<td style=\"width: 107.75pt; border: 1pt solid windowtext; background: rgb(255, 192, 0); padding: 0in 5.4pt; height: 20.5382px;\">\r\n<p style=\"margin: 0in; font-size: 11pt; font-family: Calibri, sans-serif;\"><strong><span style=\"font-size: 10.0pt; color: black;\">Cryptographic Protocol </span></strong></p>\r\n</td>\r\n<td style=\"width: 5in; border-top: 1pt solid windowtext; border-right: 1pt solid windowtext; border-bottom: 1pt solid windowtext; border-image: initial; border-left: none; background: rgb(255, 192, 0); padding: 0in 5.4pt; height: 20.5382px;\">\r\n<p style=\"margin: 0in; font-size: 11pt; font-family: Calibri, sans-serif; padding-left: 40px; text-align: left;\"><strong><span style=\"font-size: 10.0pt; color: black;\">Use within the TOE</span></strong></p>\r\n</td>\r\n</tr>\r\n<tr style=\"height: 41.0764px;\">\r\n<td style=\"width: 107.75pt; border-right: 1pt solid black; border-bottom: 1pt solid black; border-left: 1pt solid black; border-image: initial; border-top: none; padding: 0in 5.4pt; height: 41.0764px;\">\r\n<p style=\"margin: 0in; font-size: 11pt; font-family: Calibri, sans-serif;\"><span style=\"font-family: Calibri-Bold, serif; color: black; font-weight: bold; font-style: normal;\"><span style=\"font-size: 10.0pt;\">HTTPS/TLS (client) </span></span></p>\r\n</td>\r\n<td style=\"width: 5in; border-top: none; border-left: none; border-bottom: 1pt solid black; border-right: 1pt solid black; padding: 0in 5.4pt; height: 41.0764px;\">\r\n<p style=\"margin: 0in; font-size: 11pt; font-family: Calibri, sans-serif;\"><span style=\"font-family: Calibri-Bold, serif; color: black; font-weight: bold; font-style: normal;\"><span style=\"font-size: 10.0pt;\">Secure connection to syslog</span></span><strong><span style=\"font-size: 10.0pt; color: black;\"><br></span></strong><span style=\"font-family: Calibri-Bold, serif; color: black; font-weight: bold; font-style: normal;\"><span style=\"font-size: 10.0pt;\">FCS_HTTPS_EXT.1, FCS_TLSC_EXT.2</span></span></p>\r\n</td>\r\n</tr>\r\n<tr style=\"height: 41.0764px;\">\r\n<td style=\"width: 107.75pt; border-right: 1pt solid black; border-bottom: 1pt solid black; border-left: 1pt solid black; border-image: initial; border-top: none; padding: 0in 5.4pt; height: 41.0764px;\">\r\n<p style=\"margin: 0in; font-size: 11pt; font-family: Calibri, sans-serif;\"><span style=\"font-family: Calibri-Bold, serif; color: black; font-weight: bold; font-style: normal;\"><span style=\"font-size: 10.0pt;\">HTTPS/TLS (server) </span></span></p>\r\n</td>\r\n<td style=\"width: 5in; border-top: none; border-left: none; border-bottom: 1pt solid black; border-right: 1pt solid black; padding: 0in 5.4pt; height: 41.0764px;\">\r\n<p style=\"margin: 0in; font-size: 11pt; font-family: Calibri, sans-serif;\"><span style=\"font-family: Calibri-Bold, serif; color: black; font-weight: bold; font-style: normal;\"><span style=\"font-size: 10.0pt;\">Remote management</span></span><strong><span style=\"font-size: 10.0pt; color: black;\"><br></span></strong><span style=\"font-family: Calibri-Bold, serif; color: black; font-weight: bold; font-style: normal;\"><span style=\"font-size: 10.0pt;\">FCS_HTTPS_EXT.1, FCS_TLSS_EXT.1</span></span></p>\r\n</td>\r\n</tr>\r\n<tr style=\"height: 41.0764px;\">\r\n<td style=\"width: 107.75pt; border-right: 1pt solid black; border-bottom: 1pt solid black; border-left: 1pt solid black; border-image: initial; border-top: none; padding: 0in 5.4pt; height: 41.0764px;\">\r\n<p style=\"margin: 0in; font-size: 11pt; font-family: Calibri, sans-serif;\"><span style=\"font-family: Calibri-Bold, serif; color: black; font-weight: bold; font-style: normal;\"><span style=\"font-size: 10.0pt;\">SSH (server) </span></span></p>\r\n</td>\r\n<td style=\"width: 5in; border-top: none; border-left: none; border-bottom: 1pt solid black; border-right: 1pt solid black; padding: 0in 5.4pt; height: 41.0764px;\">\r\n<p style=\"margin: 0in; font-size: 11pt; font-family: Calibri, sans-serif;\"><span style=\"font-family: Calibri-Bold, serif; color: black; font-weight: bold; font-style: normal;\"><span style=\"font-size: 10.0pt;\">Remote management</span></span><strong><span style=\"font-size: 10.0pt; color: black;\"><br></span></strong><span style=\"font-family: Calibri-Bold, serif; color: black; font-weight: bold; font-style: normal;\"><span style=\"font-size: 10.0pt;\">FCS_SSHS_EXT.1</span></span></p>\r\n</td>\r\n</tr>\r\n<tr style=\"height: 61.6146px;\">\r\n<td style=\"width: 107.75pt; border-right: 1pt solid black; border-bottom: 1pt solid black; border-left: 1pt solid black; border-image: initial; border-top: none; padding: 0in 5.4pt; height: 61.6146px;\">\r\n<p style=\"margin: 0in; font-size: 11pt; font-family: Calibri, sans-serif;\"><span style=\"font-family: Calibri-Bold, serif; color: black; font-weight: bold; font-style: normal;\"><span style=\"font-size: 10.0pt;\">AES </span></span></p>\r\n</td>\r\n<td style=\"width: 5in; border-top: none; border-left: none; border-bottom: 1pt solid black; border-right: 1pt solid black; padding: 0in 5.4pt; height: 61.6146px;\">\r\n<p style=\"margin: 0in; font-size: 11pt; font-family: Calibri, sans-serif;\"><span style=\"font-family: Calibri-Bold, serif; color: black; font-weight: bold; font-style: normal;\"><span style=\"font-size: 10.0pt;\">Provides encryption/decryption in support of the TLS and SSH protocol.</span></span><strong><span style=\"font-size: 10.0pt; color: black;\"><br></span></strong><span style=\"font-size: 10.0pt; color: black;\">FCS_COP.1.1/DataEncryption</span><span style=\"font-family: Calibri-Bold, serif; color: black; font-weight: bold; font-style: normal;\"><span style=\"font-size: 10.0pt;\">, FCS_TLSC_EXT.2, FCS_TLSS_EXT.1, FCS_SSHS_EXT.1</span></span></p>\r\n</td>\r\n</tr>\r\n<tr style=\"height: 41.0764px;\">\r\n<td style=\"width: 107.75pt; border-right: 1pt solid black; border-bottom: 1pt solid black; border-left: 1pt solid black; border-image: initial; border-top: none; padding: 0in 5.4pt; height: 41.0764px;\">\r\n<p style=\"margin: 0in; font-size: 11pt; font-family: Calibri, sans-serif;\"><span style=\"font-family: Calibri-Bold, serif; color: black; font-weight: bold; font-style: normal;\"><span style=\"font-size: 10.0pt;\">DRBG </span></span></p>\r\n</td>\r\n<td style=\"width: 5in; border-top: none; border-left: none; border-bottom: 1pt solid black; border-right: 1pt solid black; padding: 0in 5.4pt; height: 41.0764px;\">\r\n<p style=\"margin: 0in; font-size: 11pt; font-family: Calibri, sans-serif;\"><span style=\"font-family: Calibri-Bold, serif; color: black; font-weight: bold; font-style: normal;\"><span style=\"font-size: 10.0pt;\">Deterministic random bit generation use to generate keys.</span></span><strong><span style=\"font-size: 10.0pt; color: black;\"><br></span></strong><span style=\"font-family: Calibri-Bold, serif; color: black; font-weight: bold; font-style: normal;\"><span style=\"font-size: 10.0pt;\">FCS_TLSS_EXT.1, FCS_RBG_EXT.1, FCS_SSHS_EXT.1</span></span></p>\r\n</td>\r\n</tr>\r\n<tr style=\"height: 41.0764px;\">\r\n<td style=\"width: 107.75pt; border-right: 1pt solid black; border-bottom: 1pt solid black; border-left: 1pt solid black; border-image: initial; border-top: none; padding: 0in 5.4pt; height: 41.0764px;\">\r\n<p style=\"margin: 0in; font-size: 11pt; font-family: Calibri, sans-serif;\"><span style=\"font-family: Calibri-Bold, serif; color: black; font-weight: bold; font-style: normal;\"><span style=\"font-size: 10.0pt;\">Secure hash </span></span></p>\r\n</td>\r\n<td style=\"width: 5in; border-top: none; border-left: none; border-bottom: 1pt solid black; border-right: 1pt solid black; padding: 0in 5.4pt; height: 41.0764px;\">\r\n<p style=\"margin: 0in; font-size: 11pt; font-family: Calibri, sans-serif;\"><span style=\"font-family: Calibri-Bold, serif; color: black; font-weight: bold; font-style: normal;\"><span style=\"font-size: 10.0pt;\">Used as part of digital signatures and firmware integrity checks.</span></span><strong><span style=\"font-size: 10.0pt; color: black;\"><br></span></strong><span style=\"font-family: Calibri-Bold, serif; color: black; font-weight: bold; font-style: normal;\"><span style=\"font-size: 10.0pt;\">FCS_COP.1/Hash, FCS_TLSC_EXT.2, FCS_TLSS_EXT.1, FCS_SSHS_EXT.1</span></span></p>\r\n</td>\r\n</tr>\r\n<tr style=\"height: 61.6146px;\">\r\n<td style=\"width: 107.75pt; border-right: 1pt solid black; border-bottom: 1pt solid black; border-left: 1pt solid black; border-image: initial; border-top: none; padding: 0in 5.4pt; height: 61.6146px;\">\r\n<p style=\"margin: 0in; font-size: 11pt; font-family: Calibri, sans-serif;\"><span style=\"font-family: Calibri-Bold, serif; color: black; font-weight: bold; font-style: normal;\"><span style=\"font-size: 10.0pt;\">HMAC</span></span></p>\r\n</td>\r\n<td style=\"width: 5in; border-top: none; border-left: none; border-bottom: 1pt solid black; border-right: 1pt solid black; padding: 0in 5.4pt; height: 61.6146px;\">\r\n<p style=\"margin: 0in; font-size: 11pt; font-family: Calibri, sans-serif;\"><span style=\"font-family: Calibri-Bold, serif; color: black; font-weight: bold; font-style: normal;\"><span style=\"font-size: 10.0pt;\">Provides keyed hashing services in support of TLS.</span></span><strong><span style=\"font-size: 10.0pt; color: black;\"><br></span></strong><span style=\"font-family: Calibri-Bold, serif; color: black; font-weight: bold; font-style: normal;\"><span style=\"font-size: 10.0pt;\">FCS_COP.1/KeyedHash, FCS_TLSC_EXT.2, FCS_TLSS_EXT.1, FCS_SSHS_EXT.1</span></span></p>\r\n</td>\r\n</tr>\r\n<tr style=\"height: 41.0764px;\">\r\n<td style=\"width: 107.75pt; border-right: 1pt solid black; border-bottom: 1pt solid black; border-left: 1pt solid black; border-image: initial; border-top: none; padding: 0in 5.4pt; height: 41.0764px;\">\r\n<p style=\"margin: 0in; font-size: 11pt; font-family: Calibri, sans-serif;\"><span style=\"font-family: Calibri-Bold, serif; color: black; font-weight: bold; font-style: normal;\"><span style=\"font-size: 10.0pt;\">EC-DH </span></span></p>\r\n</td>\r\n<td style=\"width: 5in; border-top: none; border-left: none; border-bottom: 1pt solid black; border-right: 1pt solid black; padding: 0in 5.4pt; height: 41.0764px;\">\r\n<p style=\"margin: 0in; font-size: 11pt; font-family: Calibri, sans-serif;\"><span style=\"font-family: Calibri-Bold, serif; color: black; font-weight: bold; font-style: normal;\"><span style=\"font-size: 10.0pt;\">Provides key establishment for TLS.</span></span><strong><span style=\"font-size: 10.0pt; color: black;\"><br></span></strong><span style=\"font-family: Calibri-Bold, serif; color: black; font-weight: bold; font-style: normal;\"><span style=\"font-size: 10.0pt;\">FCS_CKM.2, FCS_TLSC_EXT.2, FCS_TLSS_EXT.1, FCS_SSHS_EXT.1</span></span></p>\r\n</td>\r\n</tr>\r\n<tr style=\"height: 41.0764px;\">\r\n<td style=\"width: 107.75pt; border-right: 1pt solid black; border-bottom: 1pt solid black; border-left: 1pt solid black; border-image: initial; border-top: none; padding: 0in 5.4pt; height: 41.0764px;\">\r\n<p style=\"margin: 0in; font-size: 11pt; font-family: Calibri, sans-serif;\"><span style=\"font-family: Calibri-Bold, serif; color: black; font-weight: bold; font-style: normal;\"><span style=\"font-size: 10.0pt;\">ECDSA </span></span></p>\r\n</td>\r\n<td style=\"width: 5in; border-top: none; border-left: none; border-bottom: 1pt solid black; border-right: 1pt solid black; padding: 0in 5.4pt; height: 41.0764px;\">\r\n<p style=\"margin: 0in; font-size: 11pt; font-family: Calibri, sans-serif;\"><span style=\"font-family: Calibri-Bold, serif; color: black; font-weight: bold; font-style: normal;\"><span style=\"font-size: 10.0pt;\">Used to generate EC-DH components for key establishment for TLS.</span></span><strong><span style=\"font-size: 10.0pt; color: black;\"><br></span></strong><span style=\"font-family: Calibri-Bold, serif; color: black; font-weight: bold; font-style: normal;\"><span style=\"font-size: 10.0pt;\">FCS_CKM.1, FCS_CKM.2, FCS_TLSS_EXT.1, FCS_SSHS_EXT.1</span></span></p>\r\n</td>\r\n</tr>\r\n<tr style=\"height: 82.1528px;\">\r\n<td style=\"width: 107.75pt; border-right: 1pt solid black; border-bottom: 1pt solid black; border-left: 1pt solid black; border-image: initial; border-top: none; padding: 0in 5.4pt; height: 82.1528px;\">\r\n<p style=\"margin: 0in; font-size: 11pt; font-family: Calibri, sans-serif;\"><span style=\"font-family: Calibri-Bold, serif; color: black; font-weight: bold; font-style: normal;\"><span style=\"font-size: 10.0pt;\">RSA </span></span></p>\r\n</td>\r\n<td style=\"width: 5in; border-top: none; border-left: none; border-bottom: 1pt solid black; border-right: 1pt solid black; padding: 0in 5.4pt; height: 82.1528px;\">\r\n<p style=\"margin: 0in; font-size: 11pt; font-family: Calibri, sans-serif;\"><span style=\"font-family: Calibri-Bold, serif; color: black; font-weight: bold; font-style: normal;\"><span style=\"font-size: 10.0pt;\">Provide key generation and signature generation and verification (PKCS1_V1.5) in</span></span><strong><span style=\"font-size: 10.0pt; color: black;\"> </span></strong><span style=\"font-family: Calibri-Bold, serif; color: black; font-weight: bold; font-style: normal;\"><span style=\"font-size: 10.0pt;\">support of TLS.</span></span><strong><span style=\"font-size: 10.0pt; color: black;\"><br></span></strong><span style=\"font-family: Calibri-Bold, serif; color: black; font-weight: bold; font-style: normal;\"><span style=\"font-size: 10.0pt;\">FCS_CKM.1, FCS_COP.1/SigGen, FCS_COP.1/SigVer, FCS_TLSC_EXT.2, FCS_TLSS_EXT.1, FCS_SSHS_EXT.1</span></span></p>\r\n</td>\r\n</tr>\r\n</tbody>\r\n</table>\r\n<p style=\"margin: 0in; font-size: 11pt; font-family: Calibri, sans-serif;\">&nbsp;</p>\r\n<p style=\"margin: 0in; font-size: 11pt; font-family: Calibri, sans-serif;\">Each of these cryptographic algorithms have been validated for conformance to the requirements specified in their respective standards (refer to Table 15) <!--StartFragment--><span data-olk-copy-source=\"MessageBody\">in the ST</span>.</p>\r\n<h4 style=\"margin: 12pt 0in 0in 1.1in; text-indent: -0.6in; break-after: avoid; font-size: 11pt; font-family: Cambria, serif; color: rgb(33, 182, 215); font-weight: normal;\">1.1.1.3<span style=\"font: 7.0pt 'Times New Roman';\">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span>Identification and Authentication</h4>\r\n<p style=\"margin: 0in; font-size: 11pt; font-family: Calibri, sans-serif;\">The TOE authenticates administrative users using a username/password combination. The TOE does not allow access to any administrative functions prior to successful authentication. The TOE validates and authenticates X.509 certificates for all certificate uses.</p>\r\n<p style=\"margin: 0in; font-size: 11pt; font-family: Calibri, sans-serif;\">&nbsp;</p>\r\n<p style=\"margin: 0in; font-size: 11pt; font-family: Calibri, sans-serif;\">The TOE supports passwords consisting of alphanumeric and special characters and enforces minimum password lengths. The TSF supports certificates using RSA signature algorithms. Certificates are used to authenticate trusted channels, not administrators. The TOE only allows users to view the login warning banner prior to authentication. Remote administrators are locked out after a configurable number of unsuccessful authentication attempts.</p>\r\n<h4 style=\"margin: 12pt 0in 0in 1.1in; text-indent: -0.6in; break-after: avoid; font-size: 11pt; font-family: Cambria, serif; color: rgb(33, 182, 215); font-weight: normal;\">1.1.1.4<span style=\"font: 7.0pt 'Times New Roman';\">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span>Security Management</h4>\r\n<p style=\"margin: 0in; font-size: 11pt; font-family: Calibri, sans-serif;\">The TOE allows users with the Security Administrator role to administer the TOE over a remote web UI, remote CLI, or a local CLI. These interfaces do not allow the Security Administrator to execute arbitrary commands or executables on the TOE. Security Administrators can manage connections to an external Syslog server, as well as determine the size of local audit storage.</p>\r\n<h4 style=\"margin: 12pt 0in 0in 1.1in; text-indent: -0.6in; break-after: avoid; font-size: 11pt; font-family: Cambria, serif; color: rgb(33, 182, 215); font-weight: normal;\">1.1.1.5<span style=\"font: 7.0pt 'Times New Roman';\">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span>Protection of the TSF</h4>\r\n<p style=\"margin: 0in; font-size: 11pt; font-family: Calibri, sans-serif;\">The TOE implements several self-protection mechanisms. This protection includes self-tests to ensure the correct operations of cryptographic functions. Firmware upgrades, performed by a Security Administrator, must pass two authentication tests. The TOE does not provide an interface for the reading of secret or private keys. The TOE ensures timestamps, timeouts, and certificate checks are accurate by maintaining a real-time clock.</p>\r\n<h4 style=\"margin: 12pt 0in 0in 1.1in; text-indent: -0.6in; break-after: avoid; font-size: 11pt; font-family: Cambria, serif; color: rgb(33, 182, 215); font-weight: normal;\">1.1.1.6<span style=\"font: 7.0pt 'Times New Roman';\">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span>TOE Access</h4>\r\n<p style=\"margin: 0in 0in 12pt; font-size: 11pt; font-family: Calibri, sans-serif;\">The TOE can be configured to display a warning and consent banner when an administrator attempts to establish an interactive session over the CLI (local or remote) or remote web UI. The TOE also enforces a configurable inactivity timeout for remote administrative sessions.</p>\r\n<h4 style=\"margin: 12pt 0in 0in 1.1in; text-indent: -0.6in; break-after: avoid; font-size: 11pt; font-family: Cambria, serif; color: rgb(33, 182, 215); font-weight: normal;\">1.1.1.7<span style=\"font: 7.0pt 'Times New Roman';\">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span>Trusted Path/Channels</h4>\r\n<p style=\"margin: 0in; font-size: 11pt; font-family: Calibri, sans-serif;\">The TOE uses TLS to provide a trusted communication channel between itself and remote audit server and MAGNUM server. &nbsp;The trusted channels utilize X.509 certificates to perform mutual authentication. The TOE initiates the Syslog over TLS trusted channel with the remote audit server.</p>\r\n<p><span style=\"font-size: 11.0pt; font-family: Calibri, sans-serif;\">The TOE uses HTTPS/TLS and SSH to provide a trusted path between itself and remote administrative users. The TOE does not implement any additional methods of remote administration. The remote administrative users are responsible for initiating the trusted path when they wish to communicate with the TOE.</span></p>","features":[{"id":997,"feature_name":"Asymmetric Key Generation"},{"id":994,"feature_name":"Auditing"},{"id":1009,"feature_name":"Certificate Authentication"},{"id":1002,"feature_name":"Certificate Validation"},{"id":1000,"feature_name":"Cryptographic Hashing"},{"id":998,"feature_name":"Cryptographic Key Establishment"},{"id":999,"feature_name":"Cryptographic Signature Verification"},{"id":996,"feature_name":"DRBG"},{"id":993,"feature_name":"Flaw Remediation"},{"id":1006,"feature_name":"HTTPS Client"},{"id":1007,"feature_name":"HTTPS Server without Mutual Authentication"},{"id":1008,"feature_name":"IPsec"},{"id":1001,"feature_name":"Keyed-hash message authentication"},{"id":1005,"feature_name":"SSH Server"},{"id":1011,"feature_name":"TLS 1.1"},{"id":1010,"feature_name":"TLS 1.2"},{"id":1003,"feature_name":"TLS Client"},{"id":1004,"feature_name":"TLS Server without Mutual Authentication"}]}