{"_id": "0e81109ee41d37f0", "_type": "sec_certs.sample.cc.CCCertificate", "dgst": "0e81109ee41d37f0", "status": "active", "category": "Network and Network-Related Devices and Systems", "name": "secunet eID PKI Suite Certified CA Kernel SC, Version 4.0.0", "manufacturer": "Secunet Security Networks AG", "scheme": "DE", "security_level": {"_type": "Set", "elements": ["ALC_FLR.2", "EAL4"]}, "not_valid_before": "2026-02-11", "not_valid_after": "2031-02-10", "report_link": "https://www.commoncriteriaportal.org/nfs/ccpfiles/files/epfiles/1216V2a_pdf.pdf", "st_link": "https://www.commoncriteriaportal.org/nfs/ccpfiles/files/epfiles/1216V2b_pdf.pdf", "cert_link": "https://www.commoncriteriaportal.org/nfs/ccpfiles/files/epfiles/1216V2c_pdf.pdf", "manufacturer_web": "https://www.secunet.com/en/", "protection_profile_links": {"_type": "Set", "elements": []}, "maintenance_updates": {"_type": "Set", "elements": [{"_type": "sec_certs.sample.cc.CCCertificate.MaintenanceReport", "maintenance_date": "2026-06-25", "maintenance_title": "secunet eID PKI Suite Certified CA Kernel SC, Version 4.1.0", "maintenance_report_link": "https://www.commoncriteriaportal.org/nfs/ccpfiles/files/epfiles/1216V2MA01a_pdf.pdf", "maintenance_st_link": "https://www.commoncriteriaportal.org/nfs/ccpfiles/files/epfiles/1216V2MA01b_pdf.pdf"}]}, "state": {"_type": "sec_certs.sample.cc_eucc_common.InternalState", "report": {"_type": "sec_certs.sample.document_state.DocumentState", "download_ok": true, "convert_ok": true, "extract_ok": true, "source_hash": "850ec6e8cd00b59a28412b3129258a8b46efc3b4dcc213a21dde91152bcd306f", "txt_hash": "846d9c31ad8554826b7e5786d2f234c2fb9c6fb71a39a6cf505afeced94fe72d", "json_hash": null}, "st": {"_type": "sec_certs.sample.document_state.DocumentState", "download_ok": true, "convert_ok": true, "extract_ok": true, "source_hash": "61af1e5a5fd9f07e6dabda19464710789be4605179df94a721d03f860fcd1726", "txt_hash": "115e8d9ead15017cc9ef97216d3a6b623db41e21248fbb1aa394a14797376d0f", "json_hash": null}, "cert": {"_type": "sec_certs.sample.document_state.DocumentState", "download_ok": true, "convert_ok": true, "extract_ok": true, "source_hash": "6bff3041cda14d85b378c6b2e0b9941918179b32eefcd04a9ef56377f37b1fd5", "txt_hash": "a45b0dcb5357cbb9c474638e6d53d6cbd6b921b4b2b223f608c7e625bfd3e016", "json_hash": null}}, "pdf_data": {"_type": "sec_certs.sample.cc_eucc_common.PdfData", "report_metadata": {"pdf_file_size_bytes": 425409, "pdf_is_encrypted": false, "pdf_number_of_pages": 36, "/Author": "Federal Office for Information Security", "/Keywords": "\"Common Criteria, Certification, Zertifizierung, secunet eID PKI Suite Certified CA Kernel, Version 4.0.0, BSI-DSZ-CC-1216-V2\"", "/Subject": "Common Criteria, Certification, Zertifizierung, secunet eID PKI Suite Certified CA Kernel, Version 4.0.0, BSI-DSZ-CC-1216-V2", "/Title": "Certification Report BSI-DSZ-CC-1216-V2-2026", "pdf_hyperlinks": {"_type": "Set", "elements": []}}, "st_metadata": {"pdf_file_size_bytes": 1183626, "pdf_is_encrypted": false, "pdf_number_of_pages": 78, "/Author": "secunet Security Networks AG", "/Keywords": "secunet eID PKI Suite, Certified CA Kernel, Security Target", "/Title": "secunet eID PKI Suite Certified CA Kernel Security Target", "pdf_hyperlinks": {"_type": "Set", "elements": ["http://www.bsi.de/", "http://tools.ietf.org/html/rfc6960", "http://tools.ietf.org/html/rfc5280", "http://www.commoncriteriaportal.org/", "http://www.itu.int/", "http://www.nist.gov/", "http://tools.ietf.org/html/rfc2104"]}}, "cert_metadata": {"pdf_file_size_bytes": 237618, "pdf_is_encrypted": false, "pdf_number_of_pages": 1, "/Author": "Federal Office for Information Security", "/Keywords": "\"Common Criteria, Certification, Zertifizierung, secunet eID PKI Suite Certified CA Kernel, Version 4.0.0, BSI-DSZ-CC-1216-V2-2026\"", "/Subject": "Common Criteria, Certification, Zertifizierung, secunet eID PKI Suite Certified CA Kernel, Version 4.0.0, BSI-DSZ-CC-1216-V2-2026", "/Title": "Certificate BSI-DSZ-CC-1216-V2-2026", "pdf_hyperlinks": {"_type": "Set", "elements": []}}, "report_frontpage": {"DE": {"match_rules": ["(BSI-DSZ-CC-.+?) (?:for|For) (.+?) from (.*)"], "cert_id": "BSI-DSZ-CC-1216-V2-2026", "cert_item": "secunet eID PKI Suite Certified CA Kernel Version 4.0.0", "developer": "secunet Security Networks AG", "cert_lab": "BSI", "ref_protection_profiles": "None", "cc_version": "Product specific Security Target Common Criteria Part 2 extended", "cc_security_level": "Common Criteria Part 3 conformant EAL 4 augmented by ALC_FLR.2 valid until: 10 February 2031"}}, "st_frontpage": null, "cert_frontpage": null, "report_keywords": {"cc_cert_id": {"DE": {"BSI-DSZ-CC-1216-V2-2026": 19, "BSI-DSZ-CC-1216-2024": 3}}, "cc_protection_profile_id": {}, "cc_security_level": {"EAL": {"EAL 4": 5, "EAL 2": 3, "EAL 1": 1, "EAL 4 augmented": 3}}, "cc_sar": {"AGD": {"AGD_PRE.1": 1, "AGD_OPE.1": 1}, "ALC": {"ALC_FLR.2": 4, "ALC_FLR": 3, "ALC_CMS.4": 1}, "AVA": {"AVA_VAN.3": 1}}, "cc_sfr": {}, "cc_claims": {}, "vendor": {"NXP": {"NXP": 1}, "Infineon": {"Infineon": 1}, "GD": {"G+D": 1}}, "eval_facility": {"SRC": {"SRC Security Research & Consulting": 3}}, "symmetric_crypto": {"AES_competition": {"AES": {"AES": 5}}, "constructions": {"MAC": {"HMAC": 6, "CMAC": 1}}}, "asymmetric_crypto": {"ECC": {"ECDSA": {"ECDSA": 1}}}, "pq_crypto": {"PQC": {"PQC": 7, "Post-quantum cryptography": 1}}, "hash_function": {"SHA": {"SHA1": {"SHA-1": 2}, "SHA2": {"SHA-256": 1}}}, "crypto_scheme": {}, "crypto_protocol": {"TLS": {"TLS": {"TLS 1.2": 1}}}, "randomness": {}, "cipher_mode": {"CBC": {"CBC": 1}}, "ecc_curve": {"NIST": {"secp224r1": 2, "secp384r1": 2, "secp512r1": 2, "secp256r1": 2, "sect233k1": 4, "sect283k1": 2, "sect283r1": 2, "sect409k1": 2, "sect409r1": 2, "sect571k1": 2, "sect571r1": 2}, "Brainpool": {"brainpoolP256r1": 2, "brainpoolP256t1": 2, "brainpoolP320r1": 2, "brainpoolP320t1": 2, "brainpoolP384r1": 2, "brainpoolP384t1": 2, "brainpoolP512r1": 2, "brainpoolP512t1": 2}}, "crypto_engine": {}, "tls_cipher_suite": {}, "crypto_library": {}, "vulnerability": {}, "side_channel_analysis": {}, "technical_report_id": {"BSI": {"BSI TR-03110": 2, "BSI TR-02102": 1, "BSI TR-03111": 2}}, "device_model": {}, "tee_name": {}, "os_name": {"STARCOS": {"STARCOS 3": 4}}, "cplc_data": {}, "ic_data_group": {}, "standard_id": {"FIPS": {"FIPS 140-2": 1, "FIPS 186-5": 1, "FIPS 186-2": 2, "FIPS197": 1, "FIPS180-2": 1, "FIPS 197": 1}, "NIST": {"SP 800-38B": 2, "SP 800-38A": 1, "NIST SP 800-208": 1}, "BSI": {"AIS 32": 1, "AIS 38": 1}, "RFC": {"RFC2104": 3, "RFC 5280": 2, "RFC8017": 3}, "ISO": {"ISO/IEC 15408": 4, "ISO/IEC 18045": 4, "ISO/IEC 17065": 2}, "ICAO": {"ICAO": 2}, "X509": {"X.509": 4}}, "javacard_version": {}, "javacard_api_const": {}, "javacard_packages": {}, "certification_process": {"ConfidentialDocument": {"being maintained, is not given any longer. In particular, prior to the dissemination of confidential documentation and information related to the TOE or resulting from the evaluation and certification": 1, "09.01.2026, Evaluation Technical Report (ETR) \u2013 Summary, SRC Security Research & Consulting GmbH, (confidential document) 10 specifically \u2022 AIS 32, Version 7, CC-Interpretationen im deutschen Zertifizierungsschema \u2022 AIS": 1, "Konfigurationsliste ALC_CMS.4, cms_secunet+eID+PKI+Suite_V.1.9.4.pdf, secunet Security Networks AG (confidential document) [9] Guidance documentation for the TOE, Version 4.5.1, 11.12.2025, Handbuch (AGD_PRE.1 und AGD_OPE": 1}}}, "st_keywords": {"cc_cert_id": {}, "cc_protection_profile_id": {}, "cc_security_level": {"EAL": {"EAL 4": 3, "EAL4": 1, "EAL 4 augmented": 2, "EAL4 augmented": 1}}, "cc_sar": {"ADV": {"ADV_ARC": 1, "ADV_FSP": 1, "ADV_IMP.1": 1, "ADV_TDS": 1}, "AGD": {"AGD_OPE": 1, "AGD_PRE": 1}, "ALC": {"ALC_FLR.2": 4, "ALC_CMC": 1, "ALC_CMS": 1, "ALC_DEL": 1, "ALC_DVS.1": 1, "ALC_FLR": 1, "ALC_LCD.1": 1, "ALC_TAT.1": 1}, "ATE": {"ATE_COV": 1, "ATE_DPT.1": 1, "ATE_FUN": 1, "ATE_IND": 1}, "AVA": {"AVA_VAN": 1}}, "cc_sfr": {"FAU": {"FAU_STG.1": 10, "FAU_GEN.1": 16, "FAU_GEN.2": 6, "FAU_SEL.1": 8, "FAU_STG.4": 6, "FAU_GEN.1.1": 1, "FAU_GEN.1.2": 1, "FAU_GEN.2.1": 1, "FAU_SEL.1.1": 1, "FAU_STG.1.1": 1, "FAU_STG.1.2": 1, "FAU_STG.4.1": 1}, "FCO": {"FCO_NRO_CIMC.3": 12, "FCO_NRO_CIMC.4": 6, "FCO_NRO_CIMC.3.1": 1, "FCO_NRO_CIMC.3.2": 1, "FCO_NRO_CIMC.3.3": 5, "FCO_NRO_CIMC.4.1": 1, "FCO_NRO_CIMC.4.2": 1}, "FCS": {"FCS_COP.1": 12, "FCS_CKM.1": 14, "FCS_RNG": 2, "FCS_RNG.1": 9, "FCS_RNG.1.1": 2, "FCS_RNG.1.2": 2, "FCS_CKM_CIMC.5": 7, "FCS_CKM.4": 15, "FCS_CKM_CIMC.5.1": 1, "FCS_CKM.1.1": 1, "FCS_CKM.2": 2, "FCS_CKM.4.1": 1, "FCS_COP.1.1": 1}, "FDP": {"FDP_CIMC_CER.1": 7, "FDP_ETC_CIMC.5": 3, "FDP_UCT.1": 2, "FDP_ITT.1": 2, "FDP_ACC.1": 11, "FDP_ACF.1": 12, "FDP_CIMC_CRL.1": 7, "FDP_CIMC_CSE.1": 6, "FDP_SDI_CIMC.3": 5, "FDP_CIMC_OCSP.1": 2, "FDP_ACF_CIMC.2": 1, "FDP_ACF_CIMC.3": 1, "FDP_ACC.1.1": 1, "FDP_ACF.1.1": 5, "FDP_ACF.1.2": 1, "FDP_ACF.1.3": 2, "FDP_ACF.1.4": 2, "FDP_CIMC_CSE.1.1": 1, "FDP_SDI_CIMC.3.1": 2, "FDP_SDI_CIMC.3.2": 2, "FDP_ITC.1": 4, "FDP_ITC.2": 4, "FDP_CIMC_CER.1.1": 2, "FDP_CIMC_CER.1.2": 2, "FDP_CIMC_CER.1.3": 2, "FDP_CIMC_CER.1.4": 1, "FDP_CIMC_CRL.1.1": 1, "FDP_IFC.1": 1}, "FIA": {"FIA_ATD.1": 8, "FIA_SOS.1": 8, "FIA_UAU.1": 9, "FIA_UID.1": 19, "FIA_USB.1": 6, "FIA_ATD.1.1": 1, "FIA_SOS.1.1": 1, "FIA_UAU.1.1": 1, "FIA_UAU.1.2": 1, "FIA_UID.1.1": 1, "FIA_UID.1.2": 1, "FIA_USB.1.1": 1, "FIA_USB.1.2": 1, "FIA_USB.1.3": 1, "FIA_UAU": 1}, "FMT": {"FMT_MTD_CIMC.7": 3, "FMT_MOF.1": 16, "FMT_MOF_CIMC.3": 7, "FMT_MOF_CIMC.5": 8, "FMT_MTD.1": 10, "FMT_MSA.1": 9, "FMT_SMR.1": 18, "FMT_MOF_CIMC.6": 3, "FMT_MTD_CIMC.4": 1, "FMT_MTD_CIMC.5": 1, "FMT_MOF.1.1": 1, "FMT_MTD.1.1": 1, "FMT_SMR.1.1": 1, "FMT_SMR.1.2": 1, "FMT_MOF_CIMC.3.1": 2, "FMT_MOF_CIMC.3.2": 3, "FMT_MOF_CIMC.3.3": 3, "FMT_MOF_CIMC.3.4": 2, "FMT_MOF_CIMC.5.1": 2, "FMT_MOF_CIMC.5.2": 3, "FMT_MOF_CIMC.5.3": 3, "FMT_MSA.3": 2, "FMT_SMF.1": 6}, "FPT": {"FPT_ITC.1": 2, "FPT_ITT.1": 2, "FPT_CIMC_TSP.1": 7, "FPT_STM.1": 3, "FPT_CIMC_TSP.1.1": 1, "FPT_CIMC_TSP.1.2": 1, "FPT_CIMC_TSP.1.3": 1, "FPT_CIMC_TSP.1.4": 1}}, "cc_claims": {"A": {"A.CPS": 3, "A.HSM": 3}, "OE": {"OE.CPS": 5, "OE.HSM": 5}}, "vendor": {"NXP": {"NXP": 1}, "Infineon": {"Infineon": 1}, "GD": {"G+D": 1}}, "eval_facility": {}, "symmetric_crypto": {"AES_competition": {"AES": {"AES": 9}}, "constructions": {"MAC": {"HMAC": 10, "CMAC": 1}}}, "asymmetric_crypto": {"ECC": {"ECDSA": {"ECDSA": 3}}}, "pq_crypto": {"XMSS": {"XMSS": 2}, "LMS": {"LMS": 2}, "PQC": {"PQC": 9}}, "hash_function": {"SHA": {"SHA1": {"SHA-1": 2}, "SHA2": {"SHA-256": 2}}}, "crypto_scheme": {"MAC": {"MAC": 4}}, "crypto_protocol": {"TLS": {"SSL": {"SSL": 2}}}, "randomness": {"RNG": {"RNG": 5}}, "cipher_mode": {"CBC": {"CBC": 1}}, "ecc_curve": {"Brainpool": {"brainpoolP256r1": 1, "brainpoolP256t1": 1, "brainpoolP320t1": 1, "brainpoolP384t1": 1, "brainpoolP512t1": 1}}, "crypto_engine": {}, "tls_cipher_suite": {}, "crypto_library": {}, "vulnerability": {}, "side_channel_analysis": {}, "technical_report_id": {"BSI": {"BSI TR-03110": 7, "BSI TR-03111": 4}}, "device_model": {}, "tee_name": {}, "os_name": {}, "cplc_data": {}, "ic_data_group": {}, "standard_id": {"FIPS": {"FIPS204": 3, "FIPS197": 3, "FIPS 140-2": 2, "FIPS 186-5": 5, "FIPS180-2": 1, "FIPS 186-2": 2, "FIPS140-2": 1, "FIPS PUB 140-2": 1, "FIPS 197": 1, "FIPS180-4": 1, "FIPS 204": 1}, "NIST": {"SP 800-38B": 2, "SP 800-38A": 2, "NIST SP 800-208": 1}, "BSI": {"AIS 31": 1}, "RFC": {"RFC8017": 1, "RFC2104": 6, "RFC5639": 1, "RFC5280": 4, "RFC6960": 3, "RFC 5280": 3, "RFC4210": 1, "RFC4211": 1}, "ISO": {"ISO/IEC 15408": 2, "ISO/IEC 18045": 2}, "ICAO": {"ICAO": 2}, "X509": {"X.509": 30}, "CC": {"CCMB-2017-04-001": 1, "CCMB-2017-04-002": 1, "CCMB-2017-04-003": 1, "CCMB-2017-04-004": 1}}, "javacard_version": {}, "javacard_api_const": {}, "javacard_packages": {}, "certification_process": {}}, "cert_keywords": {"cc_cert_id": {"DE": {"BSI-DSZ-CC-1216-V2-2026": 1}}, "cc_protection_profile_id": {}, "cc_security_level": {"EAL": {"EAL 4": 1, "EAL 2": 1, "EAL 4 augmented": 1}}, "cc_sar": {"ALC": {"ALC_FLR.2": 1, "ALC_FLR": 1}}, "cc_sfr": {}, "cc_claims": {}, "vendor": {}, "eval_facility": {}, "symmetric_crypto": {}, "asymmetric_crypto": {}, "pq_crypto": {}, "hash_function": {}, "crypto_scheme": {}, "crypto_protocol": {}, "randomness": {}, "cipher_mode": {}, "ecc_curve": {}, "crypto_engine": {}, "tls_cipher_suite": {}, "crypto_library": {}, "vulnerability": {}, "side_channel_analysis": {}, "technical_report_id": {}, "device_model": {}, "tee_name": {}, "os_name": {}, "cplc_data": {}, "ic_data_group": {}, "standard_id": {"ISO": {"ISO/IEC 15408": 2, "ISO/IEC 18045": 2}}, "javacard_version": {}, "javacard_api_const": {}, "javacard_packages": {}, "certification_process": {}}, "report_filename": "1216V2a_pdf.pdf", "st_filename": "1216V2b_pdf.pdf", "cert_filename": "1216V2c_pdf.pdf"}, "heuristics": {"_type": "sec_certs.sample.cc_eucc_common.Heuristics", "extracted_versions": {"_type": "Set", "elements": ["4.0.0"]}, "cpe_matches": null, "verified_cpe_matches": null, "related_cves": null, "cert_lab": ["BSI"], "cert_id": "BSI-DSZ-CC-1216-V2-2026", "prev_certificates": null, "next_certificates": null, "st_references": {"_type": "sec_certs.sample.certificate.References", "directly_referenced_by": null, "indirectly_referenced_by": null, "directly_referencing": null, "indirectly_referencing": null}, "report_references": {"_type": "sec_certs.sample.certificate.References", "directly_referenced_by": null, "indirectly_referenced_by": null, "directly_referencing": {"_type": "Set", "elements": ["BSI-DSZ-CC-1216-2024"]}, "indirectly_referencing": {"_type": "Set", "elements": ["BSI-DSZ-CC-1216-2024"]}}, "annotated_references": null, "extracted_sars": {"_type": "Set", "elements": [{"_type": "sec_certs.sample.sar.SAR", "family": "ATE_DPT", "level": 1}, {"_type": "sec_certs.sample.sar.SAR", "family": "ADV_IMP", "level": 1}, {"_type": "sec_certs.sample.sar.SAR", "family": "ALC_DVS", "level": 1}, {"_type": "sec_certs.sample.sar.SAR", "family": "AGD_OPE", "level": 1}, {"_type": "sec_certs.sample.sar.SAR", "family": "AGD_PRE", "level": 1}, {"_type": "sec_certs.sample.sar.SAR", "family": "ALC_TAT", "level": 1}, {"_type": "sec_certs.sample.sar.SAR", "family": "AVA_VAN", "level": 3}, {"_type": "sec_certs.sample.sar.SAR", "family": "ALC_FLR", "level": 2}, {"_type": "sec_certs.sample.sar.SAR", "family": "ALC_CMS", "level": 4}, {"_type": "sec_certs.sample.sar.SAR", "family": "ALC_LCD", "level": 1}]}, "direct_transitive_cves": null, "indirect_transitive_cves": null, "scheme_data": {"cert_id": "BSI-DSZ-CC-1216-V2-2026", "product": "secunet eID PKI Suite Certified CA Kernel SC, Version 4.0.0", "vendor": "Secunet Security Networks AG", "certification_date": "2026-02-11", "category": "Network and Network related Devices and Systems", "url": "https://www.bsi.bund.de/SharedDocs/Zertifikate_CC/CC/Netzwerk_und_Kommunikationsprodukte/1216.html", "enhanced": {"product": "secunet eID PKI Suite Certified CA Kernel SC, Version 4.0.0", "applicant": "Secunet Security Networks AG Kurf\u00fcrstenstra\u00dfe 58 45138 Essen", "evaluation_facility": "SRC Security Research & Consulting GmbH", "assurance_level": "EAL4,ALC_FLR.2", "certification_date": "2026-02-11", "expiration_date": "2031-02-10", "entries": [{"id": "BSI-DSZ-CC-1216-V2-2026-MA-02", "description": "(Certification Authority) Kernel that provides request, issuance, revocation, and overall management of certificates and certificate status information."}, {"id": "BSI-DSZ-CC-1216-V2-2026-MA-01 (Ausstellungsdatum / Certification Date 25.06.2026) Maintenance Report", "description": "(Certification Authority) Kernel that provides request, issuance, revocation, and overall management of certificates and certificate status information."}, {"id": "BSI-DSZ-CC-1216-V2-2026 (Ausstellungsdatum / Certification Date 11.02.2026, g\u00fcltig bis / valid until: 10.02.2031)", "description": "The TOE is a CA (Certification Authority) Kernel that provides request, issuance, revocation, and overall management of certificates and certificate status information."}, {"id": "BSI-DSZ-CC-1216-2024-MA-01 (Ausstellungsdatum / Certification Date 19.08.2024) Maintenance Report", "description": "(Certification Authority) Kernel that provides request, issuance, revocation, and overall management of certificates and certificate status information."}, {"id": "BSI-DSZ-CC-1216-2024", "description": "Certificate"}], "report_link": "https://www.bsi.bund.de/SharedDocs/Downloads/DE/BSI/Zertifizierung/Reporte/Reporte1200/1216V2a_pdf.pdf?__blob=publicationFile&v=2", "target_link": "https://www.bsi.bund.de/SharedDocs/Downloads/DE/BSI/Zertifizierung/Reporte/Reporte1200/1216V2b_pdf.pdf?__blob=publicationFile&v=2", "cert_link": "https://www.bsi.bund.de/SharedDocs/Downloads/DE/BSI/Zertifizierung/Reporte/Reporte1200/1216V2c_pdf.pdf?__blob=publicationFile&v=2", "description": "The TOE is a CA (Certification Authority) Kernel that provides request, issuance, revocation, and overall management of certificates and certificate status information."}}, "protection_profiles": null, "eal": "EAL4"}}