{"product_id":4049,"v_id":4049,"product_name":"Opsware System 4.5 Patch 1","certification_status":"Not Certified","certification_date":"2005-12-12T00:12:00Z","tech_type":"Network Management","vendor_id":{"name":"Opsware, Inc.","website":"http://www.opsware.com/products/request.html"},"vendor_poc":"Opsware Sales","vendor_phone":"408.744.7770","vendor_email":"info@opsware.com","assigned_lab":{"cctl_name":"Leidos Common Criteria Testing Laboratory"},"product_description":"<p>The TOE is a software IT management tool that provides an organization the ability to consistently manage servers on multiple end hosts, through the establishment of best-practices.&nbsp; The TOE is designed to simplify and expedite the administration of servers and the deployment and maintenance of software across a heterogeneous environment.&nbsp; The TOE implements the following features:</p>\r\n<ul>\r\n    <li><strong>Provision UNIX, Linux and Windows - </strong>Build out large heterogeneous environments quickly and build servers in a way that they can be easily updated.<strong></strong> </li>\r\n    <li><strong>Provision Applications - </strong>Rapidly deploy multi-tier applications across multiple servers, simultaneously. </li>\r\n    <li><strong>Securely Deploy Patches - </strong>Quickly and accurately identify server vulnerabilities and patch large numbers of servers. </li>\r\n    <li><strong>Track Application Configurations - </strong>Automatically track, store and recover critical software configuration information. </li>\r\n    <li><strong>Code and Content Deployment - </strong>Consistently install and promote an application release to production, while archiving the previous version. </li>\r\n    <li><strong>Track Software Assets - </strong>Keep track of the managed servers and managed applications. </li>\r\n    <li><strong>Distributed Scripts</strong> - Run scripts across multiple servers, simultaneously. </li>\r\n    <li><strong>Custom Extensions</strong> - Run Custom Extension scripts across multiple servers, simultaneously </li>\r\n</ul>\r\n<p>There are two primary modes of operation for the Opsware System, stand-alone and multimaster.&nbsp; Multimaster mode allows the organization to be spread over several sites all acting in coordinated fashion.&nbsp; The differences between the installation modes relate solely to the requirements necessary for multiple Model Repository servers.&nbsp; However, in the evaluation configuration only stand-alone mode is allowed.</p>\r\n<p>Communication between hosts is secured via OpenSSL, a cryptography module that is FIPS-approved but has not been evaluated further during this evaluation.</p>","evaluation_configuration":null,"security_evaluation_summary":"<p>The evaluation was carried out in accordance with the Common Criteria Evaluation and Validation Scheme (CCEVS) process and scheme.&nbsp; The criteria against which the Opsware System 4.5 Patch 1 TOE was judged are described in the Common Criteria for Information Technology Security Evaluation, Version 2.1, August 1999, ISO/IEC 15408 and International Interpretations effective on 29 April 2004.&nbsp; The evaluation methodology used by the evaluation team to conduct the evaluation is the Common Methodology for Information Technology Security Evaluation, Version 1.0, August 1999.&nbsp; Science Applications International Corporation (SAIC) determined that the evaluation assurance level (EAL) for the product is EAL2 family of assurance requirements.&nbsp; The product, when configured as specified in the Opsware System 4.5 Installation Guide, satisfies all of the security functional requirements stated in the Opsware System 4.5 Security Target, Version 1.0.&nbsp; One Validator on behalf of the CCEVS Validation Body monitored the evaluation carried out by SAIC.&nbsp; The evaluation was completed in October 2005.&nbsp; Results of the evaluation can be found in the Common Criteria Evaluation and Validation Scheme Validation Report, (report number CCEVS-VR-05-0133, dated December 12, 2005) prepared by CCEVS.</p>","environmental_strengths":"<p>The TOE is a commercial product whose users require a low to moderate level of independently assured security.&nbsp; Opsware System 4.5 Patch 1 is targeted at a relatively benign environment with good physical access security and competent TOE administrators and users.&nbsp; Within such environments, it is assumed that attackers will have a low attack potential.&nbsp; Opsware System 4.5 Patch 1 supports the following four security functions:</p>\r\n<p><strong>User Data Protection</strong><br />\r\nThe TOE enforces a Management Access Control policy, which restricts access to the management functions of the TOE.&nbsp; This protection requires that users of the TOE be authenticated before any access to the management functions is granted.&nbsp; Once access is granted, user access to management functions is controlled by the assigned user privileges. </p>\r\n<p><strong>Identification and Authentication</strong><br />\r\nThe TOE requires users to provide unique identification and authentication data before any administrative access to the system is granted.&nbsp; The TOE provides the ability to define levels of authority for users, providing administrative flexibility.&nbsp; Full administrators have the ability to define groups and their authority and they have complete control over the TOE.&nbsp; Security privileges are associated with Groups, and it is by assigning users to one or more groups that users get access to features within the TOE. </p>\r\n<p><strong>Security Management</strong><br />\r\nThe TOE is managed through the Opsware Command Center, a web-based interface.&nbsp; Through this interface TOE management can be performed by providing the administrators the ability to manage user attributes and privileges, as well as assign roles for different levels of administrative access. </p>\r\n<p><strong>Protection of Security Functions</strong><br />\r\nThe TOE provides protection of all data that is transferred internally between disparate TOE components.&nbsp; The TOE protection ensures that modifications to the transferred data between disparate TOE components can be detected, preventing unauthorized data from being transferred into the TOE.&nbsp; All components, except for the Agent, are installed on the same platform.&nbsp; The Agent must be installed on each server that is managed by the TOE.&nbsp; Therefore, the only disparate communication is between the Agent and the core components (e.g. Command Engine, Software Repository).</p>","features":[]}