Hewlett Packard Enterprise’s CX-5420, CX-6200M, CX-6300, CX-6400, CX-8360, and CX-9300s Switch Series MACsec running AOS-CX version 10.16Security Target Version 0.4 08/17/2026 Prepared for: Hewlett Packard Enterprise 6280 America Center Dr San Jose, CA 95002 Prepared By: www.gossamersec.com Hewlett Packard Enterprise’s CX-5420, CX-6200M, CX-6300, CX-6400, CX-8360, and CX-9300s Switch Series MACsec running AOS-CX version 10.16 Security Target Version 0.4, 08/17/2026 Page 2 of 44 1. SECURITY TARGET INTRODUCTION........................................................................................................3 1.1 SECURITY TARGET REFERENCE......................................................................................................................3 1.2 TOE REFERENCE............................................................................................................................................4 1.3 TOE OVERVIEW .............................................................................................................................................4 1.4 TOE DESCRIPTION .........................................................................................................................................4 1.4.1 TOE Architecture...................................................................................................................................4 1.4.2 TOE Documentation ..............................................................................................................................6 2. CONFORMANCE CLAIMS..............................................................................................................................7 2.1 CONFORMANCE RATIONALE...........................................................................................................................8 3. SECURITY OBJECTIVES ................................................................................................................................9 3.1 SECURITY OBJECTIVES FOR THE OPERATIONAL ENVIRONMENT.....................................................................9 4. EXTENDED COMPONENTS DEFINITION ................................................................................................11 5. SECURITY REQUIREMENTS.......................................................................................................................12 5.1 TOE SECURITY FUNCTIONAL REQUIREMENTS .............................................................................................12 5.1.1 Security audit (FAU)............................................................................................................................13 5.1.2 Cryptographic support (FCS)..............................................................................................................16 5.1.3 Identification and authentication (FIA)...............................................................................................23 5.1.4 Security management (FMT) ...............................................................................................................24 5.1.5 Protection of the TSF (FPT) ................................................................................................................26 5.1.6 TOE access (FTA)................................................................................................................................27 5.1.7 Trusted path/channels (FTP)...............................................................................................................28 5.2 TOE SECURITY ASSURANCE REQUIREMENTS...............................................................................................28 5.2.1 Development (ADV).............................................................................................................................29 5.2.2 Guidance documents (AGD)................................................................................................................29 5.2.3 Life-cycle support (ALC) .....................................................................................................................30 5.2.4 Tests (ATE) ..........................................................................................................................................31 5.2.5 Vulnerability assessment (AVA)...........................................................................................................31 6. TOE SUMMARY SPECIFICATION..............................................................................................................32 6.1 SECURITY AUDIT ..........................................................................................................................................32 6.2 CRYPTOGRAPHIC SUPPORT ...........................................................................................................................33 6.3 IDENTIFICATION AND AUTHENTICATION.......................................................................................................37 6.4 SECURITY MANAGEMENT .............................................................................................................................38 6.5 PROTECTION OF THE TSF .............................................................................................................................39 6.6 TOE ACCESS.................................................................................................................................................41 6.7 TRUSTED PATH/CHANNELS ...........................................................................................................................41 LIST OF TABLES Table 1 TOE Models and Processors.........................................................................................................................4 Table 2 Technical Decisions........................................................................................................................................8 Table 3 TOE Security Functional Components......................................................................................................13 Table 4 Auditable Events..........................................................................................................................................14 Table 5 MACsec Auditable Events...........................................................................................................................16 Table 6 Assurance Components ...............................................................................................................................29 Table 7 TOE Cryptographic Algorithms.................................................................................................................33 Table 8 Key Establishment Methods .......................................................................................................................34 Table 9 Key Zeroziation............................................................................................................................................34 Table 10 HMAC Details...........................................................................................................................................35 Hewlett Packard Enterprise’s CX-5420, CX-6200M, CX-6300, CX-6400, CX-8360, and CX-9300s Switch Series MACsec running AOS-CX version 10.16 Security Target Version 0.4, 08/17/2026 Page 3 of 44 1. Security Target Introduction This section identifies the Security Target (ST) and Target of Evaluation (TOE) identification, ST conventions, ST conformance claims, and the ST organization. The TOE is Hewlett Packard Enterprise’s CX-5420, CX-6200M, CX- 6300, CX-6400, CX-8360, and CX-9300s Switch Series MACsec running AOS-CX version 10.16 provided by Hewlett Packard Enterprise. The TOE is being evaluated as a MACsec network device. The Security Target contains the following additional sections: • Conformance Claims (Section 2) • Security Objectives (Section 3) • Extended Components Definition (Section 4) • Security Requirements (Section 5) • TOE Summary Specification (Section 6) Conventions The following conventions have been applied in this document: • Security Functional Requirements – Part 2 of the CC defines the approved set of operations that may be applied to functional requirements: iteration, assignment, selection, and refinement. o Iteration: allows a component to be used more than once with varying operations. In this ST, iteration may be indicated by a parenthetical number placed at the end of the component. For example FDP_ACC.1(1) and FDP_ACC.1(2) indicate that the ST includes two iterations of the FDP_ACC.1 requirement. Alternately, a usually descriptive textual extension may be added after a slash (/) character to identify a specific iteration. For example, iterations of a requirement such as FCS_COP.1 might be identified as FCS_COP.1/HASH and FCS_COP.1/CRYPT. o Assignment: allows the specification of an identified parameter. Assignments are indicated using bold and are surrounded by brackets (e.g., [assignment]). Note that an assignment within a selection would be identified in italics and with embedded bold brackets (e.g., [[selected-assignment]]). o Selection: allows the specification of one or more elements from a list. Selections are indicated using bold italics and are surrounded by brackets (e.g., [selection]). o Refinement: allows the addition of details. Refinements are indicated using bold, for additions, and strike-through, for deletions (e.g., “… all objects …” or “… some big things …”). An exception to this marking convention is the case of tables that have cells that content equivalent to nothing (e.g., "None", "No events specified", "NA", "No additional information") where the cell is simply left blank since that represents no meaningful change but is effectively a refinement. Another exception to this marking convention is where extranious punctuation (e.g., extra brackets) may be omitted or incorrect punctuation (e.g., extra or missing periods) may be corrected, so long as the meaning is not changed. • Other sections of the ST – Other sections of the ST use bolding to highlight text of special interest, such as captions. 1.1 Security Target Reference ST Title – Hewlett Packard Enterprise’s CX-5420, CX-6200M, CX-6300, CX-6400, CX-8360, and CX-9300s Switch Series MACsec running AOS-CX version 10.16 Security Target ST Version – Version 0.4 ST Date – 08/17/2026 Hewlett Packard Enterprise’s CX-5420, CX-6200M, CX-6300, CX-6400, CX-8360, and CX-9300s Switch Series MACsec running AOS-CX version 10.16 Security Target Version 0.4, 08/17/2026 Page 4 of 44 1.2 TOE Reference TOE Identification – Hewlett Packard Enterprise’s CX-5420, CX-6200M, CX-6300, CX-6400, CX-8360, and CX- 9300s Switch Series MACsec running AOS-CX version 10.16 TOE Developer – Hewlett Packard Enterprise Evaluation Sponsor – Hewlett Packard Enterprise 1.3 TOE Overview The Target of Evaluation (TOE) is Hewlett Packard Enterprise’s CX-5420, CX-6200M, CX-6300, CX-6400, CX- 8360, and CX-9300s Switch Series MACsec running AOS-CX version 10.16. The TOE offers comprehensive Layer 2 and Layer 3 features. The Hewlett Packard Enterprise’s CX-5420, CX- 6200M, CX-6300, CX-6400, CX-8360, and CX-9300s Switch Series MACsec running AOS-CX version 10.16 provides security and scalability, for enterprise edge deployments. 1.4 TOE Description The TOE is a family of switches designed to support scalability, security and high performance for campus networks. For the purpose of evaluation, the TOE will be treated as a network device offering CAVP tested cryptographic functions, security auditing, secure administration, trusted updates, self-tests, and secure connections to other servers (e.g., to transmit audit records). The scope of the evaluation is limited to the NDcPP30e, SSH10 and MACSEC10 requirements. Functions outside the scope of the NDcPP30e, SSH10 and MACSEC10 were not evaluated. 1.4.1 TOE Architecture Table 1 TOE Models and Processors identifies the models included in the evaluation. The underlying architecture of each TOE appliance consists of hardware that supports physical network connections, memory, processor and software that implements switching functions, configuration information and drivers. While hardware varies between different appliance models, the software code is shared across all platforms. It is in the software code that all the security functions claimed this security target are enforced. Table 1 TOE Models and Processors identifies the processor associated with each series. Series Identifier Processor Embedded MACsec Hardware CX-5420 Ryzen V1500B BCM 82756 BCM 82399 CX-6200M NXP 1046A – ARM Cortex A72 BCM 54192 BCM 54998SM BCM 82759 CX-6300M CX-6300F NXP 1046A – ARM Cortex A72 BCM 84898M BCM 82399 BCM 54998SM BCM 82756 BCM 82759 BCM 81343 CX-6400 NXP 1046A – ARM Cortex A72 BCM 81343 CX-8360 NXP 1046A – ARM Cortex A72 BCM 82399 BCM 82398 CX-9300s Ryzen V3C48 BCM 81343 Table 1 TOE Models and Processors Hewlett Packard Enterprise’s CX-5420, CX-6200M, CX-6300, CX-6400, CX-8360, and CX-9300s Switch Series MACsec running AOS-CX version 10.16 Security Target Version 0.4, 08/17/2026 Page 5 of 44 1.4.1.1 Physical Boundaries Each TOE appliance runs the 10.16 version of the AOS-CX software and has physical network connections to its environment to facilitate the switching of network traffic. The TOE appliance can also be the destination of network traffic, where it provides interfaces for its own management. The TOE may be accessed and managed through a PC or terminal in the environment which can be remote from or directly connected to the TOE. The TOE can be configured to forward its audit records to an external SYSLOG server in the network environment. Figure 1 shows the TOE depicted in its intended environment. Figure 1: TOE Environment 1.4.1.2 Logical Boundaries This section summarizes the security functions provided by Hewlett Packard Enterprise’s CX-5420, CX-6200M, CX- 6300, CX-6400, CX-8360, and CX-9300s Switch Series MACsec running AOS-CX version 10.16: - Security audit - Cryptographic support - Identification and authentication - Security management - Protection of the TSF - TOE access - Trusted path/channels 1.4.1.2.1 Security audit The TOE is able to generate logs for a wide range of security relevant events. The TOE can be configured to store the logs locally so they can be accessed by an administrator and also to send the logs to a designated log server using TLS to protect the logs while in transit on the network. 1.4.1.2.2 Cryptographic support The TOE provides CAVP certified cryptography in support of its SSHv2, TLS v1.2 & v1.3, and MACsec protocol implementations. Cryptographic services include key management, random bit generation, encryption/decryption, digital signature and secure hashing. Hewlett Packard Enterprise’s CX-5420, CX-6200M, CX-6300, CX-6400, CX-8360, and CX-9300s Switch Series MACsec running AOS-CX version 10.16 Security Target Version 0.4, 08/17/2026 Page 6 of 44 1.4.1.2.3 Identification and authentication The TOE requires users to be identified and authenticated before they can use functions mediated by the TOE, with the exception of reading the login banner. It provides the ability to both assign attributes (user names, passwords and roles) and to authenticate users against these attributes. 1.4.1.2.4 Security management The TOE provides Command Line Interface (CLI) commands at the console and over SSH, as well as an HTTP over TLS (HTTPS/TLS) Graphical User Interface (GUI) to access the wide range of security management functions to manage its security policies. The TOE also offers HTTPS/TLS protection for REST API interfaces that can be used for administration. All administrative activity and functions including security management commands are limited to authorized users (i.e., administrators) only after they have provided acceptable user identification and authentication data to the TOE. The security management functions are controlled through the use of roles that can be assigned to TOE users. The TOE supports the following roles: Administrators, Operators. The Administrator role can make changes to the TOE configuration while the Operator role is a read-only role. 1.4.1.2.5 Protection of the TSF The TOE implements a number of measures to protect the integrity of its security features. The TOE protects stored passwords and cryptographic keys so they are not directly accessible in plaintext. The TOE also ensures that reliable time information is available for both log accountability and synchronization with the operating environment by providing a hardware clock and the ability to synchronize with the network time server. The TOE employs both dedicated communication channels as well as cryptographic means to protect communication between itself and other components in the operating environment. The TOE performs self-tests to detect failure and protect itself from malicious updates. 1.4.1.2.6 TOE access The TOE can be configured to display a logon banner before and after (a post-login banner) a user session is established. The TOE also enforces inactivity timeouts for local and remote sessions. 1.4.1.2.7 Trusted path/channels The TOE protects communication channels between itself and remote administrators using HTTPS/TLS and SSH. The SSH protocol is used to protect administrative connections utilizing the TOE’s command line interface (CLI). Additionally, web-based GUI and REST API interfaces are available for remote administration which are protected using HTTPS/TLS. The TOE protects communication with network peers, such as a log server, using TLS connections to prevent unintended disclosure or modification of logs. The TOE supports MACsec communication with MACsec peers. 1.4.2 TOE Documentation HPE offers a series of documents that describe the installation of the Hewlett Packard Enterprise’s CX-5420, CX- 6200M, CX-6300, CX-6400, CX-8360, and CX-9300s Switch Series MACsec running AOS-CX version 10.16 as well as guidance for subsequent use and administration of the applicable security features. The following document was examined as part of the evaluation: • Common Criteria Administrator Guidance, Target of Evaluation: 4100, 5000, 6000, 8000, 9000, and 10000 Switch Series, version 2.4, July 14, 2026 [CC-Guide] Hewlett Packard Enterprise’s CX-5420, CX-6200M, CX-6300, CX-6400, CX-8360, and CX-9300s Switch Series MACsec running AOS-CX version 10.16 Security Target Version 0.4, 08/17/2026 Page 7 of 44 2. Conformance Claims This TOE is conformant to the following CC specifications: • Common Criteria for Information Technology Security Evaluation Part 2: Security functional components, Version 3.1, Revision 5, April 2017. • Part 2 Extended • Common Criteria for Information Technology Security Evaluation Part 3: Security assurance components, Version 3.1, Revision 5, April 2017. • Part 3 Conformant • Package Claims: • PP-Configuration for Network Devices and MACsec Ethernet Encryption, 2024-04-25 (CFG_NDcPP-MACsec_V2.0) ▪ collaborative Protection Profile for Network Devices, Version 3.0e, 06 December 2023 (NDcPP30e) ▪ PP-Module for MACsec Ethernet Encryption, Version 1.0, 02 March 2023 (MACSEC10) • Functional Package for Secure Shell (SSH)', Version 1.0, 13 May 2021 (SSH10) Package Technical Decision Applied Notes CPP_ND_V3.0E TD1052 - NIT Technical Decision: Separation of Test Definitions for DTLSv1.2 and v1.3 (Renegotiation) No DTLS is not claimed CPP_ND_V3.0E TD1033 - Sunset Dates for NDcPP Configurations Yes CPP_ND_V3.0E TD0990 - NIT Technical Decision: CTR_DRBG in FCS_RBG_EXT.1.2 Yes CPP_ND_V3.0E TD0973 - NIT Technical Decision: FCS_(D)TLSS_EXT.1.3 Test 2 DHE Ciphersuite Conditionality Yes CPP_ND_V3.0E TD0923 - NIT Technical Decision: Auditable event for FAU_STG_EXT.1 in FAU_GEN.1.2 Yes CPP_ND_V3.0E TD0921 - NIT Technical Decision: Addition of FIPS PUB 186-5 and Correction of Assignment Yes CPP_ND_V3.0E TD0900 - NIT Technical Decision: Clarification to Local Administrator Access in FIA_UIA_EXT.1.3 Yes CPP_ND_V3.0E TD0899 - NIT Technical Decision: Correction of Renegotiation Test for TLS 1.2 Yes CPP_ND_V3.0E TD0886 - Clarification to FAU_STG_EXT.1 Test 6 Yes CPP_ND_V3.0E TD0880 - NIT Decision: Removal of Duplicate Selection in FMT_SMF.1.1 Yes CPP_ND_V3.0E TD0879 - NIT Decision: Correction of Chapter Headings in CPP_ND_V3.0E Yes CPP_ND_V3.0E TD0868 - NIT Technical Decision: Clarification of time frames in FCS_IPSEC_EXT.1.7 and FCS_IPSEC_EXT.1.8 No IPsec is not claimed CPP_ND_V3.0E TD0836 - NIT Technical Decision: Redundant Requirements in FPT_TST_EXT.1 Yes MOD_MACSEC_V1.0TD1030 - Correction to FCS_MAC_EXT.2 TSS Activity When FPT_RPL_EXT.1 is Claimed Yes MOD_MACSEC_V1.0TD0939 - Updated Conformance Claims for MOD_MACSEC Yes MOD_MACSEC_V1.0TD0891 - Correlation of Implicitly Satisfied Requirements when CPP_ND_V3.0E is the Base-PP Yes Hewlett Packard Enterprise’s CX-5420, CX-6200M, CX-6300, CX-6400, CX-8360, and CX-9300s Switch Series MACsec running AOS-CX version 10.16 Security Target Version 0.4, 08/17/2026 Page 8 of 44 Package Technical Decision Applied Notes MOD_MACSEC_V1.0TD0889 - Correction For Tests Incorrectly Requiring Group MACsec Yes MOD_MACSEC_V1.0TD0884 - Expansion of Permitted EtherTypes in FCS_MACSEC_EXT.1.4 Yes MOD_MACSEC_V1.0TD0882 - MACsec Data Delay Protection, Key Agreement, and Conditional Support for Group CAK Yes MOD_MACSEC_V1.0TD0881 - Correction to MN Usage for FPT_RPL.1 Test Yes MOD_MACSEC_V1.0TD0870 - Security Objectives Rationale for MOD_MACSEC_V1.0 Yes MOD_MACSEC_V1.0TD0840 - Alignment of Test 22.1 to FMT_SMF.1/MACSEC Yes MOD_MACSEC_V1.0TD0826 - Aligning MOD_MACSEC_V1.0 with CPP_ND_V3.0E Yes MOD_MACSEC_V1.0TD0825 - Correction to IEEE 802.1X Reference Yes MOD_MACSEC_V1.0TD0816 - Clarity for MACsec Self Test Failure Response Yes MOD_MACSEC_V1.0TD0803 - Clarification for Configurable MACsec CKN Length Yes MOD_MACSEC_V1.0TD0746 - Correction to FPT_RPL.1 Test 25 Yes MOD_MACSEC_V1.0TD0728 - Corrections to MACSec PP-Module SD Yes PKG_SSH_V1.0 TD1023 - Clarifications to FCS_SSH_EXT.1.5 When aes256- gcm@openssh.com Is Selected Yes PKG_SSH_V1.0 TD1015 - Addition of ECD to PKG_SSH_V1.0 Yes PKG_SSH_V1.0 TD0967 - Allowance of Kex-strict in PKG_SSH_V1.0 Yes PKG_SSH_V1.0 TD0909 - Updates to FCS_SSH_EXT.1.1 App Note in SSH FP 1.0 Yes PKG_SSH_V1.0 TD0777 - Clarification to Selections for Auditable Events for FCS_SSH_EXT.1 Yes PKG_SSH_V1.0 TD0732 - FCS_SSHS_EXT.1.3 Test 2 Update Yes PKG_SSH_V1.0 TD0695 - Choice of 128 or 256 bit size in AES-CTR in SSH Functional Package. Yes PKG_SSH_V1.0 TD0682 - Addressing Ambiguity in FCS_SSHS_EXT.1 Tests Yes Table 2 Technical Decisions 2.1 Conformance Rationale The ST conforms to the NDcPP30e/MACSEC10/SSH10. As explained previously, the security problem definition, security objectives, and security requirements have been drawn from the PP. Hewlett Packard Enterprise’s CX-5420, CX-6200M, CX-6300, CX-6400, CX-8360, and CX-9300s Switch Series MACsec running AOS-CX version 10.16 Security Target Version 0.4, 08/17/2026 Page 9 of 44 3. Security Objectives The Security Problem Definition may be found in the NDcPP30e/MACSEC10/SSH10 and this section reproduces only the corresponding Security Objectives for operational environment for reader convenience. The NDcPP30e/MACSEC10/SSH10 offers additional information about the identified security objectives, but that has not been reproduced here and the NDcPP30e/MACSEC10/SSH10 should be consulted if there is interest in that material. In general, the NDcPP30e/MACSEC10/SSH10 has defined Security Objectives appropriate for a MACSEC network device and as such are applicable to the Hewlett Packard Enterprise’s CX-5420, CX-6200M, CX-6300, CX-6400, CX-8360, and CX-9300s Switch Series MACsec running AOS-CX version 10.16 TOE. 3.1 Security Objectives for the Operational Environment OE.ADMIN_CREDENTIALS_SECURE The Administrator's credentials (private key) used to access the TOE must be protected on any other platform on which they reside. OE.COMPONENTS_RUNNING (applies to distributed TOEs only) For distributed TOEs, the Security Administrator ensures that the availability of every TOE component is checked as appropriate to reduce the risk of an undetected attack on (or failure of) one or more TOE components. The Security Administrator also ensures that it is checked as appropriate for every TOE component that the audit functionality is running properly. OE.NO_GENERAL_PURPOSE There are no general-purpose computing capabilities (e.g., compilers or user applications) available on the TOE, other than those services necessary for the operation, administration and support of the TOE. Note: For vNDs the TOE includes only the contents of the its own VM, and does not include other VMs or the VS. OE.NO_THRU_TRAFFIC_PROTECTION The TOE does not provide any protection of traffic that traverses it. It is assumed that protection of this traffic will be covered by other security and assurance measures in the operational environment. OE.PHYSICAL Physical security, commensurate with the value of the TOE and the data it contains, is provided by the environment. OE.PLATFORM The TOE relies upon a trustworthy computing platform for its execution. This includes the underlying operating system and any discrete execution environment provided to the TOE. OE.PROPER_ADMIN The administrator of the application software is not careless, willfully negligent or hostile, and administers the software within compliance of the applied enterprise security policy. OE.PROPER_USER The user of the application software is not willfully negligent or hostile, and uses the software within compliance of the applied enterprise security policy. OE.RESIDUAL_INFORMATION The Security Administrator ensures that there is no unauthorized access possible for sensitive residual information (e.g. cryptographic keys, keying material, PINs, passwords etc.) on networking equipment when the equipment is discarded or removed from its operational environment. For vNDs, this applies when the physical platform on which the VM runs is removed from its operational environment. Hewlett Packard Enterprise’s CX-5420, CX-6200M, CX-6300, CX-6400, CX-8360, and CX-9300s Switch Series MACsec running AOS-CX version 10.16 Security Target Version 0.4, 08/17/2026 Page 10 of 44 OE.TRUSTED_ADMIN Security Administrators are trusted to follow and apply all guidance documentation in a trusted manner. For vNDs, this includes the VS Administrator responsible for configuring the VMs that implement ND functionality. For TOEs supporting X.509v3 certificate-based authentication, the Security Administrator(s) are assumed to monitor the revocation status of all certificates in the TOE's trust store and to remove any certificate from the TOE's trust store in case such certificate can no longer be trusted. OE.UPDATES The TOE firmware and software is updated by an Administrator on a regular basis in response to the release of product updates due to known vulnerabilities. Hewlett Packard Enterprise’s CX-5420, CX-6200M, CX-6300, CX-6400, CX-8360, and CX-9300s Switch Series MACsec running AOS-CX version 10.16 Security Target Version 0.4, 08/17/2026 Page 11 of 44 4. Extended Components Definition All of the extended requirements in this ST have been drawn from the NDcPP30e/MACSEC10/SSH10. The NDcPP30e/MACSEC10/SSH10 defines the following extended requirements and since they are not redefined in this ST the NDcPP30e/MACSEC10/SSH10 should be consulted for more information in regard to those CC extensions. Extended SFRs: - NDcPP30e:FAU_STG_EXT.1: Protected Audit Event Storage - NDcPP30e:FCS_HTTPS_EXT.1: HTTPS Protocol - MACSEC10:FCS_MACSEC_EXT.1: MACsec - per TD0884 - MACSEC10:FCS_MACSEC_EXT.2: MACsec Integrity and Confidentiality - MACSEC10:FCS_MACSEC_EXT.3: MACsec Randomness - MACSEC10:FCS_MACSEC_EXT.4: MACsec Key Usage - per TD0803 - MACSEC10:FCS_MKA_EXT.1: MACsec Key Agreement - per TD0882 & TD0889 - NDcPP30e:FCS_RBG_EXT.1: Random Bit Generation - SSH10:FCS_SSH_EXT.1: SSH Protocol - per TD0909 - SSH10:FCS_SSHS_EXT.1: SSH Protocol - Server - per TD0682 - NDcPP30e:FCS_TLSC_EXT.1: TLS Client Protocol - per TD0899 - NDcPP30e:FCS_TLSC_EXT.2: TLS Client Support for Mutual Authentication - NDcPP30e:FCS_TLSS_EXT.1: TLS Server Protocol - per TD0899 - NDcPP30e:FIA_PMG_EXT.1: Password Management - MACSEC10:FIA_PSK_EXT.1: Pre-Shared Key Composition - NDcPP30e:FIA_UIA_EXT.1: User Identification and Authentication - per TD0900 - NDcPP30e:FIA_X509_EXT.1/Rev: X.509 Certificate Validation - NDcPP30e:FIA_X509_EXT.2: X.509 Certificate Authentication - NDcPP30e:FIA_X509_EXT.3: X.509 Certificate Requests - NDcPP30e:FPT_APW_EXT.1: Protection of Administrator Passwords - MACSEC10:FPT_CAK_EXT.1: Protection of CAK Data - MACSEC10:FPT_RPL_EXT.1: Replay Detection for XPN - per TD0728 - NDcPP30e:FPT_SKP_EXT.1: Protection of TSF Data (for reading of all symmetric keys) - NDcPP30e:FPT_STM_EXT.1: Reliable Time Stamps - NDcPP30e:FPT_TST_EXT.1: TSF testing - per TD0836 - NDcPP30e:FPT_TUD_EXT.1: Trusted update - NDcPP30e:FTA_SSL_EXT.1: TSF-initiated Session Locking Hewlett Packard Enterprise’s CX-5420, CX-6200M, CX-6300, CX-6400, CX-8360, and CX-9300s Switch Series MACsec running AOS-CX version 10.16 Security Target Version 0.4, 08/17/2026 Page 12 of 44 5. Security Requirements This section defines the Security Functional Requirements (SFRs) and Security Assurance Requirements (SARs) that serve to represent the security functional claims for the Target of Evaluation (TOE) and to scope the evaluation effort. The SFRs have all been drawn from the NDcPP30e/MACSEC10/SSH10. The refinements and operations already performed in the NDcPP30e/MACSEC10/SSH10 are not identified (e.g., highlighted) here, rather the requirements have been copied from the NDcPP30e/MACSEC10/SSH10 and any residual operations have been completed herein. Of particular note, the NDcPP30e/MACSEC10/SSH10 made a number of refinements and completed some of the SFR operations defined in the Common Criteria (CC) and that PP should be consulted to identify those changes if necessary. The SARs are also drawn from the NDcPP30e/MACSEC10/SSH10. The NDcPP30e/MACSEC10/SSH10 should be consulted for the assurance activity definitions. 5.1 TOE Security Functional Requirements The following table identifies the SFRs that are satisfied by Hewlett Packard Enterprise’s CX-5420, CX-6200M, CX- 6300, CX-6400, CX-8360, and CX-9300s Switch Series MACsec running AOS-CX version 10.16 TOE. Requirement Class Requirement Component FAU: Security audit NDcPP30e:FAU_GEN.1: Audit Data Generation MACSEC10:FAU_GEN.1/MACSEC: Audit Data Generation (MACsec) NDcPP30e:FAU_GEN.2: User identity association NDcPP30e:FAU_STG_EXT.1: Protected Audit Event Storage FCS: Cryptographic support NDcPP30e:FCS_CKM.1: Cryptographic Key Generation NDcPP30e:FCS_CKM.2: Cryptographic Key Establishment NDcPP30e:FCS_CKM.4: Cryptographic Key Destruction MACSEC10:FCS_COP.1/CMAC: Cryptographic Operation (AES-CMAC Keyed Hash Algorithm) NDcPP30e:FCS_COP.1/DataEncryption: Cryptographic Operation (AES Data Encryption/Decryption) NDcPP30e:FCS_COP.1/Hash: Cryptographic Operation (Hash Algorithm) NDcPP30e:FCS_COP.1/KeyedHash: Cryptographic Operation (Keyed Hash Algorithm) MACSEC10:FCS_COP.1/MACSEC: Cryptographic Operation (MACsec AES Data Encryption and Decryption) - per TD0728 NDcPP30e:FCS_COP.1/SigGen: Cryptographic Operation (Signature Generation and Verification) NDcPP30e:FCS_HTTPS_EXT.1: HTTPS Protocol MACSEC10:FCS_MACSEC_EXT.1: MACsec - per TD0884 MACSEC10:FCS_MACSEC_EXT.2: MACsec Integrity and Confidentiality MACSEC10:FCS_MACSEC_EXT.3: MACsec Randomness MACSEC10:FCS_MACSEC_EXT.4: MACsec Key Usage - per TD0803 MACSEC10:FCS_MKA_EXT.1: MACsec Key Agreement - per TD0882 & TD0889 NDcPP30e:FCS_RBG_EXT.1: Random Bit Generation SSH10:FCS_SSH_EXT.1: SSH Protocol - per TD0909 SSH10:FCS_SSHS_EXT.1: SSH Protocol - Server - per TD0682 NDcPP30e:FCS_TLSC_EXT.1: TLS Client Protocol - per TD0899 NDcPP30e:FCS_TLSC_EXT.2: TLS Client Support for Mutual Authentication NDcPP30e:FCS_TLSS_EXT.1: TLS Server Protocol - per TD0899 FIA: Identification and authentication NDcPP30e:FIA_AFL.1: Authentication Failure Management NDcPP30e:FIA_PMG_EXT.1: Password Management MACSEC10:FIA_PSK_EXT.1: Pre-Shared Key Composition NDcPP30e:FIA_UAU.7: Protected Authentication Feedback Hewlett Packard Enterprise’s CX-5420, CX-6200M, CX-6300, CX-6400, CX-8360, and CX-9300s Switch Series MACsec running AOS-CX version 10.16 Security Target Version 0.4, 08/17/2026 Page 13 of 44 NDcPP30e:FIA_UIA_EXT.1: User Identification and Authentication - per TD0900 NDcPP30e:FIA_X509_EXT.1/Rev: X.509 Certificate Validation NDcPP30e:FIA_X509_EXT.2: X.509 Certificate Authentication NDcPP30e:FIA_X509_EXT.3: X.509 Certificate Requests FMT: Security management NDcPP30e:FMT_MOF.1/Functions: Management of Security Functions Behaviour NDcPP30e:FMT_MOF.1/ManualUpdate: Management of security functions behaviour NDcPP30e:FMT_MTD.1/CoreData: Management of TSF Data NDcPP30e:FMT_MTD.1/CryptoKeys: Management of TSF Data NDcPP30e:FMT_SMF.1: Specification of Management Functions - per TD0880 MACSEC10:FMT_SMF.1/MACSEC: Specification of Management Functions (MACsec) - per TD0803, TD0840, & TD0889 NDcPP30e:FMT_SMR.2: Restrictions on Security Roles FPT: Protection of the TSF NDcPP30e:FPT_APW_EXT.1: Protection of Administrator Passwords MACSEC10:FPT_CAK_EXT.1: Protection of CAK Data MACSEC10:FPT_FLS.1: Failure with Preservation of Secure State - per TD0816 MACSEC10:FPT_RPL.1: Replay Detection - per TD0746 & TD0881 MACSEC10:FPT_RPL_EXT.1: Replay Detection for XPN - per TD0728 NDcPP30e:FPT_SKP_EXT.1: Protection of TSF Data (for reading of all symmetric keys) NDcPP30e:FPT_STM_EXT.1: Reliable Time Stamps NDcPP30e:FPT_TST_EXT.1: TSF testing - per TD0836 NDcPP30e:FPT_TUD_EXT.1: Trusted update FTA: TOE access NDcPP30e:FTA_SSL.3: TSF-initiated Termination NDcPP30e:FTA_SSL.4: User-initiated Termination NDcPP30e:FTA_SSL_EXT.1: TSF-initiated Session Locking NDcPP30e:FTA_TAB.1: Default TOE Access Banners FTP: Trusted path/channels NDcPP30e:FTP_ITC.1: Inter-TSF trusted channel MACSEC10:FTP_ITC.1/MACSEC: Inter-TSF Trusted Channel (MACsec Communications) NDcPP30e:FTP_TRP.1/Admin: Trusted Path Table 3 TOE Security Functional Components 5.1.1 Security audit (FAU) 5.1.1.1 Audit Data Generation (NDcPP30e:FAU_GEN.1) NDcPP30e:FAU_GEN.1.1 The TSF shall be able to generate an audit record of the following auditable events: a) Start-up and shut-down of the audit functions; b) All auditable events for the not specified level of audit; and c) All administrative actions comprising: - Administrative login and logout (name of Administrator account shall be logged if individual user accounts are required for administrators). - Changes to TSF data related to configuration changes (in addition to the information that a change occurred it shall be logged what has been changed). - Generating/import of, changing, or deleting of cryptographic keys (in addition to the action itself a unique key name or key reference shall be logged). - [Resetting passwords (name of related Administrator account shall be logged)]; d) Specifically defined auditable events listed in Table 4. NDcPP30e:FAU_GEN.1.2 The TSF shall record within each audit record at least the following information: a) Date and time of the event, type of event, subject identity, and the outcome (success or failure) of the event; and Hewlett Packard Enterprise’s CX-5420, CX-6200M, CX-6300, CX-6400, CX-8360, and CX-9300s Switch Series MACsec running AOS-CX version 10.16 Security Target Version 0.4, 08/17/2026 Page 14 of 44 b) For each audit event type, based on the auditable event definitions of the functional components included in the cPP/ST, information specified in column three of Table 4. Requirement Audit Event Additional Contents NDcPP30e:FAU_GEN.1 NDcPP30e:FAU_GEN.2 NDcPP30e:FAU_STG_EXT.1 Configuration of local audit settings. Identity of account making changes to the audit configuration. NDcPP30e:FCS_CKM.1 NDcPP30e:FCS_CKM.2 NDcPP30e:FCS_CKM.4 NDcPP30e:FCS_COP.1/DataEncryption NDcPP30e:FCS_COP.1/Hash NDcPP30e:FCS_COP.1/KeyedHash NDcPP30e:FCS_COP.1/SigGen NDcPP30e:FCS_HTTPS_EXT.1 Failure to establish a HTTPS Session. Reason for failure. NDcPP30e:FCS_RBG_EXT.1 SSH10:FCS_SSH_EXT.1 [Failure to establish SSH connection] [Establishment of SSH connection] [Termination of SSH connection session] [None] [Reason for failure and non- TOE endpoint of attempted connection (IP Address)] [Non-TOE endpoint of connection (IP Address)] [Non-TOE endpoint of connection (IP Address)] [No additional information] SSH10:FCS_SSHS_EXT.1 NDcPP30e:FCS_TLSC_EXT.1 Failure to establish a TLS Session. Reason for failure. NDcPP30e:FCS_TLSC_EXT.2 NDcPP30e:FCS_TLSS_EXT.1 Failure to establish a TLS Session. Reason for failure. NDcPP30e:FIA_AFL.1 Unsuccessful login attempt limit is met or exceeded. Origin of the attempt (e.g., IP address). NDcPP30e:FIA_PMG_EXT.1 NDcPP30e:FIA_UAU.7 NDcPP30e:FIA_UIA_EXT.1 All use of identification and authentication mechanism. Origin of the attempt (e.g., IP address). NDcPP30e:FIA_X509_EXT.1/Rev Unsuccessful attempt to validate a certificate. Any addition, replacement or removal of trust anchors in the TOE's trust store. Reason for failure of certificate validation. Identification of certificates added, replaced or removed as trust anchor in the TOE's trust store. NDcPP30e:FIA_X509_EXT.2 NDcPP30e:FIA_X509_EXT.3 NDcPP30e:FMT_MOF.1/Functions NDcPP30e:FMT_MOF.1/ManualUpdate Any attempt to initiate a manual update. NDcPP30e:FMT_MTD.1/CoreData NDcPP30e:FMT_MTD.1/CryptoKeys NDcPP30e:FMT_SMF.1 All management activities of TSF data. NDcPP30e:FMT_SMR.2 Hewlett Packard Enterprise’s CX-5420, CX-6200M, CX-6300, CX-6400, CX-8360, and CX-9300s Switch Series MACsec running AOS-CX version 10.16 Security Target Version 0.4, 08/17/2026 Page 15 of 44 Requirement Audit Event Additional Contents NDcPP30e:FPT_APW_EXT.1 NDcPP30e:FPT_SKP_EXT.1 NDcPP30e:FPT_STM_EXT.1 Discontinuous changes to time - either Administrator actuated or changed via an automated process. (Note that no continuous changes to time need to be logged. See also application note on FPT_STM_EXT.1) For discontinuous changes to time: The old and new values for the time. Origin of the attempt to change time for success and failure (e.g., IP address). NDcPP30e:FPT_TST_EXT.1 NDcPP30e:FPT_TUD_EXT.1 Initiation of update; result of the update attempt (success or failure). NDcPP30e:FTA_SSL.3 The termination of a remote session by the session locking mechanism. NDcPP30e:FTA_SSL.4 The termination of an interactive session. NDcPP30e:FTA_SSL_EXT.1 (if 'lock the session' is selected) Any attempts at unlocking of an interactive session. (if 'terminate the session' is selected) The termination of a local session by the session lock. NDcPP30e:FTA_TAB.1 NDcPP30e:FTP_ITC.1 Initiation of the trusted channel. Termination of the trusted channel. Failure of the trusted channel functions. None None Reason for failure NDcPP30e:FTP_TRP.1/Admin Initiation of the trusted path. Termination of the trusted path. Failure of the trusted path functions. None None Reason for failure Table 4 Auditable Events 5.1.1.2 Audit Data Generation (MACsec) (MACSEC10:FAU_GEN.1/MACSEC) MACSEC10:FAU_GEN.1.1/MACSEC The TSF shall be able to generate an audit record of the following auditable events: a. Start-up and shutdown of the audit functions; b. All auditable events for the not specified level of audit; c. All administrative actions; d. Specifically defined auditable events listed in the Auditable Events table (Table 5) MACSEC10:FAU_GEN.1.2/MACSEC The TSF shall record within each audit record at least the following information: a. Date and time of the event, type of event, subject identity (if applicable), and the outcome (success or failure) of the event; and b. For each audit event type, based on the auditable event definitions of the functional components included in the PP-Module/ST, information specified in column three of the Auditable Events table (Table 5). Hewlett Packard Enterprise’s CX-5420, CX-6200M, CX-6300, CX-6400, CX-8360, and CX-9300s Switch Series MACsec running AOS-CX version 10.16 Security Target Version 0.4, 08/17/2026 Page 16 of 44 Requirement Auditable Events Additional Audit Record Contents FCS_MACSEC_EXT.1 Session establishment Secure Channel Identifier (SCI) FCS_MACSEC_EXT.3 Creation and update of SAK Creation and update times FCS_MACSEC_EXT.4 Creation of CA Connectivity Association Key Names (CKNs) FPT_RPL.1 Detected replay attempt None Table 5 MACsec Auditable Events 5.1.1.3 User identity association (NDcPP30e:FAU_GEN.2) NDcPP30e:FAU_GEN.2.1 For audit events resulting from actions of identified users, the TSF shall be able to associate each auditable event with the identity of the user that caused the event. 5.1.1.4 Protected Audit Event Storage (NDcPP30e:FAU_STG_EXT.1) NDcPP30e:FAU_STG_EXT.1.1 The TSF shall be able to transmit the generated audit data to an external IT entity using a trusted channel according to FTP_ITC.1. NDcPP30e:FAU_STG_EXT.1.2 The TSF shall be able to store generated audit data on the TOE itself. In addition [The TOE shall consist of a single standalone component that stores audit data locally,] NDcPP30e:FAU_STG_EXT.1.3 The TSF shall maintain a [log file] of audit records in the event that an interruption of communication with the remote audit server occurs. NDcPP30e:FAU_STG_EXT.1.4 The TSF shall be able to store [persistent] audit records locally with a minimum storage size of [10MB] NDcPP30e:FAU_STG_EXT.1.5 The TSF shall [overwrite previous audit records according to the following rule: [Oldest log file is cleared]] when the local storage space for audit data is full. NDcPP30e:FAU_STG_EXT.1.6 The TSF shall provide the following mechanisms for administrative access to locally stored audit records [ability to view locally]. 5.1.2 Cryptographic support (FCS) 5.1.2.1 Cryptographic Key Generation (NDcPP30e:FCS_CKM.1) NDcPP30e:FCS_CKM.1.1 The TSF shall generate asymmetric cryptographic keys in accordance with a specified cryptographic key generation algorithm: [ - RSA schemes using cryptographic key sizes of [2048-bit] that meet the following: FIPS PUB 186-4, 'Digital Signature Standard (DSS)', Appendix B.3 or FIPS PUB 186-5, "Digital Signature Standard (DSS)", A.1, - ECC schemes using 'NIST curves' [P-256, P-384, P-521] that meet the following: FIPS PUB 186-4, 'Digital Signature Standard (DSS)', Appendix B.4 or FIPS PUB 186-5, “Digital Signature Standard (DSS)”, Appendix A.2, or ISO/IEC 14888-3, “IT Security techniques - Digital signatures with appendix - Part 3: Discrete logarithm based mechanisms”, Section 6.6.]. Hewlett Packard Enterprise’s CX-5420, CX-6200M, CX-6300, CX-6400, CX-8360, and CX-9300s Switch Series MACsec running AOS-CX version 10.16 Security Target Version 0.4, 08/17/2026 Page 17 of 44 5.1.2.2 Cryptographic Key Establishment (NDcPP30e:FCS_CKM.2) NDcPP30e:FCS_CKM.2.1 The TSF shall perform cryptographic key establishment in accordance with a specified cryptographic key establishment method: [ - RSA-based key establishment schemes that meet the following: RSAES-PKCS1-v1_5 as specified in Section 7.2 of RFC 8017, 'Public-Key Cryptography Standards (PKCS) #1: RSA Cryptography Specifications Version 2.2, - Elliptic curve-based key establishment schemes that meet the following: NIST Special Publication 800-56A Revision 3, 'Recommendation for Pair-Wise Key Establishment Schemes Using Discrete Logarithm Cryptography', ]. 5.1.2.3 Cryptographic Key Destruction (NDcPP30e:FCS_CKM.4) NDcPP30e:FCS_CKM.4.1 The TSF shall destroy cryptographic keys in accordance with a specified cryptographic key destruction method - For plaintext keys in volatile storage, the destruction shall be executed by a [single overwrite consisting of [zeroes]]; - For plaintext keys in non-volatile storage, the destruction shall be executed by the invocation of an interface provided by a part of the TSF that [logically addresses the storage location of the key and performs a [single] overwrite consisting of [zeroes]] that meets the following: No Standard. 5.1.2.4 Cryptographic Operation (AES-CMAC Keyed Hash Algorithm) (MACSEC10:FCS_COP.1/CMAC) MACSEC10:FCS_COP.1.1/CMAC The TSF shall perform keyed-hash message authentication in accordance with a specified cryptographic algorithm AES-CMAC and cryptographic key sizes [128, 256] bits and message digest size of 128 bits that meets the following: NIST SP 800-38B. 5.1.2.5 Cryptographic Operation (AES Data Encryption/Decryption) (NDcPP30e:FCS_COP.1/DataEncryption) NDcPP30e:FCS_COP.1.1/DataEncryption The TSF shall perform encryption/decryption in accordance with a specified cryptographic algorithm AES used in [CBC, CTR, GCM] mode and cryptographic key sizes [128 bits, 256 bits] that meet the following: AES as specified in ISO 18033-3, [CBC as specified in ISO 10116, CTR as specified in ISO 10116, GCM as specified in ISO 19772]. 5.1.2.6 Cryptographic Operation (Hash Algorithm) (NDcPP30e:FCS_COP.1/Hash) NDcPP30e:FCS_COP.1.1/Hash The TSF shall perform cryptographic hashing services in accordance with a specified cryptographic algorithm [SHA-256, SHA-384, SHA-512] and message digest sizes [160, 256, 384, 512] bits that meet the following: ISO/IEC 10118-3:2004. 5.1.2.7 Cryptographic Operation (Keyed Hash Algorithm) (NDcPP30e:FCS_COP.1/KeyedHash) NDcPP30e:FCS_COP.1.1/KeyedHash The TSF shall perform keyed-hash message authentication in accordance with a specified cryptographic algorithm [HMAC-SHA-256, HMAC-SHA-384, HMAC-SHA-512] and cryptographic key sizes [ 256, 384, 512] and message digest sizes [ 256, 384, 512] bits that meet the following: ISO/IEC 9797-2:2011, Section 7 'MAC Algorithm 2'. Hewlett Packard Enterprise’s CX-5420, CX-6200M, CX-6300, CX-6400, CX-8360, and CX-9300s Switch Series MACsec running AOS-CX version 10.16 Security Target Version 0.4, 08/17/2026 Page 18 of 44 5.1.2.8 Cryptographic Operation (MACsec AES Data Encryption and Decryption) - per TD0728 (MACSEC10:FCS_COP.1/MACSEC) MACSEC10:FCS_COP.1.1/MACSEC The TSF shall perform encryption and decryption in accordance with a specified cryptographic algorithm AES used in AES Key Wrap, GCM and cryptographic key sizes [128, 256] bits that meets the following: AES as specified in ISO 18033-3, AES Key Wrap as specified in NIST SP 800-38F, GCM as specified in ISO 19772. 5.1.2.9 Cryptographic Operation (Signature Generation and Verification) (NDcPP30e:FCS_COP.1/SigGen) NDcPP30e:FCS_COP.1.1/SigGen The TSF shall perform cryptographic signature services (generation and verification) in accordance with a specified cryptographic algorithm [ - RSA Digital Signature Algorithm, - Elliptic Curve Digital Signature Algorithm] and cryptographic key sizes [ - For RSA: modulus [2048 bits, 3072 bits] - For ECDSA: [256 bits]] that meet the following: [- For RSA schemes: FIPS PUB 186-4, 'Digital Signature Standard (DSS)', Section 5.5, using PKCS #1 v2.1 or FIPS PUB 186-5, "Digital Signature Standard (DSS)", Section 5.4 using PKCS #1 v2.2 Signature Schemes RSASSA-PSS and/or RSASSA-PKCS1v1_5; ISO/IEC 9796-2, Digital signature scheme 2 or Digital Signature scheme 3, - For ECDSA schemes implementing [P-256, P-384, P-521] curves that meet the following: FIPS PUB 186-4, 'Digital Signature Standard (DSS)', Section 6 and Appendix D, Implementing 'NIST Recommended' curves; or FIPS PUB 186-5, 'Digital Signature Standard (DSS)', Section 6 and NIST SP 800-186 Section 3.2.1, Implementing Weierstrass curves; or ISO/IEC 14888-3, 'IT Security techniques - Digital signatures with appendix - Part 3: Discrete logarithm based mechanisms', Section 6.6]. 5.1.2.10 HTTPS Protocol (NDcPP30e:FCS_HTTPS_EXT.1) NDcPP30e:FCS_HTTPS_EXT.1.1 The TSF shall implement the HTTPS protocol that complies with RFC 2818. NDcPP30e:FCS_HTTPS_EXT.1.2 The TSF shall implement HTTPS using TLS. 5.1.2.11 MACsec - per TD0884 (MACSEC10:FCS_MACSEC_EXT.1) MACSEC10:FCS_MACSEC_EXT.1.1 The TSF shall implement MACsec in accordance with IEEE Standard 802.1AE-2018. MACSEC10:FCS_MACSEC_EXT.1.2 The TSF shall derive a Secure Channel Identifier (SCI) from a peer's MAC address and port to uniquely identify the originator of an MPDU. MACSEC10:FCS_MACSEC_EXT.1.3 The TSF shall reject any MPDUs during a given session that contain an SCI other than the one used to establish that session. MACSEC10:FCS_MACSEC_EXT.1.4 The TSF shall permit only EAPOL (Port Access Entity (PAE) EtherType 88-8E), MACsec frames (EtherType 88-E5), and [no other frame types] and shall discard others. (TD0884 applied) 5.1.2.12 MACsec Integrity and Confidentiality (MACSEC10:FCS_MACSEC_EXT.2) MACSEC10:FCS_MACSEC_EXT.2.1 The TOE shall implement MACsec with support for integrity protection with a confidentiality offset of [0, 30, 50]. Hewlett Packard Enterprise’s CX-5420, CX-6200M, CX-6300, CX-6400, CX-8360, and CX-9300s Switch Series MACsec running AOS-CX version 10.16 Security Target Version 0.4, 08/17/2026 Page 19 of 44 MACSEC10:FCS_MACSEC_EXT.2.2 The TSF shall provide assurance of the integrity of protocol data units (MPDUs) using an Integrity Check Value (ICV) derived with the SAK. MACSEC10:FCS_MACSEC_EXT.2.3 The TSF shall provide the ability to derive an Integrity Check Value Key (ICK) from a Connectivity Association Key (CAK) using a KDF. 5.1.2.13 MACsec Randomness (MACSEC10:FCS_MACSEC_EXT.3) MACSEC10:FCS_MACSEC_EXT.3.1 The TSF shall generate unique Secure Association Keys (SAKs) using [key derivation from Connectivity Association Key (CAK) per section 9.8.1 of IEEE 802.1X-2020] such that the likelihood of a repeating SAK is no less than 1 in 2 to the power of the size of the generated key. (TD0825 applied) MACSEC10:FCS_MACSEC_EXT.3.2 The TSF shall generate unique nonces for the derivation of SAKs using the TOE's random bit generator as specified by FCS_RBG_EXT.1. 5.1.2.14 MACsec Key Usage - per TD0803 (MACSEC10:FCS_MACSEC_EXT.4) MACSEC10:FCS_MACSEC_EXT.4.1 The TSF shall support peer authentication using pre-shared keys (PSK) [no other methods]. MACSEC10:FCS_MACSEC_EXT.4.2 The TSF shall distribute SAKs between MACsec peers using AES key wrap as specified in FCS_COP.1/MACSEC. MACSEC10:FCS_MACSEC_EXT.4.3 The TSF shall support specifying a lifetime for CAKs. MACSEC10:FCS_MACSEC_EXT.4.4 The TSF shall associate Connectivity Association Key Names (CKNs) with SAKs that are defined by the KDF using the CAK as input data (per IEEE 802.1X-2020, Section 9.8.1). (TD0825 applied) MACSEC10:FCS_MACSEC_EXT.4.5 The TSF shall associate CKNs with CAKs. The length of the CKN shall be an integer number of octets, between 1 and 32 (inclusive). 5.1.2.15 MACsec Key Agreement - per TD0882 & TD0889 (MACSEC10:FCS_MKA_EXT.1) MACSEC10:FCS_MKA_EXT.1.1 The TSF shall implement Key Agreement Protocol (MKA) in accordance with IEEE 802.1X-2020 and 802.1Xbx-2014. (TD0825 applied) MACSEC10:FCS_MKA_EXT.1.2 The TSF shall provide assurance of the integrity of MKA protocol data units (MKPDUs) using an Integrity Check Value (ICV) derived from an Integrity Check Value Key (ICK). MACSEC10:FCS_MKA_EXT.1.3 The TSF shall provide the ability to derive an Integrity Check Value Key (ICK) from a CAK using a KDF. MACSEC10:FCS_MKA_EXT.1.4 The TSF shall enforce an MKA Lifetime Timeout limit of 6.0 seconds and [MKA Hello Time limit of 2 seconds]. (TD0882 applied) MACSEC10:FCS_MKA_EXT.1.5 The Key Server shall refresh a SAK when it expires. The Key Server shall distribute a SAK by [pairwise CAKs, derived from MKA, pairwise CAKs that are PSKs]. MACSEC10:FCS_MKA_EXT.1.6 The Key Server shall distribute a fresh SAK whenever a member is added to or removed from the live membership of the CA. Hewlett Packard Enterprise’s CX-5420, CX-6200M, CX-6300, CX-6400, CX-8360, and CX-9300s Switch Series MACsec running AOS-CX version 10.16 Security Target Version 0.4, 08/17/2026 Page 20 of 44 MACSEC10:FCS_MKA_EXT.1.7 The TSF shall validate MKPDUs according to IEEE 802.1X-2010 Section 11.11.2. In particular, the TSF shall discard without further processing any MKPDUs to which any of the following conditions apply: a. The destination address of the MKPDU was an individual address b. The MKPDU is less than 32 octets long c. The MKPDU comprises fewer octets than indicated by the Basic Parameter Set body length, as encoded in bits 4 through 1 of octet 3 and bits 8 through 1 of octet 4, plus 16 octets of ICV d. The CAK Name is not recognized If an MKPDU passes these tests, then the TSF will begin processing it as follows: a. If the Algorithm Agility parameter identifies an algorithm that has been implemented by the receiver, the ICV shall be verified as specified in IEEE 802.1X-2020 Section 9.4.1. b. If the Algorithm Agility parameter is unrecognized or not implemented by the receiver, its value can be recorded for diagnosis but the received MKPDU shall be discarded without further processing. Each received MKPDU that is validated as specified in this clause and verified as specified in IEEE 802.1X-2020 Section 9.4.1 shall be decoded as specified in IEEE 802.1X-2020 Section 11.11.4. (TD0825 applied) 5.1.2.16 Random Bit Generation (NDcPP30e:FCS_RBG_EXT.1) NDcPP30e:FCS_RBG_EXT.1.1 The TSF shall perform all deterministic random bit generation services in accordance with ISO/IEC 18031:2011 using [CTR_DRBG (AES)]. NDcPP30e:FCS_RBG_EXT.1.2 The deterministic RBG shall be seeded by at least one entropy source that accumulates entropy from [[1] software-based noise source] with a minimum of [256 bits] of entropy at least equal to the greatest security strength, according to ISO/IEC 18031:2011Table C.1 'Security Strength Table for Hash Functions', of the keys and hashes that it will generate. 5.1.2.17 SSH Protocol - per TD0909 (SSH10:FCS_SSH_EXT.1) SSH10:FCS_SSH_EXT.1.1 The TOE shall implement SSH acting as a [server] in accordance with that complies with RFCs 4251, 4252, 4253, 4254, [4344, 5656, 6668] and no other standard. SSH10:FCS_SSH_EXT.1.2 The TSF shall ensure that the SSH protocol implementation supports the following authentication methods: ['password' (RFC 4252), 'publickey' (RFC 4252): [ecdsa-sha2-nistp256 (RFC 5656), ecdsa- sha2-nistp384 (RFC 5656), ecdsa-sha2-nistp521 (RFC 5656)]] and no other methods. SSH10:FCS_SSH_EXT.1.3 The TSF shall ensure that, as described in RFC 4253, packets greater than [262127] in an SSH transport connection are dropped. SSH10:FCS_SSH_EXT.1.4 The TSF shall protect data in transit from unauthorised disclosure using the following mechanisms: [aes128-ctr (RFC 4344), aes256-ctr (RFC 4344), aes128-cbc (RFC 4253), aes256-cbc (RFC 4253)] and no other mechanisms. SSH10:FCS_SSH_EXT.1.5 The TSF shall protect data in transit from modification, deletion, and insertion using: [hmac-sha2-256 (RFC 6668), hmac-sha2-512 (RFC 6668)] and no other mechanisms. SSH10:FCS_SSH_EXT.1.6 The TSF shall establish a shared secret with its peer using: Hewlett Packard Enterprise’s CX-5420, CX-6200M, CX-6300, CX-6400, CX-8360, and CX-9300s Switch Series MACsec running AOS-CX version 10.16 Security Target Version 0.4, 08/17/2026 Page 21 of 44 [ecdh-sha2-nistp256 (RFC 5656), ecdh-sha2-nistp384 (RFC 5656)] and no other mechanisms. SSH10:FCS_SSH_EXT.1.7 The TSF shall use SSH KDF as defined in [RFC 5656 (Section 4)] to derive the following cryptographic keys from a shared secret: session keys. SSH10:FCS_SSH_EXT.1.8 The TSF shall ensure that [a rekey of the session keys] occurs when any of the following thresholds are met: - one hour connection time - no more than one gigabyte of transmitted data, or - no more than one gigabyte of received data. 5.1.2.18 SSH Protocol - Server - per TD0682 (SSH10:FCS_SSHS_EXT.1) SSH10:FCS_SSHS_EXT.1.1 The TSF shall authenticate itself to its peer (SSH Client) using: [ecdsa-sha2-nistp256 (RFC 5656), ecdsa-sha2-nistp384 (RFC 5656), ecdsa-sha2-nistp521 (RFC 5656)]. 5.1.2.19 TLS Client Protocol - per TD0899 (NDcPP30e:FCS_TLSC_EXT.1) NDcPP30e:FCS_TLSC_EXT.1.1 The TSF shall implement [TLS 1.3 (RFC 8446), TLS 1.2 (RFC 5246)] supporting the following ciphersuites: [[TLS_DHE_RSA_WITH_AES_128_GCM_SHA256 as defined in RFC 5288, TLS_DHE_RSA_WITH_AES_256_GCM_SHA384 as defined in RFC 5288, TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256 as defined in RFC 5289, TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384 as defined in RFC 5289, TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 as defined in RFC 5289, TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 as defined in RFC 5289], [TLS_AES_128_GCM_SHA256, TLS_AES_256_GCM_SHA384, TLS_AES_128_CCM_SHA256, TLS_AES_128_CCM_8_SHA256]] and no other ciphersuites. NDcPP30e:FCS_TLSC_EXT.1.2 The TSF shall verify that the presented identifier matches [the reference identifier per RFC 6125 Section 6, IPv4 address in the CN or in the SAN]. NDcPP30e:FCS_TLSC_EXT.1.3 The TSF shall not establish a trusted channel if the server certificate is invalid: [without any administrator override mechanism.]. NDcPP30e:FCS_TLSC_EXT.1.4 The TSF shall [present the Supported Groups Extension with the following curves/groups: [secp256r1, secp384r1, secp521r1] and no other curves/groups] in the Client Hello. NDcPP30e:FCS_TLSC_EXT.1.5 The TSF shall [present the signature_algorithms extension with support for the following algorithms: [rsa_pkcs1 with sha256(0x0401), rsa_pkcs1with sha384(0x0501), rsa_pkcs1 with sha512(0x0601), ecdsa_secp256r1 with sha256(0x0403), ecdsa_secp384r1 with sha384(0x0503), ecdsa_secp521r1 with sha512(0x0603), rsa_pss_rsae with sha256(0x0804), rsa_pss_rsae with sha384(0x0805), rsa_pss_rsae with sha512(0x0806), rsa_pss_pss with sha256(0x0809), rsa_pss_pss with sha384(0x080a), rsa_pss_pss with sha512(0x080b)] and no other algorithms, present the signature_algorithms_cert extension with the following Signature Schemes: [rsa_pkcs1 with sha256(0x0401), rsa_pkcs1with sha384(0x0501), rsa_pkcs1 with sha512(0x0601), ecdsa_secp256r1 with sha256(0x0403), ecdsa_secp384r1 with sha384(0x0503), ecdsa_secp521r1 with sha512(0x0603), rsa_pss_rsae with sha256(0x0804), rsa_pss_rsae with sha384(0x0805), rsa_pss_rsae with sha512(0x0806), rsa_pss_pss with sha256(0x0809), Hewlett Packard Enterprise’s CX-5420, CX-6200M, CX-6300, CX-6400, CX-8360, and CX-9300s Switch Series MACsec running AOS-CX version 10.16 Security Target Version 0.4, 08/17/2026 Page 22 of 44 rsa_pss_pss with sha384(0x080a), rsa_pss_pss with sha512(0x080b)] and no other SignatureSchemes]. NDcPP30e:FCS_TLSC_EXT.1.6 The TSF [does not provide] the ability to configure the list of supported ciphersuites as defined in NDcPP30e:FCS_TLSC_EXT.1.1. NDcPP30e:FCS_TLSC_EXT.1.7 The TSF shall prohibit the use of the following extensions: - Early data extension - Post-handshake client authentication according to RFC 8446, Section 4.2.6. NDcPP30e:FCS_TLSC_EXT.1.8 The TSF shall [not use PSKs]. NDcPP30e:FCS_TLSC_EXT.1.9 The TSF shall [reject [TLS 1.2, TLS 1.3] renegotiation attempts]. 5.1.2.20 TLS Client Support for Mutual Authentication (NDcPP30e:FCS_TLSC_EXT.2) NDcPP30e:FCS_TLSC_EXT.2.1 The TSF shall support TLS communication with mutual authentication using X.509v3 certificates. 5.1.2.21 TLS Server Protocol - per TD0899 (NDcPP30e:FCS_TLSS_EXT.1) NDcPP30e:FCS_TLSS_EXT.1.1 The TSF shall implement [TLS 1.3 (RFC 8446), TLS 1.2 (RFC 5246)] and reject all other TLS and SSL versions. The TLS implementation will support the following ciphersuites: [[TLS _RSA_WITH_AES_128_GCM_SHA256 as defined in RFC 5288, TLS _RSA_WITH_AES_256_GCM_SHA384 as defined in RFC 5288, TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256 as defined in RFC 5289, TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384 as defined in RFC 5289, TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 as defined in RFC 5289, TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 as defined in RFC 5289], [TLS_AES_128_GCM_SHA256, TLS_AES_256_GCM_SHA384, TLS_AES_128_CCM_SHA256, TLS_AES_128_CCM_8_SHA256]] and no other ciphersuites. NDcPP30e:FCS_TLSS_EXT.1.2 The TSF shall authenticate itself using X.509 certificate(s) using [RSA with key size [2048, 3072, 4096] bits, ECDSA over NIST curves [secp256r1, secp384r1, secp521r1] and no other curves]. NDcPP30e:FCS_TLSS_EXT.1.3 The TSF shall perform key exchange using: [EC Diffie-Hellman key agreement over NIST curves [secp256r1, secp384r1, secp521r1] and no other curves]. NDcPP30e:FCS_TLSS_EXT.1.4 The TSF shall support [session resumption based on session IDs according to RFC 5246 (TLS1.2)]. NDcPP30e:FCS_TLSS_EXT.1.5 The TSF [does not provide] the ability to configure the list of supported ciphersuites as defined in NDcPP30e:FCS_TLSS_EXT.1.1. NDcPP30e:FCS_TLSS_EXT.1.6 The TSF shall prohibit the use of the following extensions: - Early data extension NDcPP30e:FCS_TLSS_EXT.1.7 The TSF shall [not use PSKs]. NDcPP30e:FCS_TLSS_EXT.1.8 The TSF shall [reject [TLS 1.2, TLS 1.3] renegotiation attempts]. Hewlett Packard Enterprise’s CX-5420, CX-6200M, CX-6300, CX-6400, CX-8360, and CX-9300s Switch Series MACsec running AOS-CX version 10.16 Security Target Version 0.4, 08/17/2026 Page 23 of 44 5.1.3 Identification and authentication (FIA) 5.1.3.1 Authentication Failure Management (NDcPP30e:FIA_AFL.1) NDcPP30e:FIA_AFL.1.1 The TSF shall detect when an Administrator configurable positive integer within [1-10] unsuccessful authentication attempts occur related to Administrators attempting to authenticate remotely using a password. NDcPP30e:FIA_AFL.1.2 When the defined number of unsuccessful authentication attempts has been met, the TSF shall [prevent the offending Administrator from successfully establishing a remote session using any authentication method that involves a password until an Administrator defined time period has elapsed]. 5.1.3.2 Password Management (NDcPP30e:FIA_PMG_EXT.1) NDcPP30e:FIA_PMG_EXT.1.1 The TSF shall provide the following password management capabilities for administrative passwords: a) Passwords shall be able to be composed of any combination of upper and lower case letters, numbers, and the following special characters: ['!', '@', '#', '$', '%', '^', '&', '*', '(', ')', ['`', '+', '-', '.', '/', ':', ';', '<', '>', '=', '?', '[', ']', '_', ''', '_ '|', '~']]; b) Minimum password length shall be configurable to between [1] and [32] characters. 5.1.3.3 Pre-Shared Key Composition (MACSEC10:FIA_PSK_EXT.1) MACSEC10:FIA_PSK_EXT.1.1 The TSF shall use PSKs for MKA as defined by IEEE 802.1X-2020, [no other protocols]. (TD0825 applied) MACSEC10:FIA_PSK_EXT.1.2 The TSF shall be able to [accept] bit-based PSKs. 5.1.3.4 Protected Authentication Feedback (NDcPP30e:FIA_UAU.7) NDcPP30e:FIA_UAU.7.1 The TSF shall provide only obscured feedback to the administrative user while the authentication is in progress at the local console. 5.1.3.5 User Identification and Authentication - per TD0900 (NDcPP30e:FIA_UIA_EXT.1) NDcPP30e:FIA_UIA_EXT.1.1 The TSF shall allow the following actions prior to requiring the non-TOE entity to initiate the identification and authentication process: - Display the warning banner in accordance with FTA_TAB.1; - [no other actions]. NDcPP30e:FIA_UIA_EXT.1.2 The TSF shall require each administrative user to be successfully identified and authenticated before allowing any other TSF-mediated actions on behalf of that administrative user. NDcPP30e:FIA_UIA_EXT.1.3 The TSF shall provide the following remote authentication mechanisms [Web GUI password, SSH password, SSH public key] and [no other mechanism]. The TSF shall provide the following local authentication mechanisms [password-based]. (TD0900 applied) NDcPP30e:FIA_UIA_EXT.1.4 The TSF shall authenticate any administrative user's claimed identity according to each authentication mechanism specified in NDcPP30e:FIA_UIA_EXT.1.3. Hewlett Packard Enterprise’s CX-5420, CX-6200M, CX-6300, CX-6400, CX-8360, and CX-9300s Switch Series MACsec running AOS-CX version 10.16 Security Target Version 0.4, 08/17/2026 Page 24 of 44 5.1.3.6 X.509 Certificate Validation (NDcPP30e:FIA_X509_EXT.1/Rev) NDcPP30e:FIA_X509_EXT.1.1/Rev The TSF shall validate certificates in accordance with the following rules: - RFC 5280 certificate validation and certification path validation supporting a minimum path length of three certificates. - The certification path must terminate with a trusted CA certificate designated as a trust anchor. - The TSF shall validate a certification path by ensuring that all CA certificates in the certification path contain the basicConstraints extension with the CA flag set to TRUE. - The TSF shall validate the revocation status of the certificate using [the Online Certificate Status Protocol (OCSP) as specified in RFC 6960] - The TSF shall validate the extendedKeyUsage field according to the following rules: o Certificates used for trusted updates and executable code integrity verification shall have the Code Signing purpose (id-kp 3 with OID 1.3.6.1.5.5.7.3.3) in the extendedKeyUsage field. o Server certificates presented for DTLS/TLS shall have the Server Authentication purpose (id-kp 1 with OID 1.3.6.1.5.5.7.3.1) in the extendedKeyUsage field. o Client certificates presented for DTLS/TLS shall have the Client Authentication purpose (id-kp 2 with OID 1.3.6.1.5.5.7.3.2) in the extendedKeyUsage field. o OCSP certificates presented for OCSP responses shall have the OCSP Signing purpose (id-kp 9 with OID 1.3.6.1.5.5.7.3.9) in the extendedKeyUsage field. NDcPP30e:FIA_X509_EXT.1.2/Rev The TSF shall only treat a certificate as a CA certificate if the basicConstraints extension is present and the CA flag is set to TRUE. 5.1.3.7 X.509 Certificate Authentication (NDcPP30e:FIA_X509_EXT.2) NDcPP30e:FIA_X509_EXT.2.1 The TSF shall use X.509v3 certificates as defined by RFC 5280 to support authentication for [HTTPS, TLS], and [no additional uses]. NDcPP30e:FIA_X509_EXT.2.2 When the TSF cannot establish a connection to determine the validity of a certificate, the TSF shall [not accept the certificate]. 5.1.3.8 X.509 Certificate Requests (NDcPP30e:FIA_X509_EXT.3) NDcPP30e:FIA_X509_EXT.3.1 The TSF shall generate a Certification Request as specified by RFC 2986 and be able to provide the following information in the request: public key and [Common Name, Organization, Organizational Unit, Country]. NDcPP30e:FIA_X509_EXT.3.2 The TSF shall validate the chain of certificates from the Root CA upon receiving the CA Certificate Response. 5.1.4 Security management (FMT) 5.1.4.1 Management of Security Functions Behaviour (NDcPP30e:FMT_MOF.1/Functions) NDcPP30e:FMT_MOF.1.1/Functions The TSF shall restrict the ability to [determine the behaviour of, modify the behaviour of] the functions [transmission of audit data to an external IT entity] to Security Administrators. Hewlett Packard Enterprise’s CX-5420, CX-6200M, CX-6300, CX-6400, CX-8360, and CX-9300s Switch Series MACsec running AOS-CX version 10.16 Security Target Version 0.4, 08/17/2026 Page 25 of 44 5.1.4.2 Management of security functions behaviour (NDcPP30e:FMT_MOF.1/ManualUpdate) NDcPP30e:FMT_MOF.1.1/ManualUpdate The TSF shall restrict the ability to enable the functions to perform manual updates to Security Administrators. 5.1.4.3 Management of TSF Data (NDcPP30e:FMT_MTD.1/CoreData) NDcPP30e:FMT_MTD.1.1/CoreData The TSF shall restrict the ability to manage the TSF data to Security Administrators. 5.1.4.4 Management of TSF Data (NDcPP30e:FMT_MTD.1/CryptoKeys) NDcPP30e:FMT_MTD.1.1/CryptoKeys The TSF shall restrict the ability to manage the cryptographic keys to Security Administrators. 5.1.4.5 Specification of Management Functions - per TD0880 (NDcPP30e:FMT_SMF.1) NDcPP30e:FMT_SMF.1.1 The TSF shall be capable of performing the following management functions: - Ability to administer the TOE remotely; - Ability to configure the access banner; - Ability to configure the remote session inactivity time before session termination; - Ability to update the TOE, and to verify the updates using digital signature capability prior to installing those updates; - [Ability to modify the behavior of the transmission of audit data to an external IT entity, - Ability to manage the cryptographic keys, - Ability to configure the cryptographic functionality, - Ability to set the time which is used for time-stamps, - Ability to configure the reference identifier for the peer, - Ability to manage the TOE's trust store and designate X509.v3 certificates as trust anchors, - Ability to generate Certificate Signing Request (CSR) and process CA certificate response, - Ability to administer the TOE locally, - Ability to configure the local session inactivity time before session termination or locking, - Ability to configure the authentication failure parameters for FIA_AFL.1, - Ability to manage the trusted public keys database]. (TD0880 applied) 5.1.4.6 Specification of Management Functions (MACsec) - per TD0803, TD0840, & TD0889 (MACSEC10:FMT_SMF.1/MACSEC) MACSEC10:FMT_SMF.1.1/MACSEC The TSF shall be capable of performing the following management functions related to MACsec functionality: Ability of a Security Administrator to: - Manage a PSK-based CAK and install it in the device - Manage the key server to create, delete, and activate MKA participants [as specified in IEEE 802.1X-2020, Sections 9.13 and 9.16 (cf. MIB object ieee8021XKayMkaParticipant Entry) and section 12.2 (cf. function createMKA()] - Specify the lifetime of a CAK - Enable, disable, or delete a PSK-based CAK using [the MIB object ieee8021XKayMkaPartActivateControl] [No other MACsec management functions]. 5.1.4.7 Restrictions on Security Roles (NDcPP30e:FMT_SMR.2) NDcPP30e:FMT_SMR.2.1 The TSF shall maintain the roles: - Security Administrator. Hewlett Packard Enterprise’s CX-5420, CX-6200M, CX-6300, CX-6400, CX-8360, and CX-9300s Switch Series MACsec running AOS-CX version 10.16 Security Target Version 0.4, 08/17/2026 Page 26 of 44 NDcPP30e:FMT_SMR.2.2 The TSF shall be able to associate users with roles. NDcPP30e:FMT_SMR.2.3 The TSF shall ensure that the conditions - The Security Administrator role shall be able to administer the TOE remotely are satisfied. 5.1.5 Protection of the TSF (FPT) 5.1.5.1 Protection of Administrator Passwords (NDcPP30e:FPT_APW_EXT.1) NDcPP30e:FPT_APW_EXT.1.1 The TSF shall store administrative passwords in non-plaintext form. NDcPP30e:FPT_APW_EXT.1.2 The TSF shall prevent the reading of plaintext administrative passwords. 5.1.5.2 Protection of CAK Data (MACSEC10:FPT_CAK_EXT.1) MACSEC10:FPT_CAK_EXT.1.1 The TSF shall prevent reading of CAK values by administrators. 5.1.5.3 Failure with Preservation of Secure State - per TD0816 (MACSEC10:FPT_FLS.1) MACSEC10:FPT_FLS.1.1 The TSF shall fail-secure when any of the following types of failures occur: failure of the power- on self-tests, failure of integrity check of the TSF executable image, failure of noise source health tests. 5.1.5.4 Replay Detection - per TD0746 & TD0881 (MACSEC10:FPT_RPL.1) MACSEC10:FPT_RPL.1.1 The TSF shall detect replay for the following entities: MPDUs, MKA frames. MACSEC10:FPT_RPL.1.2 The TSF shall perform discarding of the replayed data, logging of the detected replay attempt when replay is detected. 5.1.5.5 Replay Detection for XPN - per TD0728 (MACSEC10:FPT_RPL_EXT.1) MACSEC10:FPT_RPL_EXT.1.1 The TSF shall support extended packet numbering (XPN) as per IEEE 802.1AE-2018. MACSEC10:FPT_RPL_EXT.1.2 The TSF shall support [GCM-AES-XPN-128, GCM-AES-XPN-256] as per IEEE 802.1AE-2018. 5.1.5.6 Protection of TSF Data (for reading of all symmetric keys) (NDcPP30e:FPT_SKP_EXT.1) NDcPP30e:FPT_SKP_EXT.1.1 The TSF shall prevent reading of all pre-shared keys, symmetric keys, and private keys. 5.1.5.7 Reliable Time Stamps (NDcPP30e:FPT_STM_EXT.1) NDcPP30e:FPT_STM_EXT.1.1 The TSF shall be able to provide reliable time stamps for its own use. NDcPP30e:FPT_STM_EXT.1.2 The TSF shall [allow the Security Administrator to set the time]. Hewlett Packard Enterprise’s CX-5420, CX-6200M, CX-6300, CX-6400, CX-8360, and CX-9300s Switch Series MACsec running AOS-CX version 10.16 Security Target Version 0.4, 08/17/2026 Page 27 of 44 5.1.5.8 TSF testing - per TD0836 (NDcPP30e:FPT_TST_EXT.1) NDcPP30e:FPT_TST_EXT.1.1 The TSF shall run a suite of the following self-tests: - During initial start-up (on power on) to verify the integrity of the TOE firmware and software - Prior to providing any cryptographic service and [at no other time] to verify correct operation of cryptographic implementation necessary to fulfil the TSF - [no other] self-tests [none] to demonstrate the correct operation of the TSF. (TD0836 applied) NDcPP30e:FPT_TST_EXT.1.2 The TSF shall respond to [all failures] by [rebooting]. 5.1.5.9 Trusted update (NDcPP30e:FPT_TUD_EXT.1) NDcPP30e:FPT_TUD_EXT.1.1 The TSF shall provide Security Administrators the ability to query the currently executing version of the TOE firmware/software and [the most recently installed version of the TOE firmware/software]. NDcPP30e:FPT_TUD_EXT.1.2 The TSF shall provide Security Administrators the ability to manually initiate updates to TOE firmware/software and [no other update mechanism]. NDcPP30e:FPT_TUD_EXT.1.3 The TSF shall provide means to authenticate firmware/software updates to the TOE using a [digital signature] prior to installing those updates. 5.1.6 TOE access (FTA) 5.1.6.1 TSF-initiated Termination (NDcPP30e:FTA_SSL.3) NDcPP30e:FTA_SSL.3.1 The TSF shall terminate a remote interactive session after a Security Administrator-configurable time interval of session inactivity. 5.1.6.2 User-initiated Termination (NDcPP30e:FTA_SSL.4) NDcPP30e:FTA_SSL.4.1 The TSF shall allow Administrator-initiated termination of the Administrator's own interactive session. 5.1.6.3 TSF-initiated Session Locking (NDcPP30e:FTA_SSL_EXT.1) NDcPP30e:FTA_SSL_EXT.1.1 The TSF shall, for local interactive sessions, [terminate the session] after a Security Administrator-specified time period of inactivity. 5.1.6.4 Default TOE Access Banners (NDcPP30e:FTA_TAB.1) NDcPP30e:FTA_TAB.1.1 Before establishing an administrative user session the TSF shall display a Security Administrator- specified advisory notice and consent warning message regarding use of the TOE. Hewlett Packard Enterprise’s CX-5420, CX-6200M, CX-6300, CX-6400, CX-8360, and CX-9300s Switch Series MACsec running AOS-CX version 10.16 Security Target Version 0.4, 08/17/2026 Page 28 of 44 5.1.7 Trusted path/channels (FTP) 5.1.7.1 Inter-TSF trusted channel (NDcPP30e:FTP_ITC.1) NDcPP30e:FTP_ITC.1.1 The TSF shall be capable of using [TLS] to provide a trusted communication channel between itself and authorized IT entities supporting the following capabilities: audit server, [no other capabilities] that is logically distinct from other communication channels and provides assured identification of its end points and protection of the channel data from disclosure and detection of modification of the channel data. NDcPP30e:FTP_ITC.1.2 The TSF shall permit [the TSF] to initiate communication via the trusted channel. NDcPP30e:FTP_ITC.1.3 The TSF shall initiate communication via the trusted channel for [audit server communications]. 5.1.7.2 Inter-TSF Trusted Channel (MACsec Communications) (MACSEC10:FTP_ITC.1/MACSEC) MACSEC10:FTP_ITC.1.1/MACSEC The TSF shall provide a communication channel between itself and a MACsec peer that is logically distinct from other communication channels and provides assured identification of its end points and protection of the channel data from modification or disclosure. MACSEC10:FTP_ITC.1.2/MACSEC The TSF shall permit [the TSF] to initiate communication via the trusted channel. MACSEC10:FTP_ITC.1.3/MACSEC The TSF shall initiate communication via the trusted channel for communications with MACsec peers that require the use of MACsec. 5.1.7.3 Trusted Path (NDcPP30e:FTP_TRP.1/Admin) NDcPP30e:FTP_TRP.1.1/Admin The TSF shall be capable of using [SSH, TLS, HTTPS] to provide a communication path between itself and authorized remote Administrators that is logically distinct from other communication paths and provides assured identification of its end points and protection of the communicated data from disclosure and provides detection of modification of the channel data. NDcPP30e:FTP_TRP.1.2/Admin The TSF shall permit remote Administrators to initiate communication via the trusted path. NDcPP30e:FTP_TRP.1.3/Admin The TSF shall require the use of the trusted path for initial Administrator authentication and all remote administration actions. 5.2 TOE Security Assurance Requirements The SARs for the TOE are the components as specified in Part 3 of the Common Criteria. Note that the SARs have effectively been refined with the assurance activities explicitly defined in association with both the SFRs and SARs. Requirement Class Requirement Component ADV: Development ADV_FSP.1: Basic functional specification AGD: Guidance documents AGD_OPE.1: Operational user guidance AGD_PRE.1: Preparative procedures ALC: Life-cycle support ALC_CMC.1: Labelling of the TOE ALC_CMS.1: TOE CM coverage ATE: Tests ATE_IND.1: Independent testing - conformance AVA: Vulnerability assessment AVA_VAN.1: Vulnerability survey Hewlett Packard Enterprise’s CX-5420, CX-6200M, CX-6300, CX-6400, CX-8360, and CX-9300s Switch Series MACsec running AOS-CX version 10.16 Security Target Version 0.4, 08/17/2026 Page 29 of 44 Table 6 Assurance Components 5.2.1 Development (ADV) 5.2.1.1 Basic functional specification (ADV_FSP.1) ADV_FSP.1.1d The developer shall provide a functional specification. ADV_FSP.1.2d The developer shall provide a tracing from the functional specification to the SFRs. ADV_FSP.1.1c The functional specification shall describe the purpose and method of use for each SFR-enforcing and SFR-supporting TSFI. ADV_FSP.1.2c The functional specification shall identify all parameters associated with each SFR-enforcing and SFR-supporting TSFI. ADV_FSP.1.3c The functional specification shall provide rationale for the implicit categorisation of interfaces as SFR-non-interfering. ADV_FSP.1.4c The tracing shall demonstrate that the SFRs trace to TSFIs in the functional specification. ADV_FSP.1.1e The evaluator shall confirm that the information provided meets all requirements for content and presentation of evidence. ADV_FSP.1.2e The evaluator shall determine that the functional specification is an accurate and complete instantiation of the SFRs. 5.2.2 Guidance documents (AGD) 5.2.2.1 Operational user guidance (AGD_OPE.1) AGD_OPE.1.1d The developer shall provide operational user guidance. AGD_OPE.1.1c The operational user guidance shall describe, for each user role, the user-accessible functions and privileges that should be controlled in a secure processing environment, including appropriate warnings. AGD_OPE.1.2c The operational user guidance shall describe, for each user role, how to use the available interfaces provided by the TOE in a secure manner. AGD_OPE.1.3c The operational user guidance shall describe, for each user role, the available functions and interfaces, in particular all security parameters under the control of the user, indicating secure values as appropriate. AGD_OPE.1.4c The operational user guidance shall, for each user role, clearly present each type of security- relevant event relative to the user-accessible functions that need to be performed, including changing the security characteristics of entities under the control of the TSF. AGD_OPE.1.5c The operational user guidance shall identify all possible modes of operation of the TOE (including operation following failure or operational error), their consequences and implications for maintaining secure operation. Hewlett Packard Enterprise’s CX-5420, CX-6200M, CX-6300, CX-6400, CX-8360, and CX-9300s Switch Series MACsec running AOS-CX version 10.16 Security Target Version 0.4, 08/17/2026 Page 30 of 44 AGD_OPE.1.6c The operational user guidance shall, for each user role, describe the security measures to be followed in order to fulfil the security objectives for the operational environment as described in the ST. AGD_OPE.1.7c The operational user guidance shall be clear and reasonable. AGD_OPE.1.1e The evaluator shall confirm that the information provided meets all requirements for content and presentation of evidence. 5.2.2.2 Preparative procedures (AGD_PRE.1) AGD_PRE.1.1d The developer shall provide the TOE including its preparative procedures. AGD_PRE.1.1c The preparative procedures shall describe all the steps necessary for secure acceptance of the delivered TOE in accordance with the developer's delivery procedures. AGD_PRE.1.2c The preparative procedures shall describe all the steps necessary for secure installation of the TOE and for the secure preparation of the operational environment in accordance with the security objectives for the operational environment as described in the ST. AGD_PRE.1.1e The evaluator shall confirm that the information provided meets all requirements for content and presentation of evidence. AGD_PRE.1.2e The evaluator shall apply the preparative procedures to confirm that the TOE can be prepared securely for operation. 5.2.3 Life-cycle support (ALC) 5.2.3.1 Labelling of the TOE (ALC_CMC.1) ALC_CMC.1.1d The developer shall provide the TOE and a reference for the TOE. ALC_CMC.1.1c The TOE shall be labelled with its unique reference. ALC_CMC.1.1e The evaluator shall confirm that the information provided meets all requirements for content and presentation of evidence. 5.2.3.2 TOE CM coverage (ALC_CMS.1) ALC_CMS.1.1d The developer shall provide a configuration list for the TOE. ALC_CMS.1.1c The configuration list shall include the following: the TOE itself; and the evaluation evidence required by the SARs. ALC_CMS.1.2c The configuration list shall uniquely identify the configuration items. ALC_CMS.1.1e The evaluator shall confirm that the information provided meets all requirements for content and presentation of evidence. Hewlett Packard Enterprise’s CX-5420, CX-6200M, CX-6300, CX-6400, CX-8360, and CX-9300s Switch Series MACsec running AOS-CX version 10.16 Security Target Version 0.4, 08/17/2026 Page 31 of 44 5.2.4 Tests (ATE) 5.2.4.1 Independent testing - conformance (ATE_IND.1) ATE_IND.1.1d The developer shall provide the TOE for testing. ATE_IND.1.1c The TOE shall be suitable for testing. ATE_IND.1.1e The evaluator shall confirm that the information provided meets all requirements for content and presentation of evidence. ATE_IND.1.2e The evaluator shall test a subset of the TSF to confirm that the TSF operates as specified. 5.2.5 Vulnerability assessment (AVA) 5.2.5.1 Vulnerability survey (AVA_VAN.1) AVA_VAN.1.1d The developer shall provide the TOE for testing. AVA_VAN.1.1c The TOE shall be suitable for testing. AVA_VAN.1.1e The evaluator shall confirm that the information provided meets all requirements for content and presentation of evidence. AVA_VAN.1.2e The evaluator shall perform a search of public domain sources to identify potential vulnerabilities in the TOE. AVA_VAN.1.3e The evaluator shall conduct penetration testing, based on the identified potential vulnerabilities, to determine that the TOE is resistant to attacks performed by an attacker possessing Basic attack potential. Hewlett Packard Enterprise’s CX-5420, CX-6200M, CX-6300, CX-6400, CX-8360, and CX-9300s Switch Series MACsec running AOS-CX version 10.16 Security Target Version 0.4, 08/17/2026 Page 32 of 44 6. TOE Summary Specification This chapter describes the security functions: - Security audit - Cryptographic support - Identification and authentication - Security management - Protection of the TSF - TOE access - Trusted path/channels 6.1 Security audit The TOE is a standalone device that is able to generate and store audit records of security relevant events as they occur. The events that can cause an audit record to be logged include starting and stopping the audit function, any use of an administrator command via the CLI interface, as well as all of the events identified in Tables 4 and 5. Audit logs are stored as strings and have a format which includes the severity, date and time of the event, the nature or type of the triggering event, an indication of whether the event succeeded, failed or had some other outcome, and the identity of the agent responsible for the event. The audit records are protected against unauthorized access by only allowing authorized administrators to have access to local audit logs, perform an authorized deletion of those logs, or modify the behavior of audit data transmission. The logged audit records also include event-specific content that includes at least all of the content required in Tables 4 and 5. For cryptographic keys, the act of importing a key is audited and the associated administrator account that performed the action is recorded. The TOE supports storage of local audit records visible through CLI commands. The accounting log is visible using the command "show accounting log" while the event log is visible using the command "show logging". Once the TOE is capable of rotating through a set of compressed files for each log type. The TOE will check periodically to determine whether or not to rotate its logs based upon log size. The TOE fills one file, the TOE rotates the contents of the current log into a compressed file, while rotating previously compressed files until finally deleting the oldest compressed file. The accounting log predominately includes the TOE’s audit records of CLI commands. The event log holds all other audit records. The administrator can configure the TOE to export all audit data to an external syslog server through a TLS protected connection. The TOE stores audit records related to client SSH public key operations (add/remove), time/date changes, and trusted updates (initiation and success/failure) in its event log. Once configured to export audit records, the TOE attempts to transmit all logs in real-time, will temporarily maintain unsent records in the event of a disrupted syslog connection, and sends those records when the remote audit server successfully reestablishes the connection. The TOE uses the TLS protocol to protect audit records transmitted to the external syslog server. The Security audit function satisfies the following security functional requirements: NDcPP30e/MACSEC10:FAU_GEN.1: Each audit record identifies the date/time, event type, outcome of the event, responsible subject/user, as well as the additional event-specific content indicated in Tables 4 and 5. When logging the administrative tasks of generating/importing/deleting MACsec PSKs, the TOE logs the type of key and its SHA256 hash as the key identifier. NDcPP30e:FAU_GEN.2: The TOE identifies the responsible user for each event based on the specific administrator or network entity (identified by IP address) that caused the event. Hewlett Packard Enterprise’s CX-5420, CX-6200M, CX-6300, CX-6400, CX-8360, and CX-9300s Switch Series MACsec running AOS-CX version 10.16 Security Target Version 0.4, 08/17/2026 Page 33 of 44 NDcPP30e:FAU_STG_EXT.1: The TOE can be configured to export audit records to an external SYSLOG server. This communication is protected with TLS 6.2 Cryptographic support The TOE includes the Hewlett Packard Enterprise OpenSSL 3 Provider version 3.1.4a to perform cryptographic operations. The network interface chipsets perform the AES-GCM data encryption for MACsec. The following functions have been CAVP certified. Functions Requirement Standard Certificate # Encryption/Decryption AES CBC (128 and 256 bits) FCS_COP.1/DataEncryption FIPS Pub 197 ISO 10116 NIST SP 800-38A A4803 AES-CTR (128 and 256 bits) FCS_COP.1/DataEncryption FIPS Pub 197 ISO 10116 NIST SP 800-38A A4803 AES GCM (128 and 256 bits) FCS_COP.1/DataEncryption ISO 19772 FIPS Pub 197 NIST SP 800- 38D A4803 Cryptographic hashing SHA-256, SHA-384, SHA-512 (digest sizes 256, 384 and 512 bits) FCS_COP.1/Hash FIPS Pub 180-4 ISO/IEC 10118- 3:2004 A4803 Keyed-hash message authentication HMAC-SHA-256, HMAC-SHA- 384, HMAC-SHA-512 (key and digest sizes of 256, 384 and 512 bits) FCS_COP.1/KeyedHash FIPS Pub 198-1 FIPS Pub 180-4 ISO/IEC 9797- 2:2011 A4803 Cryptographic signature services RSA Digital Signature (rDSA) (2048, 3072 bits) FCS_COP.1/SigGen FIPS Pub 186-4 A4803 ECDSA Digital Signature (P-256, P-384, P-521) FCS_COP.1/SigGen FIPS Pub 186-4 ISO/IEC 14888- 3 A4803 Random bit generation CTR_DRBG(AES) with sw based noise sources with a minimum of 256 bits of entropy FCS_RBG_EXT.1 NIST SP 800-90A ISO/IEC 18031:2011 A4803 Key generation RSA Key Generation (2048-bit) FCS_CKM.1 FIPS Pub 186-4 ISO/IEC 9796-2 A4803 ECC Key Generation (P-256, P- 384, P-521) FCS_CKM.1 FIPS PUB 186-4 A4803 Key establishment RSA FCS_CKM.2 RSAES-PKCS1- v1_5 Tested with known good implementation KAS ECC P-256, P-384, P-521 FCS_CKM.2 NIST SP 800-56A Rev 3 A4803 Hewlett Packard Enterprise’s CX-5420, CX-6200M, CX-6300, CX-6400, CX-8360, and CX-9300s Switch Series MACsec running AOS-CX version 10.16 Security Target Version 0.4, 08/17/2026 Page 34 of 44 Functions Requirement Standard Certificate # MACsec AES-CMAC 128 & 256 bits FCS_COP.1/CMAC SP 800-38B A4803 AES Key Wrap 128 & 256 bits FCS_COP.1/MACSEC SP 800-38F (wrap) A4803 AES GCM 128 & 256 bits FCS_COP.1/MACSEC ISO 19772 NIST SP 800-38D C1877, C1869, AES 4550, AES 4545, AES 4544 Table 7 TOE Cryptographic Algorithms The product implements and uses an SP 800-90A AES-256 CTR_DRBG. NDcPP30e:FCS_CKM.1/2: Table 8 Key Establishment Methods indicates that the TOE supports RSA key generation using 2048-bit keys, and ECC key generation using curves P-256, P-384 and P-521. These can be used to generate keys for use with a Certificate Signing Request, as well as in support of key establishment methods identified by Table 8. For asymmetric key pairs used for authentication, the TOE can generate ECDSA SSH host keys (public and private) of size P-256, P-384, and P-521 and can, upon command, regenerate a new ECDSA host key. Additionally, the administrator can load and remove user SSH public keys that the TOE will use to authenticate SSH clients. The TOE is capable of generating RSA and ECDSA key pairs for use with a certificate signing requests. For TLS, the TOE generates ECDH asymmetric keys as part of TLS key establishment during TLS negotiations. The TOE acts a client and as a server with the TLS protocol. For asymmetric key pairs used for key exchange, the TOE supports generating ephemeral ECDH keys for the SSHv2 key exchange methods selected in FCS_SSHS_EXT.1.7. This implies that the TOE generates ephemeral 256/384-bit ECDH keys using ECC schemes for P-256/384 curves. Because the TOE is an SSH server, it always acts as the recipient/responder in the key exchange process. Key Establishment Scheme SFR Service ECDHE FCS_SSHS_EXT.1 Remote Administration ECDHE, RSA FCS_TLSC_EXT.1 Audit Server communication ECDHE, RSA FCS_TLSS_EXT.1 Remote Administration Table 8 Key Establishment Methods NDcPP30e:FCS_CKM.4: The following table presents the crypto security parameters (CSPs), secret keys, and private keys provided by the TOE. The table also identifies when each CSP or key is cleared. CSP or Key: Stored in Zeroized upon: Zeroized by: SSH host ECDSA private key On Disk Command Overwriting with zeros SSH host ECDSA public key On Disk Command Overwriting with zeros SSH client ECDSA public key On Disk Command Overwriting with zeros SSH session key In Memory Close of session Overwriting with zeros TLS session key In Memory Close of session Overwriting with zeros Password hash On Disk Command Overwriting with zeros Table 9 Key Zeroziation Keys are zeroized when they are no longer needed by the TOE, and additionally, the TOE saves keys to persistent storage. Whether saving or destroying keys, the TOE delays the operation at the physical layer until the administrator issues the “write memory” command, which saves the running configuration to the startup configuration. Hewlett Packard Enterprise’s CX-5420, CX-6200M, CX-6300, CX-6400, CX-8360, and CX-9300s Switch Series MACsec running AOS-CX version 10.16 Security Target Version 0.4, 08/17/2026 Page 35 of 44 MACSEC10:FCS_COP.1/CMAC: The TOE supports keyed-hash message authentication in accordance with AES- CMAC algorithm with key sizes 128 bits and 256 bits, the message digest size (output size) of 128 bits and block size of 128-bits. The algorithm conforms to NIST SP 800-38B. NDcPP30e:FCS_COP.1/DataEncryption: As seen in Error! Reference source not found. above, the TOE supports the CBC and CTR modes of AES as available ciphers for SSH and GCM mode for TLS ciphersuites (all with both 128 and 256-bit keys). NDcPP30e:FCS_COP.1/Hash: The TOE uses the SHA-256, 384, and 512 hashing algorithms as part of SSHv2 integrity algorithms (see FCS_SSHS_EXT.1.6) and TLS ciphersuites. The TOE also uses SHA-256 during verification of a new image (trusted updates). NDcPP30e:FCS_COP.1/KeyedHash: The TOE uses the HMAC algorithms described below as part of SSHv2 (for integrity) and TLS. HMAC Algorithm Hash Alg Key size Block Size Output MAC HMAC-SHA-256 SHA-256 256 512 256 bits HMAC-SHA-384 SHA-384 384 1024 384 bits HMAC-SHA-512 SHA-512 512 1024 512 bits Table 10 HMAC Details MACSEC10:FCS_COP.1/MACSEC: The TOE performs AES key wrap with AES-GCM. AES is specified in ISO 18033-3, AES Key Wrap is specified in NIST SP 800-38F, GCM is specified in ISO 19772. NDcPP22e:FCS_COP.1/SigGen: As seen in Functions Requirement Standard Certificate # Encryption/Decryption AES CBC (128 and 256 bits) FCS_COP.1/DataEncryption FIPS Pub 197 ISO 10116 NIST SP 800-38A A4803 AES-CTR (128 and 256 bits) FCS_COP.1/DataEncryption FIPS Pub 197 ISO 10116 NIST SP 800-38A A4803 AES GCM (128 and 256 bits) FCS_COP.1/DataEncryption ISO 19772 FIPS Pub 197 NIST SP 800- 38D A4803 Cryptographic hashing SHA-256, SHA-384, SHA-512 (digest sizes 256, 384 and 512 bits) FCS_COP.1/Hash FIPS Pub 180-4 ISO/IEC 10118- 3:2004 A4803 Keyed-hash message authentication HMAC-SHA-256, HMAC-SHA- 384, HMAC-SHA-512 (key and digest sizes of 256, 384 and 512 bits) FCS_COP.1/KeyedHash FIPS Pub 198-1 FIPS Pub 180-4 ISO/IEC 9797- 2:2011 A4803 Cryptographic signature services RSA Digital Signature (rDSA) (2048, 3072 bits) FCS_COP.1/SigGen FIPS Pub 186-4 A4803 ECDSA Digital Signature (P-256, P-384, P-521) FCS_COP.1/SigGen FIPS Pub 186-4 ISO/IEC 14888- 3 A4803 Random bit generation Hewlett Packard Enterprise’s CX-5420, CX-6200M, CX-6300, CX-6400, CX-8360, and CX-9300s Switch Series MACsec running AOS-CX version 10.16 Security Target Version 0.4, 08/17/2026 Page 36 of 44 Functions Requirement Standard Certificate # CTR_DRBG(AES) with sw based noise sources with a minimum of 256 bits of entropy FCS_RBG_EXT.1 NIST SP 800-90A ISO/IEC 18031:2011 A4803 Key generation RSA Key Generation (2048-bit) FCS_CKM.1 FIPS Pub 186-4 ISO/IEC 9796-2 A4803 ECC Key Generation (P-256, P- 384, P-521) FCS_CKM.1 FIPS PUB 186-4 A4803 Key establishment RSA FCS_CKM.2 RSAES-PKCS1- v1_5 Tested with known good implementation KAS ECC P-256, P-384, P-521 FCS_CKM.2 NIST SP 800-56A Rev 3 A4803 MACsec AES-CMAC 128 & 256 bits FCS_COP.1/CMAC SP 800-38B A4803 AES Key Wrap 128 & 256 bits FCS_COP.1/MACSEC SP 800-38F (wrap) A4803 AES GCM 128 & 256 bits FCS_COP.1/MACSEC ISO 19772 NIST SP 800-38D C1877, C1869, AES 4550, AES 4545, AES 4544 Table 7 above, the TOE supports both RSA and ECDSA signing and verification. The TOE verifies RSA signatures on firmware updates (see FPT_TUD_EXT.1 in 6.5 below) and supports ECDSA authentication during SSH. NDcPP30e:FCS_HTTPS_EXT.1: An HTTPS/TLS connection is available which presents Web GUI and Rest API administrative interfaces. The TOE implements HTTPS per RFC 2818. A connection can be established only if the peer initiates the connection. MACSEC10:FCS_MACSEC_EXT.1: The TOE implements MACsec in accordance with IEEE 802.1AE-2018. The TOE derives a Secure Channel Identifier (SCI) from a peer's MAC address and port data to uniquely identify the originator of a MACsec Protocol Data Unit (MPDU) and rejects any MPDUs that do not contain the identifier. Once configured on an interface, only EAPOL (PAE EtherType 88-8E), MACsec Ethernet frames (EtherType 88-E5) and MAC control frames are permitted and others are rejected. MACSEC10:FCS_MACSEC_EXT.2: The TOE implements MACsec with support for integrity protection with a confidentiality offset of 0, 30, 50. The TSF provides assurance of the integrity of protocol data units (MPDUs) using an Integrity Check Value (ICV) of 16 bytes derived with the Secure Association Key (SAK). The TOE provides the ability to derive an Integrity Check Value Key (ICK) from a CAK using a KDF, using the SCI as the most significant bits of the Initialization Vector (IV) and the 32 least significant bits of the PN as the IV. The ICV is derived from the SCI and PN. This forms the 96-bit IV used by GCM. MACSEC10:FCS_MACSEC_EXT.3: The TOE generates unique Secure Association Keys (SAKs) using key derivation from Connectivity Association Key (CAK) per section 9.8.1 of IEEE 802.1X-2010 and the TOE’s random bit generator as specified by FCS_RBG_EXT.1 such that the likelihood of a repeating SAK is no less than 1 in 2 to the power of the size of the generated key. The TOE generates unique nonce for the derivation of SAKs using the TOE’s random bit generator as specified by FCS_RBG_EXT.1. MACSEC10:FCS_MACSEC_EXT.4: The TOE supports peer authentication using only pre-shared keys. The TOE distributes SAKs between MACsec peers using AES key wrap as specified in FCS_COP.1/MACSEC. The TOE supports specifying a lifetime for CAKs. The TOE associates Connectivity Association Key Names (CKNs) with CAKs that are defined by the key derivation function using the CAK as input data (per 802.1X, section 9.8.1). The Hewlett Packard Enterprise’s CX-5420, CX-6200M, CX-6300, CX-6400, CX-8360, and CX-9300s Switch Series MACsec running AOS-CX version 10.16 Security Target Version 0.4, 08/17/2026 Page 37 of 44 TOE associates Connectivity Association Key Names (CKNs) with CAKs. The length of the CKN is an integer number of octets, between 1 and 32 (inclusive). MACSEC10:FCS_MKA_EXT.1: The TOE implements Key Agreement Protocol (MKA) in accordance with IEEE 802.1X-2010 and 802.1Xbx-2014. The TOE enables data delay protection for MKA. The TOE provides assurance of the integrity of MKA protocol data units (MKPDUs) using an Integrity Check Value (ICV) derived from an Integrity Check Value Key (ICK). The TOE provides the ability to derive an Integrity Check Value Key (ICK) from a CAK using a KDF. The TOE enforces an MKA Lifetime Timeout limit of 6.0 seconds and Hello Timeout limit of 2.0 seconds. The TOE behaves as a Key Server. The Key Server refreshes a SAK when it expires. The Key Server distributes a SAK by using a pairwise CAK. The pairwise CAK is derived from MKA or a pre-shared key. The Key Server refreshes a CAK when it expires. The Key Server distributes a fresh SAK whenever a member is added to or removed from the live membership of the CA. The TOE validates MKPDUs according to 802.1X-2010, Section 11.11.2. In particular, the TOE discards without further processing any MKPDUs to which any of the following conditions apply: a) The destination address of the MKPDU was an individual address. b) The MKPDU is less than 32 octets long. c) The MKPDU is not a multiple of 4 octets long. d) The MKPDU comprises fewer octets than indicated by the Basic Parameter Set body length, as encoded in bits 4 through 1 of octet 3 and bits 8 through 1 of octet 4, plus 16 octets of ICV. e) The CAK Name is not recognized. If an MKPDU passes these tests, then the TOE begins processing it as follows: a) If the Algorithm Agility parameter identifies an algorithm that has been implemented by the receiver, the ICV shall be verified as specified in IEEE 802.1X-2010 Section 9.4.1. b) If the Algorithm Agility parameter is unrecognized or not implemented by the receiver, its value can be recorded for diagnosis but the received MKPDU shall be discarded without further processing. Each received MKPDU that is validated as specified in this clause and verified as specified in 802.1X-2010, section 9.4.1 shall be decoded as specified in 802.1X-2010, section 11.11.4. When Data Delay Protection (DDP) is enabled, MKA PDUs are exchanged every 0.5 seconds instead of every 2.0 seconds. The PN advertised by the peer is updated as the LPN in the Rx channel of the TOE. NDcPP30e:FCS_RBG_EXT.1: See Functions Requirement Standard Certificate # Encryption/Decryption AES CBC (128 and 256 bits) FCS_COP.1/DataEncryption FIPS Pub 197 ISO 10116 NIST SP 800-38A A4803 AES-CTR (128 and 256 bits) FCS_COP.1/DataEncryption FIPS Pub 197 ISO 10116 NIST SP 800-38A A4803 AES GCM (128 and 256 bits) FCS_COP.1/DataEncryption ISO 19772 FIPS Pub 197 NIST SP 800- 38D A4803 Cryptographic hashing SHA-256, SHA-384, SHA-512 (digest sizes 256, 384 and 512 bits) FCS_COP.1/Hash FIPS Pub 180-4 ISO/IEC 10118- 3:2004 A4803 Hewlett Packard Enterprise’s CX-5420, CX-6200M, CX-6300, CX-6400, CX-8360, and CX-9300s Switch Series MACsec running AOS-CX version 10.16 Security Target Version 0.4, 08/17/2026 Page 38 of 44 Functions Requirement Standard Certificate # Keyed-hash message authentication HMAC-SHA-256, HMAC-SHA- 384, HMAC-SHA-512 (key and digest sizes of 256, 384 and 512 bits) FCS_COP.1/KeyedHash FIPS Pub 198-1 FIPS Pub 180-4 ISO/IEC 9797- 2:2011 A4803 Cryptographic signature services RSA Digital Signature (rDSA) (2048, 3072 bits) FCS_COP.1/SigGen FIPS Pub 186-4 A4803 ECDSA Digital Signature (P-256, P-384, P-521) FCS_COP.1/SigGen FIPS Pub 186-4 ISO/IEC 14888- 3 A4803 Random bit generation CTR_DRBG(AES) with sw based noise sources with a minimum of 256 bits of entropy FCS_RBG_EXT.1 NIST SP 800-90A ISO/IEC 18031:2011 A4803 Key generation RSA Key Generation (2048-bit) FCS_CKM.1 FIPS Pub 186-4 ISO/IEC 9796-2 A4803 ECC Key Generation (P-256, P- 384, P-521) FCS_CKM.1 FIPS PUB 186-4 A4803 Key establishment RSA FCS_CKM.2 RSAES-PKCS1- v1_5 Tested with known good implementation KAS ECC P-256, P-384, P-521 FCS_CKM.2 NIST SP 800-56A Rev 3 A4803 MACsec AES-CMAC 128 & 256 bits FCS_COP.1/CMAC SP 800-38B A4803 AES Key Wrap 128 & 256 bits FCS_COP.1/MACSEC SP 800-38F (wrap) A4803 AES GCM 128 & 256 bits FCS_COP.1/MACSEC ISO 19772 NIST SP 800-38D C1877, C1869, AES 4550, AES 4545, AES 4544 Table 7 above. The TOE instantiates it’s AES-256 CTR_DRBG with a 384-bit seed (containing a minimum of 256 bits of entropy) from one software-based noise source. NDcPP30e:FCS_SSH_EXT.1 & FCS_SSHS_EXT.1: The TOE supports SSHv2 interactive command-line secure administrator sessions and syslog export as indicated above. The TOE implements the SSHv2 protocol, compliant to the following RFCs: 4251, 4252, 4253, 4254, 5656, 6668. The TOE supports public key-based and password-based authentication. The TOE allows use of the ecdsa-sha2-nistp256, ecdsa-sha2-nistp384, and ecdsa-sha2-nistp521 algorithms for both host and user public key authentication. The TOE establishes a user identity when an SSH client presents a public key or correct password. The TOE supports AES-CBC and AES-CTR (both 128 and 256 keyed variants) ciphers for data encryption and hmac-sha2-256/sha2-512 for data integrity (and does not allow the “none” MAC algorithm). The TOE uses ecdh-sha2-nistp256/384 for SSHv2 key exchange. The TOE’s SSHv2 implementation limits SSH packets to a size of 262127 kilobytes. Anything larger will be dropped by the TOE. The TOE initiates a rekey before 1 hour has passes or before 1GB of data transfer occurs, whichever comes first. Hewlett Packard Enterprise’s CX-5420, CX-6200M, CX-6300, CX-6400, CX-8360, and CX-9300s Switch Series MACsec running AOS-CX version 10.16 Security Target Version 0.4, 08/17/2026 Page 39 of 44 NDcPP30e:FCS_TLSC_EXT.1: The TOE provides TLS v1.2 & TLS v1.3 for use when exporting audit records to a SYSLOG server. The following ciphersuites are supported by default and are not configurable when in the evaluated configuration: • TLS _RSA_WITH_AES_128_GCM_SHA256, • TLS _RSA_WITH_AES_256_GCM_SHA384, • TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256, • TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384, • TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256, • TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384, • TLS_AES_128_GCM_SHA256, • TLS_AES_256_GCM_SHA384, • TLS_AES_128_CCM_SHA256, • TLS_AES_128_CCM_8_SHA256 The TOE does not support certificate pinning. The TOE supports the use of FQDN and IPv4 addresses as reference identifiers within a certificate’s CommonName (CN) or Subject Alternate Name (SAN) extension. The TOE checks the SAN/CN when performing certificate validation as described in NDcPP30e:FIA_X509_EXT.1/Rev. Wildcards are allowed in certificates. IP addresses are converted to binary by parsing decimal delimited by periods. The conversion happens before any comparisons are made. Canonical format is enforced. Key exchanges using elliptical curves P-256, P-384, and P-521 are supported. The signature_algorithms extension presented supports the rsa_pkcs1 with sha256(0x0401), rsa_pkcs1with sha384(0x0501), rsa_pkcs1 with sha512(0x0601), ecdsa_secp256r1 with sha256(0x0403), ecdsa_secp384r1 with sha384(0x0503), ecdsa_secp521r1 with sha512(0x0603), rsa_pss_rsae with sha256(0x0804), rsa_pss_rsae with sha384(0x0805), rsa_pss_rsae with sha512(0x0806), rsa_pss_pss with sha256(0x0809), rsa_pss_pss with sha384(0x080a), rsa_pss_pss with sha512(0x080b) algorithms.For TLS 1.3, the TOE shall not permit out-of-band provisioning of pre-shared keys (PSKs) in the evaluated configuration. These are not configurable. NDcPP30e:FCS_TLSC_EXT.2: The TOE can be configured with an X509 certificate which it will send to a TLS server in response to a certificate request message sent by the TLS server. NDcPP30e:FCS_TLSS_EXT.1: An HTTPS/TLS connection is available which presents a Web GUI and REST API administrative interface. Thus, the TOE acts as a TLS server supporting TLSv1.2 & TLSv1.3 only. No older versions of TLS, and no version of SSL are supported. The TOE supports the following ciphersuites: • TLS_RSA_WITH_AES_256_GCM_SHA384, • TLS_RSA_WITH_AES_128_GCM_SHA256, • TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256, • TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384, • TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256, and • TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384. • TLS_AES_128_GCM_SHA256, • TLS_AES_256_GCM_SHA384, • TLS_AES_128_CCM_SHA256, • TLS_AES_128_CCM_8_SHA256 These ciphersuites are not configurable. ECDSA key exchanges using secp256r1, secp384r1, and secp521r1 are supported, in addition to RSA key sizes 2048, 3072, and 4096. Key exchanges are not configurable. The TOE does support session resumption using session ID values. For TLS 1.3, the TOE shall not permit out-of-band provisioning of pre-shared keys (PSKs) in the evaluated configuration; this is not configurable. Hewlett Packard Enterprise’s CX-5420, CX-6200M, CX-6300, CX-6400, CX-8360, and CX-9300s Switch Series MACsec running AOS-CX version 10.16 Security Target Version 0.4, 08/17/2026 Page 40 of 44 6.3 Identification and authentication The TOE requires users to be identified and authenticated before they can access any of the TOE functions except to display a warning banner and to permit network switching services without identification or authentication. In the evaluated configuration, users can connect to the TOE via a local console or remotely using SSHv2, WebUI or REST API. The user is required to log in prior to successfully establishing a session through which TOE functions can be exercised. Passwords can be composed of any alphabetic, numeric, and a wide range of special characters (identified in FIA_PMG_EXT.1). Required minimum password length can be configured by an administrator to be between 1- 32 characters. Passwords may be comprised of any uppercase and lowercase characters, and the following special characters: '!', '@', '#', '$', '%', '^', '&', '*', '(', ')', ['`', '+', '-', '.', '/', ':', ';', '<', '>', '=', '?', '[', ']', '_', ''', '_ '|', '~’. When logging in the TOE will not echo passwords so that passwords are not inadvertently displayed to the user and any other users that might be able to view the login display. The Authorized Administrator can set a lockout failure count for login attempts as the TOE’s default configuration does not enforce a failed login limit. If the count is exceeded, the targeted account is locked (preventing remote administrators from logging in through SSH under the locked account/username) for an administrator-configurable time limit. Note that the TOE does not lock administrative access through local console, only remote/SSHv2 or WedUI administrator access. The Identification and authentication function satisfies the following security functional requirements: • NDcPP30e:FIA_AFL.1: An administrator account can be locked after failed authentication attempts. In order to re-establish the account, an administrator configured time period must elapse. • NDcPP30e:FIA_PMG_EXT.1: The TOE offers a wide range of characters for passwords as described above. • MACSEC10:FIA_PSK_EXT.1: The TOE supports the use of pre-shared keys for MKA as defined by IEEE 802.1X-2010. The pre-shared keys are not generated by the TOE but rather the TOE will accept a PSK as a string of hexadecimal characters. • NDcPP30e:FIA_UAU.7: The TOE does not echo passwords as they are entered. • NDcPP30e:FIA_UIA_EXT.1: The TOE uses local and WebGUI password-based and SSH public key-based authentication. The TOE does not offer any services or access to its functions, except for displaying a warning banner, without requiring a user to be identified and authenticated. • NDcPP30e:FIA_X509_EXT.1/Rev: OCSP is supported for X509v3 certificate validation. Certificates are validated as part of the authentication process when they are presented to the TOE and when they are loaded into the TOE. The following fields are verified: • Chain length • Certificate revocation check with OCSP • Certificate Validity • CA validity check • keyUsage verification • Signature verification • SAN/CN check with wild card support • NDcPP30e:FIA_X509_EXT.2: Certificates are checked and if found not valid are not accepted or if the OCSP server cannot be contacted for validity checks, then the connection is rejected. • NDcPP30e:FIA_X509_EXT.3: The TOE generates certificate requests and validates the CA used to sign the certificates. A certificate signing request can be generated with fields for Common Name, Organization, Organizational Unit, or Country. Hewlett Packard Enterprise’s CX-5420, CX-6200M, CX-6300, CX-6400, CX-8360, and CX-9300s Switch Series MACsec running AOS-CX version 10.16 Security Target Version 0.4, 08/17/2026 Page 41 of 44 6.4 Security management The TOE provides two roles: Administrators (Security Administrator) and Operators. The Security Administrator role is simply an admin and has full control over the device whereas the Operator role may view status information only. Upon successful authentication to the TOE, the admin can manage the TSF data. The TOE offers command line functions which are accessible via the CLI. The CLI is a text-based interface which can be accessed from a directly connected terminal or via a remote terminal using SSHv2. These command line functions can be used to manage every security policy, as well as the non-security relevant aspects of the TOE. The TOE also permits administrators to perform administrative tasks using an HTTPS/TLS protected communication channel offering a Web-based GUI and upload certificates through a REST API interface. Once authenticated (none of these functions is available to any user before being identified and authenticated), authorized administrators have access to the following security functions: • Ability to administer the TOE remotely • Ability to configure the access banner • Ability to configure the remote session inactivity time before session termination; • Ability to update the TOE, and to verify the updates using digital signature capability prior to installing those updates • Ability to modify the behavior of the transmission of audit data to an external IT entity • Ability to manage the cryptographic keys • Ability to configure the cryptographic functionality • Ability to set the time which is used for time-stamps • Ability to configure the reference identifier for the peer • Ability to manage the TOE's trust store and designate X509.v3 certificates as trust anchors • Ability to generate Certificate Signing Request (CSR) and process CA certificate response • Ability to administer the TOE locally • Ability to configure the local session inactivity time before session termination or locking • Ability to configure the authentication failure parameters for FIA_AFL.1 • Ability to manage the trusted public keys database • Manage a PSK-based CAK and install it in the device; • Manage the Key Server to create, delete, and activate MKA participants as specified in 802.1X-2020, sections 9.13 and 9.16 (cf. MIB object ieee8021XKayMkaParticipantEntry) and section.12.2 (cf. function createMKA()); • Specify a lifetime of a CAK; and • Enable, disable, or delete a PSK-based CAK using the MIB object ieee8021XKayMkaPartActivateControl. The Security management function satisfies the following security functional requirements: • NDcPP30e:FMT_MOF.1/Functions: The administrator has the ability to determine and modify auditing behavior to an external syslog server. • NDcPP30e:FMT_MOF.1/ManualUpdate: Only the administrator can initiate product updates. • NDcPP30e:FMT_MTD.1/CoreData: Only the administrator can configure TSF-related functions. The trust store is accessed when administrators import/remove certificates as described in the [CC-Guide]. The trust store is protected by default and is restricted such that only administrators have access. • NDcPP30e:FMT_MTD.1/CryptoKeys: Only administrators can perform management operations including the command to generate, import and delete cryptographic keys as defined by Table 9 Key Zeroziation. • NDcPP30e:FMT_SMF.1: The TOE includes the functions necessary to manage its cryptographic functionality and associated functions, configure the warning banner, manage user accounts, set time, and to manage and verify updates of the TOE software and firmware. Hewlett Packard Enterprise’s CX-5420, CX-6200M, CX-6300, CX-6400, CX-8360, and CX-9300s Switch Series MACsec running AOS-CX version 10.16 Security Target Version 0.4, 08/17/2026 Page 42 of 44 • MACSEC10:FMT_SMF.1/MACSEC: As enumerated in the text above, the TOE include management functions to manage, install and configure constraints on a CAK. The TOE can also manage the key server to create, delete, and activate MKA participants as described above. • NDcPP30e:FMT_SMR.2: The TOE includes a manager account that corresponds to the required ‘Authorized Administrator’ also referred to as ‘Security Administrator’ in some requirements or text. 6.5 Protection of the TSF The TOE is an appliance and does not offer general purpose operating system interfaces to users. The TOE is designed to not provide access to locally stored passwords and also, while cryptographic keys can be entered, the TOE does not disclose any cryptographic keys stored in the TOE. The TOE is a hardware appliance that includes a reliable real-time clock for maintaining time (note that the 8400 model also has a battery to maintain time across power cycles). The TOE uses the clock to support several security functions including timestamps for audit records, timing elements of cryptographic functions, and inactivity timeouts. The TOE provides the administrator the ability to manually set the clock. The TOE performs diagnostic self-tests during start-up and generates audit records to document failure. Some low- level critical failure modes can prevent TOE start-up and as a result will not generate audit records. In such cases, the TOE appliance will enter failure mode displaying error codes, typically displayed on the console. The TOE will reboot with errors displayed when non-critical errors are encountered. The cryptographic library performs self-tests during startup; the messages are displayed on the console and syslog records generated for both successful and failed tests. Upgrading the AOS-CX firmware is a manual process performed by an authorized administrator. An administrator can use the “show version” and “show images” commands to query the TOE’s loaded and active firmware versions. The firmware is digitally signed with RSA 3072 using SHA-256. The TOE uses one of two embedded (within the TOE’s firmware images) public keys to verify the digital signature (the vendor includes a primary and a backup signing public key). The firmware is readily available on the Hewlett Packard Enterprise (HPE) website. Uploading the firmware to the devices does require successful authentication to the devices in order to issue the CLI commands needed to update. The TOE will validate the firmware validation during the loading process and will reject the firmware if validation fails. HPE signs the firmware images and includes the HPE signing public keys within the running firmware. Once the TOE has successfully verified a new firmware image, it is loaded and becomes active upon the next reboot. The Protection of the TSF function satisfies the following security functional requirements: • NDcPP30e:FPT_APW_EXT.1: The TOE maintains and protects passwords for administrative user accounts as authentication data. Locally defined passwords are not stored in plaintext form, instead the TOE stores the password as salted SHA-512 hashes. The TOE does not offer any functions that will disclose to any user a plain text password. • MACSEC10:FPT_CAK_EXT.1: The CAK is stored in an encrypted form in the configuration. There is no mechanism provided for the administrator to decrypt the key and reveal the plain-text form. • MACSEC10:FPT_FLS.1/SelfTest: If the TOE encounters a self-test failure, failure of integrity check of the TSF executable image, or failure of noise source health tests it will shut down. The TOE will not restart as long as it has a failure and will need administrator intervention. • MACSEC10:FPT_RPL.1: The TOE detects and logs all attempts to replay MPDUs and MKA frames. The TOE allows an administrator to enables replay protection within the MACsec policy context with either a default or admin-specified window size. With replay protection enabled, packets are expected to arrive within the replay protection window number of packets. For example, with a window size of 10, any packet arriving out-of-sequence by more than 10 packets will be discarded. A window size of 0 (the default) enforces strict order of packet reception, discarding all packets not received in perfect sequence. The no form of this command disables replay protections and resets the window size to its 0 default. • MACSEC10:FPT_RPL_EXT.1: The TOE supports extended packet numbering (XPN) per IEE 802.1AE- 2018 using a MACsec policy configured with XPN specific GCM cipher suites that are based on 128-bit or Hewlett Packard Enterprise’s CX-5420, CX-6200M, CX-6300, CX-6400, CX-8360, and CX-9300s Switch Series MACsec running AOS-CX version 10.16 Security Target Version 0.4, 08/17/2026 Page 43 of 44 256-bit AES keys. When leveraging an XPN cipher suite, the counter used to detect replayed packets is extended to 64 bits. All other replay detection logic and mechanisms remain the same. • NDcPP30e:FPT_SKP_EXT.1: The TOE stores it’s SSH host private keys and TLS server certificate private keys in plaintext form but does not offer any functions to output the cryptographic key value. Similarly, there is no function to view any other encrypted key. • NDcPP30e:FPT_STM_EXT.1: The TOE includes its own hardware clock and allows the administrator to manually configure the time. • NDcPP30e:FPT_TST_EXT.1: The TOE performs a suite of self-tests to verify its integrity. The TOE performs an integrity test of its firmware (by validating the firmware’s RSA digital signature) product and also performs a set of power-up self-tests including AES, SHS, HMAC, RSA, ECDSA and DRBG known answer tests. The TOE automatically performs its known answer power on self-tests (POST) on its CryptoComply cryptography library by computing a trial cryptographic operation (e.g., AES encryption) and then comparing the calculated result to the known correct result (already compiled into the library). This ensures that the TOE’s implementations work correctly. Should any of the tests fail, the TOE halts the boot process. • NDcPP30e:FPT_TUD_EXT.1: The TOE provides the administrator a CLI command to manually install digitally signed (using RSA 3072 with SHA-256) updates. 6.6 TOE access The TOE can be configured by an administrator to set an inactivity session timeout value (any integer value in minutes). The inactivity timeout is 30 minutes by default. This session timeout value is applicable to both local and remote CLI sessions. An SSHv2, Web, or REST API remote session that is inactive (i.e., no commands issuing from the remote client) for the defined timeout value will be terminated. A local session that is similarly inactive for the defined timeout period will be terminated. The user will be required to re-enter their user ID and their password so they can establish a new session once a session is terminated. If the user ID and password match those of the user that was locked, the session is reconnected with the console and normal input/output can again occur for that user. The TOE can be configured to display administrator-configured advisory banners. A login banner can be configured to display warning information along with login prompts. The banners will be displayed when accessing the TOE via the console, SSH, and Web interfaces. The TOE access function satisfies the following security functional requirements: • NDcPP30e:FTA_SSL.3: The TOE terminates remote SSHv2, Web and RestAPI sessions that have been inactive for an administrator-configured period of time. The TOE RestAPI interface is not interactive, but does enforce the same session timeout as the Web interface. • NDcPP30e:FTA_SSL.4: The TOE allows a user to terminate both local and remote sessions (including SSH, Web and RestAPI sessions). The TOE accepts the ‘exit’ command to terminate local and remote CLI sessions. The TOE offers a logout Web operation and a RestAPI logout URL to terminate Web and RestAPI sessions. • NDcPP30e:FTA_SSL_EXT.1: The TOE terminates local sessions that have been inactive for an administrator-configured period of time. • NDcPP30e:FTA_TAB.1: The TOE can be configured to display a warning banner before administrators successfully establish interactive sessions with the TOE (i.e., console, SSH CLI and WebUI), allowing users to terminate their session prior to performing any functions. 6.7 Trusted path/channels The Trusted path/channels function satisfies the following security functional requirements: Hewlett Packard Enterprise’s CX-5420, CX-6200M, CX-6300, CX-6400, CX-8360, and CX-9300s Switch Series MACsec running AOS-CX version 10.16 Security Target Version 0.4, 08/17/2026 Page 44 of 44 • NDcPP30e/MACSEC10:FTP_ITC.1: In the evaluated configuration, the TOE must be configured to use TLS to ensure that any exported audit records are sent only to the configured server so they are not subject to inappropriate disclosure or modification. The TOE is acting as a client in this instance and receives a certificate from the audit server for identification. See section 6.2 for a description of the TLS protocol implemented by the TOE. The TOE uses MACsec to communicate with MACsec peers. • NDcPP30e:FTP_TRP.1/Admin: The TOE provides multiple methods of remote administration. A command line interface is available remotely via an SSH protected channel. Additionally, an HTTPS/TLS connection is available which presents a Web GUI administrative interface and the REST API interface. The administrator can initiate the remote session. The remote session is secured (disclosure and modification) using CAVP tested cryptographic operations, and all remote security management functions require the use of an SSHv2 protected channel or HTTPS/TLS protected channel.