{
"_type": "sec_certs.sample.cc.CCCertificate",
"category": "Mobility",
"cert_link": "https://www.commoncriteriaportal.org/nfs/ccpfiles/files/epfiles/1265c_pdf.pdf",
"dgst": "8e7743c51c1f05b5",
"heuristics": {
"_type": "sec_certs.sample.cc_eucc_common.Heuristics",
"annotated_references": null,
"cert_id": "BSI-DSZ-CC-1265-2026",
"cert_lab": [
"BSI"
],
"cpe_matches": null,
"direct_transitive_cves": null,
"eal": "EAL2",
"extracted_sars": {
"_type": "Set",
"elements": [
{
"_type": "sec_certs.sample.sar.SAR",
"family": "ASE_CCL",
"level": 1
},
{
"_type": "sec_certs.sample.sar.SAR",
"family": "AGD_PRE",
"level": 1
},
{
"_type": "sec_certs.sample.sar.SAR",
"family": "AVA_VAN",
"level": 2
},
{
"_type": "sec_certs.sample.sar.SAR",
"family": "ATE_COV",
"level": 1
},
{
"_type": "sec_certs.sample.sar.SAR",
"family": "ALC_CMS",
"level": 2
},
{
"_type": "sec_certs.sample.sar.SAR",
"family": "ASE_TSS",
"level": 1
},
{
"_type": "sec_certs.sample.sar.SAR",
"family": "ATE_FUN",
"level": 1
},
{
"_type": "sec_certs.sample.sar.SAR",
"family": "ALC_DEL",
"level": 1
},
{
"_type": "sec_certs.sample.sar.SAR",
"family": "ASE_ECD",
"level": 1
},
{
"_type": "sec_certs.sample.sar.SAR",
"family": "ASE_OBJ",
"level": 2
},
{
"_type": "sec_certs.sample.sar.SAR",
"family": "ALC_CMC",
"level": 2
},
{
"_type": "sec_certs.sample.sar.SAR",
"family": "ADV_TDS",
"level": 1
},
{
"_type": "sec_certs.sample.sar.SAR",
"family": "ADV_FSP",
"level": 2
},
{
"_type": "sec_certs.sample.sar.SAR",
"family": "ADV_ARC",
"level": 1
},
{
"_type": "sec_certs.sample.sar.SAR",
"family": "AGD_OPE",
"level": 1
},
{
"_type": "sec_certs.sample.sar.SAR",
"family": "ASE_INT",
"level": 1
},
{
"_type": "sec_certs.sample.sar.SAR",
"family": "ATE_IND",
"level": 2
},
{
"_type": "sec_certs.sample.sar.SAR",
"family": "ASE_SPD",
"level": 1
},
{
"_type": "sec_certs.sample.sar.SAR",
"family": "ASE_REQ",
"level": 2
}
]
},
"extracted_versions": {
"_type": "Set",
"elements": [
"2.1"
]
},
"indirect_transitive_cves": null,
"next_certificates": null,
"prev_certificates": null,
"protection_profiles": null,
"related_cves": null,
"report_references": {
"_type": "sec_certs.sample.certificate.References",
"directly_referenced_by": null,
"directly_referencing": {
"_type": "Set",
"elements": [
"BSI-DSZ-CC-1150-2021"
]
},
"indirectly_referenced_by": null,
"indirectly_referencing": {
"_type": "Set",
"elements": [
"BSI-DSZ-CC-1150-2021",
"BSI-DSZ-CC-0943-2015",
"BSI-DSZ-CC-1038-2017"
]
}
},
"scheme_data": {
"category": "Server applications",
"cert_id": "BSI-DSZ-CC-1265-2026",
"certification_date": "2026-02-10",
"enhanced": {
"applicant": "GDV Dienstleistungs-GmbH Frankenstra\u00dfe 18 20097 Hamburg",
"assurance_level": "EAL2",
"cert_link": "https://www.bsi.bund.de/SharedDocs/Downloads/DE/BSI/Zertifizierung/Reporte/Reporte1200/1265c_pdf.pdf?__blob=publicationFile\u0026v=2",
"certification_date": "2026-02-10",
"description": "The Target of Evaluation (TOE) is a Security Token Service (STS). It has been implemented as a pure software application and due to the field of operation in the context of insurance it is further referenced as Insurance Security Token Service (ISTS). The software application provides software-based security tokens used for authentication purposes of the Trusted German Insurance Cloud (TGIC) web services. In addition, the TOE provides the possibility to validate and to cancel the issued tokens. Further, the security features of the TOE comprise the functionality Security Audit, Identification and Authentication, whereas some authentication mechanisms are provided by the operational environment and finally Security Management.",
"evaluation_facility": "T\u00dcV Informationstechnik GmbH",
"expiration_date": "2031-02-09",
"product": "Insurance Security Token Server (ISTS), Version 2.1",
"report_link": "https://www.bsi.bund.de/SharedDocs/Downloads/DE/BSI/Zertifizierung/Reporte/Reporte1200/1265a_pdf.pdf?__blob=publicationFile\u0026v=2",
"target_link": "https://www.bsi.bund.de/SharedDocs/Downloads/DE/BSI/Zertifizierung/Reporte/Reporte1200/1265b_pdf.pdf?__blob=publicationFile\u0026v=2"
},
"product": "Insurance Security Token Server (ISTS), Version 2.1",
"subcategory": "Other server applications",
"url": "https://www.bsi.bund.de/SharedDocs/Zertifikate_CC/CC/Serveranwendungen_Sonstiges/1265.html",
"vendor": "GDV Dienstleistungs-GmbH"
},
"st_references": {
"_type": "sec_certs.sample.certificate.References",
"directly_referenced_by": null,
"directly_referencing": null,
"indirectly_referenced_by": null,
"indirectly_referencing": null
},
"verified_cpe_matches": null
},
"maintenance_updates": {
"_type": "Set",
"elements": []
},
"manufacturer": "GDV Dienstleistungs-GmbH",
"manufacturer_web": "https://www.gdv-dl.de",
"name": "Insurance Security Token Server (ISTS), Version 2.1",
"not_valid_after": "2031-02-10",
"not_valid_before": "2026-02-10",
"pdf_data": {
"_type": "sec_certs.sample.cc_eucc_common.PdfData",
"cert_filename": "1265c_pdf.pdf",
"cert_frontpage": null,
"cert_keywords": {
"asymmetric_crypto": {},
"cc_cert_id": {
"DE": {
"BSI-DSZ-CC-1265-2026": 1
}
},
"cc_claims": {},
"cc_protection_profile_id": {},
"cc_sar": {},
"cc_security_level": {
"EAL": {
"EAL 2": 1
}
},
"cc_sfr": {},
"certification_process": {},
"cipher_mode": {},
"cplc_data": {},
"crypto_engine": {},
"crypto_library": {},
"crypto_protocol": {},
"crypto_scheme": {},
"device_model": {},
"ecc_curve": {},
"eval_facility": {},
"hash_function": {},
"ic_data_group": {},
"javacard_api_const": {},
"javacard_packages": {},
"javacard_version": {},
"os_name": {},
"pq_crypto": {},
"randomness": {},
"side_channel_analysis": {},
"standard_id": {
"ISO": {
"ISO/IEC 15408": 2,
"ISO/IEC 18045": 2
}
},
"symmetric_crypto": {},
"technical_report_id": {},
"tee_name": {},
"tls_cipher_suite": {},
"vendor": {},
"vulnerability": {}
},
"cert_metadata": {
"/Author": "Bundesamt f\u00fcr Sicherheit in der Informationstechnik",
"/Keywords": "\"\"\"Common Criteria, Certification, Zertifizierung, Protection Profile, Schutzprofil\"\"\"",
"/Subject": "\"Common Criteria, Certification, Zertifizierung, Protection Profile, Schutzprofil\"",
"/Title": "Zertifizierungsreport BSI-DSZ-CC-1265-2026",
"pdf_file_size_bytes": 251149,
"pdf_hyperlinks": {
"_type": "Set",
"elements": []
},
"pdf_is_encrypted": false,
"pdf_number_of_pages": 1
},
"report_filename": "1265a_pdf.pdf",
"report_frontpage": {
"DE": {
"cert_id": "BSI-DSZ-CC-1265-2026",
"cert_item": "lnsurance Security Token Server (ISTS), Version 2.1",
"cert_lab": "BSI",
"developer": "GDV Dienstleistungs-GmbH",
"match_rules": [
"(BSI-DSZ-CC-.+?) zu (.+?) der (.*)"
]
}
},
"report_keywords": {
"asymmetric_crypto": {},
"cc_cert_id": {
"DE": {
"BSI-DSZ-CC-1150-2021": 3,
"BSI-DSZ-CC-1265-2026": 17
},
"NL": {
"CC-1032": 1
}
},
"cc_claims": {
"OE": {
"OE.ENVIRONMENT": 1,
"OE.NOEVIL": 1,
"OE.PHYSEC": 1,
"OE.PKI": 1,
"OE.PUBLIC": 1
}
},
"cc_protection_profile_id": {},
"cc_sar": {
"AGD": {
"AGD_OPE": 2,
"AGD_PRE": 2
},
"ALC": {
"ALC_FLR": 1
}
},
"cc_security_level": {
"EAL": {
"EAL 1": 1,
"EAL 2": 5,
"EAL 4": 1
}
},
"cc_sfr": {},
"certification_process": {},
"cipher_mode": {},
"cplc_data": {},
"crypto_engine": {},
"crypto_library": {
"OpenSSL": {
"OpenSSL": 2
}
},
"crypto_protocol": {
"TLS": {
"SSL": {
"SSL": 1
}
},
"VPN": {
"VPN": 2
}
},
"crypto_scheme": {},
"device_model": {},
"ecc_curve": {},
"eval_facility": {
"TUV": {
"T\u00dcV Informationstechnik": 3,
"T\u00dcViT": 1
}
},
"hash_function": {
"SHA": {
"SHA2": {
"SHA-256": 1,
"SHA-512": 2
}
}
},
"ic_data_group": {},
"javacard_api_const": {},
"javacard_packages": {
"com": {
"com.ibm.dp": 1
}
},
"javacard_version": {},
"os_name": {},
"pq_crypto": {},
"randomness": {},
"side_channel_analysis": {},
"standard_id": {
"BSI": {
"AIS 14": 1,
"AIS 19": 1,
"AIS 32": 1,
"AIS 41": 2
},
"ISO": {
"ISO/IEC 15408": 4,
"ISO/IEC 17065": 2,
"ISO/IEC 18045": 4
},
"X509": {
"X.509": 4
}
},
"symmetric_crypto": {},
"technical_report_id": {},
"tee_name": {},
"tls_cipher_suite": {},
"vendor": {},
"vulnerability": {}
},
"report_metadata": {
"/Author": "Bundesamt f\u00fcr Sicherheit in der Informationstechnik",
"/Keywords": "\"\"\"Common Criteria, Certification, Zertifizierung, Protection Profile, Schutzprofil\"\"\"",
"/Subject": "\"Common Criteria, Certification, Zertifizierung, Protection Profile, Schutzprofil\"",
"/Title": "Zertifizierungsreport BSI-DSZ-CC-1265-2026",
"pdf_file_size_bytes": 394100,
"pdf_hyperlinks": {
"_type": "Set",
"elements": []
},
"pdf_is_encrypted": false,
"pdf_number_of_pages": 34
},
"st_filename": "1265b_pdf.pdf",
"st_frontpage": null,
"st_keywords": {
"asymmetric_crypto": {
"RSA": {
"RSA-OAEP": 4
}
},
"cc_cert_id": {
"DE": {
"BSI-DSZ-CC-1265": 1
}
},
"cc_claims": {
"A": {
"A.ENVIRONMENT": 3,
"A.NOEVIL": 3,
"A.PHYSEC": 3,
"A.PKI": 3,
"A.PUBLIC": 3
},
"O": {
"O.ACCOUNT": 6,
"O.AUDREC": 4,
"O.STS": 5
},
"OE": {
"OE.ENVIRONMENT": 3,
"OE.NOEVIL": 2,
"OE.PHYSEC": 3,
"OE.PKI": 3,
"OE.PUBLIC": 2
},
"T": {
"T.UNDETECTED": 3
}
},
"cc_protection_profile_id": {},
"cc_sar": {
"ADV": {
"ADV_ARC.1": 1,
"ADV_FSP.2": 1,
"ADV_TDS.1": 1
},
"AGD": {
"AGD_OPE.1": 1,
"AGD_PRE.1": 1
},
"ALC": {
"ALC_CMC.2": 1,
"ALC_CMS.2": 1,
"ALC_DEL.1": 1
},
"ASE": {
"ASE_CCL.1": 1,
"ASE_ECD.1": 1,
"ASE_INT.1": 1,
"ASE_OBJ.2": 1,
"ASE_REQ.2": 1,
"ASE_SPD.1": 1,
"ASE_TSS.1": 1
},
"ATE": {
"ATE_COV.1": 1,
"ATE_FUN.1": 1,
"ATE_IND.2": 1
},
"AVA": {
"AVA_VAN.2": 2
}
},
"cc_security_level": {
"EAL": {
"EAL 2": 1,
"EAL2": 6
}
},
"cc_sfr": {
"FAU": {
"FAU_GEN": 3,
"FAU_GEN.1": 11,
"FAU_GEN.1.1": 1,
"FAU_GEN.1.2": 1,
"FAU_GEN.2": 9,
"FAU_GEN.2.1": 1
},
"FIA": {
"FIA_UAU.1": 13,
"FIA_UAU.1.1": 1,
"FIA_UAU.1.2": 1,
"FIA_UAU.5": 10,
"FIA_UAU.5.1": 1,
"FIA_UAU.5.2": 1,
"FIA_UID.1": 11,
"FIA_UID.1.1": 1,
"FIA_UID.1.2": 1
},
"FMT": {
"FMT_SMF.1": 8,
"FMT_SMF.1.1": 1
},
"FPT": {
"FPT_STM.1": 2
}
},
"certification_process": {},
"cipher_mode": {},
"cplc_data": {},
"crypto_engine": {},
"crypto_library": {},
"crypto_protocol": {
"TLS": {
"SSL": {
"SSL": 1
},
"TLS": {
"TLS": 2,
"TLS 1.3": 1
}
}
},
"crypto_scheme": {},
"device_model": {},
"ecc_curve": {},
"eval_facility": {
"TUV": {
"T\u00dcV Informationstechnik": 2,
"T\u00dcViT": 1
}
},
"hash_function": {
"SHA": {
"SHA2": {
"SHA-384": 1,
"SHA-512": 5
}
}
},
"ic_data_group": {},
"javacard_api_const": {},
"javacard_packages": {},
"javacard_version": {},
"os_name": {},
"pq_crypto": {},
"randomness": {},
"side_channel_analysis": {},
"standard_id": {
"CC": {
"CCMB-2022-11-001": 1,
"CCMB-2022-11-002": 1,
"CCMB-2022-11-003": 1,
"CCMB-2022-11-004": 1,
"CCMB-2022-11-005": 1
},
"FIPS": {
"FIPS PUB 180-4": 1,
"FIPS PUB 197": 1
},
"PKCS": {
"PKCS#1": 4
},
"RFC": {
"RFC 4226": 1,
"RFC 5246": 1,
"RFC 6234": 1,
"RFC 6238": 2,
"RFC 6749": 1,
"RFC 7515": 1,
"RFC 7516": 1,
"RFC 7518": 2,
"RFC 9231": 1,
"RFC4226": 1,
"RFC5246": 1,
"RFC6234": 1,
"RFC6238": 2,
"RFC6749": 4,
"RFC7515": 1,
"RFC7516": 2,
"RFC7518": 3,
"RFC7519": 2,
"RFC8446": 1,
"RFC9231": 3
},
"X509": {
"X.509": 11
}
},
"symmetric_crypto": {
"AES_competition": {
"AES": {
"AES": 3
}
},
"DES": {
"DES": {
"DES": 1
}
},
"constructions": {
"MAC": {
"HMAC": 4,
"HMAC-SHA-512": 1
}
}
},
"technical_report_id": {},
"tee_name": {},
"tls_cipher_suite": {},
"vendor": {},
"vulnerability": {}
},
"st_metadata": {
"/Author": "Ewald Ros",
"/Keywords": "CC, ST, Common Criteria, Security Target, ISTS",
"/Subject": "Security Target",
"/Title": "Common Criteria Evaluation",
"pdf_file_size_bytes": 934107,
"pdf_hyperlinks": {
"_type": "Set",
"elements": [
"http://www.w3.org/2009/xmlenc11#rsa-oaep",
"http://gdv-dl.de/",
"http://www.w3.org/2001/04/xmldsig-more#rsa-sha384"
]
},
"pdf_is_encrypted": false,
"pdf_number_of_pages": 53
}
},
"protection_profile_links": {
"_type": "Set",
"elements": []
},
"report_link": "https://www.commoncriteriaportal.org/nfs/ccpfiles/files/epfiles/1265a_pdf.pdf",
"scheme": "DE",
"security_level": {
"_type": "Set",
"elements": [
"EAL2"
]
},
"st_link": "https://www.commoncriteriaportal.org/nfs/ccpfiles/files/epfiles/1265b_pdf.pdf",
"state": {
"_type": "sec_certs.sample.cc_eucc_common.InternalState",
"cert": {
"_type": "sec_certs.sample.document_state.DocumentState",
"convert_ok": true,
"download_ok": true,
"extract_ok": true,
"json_hash": null,
"source_hash": "d9bba6ba97f3f4fbeb043b6ba660c6c3f75b62dce7536495a3c3bfe35915dbb3",
"txt_hash": "0f11c5ed01ef6af6a2c06819f4a9a8d7cbce7e1aea8c7ef9806ad0a5b24c02c3"
},
"report": {
"_type": "sec_certs.sample.document_state.DocumentState",
"convert_ok": true,
"download_ok": true,
"extract_ok": true,
"json_hash": null,
"source_hash": "22e2d86b23adca3f5404279b9217a8886e3548ee67caf3225b343592dc0630ed",
"txt_hash": "586273df3a7f14f2263921932248a80b8361ac9750a07dfa2fa69a30e22231f5"
},
"st": {
"_type": "sec_certs.sample.document_state.DocumentState",
"convert_ok": true,
"download_ok": true,
"extract_ok": true,
"json_hash": null,
"source_hash": "e96a165a8e006c8bae207b6cdeb5494fd69b9f594d323f266c1eb3639087c131",
"txt_hash": "80e1d3fd57d2fb7b875a579116fed710cefa8d2ebb5074643bafaf8da5771956"
}
},
"status": "active"
}