{"product_id":3010,"v_id":3010,"product_name":"Groove Cryptographic Services, (GrooveMisc.dll 2.5.0.1774, cryptopp.dll 5.0.4.0)","certification_status":"Not Certified","certification_date":"2003-09-17T00:09:00Z","tech_type":"Sensitive Data Protection","vendor_id":{"name":"Groove Networks, Inc.","website":"http://www.groove.net"},"vendor_poc":"Donna Shaw","vendor_phone":null,"vendor_email":"SecuritySupport@groove.net","assigned_lab":{"cctl_name":"CygnaCom Solutions, Inc"},"product_description":"<p>Groove Cryptographic Services is binary executable code (software) that provides cryptographic services, and certain non-cryptographic support services. It contains the following two components: GrooveMisc.dll version 2.5.0.1774 and cryptopp.dll version 5.0.4.0. The latter is the (FIPS 140-2 validated) DLL of Wei Dai's Crypto++TM Library, version 5.0.4. </p>\r\n<p>The Groove Cryptographic Services Target of Evaluation (TOE) is incorporated into the following Groove products: </p>\r\n<ul>\r\n    <li>Groove Workspace (including Enterprise Installer for Closed Networks Groove) </li>\r\n    <li>Enterprise Management Server (including Closed Network edition) </li>\r\n    <li>Groove Enterprise Relay Server (including Closed Network edition) </li>\r\n    <li>Groove Enterprise Integration Server (including Closed Network edition) </li>\r\n    <li>Groove Enterprise Backup Service </li>\r\n</ul>\r\n<p>Groove Cryptographic Services is loaded into a PC running one of three operating systems, i.e., running either the Windows 2000, Windows NT, or Windows XP operating system. </p>\r\n<p>GrooveMisc.dll performs cryptographic functions including: </p>\r\n<ul>\r\n    <li>Generation of symmetric keys for use with various cryptographic algorithms and security functions </li>\r\n    <li>Performance of various symmetric and asymmetric encryption, digital signature, and key agreement operations </li>\r\n    <li>Performance of secure hash operations using SHA-1 </li>\r\n    <li>Generation and verification of message authentication codes using the FIPS-approved HMAC algorithm </li>\r\n    <li>Self-test capability </li>\r\n</ul>\r\n<p>Groove Cryptographic Services provides the following cryptographic functions: </p>\r\n<ul>\r\n    <li>RSA &mdash; Key generation (IEEE 1363-2000) </li>\r\n    <li>AES &mdash; Advanced Encryption Standard key generation (FIPS Publication 197) </li>\r\n    <li>DES &mdash; Data Encryption Standard key generation (FIPS Publication 46-3) performed for backward compatibility. </li>\r\n    <li>DH &mdash; Diffie-Hellman key generation (IEEE 1363-2000) </li>\r\n    <li>ESIGN &ndash; Key Generation (IEEE P1363a/D11) </li>\r\n    <li>RSA &mdash; Encryption and decryption for key transport (IEEE 1363-2000) </li>\r\n    <li>RSA &mdash; Encryption and decryption for key transport (IEEE 1363-2000) </li>\r\n    <li>SHA-1 &mdash; Secure Hash Algorithm (FIPS Publication 180-1) </li>\r\n    <li>HMAC-SHA1 &mdash; Keyed-Hashing for Message Authentication (FIPS Publication 198) used with SHA-1 </li>\r\n    <li>DH &mdash; Diffie-Hellman key agreement (IEEE 1363-2000) </li>\r\n    <li>DES-ECB &mdash; DES Electronic Code Book encryption and decryption (FIPS Publication 46-3) performed for backward compatibility. </li>\r\n    <li>AES-CTR &mdash; AES - Counter Mode encryption and decryption (FIPS Publication 197) </li>\r\n    <li>GDSA &mdash; Generalized Digital Signature Algorithm for signature generation and signature verification (IEEE 1363-2000) </li>\r\n    <li>DLIES &mdash; Discrete Logarithm Integrated Encryption Scheme encryption and decryption (IEEE P1363a/D11) </li>\r\n    <li>ESIGN &mdash; Signature generation and verification (IEEE P1363a/D11) </li>\r\n    <li>RNG &mdash; Random number generation (ANSI X9.31) </li>\r\n</ul>","evaluation_configuration":null,"security_evaluation_summary":"<p>The evaluation was carried out in accordance to the Common Criteria Evaluation and Validation Scheme (CCEVS) processes and procedures. Groove Cryptographic Services was evaluated against the criteria contained in the Common Criteria for Information Technology Security Evaluation, Version 2.1. The evaluation methodology used by the evaluation team to conduct the evaluation is the Common Methodology for Information Technology Security Evaluation, Version 1.0. CygnaCom Solutions has determined that the product meets the security criteria in the Security Target, which specifies an assurance level of EAL 2 augmented by ADV_SPM.1. Groove Cryptographic Services was successfully evaluated on three platforms: Windows 2000 Service Pack 2, Windows NT 4.0 Service Pack 6a, and Windows XP Service Pack 1. The Groove Cryptographic Services TOE was tested using Groove Workspace as a test harness. Although the TOE is incorporated into the Groove Enterprise Management Server, Groove Enterprise Relay Server, and Groove Enterprise Integration Server, it was not tested using these products. A validator, on behalf of the CCEVS Validation Body, monitored the evaluation. The evaluation was completed in August 2003.</p>","environmental_strengths":"<p>The Groove Cryptographic Services TOE uses Wei Dai's Crypto++ Library. Crypto++ Library version 5.0.4 has been validated by NIST and found to be in conformance with FIPS 140-2 <em>(Security Requirements for Cryptographic Modules)</em> Level 1.</p>","features":[]}