NIAP: Assurance Continuity
NIAP/CCEVS
  NIAP  »»  Product Compliant List  »»  Product Entry  »»  Assurance Continuity  
Assurance Continuity - Nokia 7x50 SR OS 20.10.R12 for 7750 SR-7, 7750 SR-12, 7750 SR-12e, 7750 SR-1e, 7750 SR-2e, 7750 SR-3e, 7750 SR-a4, and 7750 SR-a8 with maxp10-10/1Gb-msec-sfp+ and me12-10/1gb-sfp+ MDAs

CC Certificate [PDF] Validation Report [PDF] Assurance Activity [PDF]

Administrative Guide [PDF]

Please note:  The above files are for the Original Evaluated TOE.  Consequently, they do not refer to this maintained version, although they apply to the maintained version. 

Security Target [PDF] * Assurance Continuity Maintenance Report [PDF] Administrative Guide [PDF]

Please note:  This serves as an addendum to the VR for the Original Evaluated TOE. 

* This is the Security Target (ST) associated with this latest Maintenance Release.  To view previous STs for this TOE, click here.

Readers are reminded that the certification of this product (TOE) is the result of maintenance, rather than an actual re-evaluation of the product.  Maintenance only considers the affect of TOE changes on the assurance baseline (i.e. the original evaluated TOE); maintenance is not intended to provide assurance in regard to the resistance of the TOE to new vulnerabilities or attack methods discovered since the date of the initial certificate.  Such assurance can only be gained through re-evaluation. 

Using a security impact analysis of the changes made to the TOE, which was provided by the developer, the CCEVS has determined that the impact of changes on the TOE are considered minor and that independent evaluator analysis was not necessary.  A summary of the results can be found in the Maintenance Report, which is written in relation to the product's original validation report and Security Target.  Readers are therefore reminded to read the Security Target, Validation Report, and the Assurance Maintenance Report to fully understand the meaning of what a maintained certificate represents. 

Product Description

For this Assurance Continuity, the version number of TOE changed from Nokia 7x50 SR OS 20.10.R4 to Nokia 7x50 SR OS 20.10.R12. The following paragraphs list the minor  hardware and software changes made to the TOE during the maintenance cycle.

1.      Hardware Changes

The developer reported the new hardware features/changes to the product located in the table below:

Support for MDA-e-XP 16pt 10/25G SFP28+2pt QSFP28 -B, MDA-s - 16pt SFPDD MACsec+4pt QSFP28 -B, and MDA-s - 8pt SFPDD MACsec+2pt QSFP28 -B

Release 20.10.R12 introduces the MDA-e-XP 16pt 10/25G SFP28+2pt QSFP28 -B on the 7750 SR product family. The MDA-s - 16pt SFPDD MACsec+4pt QSFP28 -B and MDA-s - 8pt SFPDD MACsec+2pt QSFP28 -B are introduced on the 7750 SR-s product family.

MACsec is not supported in Release 20.10.Rx for the MDA-s - 8pt SFPDD MACsec+2pt QSFP28 -B card.

·       Impact: Minor

·       Rationale: This was an update to support additional pluggable card in the 7750 SR chassis. “MDA-e-XP 16pt 10/25G SFP28+2pt QSFP28 -B” is a non-MACsec card.  Non-MACsec cards do not have any security functionality and therefore do not impact the evaluated functionality. “MDA-s - 16pt SFPDD MACsec+4pt QSFP28 -B”, and “MDA-s - 8pt SFPDD MACsec+2pt QSFP28 -B” are pluggable cards. These pluggable cards are not part of the evaluation. Therefore any changes or additions to them does not impact the equivalency analysis or evaluated functionality.

QSFP28 100G LR Single Lambda

Release 20.10.R12 introduces support the for the QSFP28 100G LR single lambda pluggable module for the 7250 IXR, 7750 SR, 7750 SR-s, and 7950 XRS platforms.

·       Impact: Minor

·       Rationale: This was an update to support additional pluggable card in the 7750 SR chassis. This pluggable card do not support MACsec. Non-MACsec cards do not have any security functionality and therefore do not impact the evaluated functionality. Non-MACsec cards are not part of the evaluation and therefore any changes or additions to them does not impact the equivalency analysis or evaluated functionality.

Support for QSFP28 100G ER4 0/70C

Release 20.10.R12 introduces support for the QSFP28 100G ER4 0/70C. This new pluggable is supported on the 7250 IXR, 7750 SR, 7750 SR-s, and 7950 XRS platforms.

·       Impact: Minor

·       Rationale: This was an update to support additional pluggable card in the 7750 SR chassis. This pluggable card do not support MACsec. Non-MACsec cards do not have any security functionality and therefore do not impact the evaluated functionality. Non-MACsec cards are not part of the evaluation and therefore any changes or additions to them does not impact the equivalency analysis or evaluated functionality.

QSFP56-DD 4x100G LR

Release 20.10.R12 introduces support the for the QSFP56-DD 4x100G LR single lambda pluggable module for the 7250 IXR, 7750 SR, 7750 SR-s, and 7950 XRS platforms.

·       Impact: Minor

·       This was an update to support additional pluggable card in the 7750 SR chassis. This pluggable card do not support MACsec. Non-MACsec cards do not have any security functionality and therefore do not impact the evaluated functionality. Non-MACsec cards are not part of the evaluation and therefore any changes or additions to them does not impact the equivalency analysis or evaluated functionality.

QSFP56-DD 400G ER8

Release 20.10.R12 introduces support the for the QSFP56-DD 400G ER8 pluggable module for the 7250 IXR, 7750 SR, 7750 SR-s, and 7950 XRS platforms.

·       Impact: Minor

·       Rationale: This was an update to support additional pluggable card in the 7750 SR chassis. This pluggable card do not support MACsec. Non-MACsec cards do not have any security functionality and therefore do not impact the evaluated functionality. Non-MACsec cards are not part of the evaluation and therefore any changes or additions to them does not impact the equivalency analysis or evaluated functionality.

QSFP-DD Support for 1x100g, 2x100g, and 3x100g

Release 20.10.R9 provides support of the 1x100g, 2x100g, 3x100g for the QSFP-DD 400G ZR+ optical modules.

·       Impact: Minor

·       Rationale: This was an update to support additional connector breakout configurations to support various data speeds. This update does not change the equivalency analysis.

Option to Configure DWDM Transmit Frequency

Release 20.10.R9 adds a new attribute to allow the configuration of the frequency of the transmit for a coherent DWDM port. This allows frequencies on grids other than the 100 GHz or 50 GHz grids to be specified for supported optical modules.

·       Impact: Minor

·       Rationale: This was an update to the hardware that does not change the equivalency analysis.

Support for QSFP28 100G ZR4 on the 7750 SR/SR-s

Release 20.10.R8 introduces support for the QSFP28 100G ZR4 on the 7750 SR/SRs for the following FP4-based hardware: XMA-s, 7750 SR-1s and the MDA-s for the 7750 SR-1s SR-1s Modular, SR-2s, SR-7s, SR-14s, and MDA-e-XP for the 7750 SR- 1, SR-7, SR-12, and SR-12e.

·       Impact: Minor

·       Rationale: This was an update to support additional pluggable card in the 7750 SR chassis. This pluggable card do not support MACsec. Non-MACsec cards do not have any security functionality and therefore do not impact the evaluated functionality. Non-MACsec cards are not part of the evaluation and therefore any changes or additions to them does not impact the equivalency analysis or evaluated functionality.

Support for QSFP28 BX20-U/D

Release 20.10.R8 introduces support for the QSFP28 100G BX20 (bidirectional) pluggable modules on the 7250 IXR-R6, IXR-6, IXR-10, IXR-X1, IXR-Xs, 7750 SR, and 7950 XRS platforms.

·       Impact: Minor

·       Rationale: This was an update to support additional pluggable card in the 7750 SR chassis. This pluggable card do not support MACsec. Non-MACsec cards do not have any security functionality and therefore do not impact the evaluated functionality. Non-MACsec cards are not part of the evaluation and therefore any changes or additions to them does not impact the equivalency analysis or evaluated functionality.

Support for SFP-DD 100G DR, FR, and LR Single Lambda Pluggable Modules

Release 20.10.R8 introduces support for the SFP-DD 100G DR, FR, and LR single lambda pluggable modules on the 7750 SR-s platform.

·       Impact: Minor

·       Rationale: This was an update to support additional pluggable cards in the 7750 SR chassis. These pluggable cards do not support MACsec. Non-MACsec cards do not have any security functionality and therefore do not impact the evaluated functionality. Non-MACsec cards are not part of the evaluation and therefore any changes or additions to them does not impact the equivalency analysis or evaluated functionality.

Support for QSFP-DD 400G ZR and ZR+ Optical Modules

Release 20.10.R7 introduces support for the QSFP-DD 400G ZR and QSFP-DD 400G ZR+ coherent pluggable modules.

·       Impact: Minor

·       Rationale: This was an update to support additional pluggable cards in the 7750 SR chassis. These pluggable cards do not support MACsec. Non-MACsec cards do not have any security functionality and therefore do not impact the evaluated functionality. Non-MACsec cards are not part of the evaluation and therefore any changes or additions to them does not impact the equivalency analysis or evaluated functionality.

LR4 Optical Module on the ESA 100G

Release 20.10 R7 introduces support for the LR4 Optics (3HE10550AA QSFP28-100G LR4 10KM LC) optical module on the ESA 100G.

·       Impact: Minor

·       Rationale: This was an update to support optical module on ESA 100G. ESA 100G is not part of the evaluated hardware models or cards. Therefore this change does not impact the equivalency analysis or evaluated functionality.

Support for SFP28 Tunable Optical Module on the 7250 IXR, 7750 SR, and 7750 SR-s

Release 20.10.R6 introduces the SFP28 25G tunable DWDM optical module supporting 40 channels and 100 GHz spacing. The SFP28 25G tunable DWDM optical module is supported on the following cards and systems: 7250 IXR-Xs, 7250 IXR-R4/R6 MDA 6pt 10G + 4pt 25G, 7250 IXR-e, MDA-s 16-port SFP-DD MACsec + 4pt QSFP28, MDA-s 8-port SFP-DD MACsec + 2-port QSFP28, and the MDA-e 8- port 10/25GE SFP+/28.

·       Impact: Minor

·       Rationale: This was an update to support SFP28 optical module in the “MDA-s 16-port SFP-DD MACsec + 4pt QSFP28”, and “MDA-s 8-port SFP-DD MACsec + 2-port QSFP28” pluggable cards. These pluggable cards are not part of the evaluation. Therefore any changes or additions to them does not impact the equivalency analysis or evaluated functionality.

2.      Software Changes

The developer reported the new software features/changes to the product located in the table below:

 

BGP

Release 20.10.R12 is enhanced to treat a received BGP update message with an Atomic-Aggregate path attribute flag value of “0x00 0x80 0xc0” as treat-as-withdraw when update-fault-tolerance is enabled or as session-reset when update-fault-tolerance is disabled. This change is made to conform with RFC 7606 section 3, clause c. [408832].

·       Impact: Minor

·       Rationale: This was an update to a non-evaluated feature that does not affect the evaluated functionality.

Application Assurance

Changes to modern browsers and handsets have made the underlying mechanism of AA's HTTPS redirect feature outdated. This means that on more recent systems, the scope of eligible sites for HTTPS redirect has been severely narrowed. In Release 20.10.R12, an update to the AA redirect mechanism restores the previous scope of eligible sites for more recent systems. As before, websites that the client has previous knowledge of stricter security policies (like Google, Facebook, and others) cannot be redirected. [407320].

·       Impact: Minor

·       Rationale: This was a feature enhancement that does not change the demonstrated TOE boundary or any evaluated functionality.

BFD

Release 20.10.R12 changes the restriction that a Seamless BFD (S-BFD) reflector can only be configured on a router comprising only FP3 or newer IOMs or IMMs. The check that is performed when configuring config>bfd>seamlessbfd> reflector is changed so that an S-BFD reflector can only be configured if all the network and hybrid ports are on FP3+ cards, and none of the network or hybrid ports are on FP2-based cards. [415636].

·       Impact: Minor

·       Rationale: This was an update to a non-evaluated feature that does not affect the evaluated functionality.

OAM

In Release 20.10.R12, TWAMP Light Session-Reflector processes the Z-bit from the Error Estimate filed and received in the TWAMP Light test packet from the Session-Sender. The Session-Reflector uses the inbound Z-bit to choose the timestamp format to encode in the response packet, replying in-kind, marking the Z-bit to align with the timestamp format encoded in the Session-Sender TWAMP Light test packet. [417211].

·       Impact: Minor

  • Rationale: This was an update to a non-evaluated feature that does not affect the evaluated functionality.

Release 20.10.R11 introduces improvements to BGP error handling for errors detected in received update messages. Most of the error handling improvements only apply when the BGP update-fault-tolerance command is enabled. These improvements align SR OS with RFC 7606.

·       Impact: Minor

·       Rationale: This was an update to a non-evaluated feature that does not affect the evaluated functionality.

Application Assurance

Release 20.10.R11 provides more flexibility to operators using web filtering by introducing the “Marijuana” and “Provocative Attire” categories. Operators can configure these categories to allow, block, or redirect like the already supported categories. [403980].

·       Impact: Minor

·       Rationale: This was an update to a non-evaluated feature that does not affect the evaluated functionality.

IPsec/TLS

CVE-2022-0778 describes a vulnerability in OpenSSL where it is possible to trigger an infinite loop by crafting a certificate that has invalid elliptic curve parameters. Since certificate parsing happens before verification of the certificate signature, a process that parses an externally supplied certificate may be subject to a denial-of-service attack.

In Release 20.10.R10, this vulnerability was fixed.

·       Impact: Minor

·       Rationale: This was a security fix to mitigate a vulnerability. This does not affect the evaluated functionality.

Timing/Clocking

In Release 20.10.R9, as a grandmaster clock, PTP supports clock class 7 (in holdover, within holdover specification). During a short interruption of the local GNSS port, PTP degrades the clock class from 6 to 7, instead of 248. This allows better interoperability with some implementation of PTP slave clocks, which do not synchronize to a master clock advertising clock class 248. [403029].

·       Impact: Minor

·       Rationale: This was an update to a non-evaluated feature that does not affect the evaluated functionality.

System

Release 20.10.R6 introduces the following commands for the 7750 SR-s PSUs. [377870].

-       A command to initiate operational off/operational on to reset the output power of a specified PSU in the chassis (clear chassis power-shelf power-shelf-id power-module power-module-id).

-       A command to display PSU telemetry (tools dump power-shelf power-shelf-id power-module power-module-id telemetry).

-       A command to clear latched faults that are no longer current (tools perform power-shelf power-shelf-id power-module power-module-id clear-faults).

·       Impact: Minor

·       Rationale: This was an update to a non-evaluated feature that does not affect the evaluated functionality.

BGP

Release 20.10.R6 enhances BGP so that when a received BGP route with an IGP cost to reach its BGP next hop of value M is imported into another BGP RIB and then re-advertised to other BGP peers subject to a med-out igp-cost command (or the policy equivalent), the MED correctly indicates a value of M rather than zero. [381301].

·       Impact: Minor

·       Rationale: This was an update to a non-evaluated feature that does not affect the evaluated functionality.

MD-CLI

The MD-CLI bof auto-configure and bof auto-boot dhcp commands are now ready for production networks. This feature was introduced in Release 20.10.R1.

·       Impact: Minor

·       Rationale: This was an update to a non-evaluated feature that does not affect the evaluated functionality.

gNMI

Release 20.10.R5 introduces the ability for the gNMI client to retrieve information about how PROTO encoding must be decoded. This information can be obtained by requesting the path with the “gnmi.schemas” origin. [370174]

·       Impact: Minor

·       Rationale: This was an update to a non-evaluated feature that does not affect the evaluated functionality.

Subscriber Management

Release 20.10.R5 introduces the tools perform subscriber-mgmt systembehavior laa-priority command to lower the authentication origin priority for local-address-assignment client applications ppp-v4. With this feature enabled, RADIUS can override DNSv4 server addresses obtained using LAA and assigned to PPPoE sessions. Contact your Nokia representative for more details.

·       Impact: Minor

·       Rationale: This was an update to a non-evaluated feature that does not affect the evaluated functionality.

Application Assurance

Release 20.10.R5 introduces AA transit-IP subscriber support on ESA 100G. [369135].

·       Impact: Minor

·       Rationale: This was an update to a non-evaluated feature that does not affect the evaluated functionality.

 

Vendor Information


Nokia Corporation
Hooman Bidgoli
(866) 582-3688
hooman.bidgoli@nokia.com

www.nokia.com
Site Map              Contact Us              Home