{
"_type": "sec_certs.sample.cc.CCCertificate",
"category": "Operating Systems",
"cert_link": "https://www.commoncriteriaportal.org/nfs/ccpfiles/files/epfiles/1087c_pdf.pdf",
"dgst": "155c8c55882ad972",
"heuristics": {
"_type": "sec_certs.sample.cc_eucc_common.Heuristics",
"annotated_references": null,
"cert_id": "BSI-DSZ-CC-1087-2026",
"cert_lab": [
"BSI"
],
"cpe_matches": null,
"direct_transitive_cves": null,
"eal": "EAL4+",
"extracted_sars": {
"_type": "Set",
"elements": [
{
"_type": "sec_certs.sample.sar.SAR",
"family": "ALC_CMC",
"level": 4
},
{
"_type": "sec_certs.sample.sar.SAR",
"family": "ATE_COV",
"level": 2
},
{
"_type": "sec_certs.sample.sar.SAR",
"family": "ASE_OBJ",
"level": 2
},
{
"_type": "sec_certs.sample.sar.SAR",
"family": "ASE_REQ",
"level": 2
},
{
"_type": "sec_certs.sample.sar.SAR",
"family": "ADV_FSP",
"level": 4
},
{
"_type": "sec_certs.sample.sar.SAR",
"family": "ALC_CMS",
"level": 4
},
{
"_type": "sec_certs.sample.sar.SAR",
"family": "AGD_OPE",
"level": 1
},
{
"_type": "sec_certs.sample.sar.SAR",
"family": "ASE_TSS",
"level": 1
},
{
"_type": "sec_certs.sample.sar.SAR",
"family": "ALC_DVS",
"level": 1
},
{
"_type": "sec_certs.sample.sar.SAR",
"family": "ASE_SPD",
"level": 1
},
{
"_type": "sec_certs.sample.sar.SAR",
"family": "ADV_ARC",
"level": 1
},
{
"_type": "sec_certs.sample.sar.SAR",
"family": "ALC_TAT",
"level": 1
},
{
"_type": "sec_certs.sample.sar.SAR",
"family": "ASE_CCL",
"level": 1
},
{
"_type": "sec_certs.sample.sar.SAR",
"family": "ALC_DEL",
"level": 1
},
{
"_type": "sec_certs.sample.sar.SAR",
"family": "ATE_DPT",
"level": 1
},
{
"_type": "sec_certs.sample.sar.SAR",
"family": "ASE_INT",
"level": 1
},
{
"_type": "sec_certs.sample.sar.SAR",
"family": "ATE_FUN",
"level": 1
},
{
"_type": "sec_certs.sample.sar.SAR",
"family": "ALC_FLR",
"level": 2
},
{
"_type": "sec_certs.sample.sar.SAR",
"family": "ADV_IMP",
"level": 1
},
{
"_type": "sec_certs.sample.sar.SAR",
"family": "ASE_ECD",
"level": 1
},
{
"_type": "sec_certs.sample.sar.SAR",
"family": "ATE_IND",
"level": 2
},
{
"_type": "sec_certs.sample.sar.SAR",
"family": "ALC_LCD",
"level": 1
},
{
"_type": "sec_certs.sample.sar.SAR",
"family": "ADV_TDS",
"level": 3
}
]
},
"extracted_versions": {
"_type": "Set",
"elements": [
"8.0"
]
},
"indirect_transitive_cves": null,
"next_certificates": null,
"prev_certificates": null,
"protection_profiles": null,
"related_cves": null,
"report_references": {
"_type": "sec_certs.sample.certificate.References",
"directly_referenced_by": null,
"directly_referencing": null,
"indirectly_referenced_by": null,
"indirectly_referencing": null
},
"scheme_data": {
"category": "Server applications",
"cert_id": "BSI-DSZ-CC-1087-2026",
"certification_date": "2026-02-25",
"enhanced": {
"applicant": "Broadcom, Inc. 3421 Hillview Ave California 94304 Palo Alto USA",
"assurance_level": "EAL4,ALC_FLR.2",
"cert_link": "https://www.bsi.bund.de/SharedDocs/Downloads/DE/BSI/Zertifizierung/Reporte/Reporte1000/1087c_pdf.pdf?__blob=publicationFile\u0026v=2",
"certification_date": "2026-02-25",
"description": "The Target of Evaluation (TOE) is VMware ESXi 8.0g, a VMware software product implementing a hypervisor. The TOE is designed as a virtualization platform, providing the ability to implement and virtualize different workloads across multiple virtual machines (VMs) while providing isolation and efficient use of compute, storage and network resources. This allows for implementation of cloud environments in support of wide array of various data center workloads or on-demand infrastructure.",
"evaluation_facility": "T\u00dcV Informationstechnik GmbH",
"expiration_date": "2031-02-24",
"product": "VMware ESXi, Version 8.0g",
"report_link": "https://www.bsi.bund.de/SharedDocs/Downloads/DE/BSI/Zertifizierung/Reporte/Reporte1000/1087a_pdf.pdf?__blob=publicationFile\u0026v=2",
"target_link": "https://www.bsi.bund.de/SharedDocs/Downloads/DE/BSI/Zertifizierung/Reporte/Reporte1000/1087b_pdf.pdf?__blob=publicationFile\u0026v=2"
},
"product": "VMware ESXi, Version 8.0g",
"subcategory": "Virtualisation",
"url": "https://www.bsi.bund.de/SharedDocs/Zertifikate_CC/CC/Serveranwendungen_Virtualisierung/1087.html",
"vendor": "Broadcom, Inc."
},
"st_references": {
"_type": "sec_certs.sample.certificate.References",
"directly_referenced_by": null,
"directly_referencing": null,
"indirectly_referenced_by": null,
"indirectly_referencing": null
},
"verified_cpe_matches": null
},
"maintenance_updates": {
"_type": "Set",
"elements": []
},
"manufacturer": "Broadcom",
"manufacturer_web": "https://www.vmware.com/",
"name": "VMware ESXi, Version 8.0g",
"not_valid_after": "2031-07-25",
"not_valid_before": "2026-02-25",
"pdf_data": {
"_type": "sec_certs.sample.cc_eucc_common.PdfData",
"cert_filename": "1087c_pdf.pdf",
"cert_frontpage": null,
"cert_keywords": {
"asymmetric_crypto": {},
"cc_cert_id": {
"DE": {
"BSI-DSZ-CC-1087-2026": 1
}
},
"cc_claims": {},
"cc_protection_profile_id": {},
"cc_sar": {
"ALC": {
"ALC_FLR": 1,
"ALC_FLR.2": 1
}
},
"cc_security_level": {
"EAL": {
"EAL 2": 1,
"EAL 4": 1,
"EAL 4 augmented": 1
}
},
"cc_sfr": {},
"certification_process": {},
"cipher_mode": {},
"cplc_data": {},
"crypto_engine": {},
"crypto_library": {},
"crypto_protocol": {},
"crypto_scheme": {},
"device_model": {},
"ecc_curve": {},
"eval_facility": {},
"hash_function": {},
"ic_data_group": {},
"javacard_api_const": {},
"javacard_packages": {},
"javacard_version": {},
"os_name": {},
"pq_crypto": {},
"randomness": {},
"side_channel_analysis": {},
"standard_id": {
"ISO": {
"ISO/IEC 15408": 2,
"ISO/IEC 18045": 2
}
},
"symmetric_crypto": {},
"technical_report_id": {},
"tee_name": {},
"tls_cipher_suite": {},
"vendor": {
"Broadcom": {
"Broadcom": 1
}
},
"vulnerability": {}
},
"cert_metadata": {
"/Author": "Federal Office for Information Security",
"/Keywords": "\"Common Criteria, Certification, Zertifizierung, Virtualisierung, Virtualization, Betriebssystem, Operating System, BSI-DSZ-CC-1087-2026\"",
"/Subject": "Common Criteria, Certification, Zertifizierung, Virtualisierung, Virtualization, Betriebssystem, Operating System, BSI-DSZ-CC-1087-2026",
"/Title": "Certificate BSI-DSZ-CC-1087-2026",
"pdf_file_size_bytes": 235573,
"pdf_hyperlinks": {
"_type": "Set",
"elements": []
},
"pdf_is_encrypted": false,
"pdf_number_of_pages": 1
},
"report_filename": "1087a_pdf.pdf",
"report_frontpage": {
"DE": {
"cc_security_level": "Common Criteria Part 3 conformant EAL 4 augmented by ALC_FLR.2 valid until: 24 February 2031",
"cc_version": "Product specific Security Target Common Criteria Part 2 extended",
"cert_id": "BSI-DSZ-CC-1087-2026",
"cert_item": "VMware ESXi, Version 8.0g",
"cert_lab": "BSI",
"developer": "Broadcom, Inc",
"match_rules": [
"(BSI-DSZ-CC-.+?) (?:for|For) (.+?) from (.*)"
],
"ref_protection_profiles": "none"
}
},
"report_keywords": {
"asymmetric_crypto": {
"ECC": {
"ECC": {
"ECC": 1
},
"ECDH": {
"ECDHE": 1
}
},
"FF": {
"DH": {
"DHE": 1
}
}
},
"cc_cert_id": {
"DE": {
"BSI-DSZ-CC-1087-2026": 13
}
},
"cc_claims": {
"T": {
"T.UNAUTHORIZED_MODIFICATION": 1
}
},
"cc_protection_profile_id": {},
"cc_sar": {
"ALC": {
"ALC_FLR": 3,
"ALC_FLR.2": 4
}
},
"cc_security_level": {
"EAL": {
"EAL 1": 1,
"EAL 2": 3,
"EAL 4": 5,
"EAL 4 augmented": 3,
"EAL4+": 1
}
},
"cc_sfr": {
"FCS": {
"FCS_CKM": 3,
"FCS_COP": 5
},
"FDP": {
"FDP_IFF.1": 1
}
},
"certification_process": {
"ConfidentialDocument": {
"ESXi 8.0g (confidential document) [8] Guidance documentation for the TOE, Version 1.0, 13 February 2026, Installation and": 1,
"Inc. [6] Evaluation Technical Report, Version 3, 24 February 2026, T\u00dcV Informationstechnik GmbH (confidential document) [7] Configuration list for the TOE, Version 0.08, 19 February 2026, EAL 4: Configuration List": 1,
"being maintained, is not given any longer. In particular, prior to the dissemination of confidential documentation and information related to the TOE or resulting from the evaluation and certification": 1
}
},
"cipher_mode": {
"GCM": {
"GCM": 2
}
},
"cplc_data": {},
"crypto_engine": {},
"crypto_library": {
"OpenSSL": {
"OpenSSL": 2
}
},
"crypto_protocol": {
"TLS": {
"TLS": {
"TLS": 10
}
}
},
"crypto_scheme": {
"KA": {
"Key Agreement": 1
}
},
"device_model": {},
"ecc_curve": {
"NIST": {
"P-256": 2,
"P-384": 2,
"P-521": 2
}
},
"eval_facility": {
"TUV": {
"T\u00dcV Informationstechnik": 3
}
},
"hash_function": {
"SHA": {
"SHA2": {
"SHA-256": 2
}
}
},
"ic_data_group": {},
"javacard_api_const": {},
"javacard_packages": {},
"javacard_version": {},
"os_name": {},
"pq_crypto": {},
"randomness": {
"RNG": {
"RNG": 1
}
},
"side_channel_analysis": {},
"standard_id": {
"BSI": {
"AIS 20": 2,
"AIS 32": 1
},
"FIPS": {
"FIPS180-4": 2,
"FIPS186-4": 2,
"FIPS186-5": 2,
"FIPS197": 2,
"FIPS198-1": 2
},
"ISO": {
"ISO/IEC 15408": 4,
"ISO/IEC 17065": 2,
"ISO/IEC 18045": 4
},
"RFC": {
"RFC2104": 2,
"RFC5116": 2,
"RFC5246": 3,
"RFC5288": 2,
"RFC8422": 2
}
},
"symmetric_crypto": {
"AES_competition": {
"AES": {
"AES": 2
}
},
"constructions": {
"MAC": {
"HMAC": 1
}
}
},
"technical_report_id": {
"BSI": {
"BSI TR-02102": 1
}
},
"tee_name": {},
"tls_cipher_suite": {},
"vendor": {
"Broadcom": {
"Broadcom": 10
}
},
"vulnerability": {}
},
"report_metadata": {
"/Author": "Federal Office for Information Security",
"/Keywords": "\"Common Criteria, Certification, Zertifizierung, Virtualisierung, Virtualization, Betriebssystem, Operating System, BSI-DSZ-CC-1087-2026\"",
"/Subject": "Common Criteria, Certification, Zertifizierung, Virtualisierung, Virtualization, Betriebssystem, Operating System, BSI-DSZ-CC-1087-2026",
"/Title": "Certification Report BSI-DSZ-CC-1087-2026",
"pdf_file_size_bytes": 340709,
"pdf_hyperlinks": {
"_type": "Set",
"elements": []
},
"pdf_is_encrypted": false,
"pdf_number_of_pages": 22
},
"st_filename": "1087b_pdf.pdf",
"st_frontpage": null,
"st_keywords": {
"asymmetric_crypto": {
"ECC": {
"ECC": {
"ECC": 4
},
"ECDH": {
"ECDH": 1,
"ECDHE": 5
}
},
"FF": {
"DH": {
"DH": 2,
"Diffie-Hellman": 4
}
}
},
"cc_cert_id": {
"DE": {
"BSI-DSZ-CC-1087": 64
}
},
"cc_claims": {
"A": {
"A.ENTROPY": 2,
"A.NETWORK": 2,
"A.PHYSICAL": 2,
"A.PLATFORM_INTEGRITY": 2,
"A.TIME": 3,
"A.TRUSTED_ADMIN": 2
},
"O": {
"O.AUDIT": 2,
"O.DOMAIN_INTEGRITY": 2,
"O.MANAGEMENT_ACCESS": 3,
"O.PLATFORM_INTEGRITY": 3,
"O.VMM_INTEGRITY": 4,
"O.VM_ISOLATION": 3
},
"OE": {
"OE.ENTROPY": 2,
"OE.NETWORK": 2,
"OE.PHYSICAL": 6,
"OE.TIME": 2,
"OE.TRUSTED_ADMIN": 2
},
"T": {
"T.DATA_LEAKAGE": 2,
"T.PLATFORM_COMPROMISE": 2,
"T.UNAUTHORIZED_ACCESS": 2,
"T.UNAUTHORIZED_MODIFICA": 1,
"T.UNAUTHORIZED_MODIFICATION": 2,
"T.VMM_COMPROMISE": 2
}
},
"cc_protection_profile_id": {},
"cc_sar": {
"ADV": {
"ADV_ARC.1": 1,
"ADV_FSP.4": 1,
"ADV_IMP.1": 1,
"ADV_TDS.3": 1
},
"AGD": {
"AGD_OPE.1": 1
},
"ALC": {
"ALC_CMC.4": 1,
"ALC_CMS.4": 1,
"ALC_DEL.1": 1,
"ALC_DVS.1": 1,
"ALC_FLR": 1,
"ALC_FLR.2": 7,
"ALC_LCD.1": 1,
"ALC_TAT.1": 1
},
"ASE": {
"ASE_CCL.1": 1,
"ASE_ECD.1": 1,
"ASE_INT.1": 1,
"ASE_OBJ.2": 1,
"ASE_REQ.2": 1,
"ASE_SPD.1": 1,
"ASE_TSS.1": 1
},
"ATE": {
"ATE_COV.2": 1,
"ATE_DPT.1": 1,
"ATE_FUN.1": 1,
"ATE_IND.2": 1
},
"AVA": {
"AVA_VAN": 1
}
},
"cc_security_level": {
"EAL": {
"EAL4": 10,
"EAL4 augmented": 7,
"EAL4+": 3
}
},
"cc_sfr": {
"FAU": {
"FAU_GEN.1": 11,
"FAU_GEN.1.1": 1,
"FAU_GEN.1.2": 1,
"FAU_SAR.1": 7,
"FAU_SAR.1.1": 1,
"FAU_SAR.1.2": 1,
"FAU_STG.1": 7,
"FAU_STG.1.1": 1,
"FAU_STG.1.2": 1
},
"FCS": {
"FCS_CKM": 26,
"FCS_CKM.1": 9,
"FCS_CKM.2": 4,
"FCS_CKM.4": 18,
"FCS_CKM.4.1": 1,
"FCS_COP": 43,
"FCS_COP.1": 8,
"FCS_RNG.1": 13,
"FCS_RNG.1.1": 2,
"FCS_RNG.1.2": 2
},
"FDP": {
"FDP_ACC.1": 17,
"FDP_ACC.1.1": 1,
"FDP_ACF.1": 7,
"FDP_ACF.1.1": 1,
"FDP_ACF.1.2": 1,
"FDP_ACF.1.3": 1,
"FDP_ACF.1.4": 1,
"FDP_IFC.1": 14,
"FDP_IFC.1.1": 1,
"FDP_IFF.1": 11,
"FDP_IFF.1.1": 1,
"FDP_IFF.1.2": 1,
"FDP_IFF.1.3": 1,
"FDP_IFF.1.4": 1,
"FDP_IFF.1.5": 1,
"FDP_ITC.1": 13,
"FDP_ITC.1.1": 1,
"FDP_ITC.1.2": 1,
"FDP_ITC.1.3": 1,
"FDP_ITC.2": 6,
"FDP_RIP.1": 8,
"FDP_RIP.1.1": 1
},
"FIA": {
"FIA_AFL.1": 7,
"FIA_AFL.1.1": 1,
"FIA_AFL.1.2": 1,
"FIA_SOS.1": 7,
"FIA_SOS.1.1": 1,
"FIA_SOS.2": 8,
"FIA_SOS.2.1": 1,
"FIA_SOS.2.2": 1,
"FIA_UAU.2": 7,
"FIA_UAU.2.1": 1,
"FIA_UID.1": 8,
"FIA_UID.1.1": 1,
"FIA_UID.1.2": 1
},
"FMT": {
"FMT_MOF.1": 7,
"FMT_MOF.1.1": 1,
"FMT_MSA.1": 7,
"FMT_MSA.1.1": 1,
"FMT_MSA.3": 12,
"FMT_MSA.3.1": 1,
"FMT_MSA.3.2": 1,
"FMT_SMF.1": 13,
"FMT_SMF.1.1": 1,
"FMT_SMR.1": 13,
"FMT_SMR.1.1": 1,
"FMT_SMR.1.2": 1
},
"FPT": {
"FPT_HCL_EXT": 2,
"FPT_HCL_EXT.1": 11,
"FPT_HCL_EXT.1.1": 2,
"FPT_HCL_EXT.1.2": 2,
"FPT_RDM_EXT": 2,
"FPT_RDM_EXT.1": 10,
"FPT_RDM_EXT.1.1": 2,
"FPT_RDM_EXT.1.2": 2,
"FPT_STM.1": 1,
"FPT_VIV_EXT": 2,
"FPT_VIV_EXT.1": 12,
"FPT_VIV_EXT.1.1": 2,
"FPT_VIV_EXT.1.2": 2
},
"FTP": {
"FTP_ITC": 2,
"FTP_ITC.1": 8,
"FTP_ITC.1.1": 1,
"FTP_ITC.1.2": 1,
"FTP_ITC.1.3": 1
}
},
"certification_process": {},
"cipher_mode": {
"CBC": {
"CBC": 1
},
"GCM": {
"GCM": 1
}
},
"cplc_data": {},
"crypto_engine": {},
"crypto_library": {
"OpenSSL": {
"OpenSSL": 22
}
},
"crypto_protocol": {
"IPsec": {
"IPsec": 1
},
"SSH": {
"SSH": 1
},
"TLS": {
"SSL": {
"SSL": 1
},
"TLS": {
"TLS": 50,
"TLS 1.2": 2,
"TLS v1.2": 2,
"TLS1.2": 1,
"TLSv1.2": 10
}
}
},
"crypto_scheme": {
"KA": {
"Key Agreement": 2
},
"KEX": {
"Key Exchange": 3
},
"MAC": {
"MAC": 2
}
},
"device_model": {},
"ecc_curve": {
"NIST": {
"P-256": 14,
"P-384": 14,
"P-521": 12
}
},
"eval_facility": {},
"hash_function": {
"SHA": {
"SHA2": {
"SHA-256": 3,
"SHA-384": 5,
"SHA-512": 2,
"SHA384": 2
}
}
},
"ic_data_group": {},
"javacard_api_const": {},
"javacard_packages": {},
"javacard_version": {},
"os_name": {},
"pq_crypto": {},
"randomness": {
"PRNG": {
"DRBG": 6
},
"RNG": {
"RBG": 1,
"RNG": 11
}
},
"side_channel_analysis": {
"FI": {
"physical tampering": 1
},
"SCA": {
"side-channels": 2
}
},
"standard_id": {
"CC": {
"CCMB-2017-04-001": 1,
"CCMB-2017-04-002": 1,
"CCMB-2017-04-003": 1
},
"FIPS": {
"FIPS 198": 1,
"FIPS PUB 186-4": 3,
"FIPS PUB 186-5": 1,
"FIPS PUB 198-1": 1,
"FIPS180-4": 1
},
"NIST": {
"SP 800-38D": 1,
"SP 800-90A": 1
},
"RFC": {
"RFC 2818": 1,
"RFC2104": 2,
"RFC5116": 1,
"RFC5246": 9,
"RFC5288": 3,
"RFC5289": 1,
"RFC8422": 2
}
},
"symmetric_crypto": {
"AES_competition": {
"AES": {
"AES": 6
}
},
"constructions": {
"MAC": {
"HMAC": 5,
"HMAC-SHA-256": 1
}
}
},
"technical_report_id": {},
"tee_name": {},
"tls_cipher_suite": {
"TLS": {
"TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384": 2
}
},
"vendor": {
"Broadcom": {
"Broadcom": 12,
"Broadcom Inc": 1
}
},
"vulnerability": {}
},
"st_metadata": {
"/Author": "Broadcom",
"/Keywords": "",
"/Subject": "",
"/Title": "",
"pdf_file_size_bytes": 1410436,
"pdf_hyperlinks": {
"_type": "Set",
"elements": [
"https://www.vmware.com/",
"http://www.broadcom.com/"
]
},
"pdf_is_encrypted": false,
"pdf_number_of_pages": 64
}
},
"protection_profile_links": {
"_type": "Set",
"elements": []
},
"report_link": "https://www.commoncriteriaportal.org/nfs/ccpfiles/files/epfiles/1087a_pdf.pdf",
"scheme": "DE",
"security_level": {
"_type": "Set",
"elements": [
"ALC_FLR.2",
"EAL4+"
]
},
"st_link": "https://www.commoncriteriaportal.org/nfs/ccpfiles/files/epfiles/1087b_pdf.pdf",
"state": {
"_type": "sec_certs.sample.cc_eucc_common.InternalState",
"cert": {
"_type": "sec_certs.sample.document_state.DocumentState",
"convert_ok": true,
"download_ok": true,
"extract_ok": true,
"json_hash": null,
"source_hash": "797202127e0ac9a43fd0bcc12caeeb52210d3311d1b4e4a966cd9c6c6adf9a00",
"txt_hash": "06a66b5a05d957510604ed1e0b4aa97ea7a38b38e5b733dc9ed3c3ccd5333e2b"
},
"report": {
"_type": "sec_certs.sample.document_state.DocumentState",
"convert_ok": true,
"download_ok": true,
"extract_ok": true,
"json_hash": null,
"source_hash": "e42b0718f425e6355ba9cd2c536d6313d7a3ad45880817bfbff9f7f91d05bb59",
"txt_hash": "c6564d938d331c39a1315384b8a821a0c3def6549daa4efe4a986ba589cfc09f"
},
"st": {
"_type": "sec_certs.sample.document_state.DocumentState",
"convert_ok": true,
"download_ok": true,
"extract_ok": true,
"json_hash": null,
"source_hash": "3ee372193c0bf29925d3ba04cbd6ceef0d0c60197fef46c53182853a22df427a",
"txt_hash": "ac32cd99c9e7b7094e34a56d3bac923040940c3fdd0d284e3f61966cf9aaa009"
}
},
"status": "active"
}