{
"_type": "sec_certs.sample.cc.CCCertificate",
"category": "Network and Network-Related Devices and Systems",
"cert_link": "https://www.commoncriteriaportal.org/nfs/ccpfiles/files/epfiles/st_vid11090-ci.pdf",
"dgst": "85a9fbc9b8fbaf22",
"heuristics": {
"_type": "sec_certs.sample.cc_eucc_common.Heuristics",
"annotated_references": null,
"cert_id": "CCEVS-VR-11090-2020",
"cert_lab": [
"US"
],
"cpe_matches": null,
"direct_transitive_cves": null,
"eal": "EAL1",
"extracted_sars": {
"_type": "Set",
"elements": [
{
"_type": "sec_certs.sample.sar.SAR",
"family": "AVA_VAN",
"level": 1
},
{
"_type": "sec_certs.sample.sar.SAR",
"family": "AGD_OPE",
"level": 1
},
{
"_type": "sec_certs.sample.sar.SAR",
"family": "ATE_IND",
"level": 1
},
{
"_type": "sec_certs.sample.sar.SAR",
"family": "ALC_CMC",
"level": 1
},
{
"_type": "sec_certs.sample.sar.SAR",
"family": "AGD_PRE",
"level": 1
},
{
"_type": "sec_certs.sample.sar.SAR",
"family": "ADV_FSP",
"level": 1
},
{
"_type": "sec_certs.sample.sar.SAR",
"family": "ALC_CMS",
"level": 1
}
]
},
"extracted_versions": {
"_type": "Set",
"elements": [
"9.12"
]
},
"indirect_transitive_cves": null,
"next_certificates": null,
"prev_certificates": null,
"protection_profiles": {
"_type": "Set",
"elements": [
"fa0610a54305df78",
"cf18fa171ef6e928"
]
},
"related_cves": null,
"report_references": {
"_type": "sec_certs.sample.certificate.References",
"directly_referenced_by": null,
"directly_referencing": null,
"indirectly_referenced_by": null,
"indirectly_referencing": null
},
"scheme_data": {
"api_url": "https://www.niap-ccevs.org/api/project/product/pcl_products/11090/",
"categories": [
"Firewall",
" Network Device",
" Virtual Private Network"
],
"category": "Firewall",
"certification_date": "2020-12-09",
"evaluation_facility": "Gossamer Security Solutions",
"expiration_date": "2022-12-09",
"id": "CCEVS-VR-VID11090",
"product": "Cisco Adaptive Security Appliances (ASA) 9.12 running on Firepower 2100 Series Appliances",
"scheme": "US",
"url": "https://www.niap-ccevs.org/products/11090",
"vendor": "Cisco Systems, Inc."
},
"st_references": {
"_type": "sec_certs.sample.certificate.References",
"directly_referenced_by": null,
"directly_referencing": null,
"indirectly_referenced_by": null,
"indirectly_referencing": null
},
"verified_cpe_matches": null
},
"maintenance_updates": {
"_type": "Set",
"elements": []
},
"manufacturer": "Cisco Systems, Inc.",
"manufacturer_web": "https://www.cisco.com",
"name": "Cisco Adaptive Security Appliances (ASA) 9.12 running on Firepower 2100 Series Appliances",
"not_valid_after": "2022-12-09",
"not_valid_before": "2020-12-09",
"pdf_data": {
"_type": "sec_certs.sample.cc_eucc_common.PdfData",
"cert_filename": "st_vid11090-ci.pdf",
"cert_frontpage": null,
"cert_keywords": {
"asymmetric_crypto": {},
"cc_cert_id": {
"US": {
"CCEVS-VR-VID11090-2020": 1
}
},
"cc_claims": {},
"cc_protection_profile_id": {},
"cc_sar": {},
"cc_security_level": {},
"cc_sfr": {},
"certification_process": {},
"cipher_mode": {},
"cplc_data": {},
"crypto_engine": {},
"crypto_library": {},
"crypto_protocol": {
"VPN": {
"VPN": 1
}
},
"crypto_scheme": {},
"device_model": {},
"ecc_curve": {},
"eval_facility": {
"Gossamer": {
"Gossamer Security": 1
}
},
"hash_function": {},
"ic_data_group": {},
"javacard_api_const": {},
"javacard_packages": {},
"javacard_version": {},
"os_name": {},
"pq_crypto": {},
"randomness": {},
"side_channel_analysis": {},
"standard_id": {},
"symmetric_crypto": {},
"technical_report_id": {},
"tee_name": {},
"tls_cipher_suite": {},
"vendor": {
"Cisco": {
"Cisco": 1,
"Cisco Systems, Inc": 1
}
},
"vulnerability": {}
},
"cert_metadata": {
"/CreationDate": "D:20201210153910-05\u002700\u0027",
"/ModDate": "D:20201210153910-05\u002700\u0027",
"/Producer": "iText 2.1.0 (by lowagie.com)",
"pdf_file_size_bytes": 180344,
"pdf_hyperlinks": {
"_type": "Set",
"elements": []
},
"pdf_is_encrypted": false,
"pdf_number_of_pages": 1
},
"report_filename": "st_vid11090-vr.pdf",
"report_frontpage": {
"US": {
"cert_id": "CCEVS-VR-11090-2020",
"cert_item": "Cisco Adaptive Security Appliances (ASA) 9.12 running on Firepower 2100 Series Appliances",
"cert_lab": "US NIAP"
}
},
"report_keywords": {
"asymmetric_crypto": {},
"cc_cert_id": {
"US": {
"CCEVS-VR-11090-2020": 1
}
},
"cc_claims": {},
"cc_protection_profile_id": {},
"cc_sar": {},
"cc_security_level": {
"EAL": {
"EAL 1": 1
}
},
"cc_sfr": {},
"certification_process": {},
"cipher_mode": {},
"cplc_data": {},
"crypto_engine": {},
"crypto_library": {},
"crypto_protocol": {
"IKE": {
"IKE": 1
},
"IPsec": {
"IPsec": 14
},
"SSH": {
"SSH": 5,
"SSHv2": 6
},
"TLS": {
"TLS": {
"TLS": 7
}
},
"VPN": {
"VPN": 24
}
},
"crypto_scheme": {},
"device_model": {},
"ecc_curve": {},
"eval_facility": {
"Gossamer": {
"Gossamer Security": 5
}
},
"hash_function": {},
"ic_data_group": {},
"javacard_api_const": {},
"javacard_packages": {},
"javacard_version": {},
"os_name": {},
"pq_crypto": {},
"randomness": {},
"side_channel_analysis": {},
"standard_id": {},
"symmetric_crypto": {},
"technical_report_id": {},
"tee_name": {},
"tls_cipher_suite": {},
"vendor": {
"Cisco": {
"Cisco": 25,
"Cisco Systems, Inc": 3
},
"Microsoft": {
"Microsoft": 1
}
},
"vulnerability": {}
},
"report_metadata": {
"/CreationDate": "D:20201210145924-05\u002700\u0027",
"/ModDate": "D:20201210153312-05\u002700\u0027",
"pdf_file_size_bytes": 914472,
"pdf_hyperlinks": {
"_type": "Set",
"elements": []
},
"pdf_is_encrypted": false,
"pdf_number_of_pages": 18
},
"st_filename": "st_vid11090-st.pdf",
"st_frontpage": null,
"st_keywords": {
"asymmetric_crypto": {
"ECC": {
"ECC": {
"ECC": 5
},
"ECDH": {
"ECDHE": 2
},
"ECDSA": {
"ECDSA": 20
}
},
"FF": {
"DH": {
"DH": 9,
"DHE": 2,
"Diffie-Hellman": 8
},
"DSA": {
"DSA": 1
}
},
"RSA": {
"RSA-2048": 1
}
},
"cc_cert_id": {},
"cc_claims": {
"A": {
"A.ADMIN_CREDENTIALS_": 1,
"A.CONNECTIONS": 2,
"A.LIMITED_FUNCTIONALITY": 1,
"A.NO_THRU_TRAFFIC_PROTECTION": 1,
"A.PHYSICAL_PROTECTION": 1,
"A.REGULAR_UPDATES": 1,
"A.RESIDUAL_INFORMATION": 1,
"A.TRUSTED_ADMINSTRATOR": 1
},
"O": {
"O.ADDRESS_FILTERING": 1,
"O.AUTHENTICATION": 1,
"O.CRYPTOGRAPHIC_FUNCTIONS": 1,
"O.FAIL_SECURE": 1,
"O.PORT_FILTERING": 1,
"O.RESIDUAL_INFORMATION": 1,
"O.STATEFUL_TRAFFIC_FILTERING": 1,
"O.SYSTEM_MONITORING": 1,
"O.TOE_ADMINISTRATION": 1
},
"OE": {
"OE.ADMIN_CREDENTIALS_": 1,
"OE.CONNECTIONS": 1,
"OE.NO_GENERAL_PURPOSE": 1,
"OE.NO_THRU_TRAFFIC_PROTECTION": 1,
"OE.PHYSICAL": 1,
"OE.RESIDUAL_INFORMATION": 1,
"OE.TRUSTED_ADMIN": 1,
"OE.UPDATES": 1
},
"T": {
"T.DATA_INTEGRITY": 1,
"T.MALICIOUS_TRAFFIC": 1,
"T.NETWORK_ACCESS": 1,
"T.NETWORK_DISCLOSURE": 2,
"T.NETWORK_MISUSE": 2,
"T.PASSWORD_CRACKING": 1,
"T.REPLAY_ATTACK": 1,
"T.SECURITY_FUNCTIONALITY_": 2,
"T.UNAUTHORIZED_": 1,
"T.UNDETECTED_ACTIVITY": 1,
"T.UNTRUSTED_COMMUNICATIONS": 1,
"T.UPDATE_COMPROMISE": 1,
"T.WEAK_AUTHENTICATION_": 1,
"T.WEAK_CRYPTOGRAPHY": 1
}
},
"cc_protection_profile_id": {},
"cc_sar": {
"ADV": {
"ADV_FSP.1": 2
},
"AGD": {
"AGD_OPE.1": 2,
"AGD_PRE.1": 2
},
"ALC": {
"ALC_CMC.1": 2,
"ALC_CMS.1": 2
},
"ATE": {
"ATE_IND.1": 2
},
"AVA": {
"AVA_VAN": 1,
"AVA_VAN.1": 4
}
},
"cc_security_level": {},
"cc_sfr": {
"FAU": {
"FAU_GEN.1": 9,
"FAU_GEN.1.1": 1,
"FAU_GEN.1.2": 1,
"FAU_GEN.2": 5,
"FAU_GEN.2.1": 1,
"FAU_STG_EXT.1": 5,
"FAU_STG_EXT.1.1": 1,
"FAU_STG_EXT.1.2": 1,
"FAU_STG_EXT.1.3": 1
},
"FCS": {
"FCS_CKM": 5,
"FCS_CKM.1": 12,
"FCS_CKM.1.1": 1,
"FCS_CKM.2": 11,
"FCS_CKM.2.1": 1,
"FCS_CKM.4": 6,
"FCS_CKM.4.1": 1,
"FCS_COP": 27,
"FCS_COP.1": 4,
"FCS_NTP_EXT.1": 1,
"FCS_NTP_EXT.1.4": 1,
"FCS_RBG_EXT.1": 8,
"FCS_RBG_EXT.1.1": 1,
"FCS_RBG_EXT.1.2": 2,
"FCS_SSHC_EXT.1": 2,
"FCS_SSHC_EXT.1.5": 1,
"FCS_SSHS_EXT.1": 9,
"FCS_SSHS_EXT.1.1": 2,
"FCS_SSHS_EXT.1.2": 1,
"FCS_SSHS_EXT.1.3": 1,
"FCS_SSHS_EXT.1.4": 1,
"FCS_SSHS_EXT.1.5": 4,
"FCS_SSHS_EXT.1.6": 1,
"FCS_SSHS_EXT.1.7": 2,
"FCS_SSHS_EXT.1.8": 1,
"FCS_TLSC_EXT.1.1": 3,
"FCS_TLSC_EXT.2": 8,
"FCS_TLSC_EXT.2.1": 2,
"FCS_TLSC_EXT.2.2": 1,
"FCS_TLSC_EXT.2.3": 1,
"FCS_TLSC_EXT.2.4": 1,
"FCS_TLSC_EXT.2.5": 1,
"FCS_TLSS_EXT": 1,
"FCS_TLSS_EXT.1": 7,
"FCS_TLSS_EXT.1.1": 2,
"FCS_TLSS_EXT.1.2": 1,
"FCS_TLSS_EXT.1.3": 1,
"FCS_TLSS_EXT.2": 1
},
"FDP": {
"FDP_RIP.2": 5,
"FDP_RIP.2.1": 1
},
"FIA": {
"FIA_AFL.1": 8,
"FIA_AFL.1.1": 2,
"FIA_AFL.1.2": 2,
"FIA_PMG_EXT.1": 5,
"FIA_PMG_EXT.1.1": 1,
"FIA_PSK_EXT.1": 5,
"FIA_PSK_EXT.1.1": 1,
"FIA_PSK_EXT.1.2": 1,
"FIA_PSK_EXT.1.3": 1,
"FIA_PSK_EXT.1.4": 1,
"FIA_UAU.7": 5,
"FIA_UAU.7.1": 1,
"FIA_UAU_EXT.2": 5,
"FIA_UAU_EXT.2.1": 2,
"FIA_UIA_EXT.1": 5,
"FIA_UIA_EXT.1.1": 1,
"FIA_UIA_EXT.1.2": 1
},
"FMT": {
"FMT_MOF": 10,
"FMT_MOF.1": 2,
"FMT_MTD": 10,
"FMT_MTD.1": 2,
"FMT_SMF": 5,
"FMT_SMF.1": 7,
"FMT_SMF.1.1": 1,
"FMT_SMR.2": 5,
"FMT_SMR.2.1": 1,
"FMT_SMR.2.2": 1,
"FMT_SMR.2.3": 1
},
"FPT": {
"FPT_APW_EXT.1": 7,
"FPT_APW_EXT.1.1": 1,
"FPT_APW_EXT.1.2": 1,
"FPT_FLS": 5,
"FPT_FLS.1": 2,
"FPT_ITT": 1,
"FPT_SKP_EXT.1": 5,
"FPT_SKP_EXT.1.1": 1,
"FPT_STM_EXT.1": 6,
"FPT_STM_EXT.1.1": 1,
"FPT_STM_EXT.1.2": 1,
"FPT_TST_EXT": 1,
"FPT_TST_EXT.1": 5,
"FPT_TST_EXT.1.1": 1,
"FPT_TST_EXT.3": 5,
"FPT_TST_EXT.3.1": 1,
"FPT_TST_EXT.3.2": 1,
"FPT_TUD_EXT.1": 8,
"FPT_TUD_EXT.1.1": 1,
"FPT_TUD_EXT.1.2": 1,
"FPT_TUD_EXT.1.3": 2
},
"FTA": {
"FTA_SSL": 4,
"FTA_SSL.3": 10,
"FTA_SSL.3.1": 1,
"FTA_SSL.4": 4,
"FTA_SSL.4.1": 1,
"FTA_SSL_EXT": 1,
"FTA_SSL_EXT.1": 7,
"FTA_SSL_EXT.1.1": 1,
"FTA_TAB.1": 6,
"FTA_TAB.1.1": 1,
"FTA_TSE.1": 5,
"FTA_TSE.1.1": 1,
"FTA_VCM_EXT.1": 5,
"FTA_VCM_EXT.1.1": 1
},
"FTP": {
"FTP_ITC": 4,
"FTP_ITC.1": 14,
"FTP_ITC.1.1": 2,
"FTP_ITC.1.2": 1,
"FTP_ITC.1.3": 1,
"FTP_TRP": 6,
"FTP_TRP.1": 3,
"FTP_TUD.1": 1
}
},
"certification_process": {
"OutOfScope": {
"ECDSA-based, DH-based, and RSA-based schemes. The RSA-based implementation is vendor affirmation (out of scope) and the KAS ECC and FFC + CVL algorithms testing is provided below. Scheme SFR Services RSA": 1,
"out of scope": 1
}
},
"cipher_mode": {
"CBC": {
"CBC": 5
},
"GCM": {
"GCM": 6
}
},
"cplc_data": {},
"crypto_engine": {},
"crypto_library": {},
"crypto_protocol": {
"IKE": {
"IKE": 36,
"IKEv2": 21
},
"IPsec": {
"IPsec": 91
},
"SSH": {
"SSH": 46,
"SSHv2": 13
},
"TLS": {
"SSL": {
"SSL": 2,
"SSL 2.0": 1,
"SSL 3.0": 1
},
"TLS": {
"TLS": 49,
"TLS 1.0": 1,
"TLS 1.1": 2,
"TLS 1.2": 2,
"TLS v1.2": 5,
"TLS1.1": 1,
"TLS1.2": 1,
"TLSv1.1": 3,
"TLSv1.2": 3
}
},
"VPN": {
"VPN": 166
}
},
"crypto_scheme": {
"KEX": {
"Key Exchange": 3
},
"MAC": {
"MAC": 4
}
},
"device_model": {},
"ecc_curve": {
"NIST": {
"P-256": 12,
"P-348": 2,
"P-384": 10,
"P-521": 12,
"secp256r1": 4,
"secp384r1": 3,
"secp521r1": 4
}
},
"eval_facility": {},
"hash_function": {
"PBKDF": {
"PBKDF2": 2
},
"SHA": {
"SHA1": {
"SHA-1": 6
},
"SHA2": {
"SHA-256": 5,
"SHA-384": 4,
"SHA-512": 6
}
}
},
"ic_data_group": {},
"javacard_api_const": {},
"javacard_packages": {},
"javacard_version": {},
"os_name": {},
"pq_crypto": {},
"randomness": {
"PRNG": {
"DRBG": 4
},
"RNG": {
"RBG": 1
}
},
"side_channel_analysis": {},
"standard_id": {
"CC": {
"CCMB-2017-04-001": 1,
"CCMB-2017-04-002": 1,
"CCMB-2017-04-003": 1,
"CCMB-2017-04-004": 1
},
"FIPS": {
"FIPS 140-2": 3,
"FIPS PUB 140-2": 1,
"FIPS PUB 180-4": 2,
"FIPS PUB 186-3": 1,
"FIPS PUB 186-4": 10,
"FIPS PUB 198-1": 1
},
"ISO": {
"ISO/IEC 14888-3": 1,
"ISO/IEC 18031:2011": 2,
"ISO/IEC 9796-2": 1
},
"NIST": {
"NIST SP 800-38A": 1,
"NIST SP 800-56A": 1,
"NIST SP 800-90": 2
},
"PKCS": {
"PKCS #1": 1
},
"RFC": {
"RFC 2460": 4,
"RFC 2818": 1,
"RFC 2986": 1,
"RFC 3268": 4,
"RFC 3513": 2,
"RFC 3526": 4,
"RFC 3602": 2,
"RFC 4106": 1,
"RFC 4253": 1,
"RFC 4301": 1,
"RFC 4303": 2,
"RFC 4346": 3,
"RFC 4443": 2,
"RFC 4868": 1,
"RFC 4945": 1,
"RFC 5246": 7,
"RFC 5280": 4,
"RFC 5282": 1,
"RFC 5289": 4,
"RFC 5735": 2,
"RFC 5759": 1,
"RFC 5996": 2,
"RFC 6125": 1,
"RFC 6960": 1,
"RFC 768": 4,
"RFC 791": 4,
"RFC 792": 2,
"RFC 793": 4
},
"X509": {
"X.509": 6
}
},
"symmetric_crypto": {
"AES_competition": {
"AES": {
"AES": 13,
"AES-": 1,
"AES-192": 1
}
},
"constructions": {
"MAC": {
"HMAC": 3,
"HMAC-SHA-256": 5,
"HMAC-SHA-384": 4,
"HMAC-SHA-512": 5
}
},
"miscellaneous": {
"Skinny": {
"Skinny": 2
}
}
},
"technical_report_id": {},
"tee_name": {},
"tls_cipher_suite": {
"TLS": {
"TLS_DHE_RSA_WITH_AES_128_CBC_SHA": 4,
"TLS_DHE_RSA_WITH_AES_128_CBC_SHA256": 4,
"TLS_DHE_RSA_WITH_AES_256_CBC_SHA": 4,
"TLS_DHE_RSA_WITH_AES_256_CBC_SHA256": 4,
"TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256": 3,
"TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384": 3,
"TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256": 1,
"TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384": 1
}
},
"vendor": {
"Cisco": {
"Cisco": 24,
"Cisco Systems, Inc": 2
},
"Microsoft": {
"Microsoft": 1
}
},
"vulnerability": {}
},
"st_metadata": {
"/CreationDate": "D:20201210151433-05\u002700\u0027",
"/ModDate": "D:20201210151931-05\u002700\u0027",
"pdf_file_size_bytes": 1726810,
"pdf_hyperlinks": {
"_type": "Set",
"elements": [
"http://tools.ietf.org/rfcmarkup?doc=793#section-2.7",
"http://en.wikipedia.org/wiki/Internet_Control_Message_Protocol",
"https://csrc.nist.gov/projects/cryptographic-algorithm-validation-program/details?product=12365"
]
},
"pdf_is_encrypted": false,
"pdf_number_of_pages": 102
}
},
"protection_profile_links": {
"_type": "Set",
"elements": [
"https://www.commoncriteriaportal.org/nfs/ccpfiles/files/ppfiles/MOD_VPNGW_V1.0.pdf",
"https://www.commoncriteriaportal.org/nfs/ccpfiles/files/ppfiles/CPP_ND_V2.1.pdf",
"https://www.commoncriteriaportal.org/nfs/ccpfiles/files/ppfiles/MOD_CPP_FW_v1.3.pdf"
]
},
"report_link": "https://www.commoncriteriaportal.org/nfs/ccpfiles/files/epfiles/st_vid11090-vr.pdf",
"scheme": "US",
"security_level": {
"_type": "Set",
"elements": []
},
"st_link": "https://www.commoncriteriaportal.org/nfs/ccpfiles/files/epfiles/st_vid11090-st.pdf",
"state": {
"_type": "sec_certs.sample.cc_eucc_common.InternalState",
"cert": {
"_type": "sec_certs.sample.document_state.DocumentState",
"convert_ok": true,
"download_ok": true,
"extract_ok": true,
"json_hash": null,
"source_hash": "3538221b3dafc9077b6c873bd5aa90751b17c5d404636113f210468a0194ce54",
"txt_hash": "84fc8b3630037a20fb9f4c28ca9edf1868a0f8cc93e2580e0606b6a30557a8b3"
},
"report": {
"_type": "sec_certs.sample.document_state.DocumentState",
"convert_ok": true,
"download_ok": true,
"extract_ok": true,
"json_hash": null,
"source_hash": "b4e0a1dea54587d6f563f14eb95c7bcbf3fb0884afc201c98dd4a3cf18959eaf",
"txt_hash": "e3232af14c29b4682ba0c848a8a12d38e74f03c1dc40a51611dd03b1d0262f21"
},
"st": {
"_type": "sec_certs.sample.document_state.DocumentState",
"convert_ok": true,
"download_ok": true,
"extract_ok": true,
"json_hash": null,
"source_hash": "7038408827d53195225f559afc6a22047a435103208594c557a624be6da28454",
"txt_hash": "5b2e36518e4871f5de2b248226e0dd6c46f17fba0862ff9c5ad3a9949806668a"
}
},
"status": "archived"
}