{"product_id":11691,"v_id":11691,"product_name":"Progress LoadMaster","certification_status":"Certified","certification_date":"2026-07-08T00:00:00Z","tech_type":"Network Device","vendor_id":{"name":"Progress Software Technologies Ltd","website":"https://www.progress.com/ [progress.com]"},"vendor_poc":"Tony Vaughan","vendor_phone":"1-781-280-4000","vendor_email":"Tony.Vaughan@progress.com","assigned_lab":{"cctl_name":"Acumen Security"},"product_description":"<p>The TOE is the Progress Software Corporation&rsquo;s Progress LoadMaster X25-NG, LoadMaster X40-NG, ECS CM H2 NG, ECS CM H3 NG and Virtual LoadMaster running on LoadMaster OS 7.2.54.18. The LoadMaster simplifies the management of networked resources, and optimizes and accelerates user access to diverse servers, content, and transaction-based systems. The TOE is comprised of hardware and software and represents a complete network device providing load balancing functionality.&nbsp;</p>","evaluation_configuration":"<p>The following environmental components are required to operate the TOE in the evaluated configuration:</p>\r\n<ul>\r\n<li>Management Workstation providing local console access to the TOE and a browser to connect to the Web User Interface (WUI) over TLSv1.2.</li>\r\n<li>Syslog server that receives audit logs from the TOE over TLSv1.2.</li>\r\n<li>ESXi v7.0 U3 acting as the hypervisor for Virtual LoadMaster.</li>\r\n<li>Authentication server supporting LDAP over TLSv1.2.</li>\r\n<li>NTP server supporting SHA-1 integrity verification with NTPv4.</li>\r\n<li>OCSP server that receives ocsp requests from TOE over HTTP.</li>\r\n<li>CA Server that provides signed certificates over HTTP.</li>\r\n</ul>\r\n<p>&nbsp;</p>","security_evaluation_summary":"<p data-pm-slice=\"1 1 []\">The evaluation was carried out in accordance with the Common Criteria Evaluation and Validation Scheme (CCEVS) process and scheme. The criteria against which the Progress LoadMaster of Evaluation (TOE) was evaluated is described in the Common Criteria for Information Technology Security Evaluation, Version 3.1 rev 5.&nbsp; The evaluation methodology used by the evaluation team to conduct the evaluation is the Common Methodology for Information Technology Security Evaluation, Version 3.1 rev 5.&nbsp; The product, when delivered and configured as identified in the Common Criteria Administrator Guidance, satisfies all of the security functional requirements stated in the Progress LoadMaster Security Target. The project underwent CCEVS Validator review.&nbsp; The evaluation was completed in July 2026.&nbsp; Results of the evaluation can be found in the Common Criteria Evaluation and Validation Scheme Validation Report prepared by CCEVS.</p>","environmental_strengths":"<div>\r\n<h3>&nbsp;Security Functions Provided by the TOE</h3>\r\n</div>\r\n<p>The TOE provides the security functions required by the Collaborative Protection Profile for Network Devices, hereafter referred to as NDcPP v3.0e or NDcPP.</p>\r\n<div>\r\n<h4>Security Audit</h4>\r\n</div>\r\n<p>The TOE generates audit records for security relevant events. The audit events are associated with the administrator or processes. The audit records are transmitted over TLS to an external audit server.</p>\r\n<div>\r\n<h4>Cryptographic Support</h4>\r\n</div>\r\n<p>The TOE provides the following cryptographic services described below.</p>\r\n<p>Table 3&ndash; Cryptographic Services</p>\r\n<div align=\"center\">\r\n<table style=\"width: 100%;\" border=\"1\" cellspacing=\"0\" cellpadding=\"0\">\r\n<thead>\r\n<tr style=\"height: 5.85pt;\">\r\n<td style=\"width: 116.75pt;\" valign=\"bottom\">\r\n<p><a name=\"_Hlk122123137\"></a><strong>Service</strong></p>\r\n</td>\r\n<td style=\"width: 350.75pt;\" valign=\"top\">\r\n<p><strong>Use</strong></p>\r\n</td>\r\n</tr>\r\n</thead>\r\n<tbody>\r\n<tr style=\"height: 6.8pt;\">\r\n<td style=\"width: 116.75pt;\" valign=\"top\">\r\n<p>TLS Client</p>\r\n</td>\r\n<td style=\"width: 350.75pt;\" valign=\"top\">\r\n<p>Secure connection to remote syslog servers.</p>\r\n</td>\r\n</tr>\r\n<tr style=\"height: 6.8pt;\">\r\n<td style=\"width: 116.75pt;\" valign=\"top\">\r\n<p>TLS Client</p>\r\n</td>\r\n<td style=\"width: 350.75pt;\" valign=\"top\">\r\n<p>Secure connection to remote LDAP server.</p>\r\n</td>\r\n</tr>\r\n<tr style=\"height: 6.8pt;\">\r\n<td style=\"width: 116.75pt;\" valign=\"top\">\r\n<p>TLS/HTTPS Server</p>\r\n</td>\r\n<td style=\"width: 350.75pt;\" valign=\"top\">\r\n<p>Secures connections with remote administrators.</p>\r\n</td>\r\n</tr>\r\n<tr style=\"height: 6.8pt;\">\r\n<td style=\"width: 116.75pt;\" valign=\"top\">\r\n<p>Verification of Updates</p>\r\n</td>\r\n<td style=\"width: 350.75pt;\" valign=\"top\">\r\n<p>Digital signature verification prior to installing an update.</p>\r\n</td>\r\n</tr>\r\n</tbody>\r\n</table>\r\n</div>\r\n<p>Each of these cryptographic algorithms have been validated for conformance to the requirements specified in their respective standards, as identified below.</p>\r\n<div>\r\n<h4>Identification and Authentication</h4>\r\n</div>\r\n<p>The TOE supports a password-based authentication mechanism which automatically locks users after a pre-configured number of failed attempts. The TOE also validates X.509 certificates in support of TLS.</p>\r\n<div>\r\n<h4>&nbsp;Security Management</h4>\r\n</div>\r\n<p>The TOE provides management capabilities via Console and a Web-based GUI, accessed over HTTPS. Management functions allow the administrators to configure the system, install updates, and manage users.</p>\r\n<div>\r\n<h4>&nbsp;Protection of the TSF</h4>\r\n</div>\r\n<p>The TOE prevents the reading of plaintext passwords and keys. The TOE provides a reliable timestamp for its own use. The reliable timestamp can be set by a security administrator or authenticated NTP. To protect the integrity of its security functions, the TOE implements a suite of self-tests at startup and halts or disables affected functionality if a self-test fails. The TOE ensures that updates to the TOE are authenticated by verifying a digital signature prior to installing any update.</p>\r\n<div>\r\n<h4>&nbsp;TOE Access</h4>\r\n</div>\r\n<p>The TOE monitors local and remote administrative sessions for inactivity and either locks or terminates the session when a threshold time period is reached. An advisory notice is displayed at the start of each session.</p>\r\n<div>\r\n<h4>Trusted Path/Channels</h4>\r\n</div>\r\n<p>The TOE initiates a TLS trusted channel with a syslog server and LDAP authentication server (as configured).</p>\r\n<p>The TOE is a TLS/HTTPS server that allows remote administrators to establish a trusted path with the TOE.</p>","features":[{"id":5571,"feature_name":"Auditing"},{"id":5572,"feature_name":"Cryptograhic Key Generation"},{"id":5576,"feature_name":"Cryptographic Hashing"},{"id":5573,"feature_name":"Cryptographic Key Establishment"},{"id":5574,"feature_name":"Cryptographic Signature Generation"},{"id":5575,"feature_name":"Cryptographic Signature Verification"},{"id":5577,"feature_name":"Network Device"},{"id":5578,"feature_name":"TLS 1.2"},{"id":5579,"feature_name":"TLS Client"},{"id":5580,"feature_name":"TLS Server without Mutual Authentication"}]}