This page was not yet optimized for use on mobile
devices.
SUSE Linux Enterprise Server 15, SP4
Known vulnerabilities detected
Our automated heuristics have identified vulnerabilities that may be associated with this certificate. See the CVEs section for details.
This certificate has disappeared from the Common Criteria portal listing*.
However, there is a certificate
that matches this one in the current listing:
You can also examine other similar certificates below.
| SUSE Linux Enterprise Server 15, SP4 | BSI-DSZ-CC-1248-2026 | Compare |
CSV information
| Status | active |
|---|---|
| Valid from | 24.02.2026 |
| Valid until | 24.02.2031 |
| Scheme | 🇩🇪 DE |
| Manufacturer | SUSE Software Solutions Germany GmbH |
| Category | Other Devices and Systems |
| Security level | |
| Protection profiles |
Heuristics summary
Certificate ID: BSI-DSZ-CC-1248-2026
Certificate
Extracted keywords
Security level
EAL 4, EAL 2, EAL 4 augmentedSecurity Assurance Requirements (SAR)
ALC_FLR.3, ALC_FLRProtection profiles
BSI-CC-PP-0067-2010Certificates
BSI-DSZ-CC-1248-2026Standards
ISO/IEC 15408, ISO/IEC 18045File metadata
| Title | Certificate BSI-DSZ-CC-1248-2026 |
|---|---|
| Subject | "Common Criteria, Certification, Zertifizierung, Linux-basiertes Betriebssystem, Operating System Protection Profile, Virtualization" |
| Keywords | """Common Criteria, Certification, Zertifizierung, Linux-basiertes Betriebssystem, Operating System Protection Profile, Virtualization""" |
| Author | Federal Office for Information Security |
| Pages | 1 |
Certification report
Extracted keywords
Symmetric Algorithms
AES, HMACAsymmetric Algorithms
ECDH, ECDSA, ECC, DHHash functions
SHA256, SHA-256, SHA-384, SHA-512, SHA-2, PBKDF2Schemes
MAC, Key Exchange, Key AgreementProtocols
SSHv2, SSH, SSL, TLS, IKEv1, IKEv2, IKE, IPsec, VPNRandomness
RNGLibraries
OpenSSLElliptic Curves
P-256, P-384, P-521Block cipher modes
CBC, CTR, GCM, CCM, XTSSecurity level
EAL 4, EAL 2, EAL 1, EAL4+, EAL 4 augmentedSecurity Assurance Requirements (SAR)
ALC_FLR.3, ALC_FLRSecurity Functional Requirements (SFR)
FCS_RNG.1, FIA_AFL.1, FIA_UAU.7, FTP_ITC_EXT.1, FTP_ITC.1Protection profiles
BSI-CC-PP-0067-2010, BSI-CC-PP-0067-Certificates
BSI-DSZ-CC-1248-2026Evaluation facilities
atsecVulnerabilities
CVE-2024-28956Certification process
being maintained, is not given any longer. In particular, prior to the dissemination of confidential documentation and information related to the TOE or resulting from the evaluation and certification, GmbH [6] Final Evaluation Technical Report, Version 3, 2026-02-20, atsec information security GmbH (confidential document) [7] Operating System Protection Profile, Version 2.0, 01 June 2010, BSI-CC-PP-0067- 2010, OSPP, Version 2.0, 28 May 2010 [8] MASTER CM List, 2026-02-20, SUSE Software Solutions Germany GmbH (confidential document) [9] Common Criteria EAL4+ Evaluated Configuration Guide for SUSE LINUX Enterprise Server 15 SP4, GmbH [10] Linux Specification High-level design, 2024-10-24, SUSE Software Solutions Germany GmbH (confidential document) 7 specifically • AIS 1, Version 14, Durchführung der Ortsbesichtigung in der EntwicklungsumgebungStandards
FIPS180-4, FIPS197, FIPS 186-5, FIPS198-1, PKCS#1, AIS 20, AIS 1, AIS 14, AIS 19, AIS 23, AIS 32, RFC8017, RFC4253, RFC4252, RFC8332, RFC5656, RFC 4344, RFC5647, RFC2104, RFC4251, RFC6668, RFC7296, RFC3447, RFC7427, RFC4754, RFC3526, RFC4868, RFC3602, RFC5930, RFC3686, RFC5282, RFC4309, RFC5116, RFC4106, RFC4303, RFC2898, ISO/IEC 15408, ISO/IEC 18045, ISO/IEC 17065Technical reports
BSI TR-02102File metadata
| Title | Certification Report BSI-DSZ-CC-1248-2026 |
|---|---|
| Subject | "Common Criteria, Certification, Zertifizierung, Linux-basiertes Betriebssystem, Operating System Protection Profile, Virtualization" |
| Keywords | """Common Criteria, Certification, Zertifizierung, Linux-basiertes Betriebssystem, Operating System Protection Profile, Virtualization""" |
| Author | Federal Office for Information Security |
| Pages | 32 |
Frontpage
| Certificate ID | BSI-DSZ-CC-1248-2026 |
|---|---|
| Certified item | SUSE Linux Enterprise Server 15 SP4 |
| Certification lab | BSI |
| Developer | SUSE Software Solutions Germany GmbH |
Security target
Extracted keywords
Symmetric Algorithms
AES128, AES256, AES, AES-256, Triple-DES, HMAC, CMACAsymmetric Algorithms
ECDSA, ECC, Diffie-Hellman, DH, DSAHash functions
SHA-1, SHA-256, SHA-384, SHA-512, SHA256, SHA384, SHA512, SHA-2, PBKDF2Schemes
MAC, Key ExchangeProtocols
SSHv2, SSH, SSL, TLS, IKEv2, IKE, IKEv1, IPsec, VPNRandomness
DRBG, RNGLibraries
OpenSSLElliptic Curves
curve P-256, curve P-384, curve P-521, P-256, P-384, P-521Block cipher modes
CBC, CTR, GCM, CCM, XTSSecurity level
EAL4, EAL4 augmentedClaims
O.AUDITING, O.CRYPTO, O.DISCRETIONARY, O.NETWORK, O.SUBJECT, O.MANAGE, O.TRUSTED_CHANNEL, O.COMP, O.ROLE, O.REMOTE_AUDIT, O.ANALYZE_AUDIT, O.CP, T.ACCESS, T.RESTRICT, T.IA, T.INFOFLOW, T.COMM, T.ROLE, T.UNOBSERVED_AUDIT, A.CONNECT, A.PHYSICAL, A.MANAGE, A.AUTHUSER, A.TRAINEDUSER, A.DETECT, A.PEER, A.IT, A.KEYS, OE.ADMIN, OE.REMOTE, OE.INFO_PROTECT, OE.INSTALL, OE.MAINTENANCE, OE.PHYSICAL, OE.RECOVER, OE.TRUSTED, OE.ITSecurity Assurance Requirements (SAR)
ALC_FLR.3, ASE_CCL.1Security Functional Requirements (SFR)
FAU_GEN.1, FAU_GEN.2, FAU_SAR.1, FAU_SAR.2, FAU_SAR.3, FAU_SEL.1, FAU_STG.1, FAU_STG.3, FAU_STG.4, FAU_GEN, FAU_GEN.1.1, FAU_GEN.1.2, FAU_GEN.2.1, FAU_SAR.1.1, FAU_SAR.1.2, FAU_SAR.2.1, FAU_SAR.3.1, FAU_SEL.1.1, FAU_STG.1.1, FAU_STG.1.2, FAU_STG.3.1, FAU_STG.4.1, FCS_RNG.1, FCS_CKM.1, FCS_CKM.2, FCS_CKM.4, FCS_COP.1, FCS_RNG, FCS_RNG.1.1, FCS_RNG.1.2, FCS_CKM.1.1, FCS_CKM.2.1, FCS_CKM.4.1, FCS_COP.1.1, FDP_CDP, FDP_CDP.1, FDP_ACC.1, FDP_ACF.1, FDP_IFC.2, FDP_IFF.1, FDP_ITC.2, FDP_RIP.2, FDP_RIP.3, FDP_ACC.2, FDP_ETC.2, FDP_IFC.1, FDP_CDP.1.1, FDP_UCT, FDP_ACC.1.1, FDP_ACF.1.1, FDP_ACF.1.2, FDP_ACF.1.3, FDP_ACF.1.4, FDP_IFC.2.1, FDP_IFC.2.2, FDP_IFF.1.1, FDP_IFF.1.2, FDP_IFF.1.3, FDP_IFF.1.4, FDP_IFF.1.5, FDP_ITC.2.1, FDP_ITC.2.2, FDP_ITC.2.3, FDP_ITC.2.4, FDP_ITC.2.5, FDP_RIP.2.1, FDP_RIP.3.1, FDP_ACC.2.1, FDP_ACC.2.2, FDP_ETC.2.1, FDP_ETC.2.2, FDP_ETC.2.3, FDP_ETC.2.4, FDP_ITC.1, FIA_AFL.1, FIA_ATD.1, FIA_SOS.1, FIA_UAU.1, FIA_UAU.5, FIA_UAU.7, FIA_UID.1, FIA_USB.2, FIA_UID.2, FIA_AFL.1.1, FIA_AFL.1.2, FIA_ATD.1.1, FIA_SOS.1.1, FIA_UAU.1.1, FIA_UAU.1.2, FIA_UAU.5.1, FIA_UAU.5.2, FIA_UAU.7.1, FIA_UID.1.1, FIA_UID.1.2, FIA_USB.2.1, FIA_USB.2.2, FIA_USB.2.3, FIA_USB.2.4, FIA_UID.2.1, FMT_MSA.3, FMT_MSA.1, FMT_MTD.1, FMT_MSA.4, FMT_REV.1, FMT_SMF.1, FMT_SMR.1, FMT_MSA.3.1, FMT_MSA.3.2, FMT_MSA.1.1, FMT_MTD.1.1, FMT_MSA.4.1, FMT_REV.1.1, FMT_REV.1.2, FMT_SMF.1.1, FMT_SMR.1.1, FMT_SMR.1.2, FPT_STM.1, FPT_TDC.1, FPT_STM.1.1, FPT_TDC.1.1, FPT_TDC.1.2, FTA_SSL.1, FTA_SSL.2, FTA_SSL.1.1, FTA_SSL.1.2, FTA_SSL.2.1, FTA_SSL.2.2, FTP_ITC.1, FTP_ITC.1.1, FTP_ITC.1.2, FTP_ITC.1.3Certificates
BSI-DSZ-CC-1248Evaluation facilities
atsecCertification process
out of scope, PAT) for simple as well as more complex protocols. This mechanism is out of scope for the evaluation, as Port Address Translation (PAT) for simple as well as more complex protocols. This mechanism is out of scope for the evaluation. Furthermore, packet mangling support is provided with NFTables which is also, DAC mechanism but may be supplemented by further restrictions. These additional restrictions are out of scope for this evaluation. Examples of objects which are accessible to users that cannot be used to storeStandards
FIPS 140-3, FIPS PUB 186-3, FIPS PUB 186-5, FIPS PUB 186-4, FIPS197, AIS 20, AIS 31, RFC 2460, RFC 3484, RFC 3542, RFC 4213, RFC4253, RFC4306, RFC5656, RFC7296, RFC2409, RFC3526, RFC4753, RFC5114, RFC6954, RFC5647, RFC6668, RFC4252, RFC3602, RFC4307, RFC4301, RFC4303, RFC4309, RFC4106, RFC 791, RFC 793, RFC 768, RFC 792, RFC 4253, RFC 4252Technical reports
BSI TR-02102File metadata
| Title | Security Target for SUSE Linux Enterprise Server 15 SP4 including KVM virtualization (version 4.0 as of 2026-02-20) |
|---|---|
| Subject | Security Target, Common Criteria, Linux Distribution |
| Keywords | "Security Target, Common Criteria, Linux Distribution" |
| Author | SUSE Software Solutions Germany GmbH |
| Pages | 115 |
Heuristics
Automated inference - use with caution
All attributes shown in this section (e.g., links between certificates, products, vendors, and known CVEs) are generated by automated heuristics and have not been reviewed by humans. These methods can produce false positives or false negatives and should not be treated as definitive without independent verification. For details on our data sources and inference methods, see our methodology. If you believe any information here is inaccurate or harmful, please submit feedback.Certificate ID
BSI-DSZ-CC-1248-2026Extracted SARs
ALC_FLR.3, ASE_CCL.1CPE matches
- cpe:2.3:o:suse:linux_enterprise_server:15:sp4:*:*:*:*:*:*
- cpe:2.3:o:suse:linux_enterprise_server:15:sp4:*:*:-:-:*:*
- cpe:2.3:o:suse:linux_enterprise_server:15:sp4:*:*:-:sap:*:*
- cpe:2.3:o:suse:linux_enterprise_server:15:sp4:*:*:ltss:-:*:*
- cpe:2.3:o:suse:linux_enterprise_server:15:sp5:*:*:*:*:*:*
- cpe:2.3:o:suse:linux_enterprise_server:15:sp5:*:*:-:-:*:*
- cpe:2.3:o:suse:linux_enterprise_server:15:sp5:*:*:-:sap:*:*
- cpe:2.3:o:suse:linux_enterprise_server:15:sp5:*:*:ltss:-:*:*
- cpe:2.3:o:suse:linux_enterprise_server:15:sp6:*:*:-:-:*:*
- cpe:2.3:o:suse:linux_enterprise_server:15:sp6:*:*:-:sap:*:*
- cpe:2.3:o:suse:linux_enterprise_server:15:sp6:*:*:ltss:-:*:*
- cpe:2.3:o:suse:linux_enterprise_server:15:sp7:*:*:-:-:*:*
- cpe:2.3:o:suse:linux_enterprise_server:15:sp7:*:*:-:sap:*:*
Related CVEs
| ID | Links | Severity | CVSS Score | Published on |
|---|---|---|---|---|
| Base score | ||||
| CVE-2002-20001 | HIGH | 7.5 | 11.11.2021 | |
| CVE-2018-17962 | HIGH | 7.5 | 09.10.2018 | |
| CVE-2019-18897 | HIGH | 7.8 | 02.03.2020 | |
| CVE-2019-18901 | MEDIUM | 5.5 | 02.03.2020 | |
| CVE-2019-18902 | CRITICAL | 9.8 | 02.03.2020 | |
| CVE-2019-18903 | CRITICAL | 9.8 | 02.03.2020 | |
| CVE-2020-8013 | LOW | 2.5 | 02.03.2020 | |
| CVE-2022-27239 | HIGH | 7.8 | 27.04.2022 | |
| CVE-2023-23005 | MEDIUM | 5.5 | 01.03.2023 | |
| CVE-2026-31431 | HIGH | 7.8 | 22.04.2026 |
Showing 5 out of 10.
Similar certificates
| Name | Certificate ID | Actions |
|---|---|---|
| SUSE Linux Enterprise Server 15, SP4 | BSI-DSZ-CC-1248-2026 | Compare |
Scheme data
| Cert Id | BSI-DSZ-CC-1248-2026 | |
|---|---|---|
| Product | SUSE Linux Enterprise Server 15, SP4 | |
| Vendor | SUSE Software Solutions Germany GmbH | |
| Certification Date | 24.02.2026 | |
| Category | Operating systems | |
| Url | https://www.bsi.bund.de/SharedDocs/Zertifikate_CC/CC/Betriebssysteme/1248.html | |
| Enhanced | ||
| Product | SUSE Linux Enterprise Server 15, SP4 | |
| Applicant | SUSE Software Solutions Germany GmbH Frankenstraße 146 90461 Nürnberg | |
| Evaluation Facility | atsec information security GmbH | |
| Protection Profile | Operating System Protection Profile, Version 2.0, 01 June 2010, BSI-CC-PP-0067-2010; OSPP Extended Package – Virtualization, Version 2.0, 28 May 2010; OSPP Extended Package – Advanced Audit, Version 2.0, 28 May 2010; OSPP Extended Package – Advanced Management, Version 2.0, 28 May 2010; | |
| Certification Date | 24.02.2026 | |
| Expiration Date | 23.02.2031 | |
| Report Link | https://www.bsi.bund.de/SharedDocs/Downloads/DE/BSI/Zertifizierung/Reporte/Reporte1200/1248a_pdf.pdf?__blob=publicationFile&v=2 | |
| Target Link | https://www.bsi.bund.de/SharedDocs/Downloads/DE/BSI/Zertifizierung/Reporte/Reporte1200/1248b_pdf.pdf?__blob=publicationFile&v=2 | |
| Cert Link | https://www.bsi.bund.de/SharedDocs/Downloads/DE/BSI/Zertifizierung/Reporte/Reporte1200/1248c_pdf.pdf?__blob=publicationFile&v=2 | |
| Description | SUSE Linux Enterprise Server is a highly-configurable Linux-based operating system which has been developed to provide a good level of security as required in commercial environments. It also meets all requirements of the Operating System Protection Profile, together with the extended packages for Virtualization, Advanced Management and Advanced Audit. | |
References
No references are available for this certificate.
Updates Feed
-
The certificate became unavailable — it disappeared from the upstream listing.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate was first processed.
Raw data
{
"_type": "sec_certs.sample.cc.CCCertificate",
"category": "Other Devices and Systems",
"cert_link": "https://www.commoncriteriaportal.org/nfs/ccpfiles/files/epfiles/1248c_pdf.pdf",
"dgst": "bb7f45e5dbacf3d8",
"heuristics": {
"_type": "sec_certs.sample.cc_eucc_common.Heuristics",
"annotated_references": null,
"cert_id": "BSI-DSZ-CC-1248-2026",
"cert_lab": [
"BSI"
],
"cpe_matches": {
"_type": "Set",
"elements": [
"cpe:2.3:o:suse:linux_enterprise_server:15:sp6:*:*:-:-:*:*",
"cpe:2.3:o:suse:linux_enterprise_server:15:sp5:*:*:-:sap:*:*",
"cpe:2.3:o:suse:linux_enterprise_server:15:sp7:*:*:-:-:*:*",
"cpe:2.3:o:suse:linux_enterprise_server:15:sp4:*:*:ltss:-:*:*",
"cpe:2.3:o:suse:linux_enterprise_server:15:sp5:*:*:-:-:*:*",
"cpe:2.3:o:suse:linux_enterprise_server:15:sp4:*:*:*:*:*:*",
"cpe:2.3:o:suse:linux_enterprise_server:15:sp4:*:*:-:-:*:*",
"cpe:2.3:o:suse:linux_enterprise_server:15:sp5:*:*:*:*:*:*",
"cpe:2.3:o:suse:linux_enterprise_server:15:sp7:*:*:-:sap:*:*",
"cpe:2.3:o:suse:linux_enterprise_server:15:sp5:*:*:ltss:-:*:*",
"cpe:2.3:o:suse:linux_enterprise_server:15:sp6:*:*:-:sap:*:*",
"cpe:2.3:o:suse:linux_enterprise_server:15:sp6:*:*:ltss:-:*:*",
"cpe:2.3:o:suse:linux_enterprise_server:15:sp4:*:*:-:sap:*:*"
]
},
"direct_transitive_cves": null,
"eal": "EAL4+",
"extracted_sars": {
"_type": "Set",
"elements": [
{
"_type": "sec_certs.sample.sar.SAR",
"family": "ALC_FLR",
"level": 3
},
{
"_type": "sec_certs.sample.sar.SAR",
"family": "ASE_CCL",
"level": 1
}
]
},
"extracted_versions": {
"_type": "Set",
"elements": [
"15"
]
},
"indirect_transitive_cves": null,
"next_certificates": null,
"prev_certificates": null,
"protection_profiles": {
"_type": "Set",
"elements": [
"70cdc8b0cf910af7"
]
},
"related_cves": {
"_type": "Set",
"elements": [
"CVE-2022-27239",
"CVE-2020-8013",
"CVE-2026-31431",
"CVE-2023-23005",
"CVE-2019-18901",
"CVE-2018-17962",
"CVE-2002-20001",
"CVE-2019-18897",
"CVE-2019-18903",
"CVE-2019-18902"
]
},
"report_references": {
"_type": "sec_certs.sample.certificate.References",
"directly_referenced_by": null,
"directly_referencing": null,
"indirectly_referenced_by": null,
"indirectly_referencing": null
},
"scheme_data": {
"category": "Operating systems",
"cert_id": "BSI-DSZ-CC-1248-2026",
"certification_date": "2026-02-24",
"enhanced": {
"applicant": "SUSE Software Solutions Germany GmbH Frankenstra\u00dfe 146 90461 N\u00fcrnberg",
"cert_link": "https://www.bsi.bund.de/SharedDocs/Downloads/DE/BSI/Zertifizierung/Reporte/Reporte1200/1248c_pdf.pdf?__blob=publicationFile\u0026v=2",
"certification_date": "2026-02-24",
"description": "SUSE Linux Enterprise Server is a highly-configurable Linux-based operating system which has been developed to provide a good level of security as required in commercial environments. It also meets all requirements of the Operating System Protection Profile, together with the extended packages for Virtualization, Advanced Management and Advanced Audit.",
"evaluation_facility": "atsec information security GmbH",
"expiration_date": "2031-02-23",
"product": "SUSE Linux Enterprise Server 15, SP4",
"protection_profile": "Operating System Protection Profile, Version 2.0, 01 June 2010, BSI-CC-PP-0067-2010; OSPP Extended Package \u2013 Virtualization, Version 2.0, 28 May 2010; OSPP Extended Package \u2013 Advanced Audit, Version 2.0, 28 May 2010; OSPP Extended Package \u2013 Advanced Management, Version 2.0, 28 May 2010;",
"report_link": "https://www.bsi.bund.de/SharedDocs/Downloads/DE/BSI/Zertifizierung/Reporte/Reporte1200/1248a_pdf.pdf?__blob=publicationFile\u0026v=2",
"target_link": "https://www.bsi.bund.de/SharedDocs/Downloads/DE/BSI/Zertifizierung/Reporte/Reporte1200/1248b_pdf.pdf?__blob=publicationFile\u0026v=2"
},
"product": "SUSE Linux Enterprise Server 15, SP4",
"url": "https://www.bsi.bund.de/SharedDocs/Zertifikate_CC/CC/Betriebssysteme/1248.html",
"vendor": "SUSE Software Solutions Germany GmbH"
},
"st_references": {
"_type": "sec_certs.sample.certificate.References",
"directly_referenced_by": null,
"directly_referencing": null,
"indirectly_referenced_by": null,
"indirectly_referencing": null
},
"verified_cpe_matches": null
},
"maintenance_updates": {
"_type": "Set",
"elements": []
},
"manufacturer": "SUSE Software Solutions Germany GmbH",
"manufacturer_web": "https://www.suse.com/",
"name": "SUSE Linux Enterprise Server 15, SP4",
"not_valid_after": "2031-02-24",
"not_valid_before": "2026-02-24",
"pdf_data": {
"_type": "sec_certs.sample.cc_eucc_common.PdfData",
"cert_filename": "1248c_pdf.pdf",
"cert_frontpage": null,
"cert_keywords": {
"asymmetric_crypto": {},
"cc_cert_id": {
"DE": {
"BSI-DSZ-CC-1248-2026": 1
}
},
"cc_claims": {},
"cc_protection_profile_id": {
"BSI": {
"BSI-CC-PP-0067-2010": 1
}
},
"cc_sar": {
"ALC": {
"ALC_FLR": 1,
"ALC_FLR.3": 1
}
},
"cc_security_level": {
"EAL": {
"EAL 2": 1,
"EAL 4": 1,
"EAL 4 augmented": 1
}
},
"cc_sfr": {},
"certification_process": {},
"cipher_mode": {},
"cplc_data": {},
"crypto_engine": {},
"crypto_library": {},
"crypto_protocol": {},
"crypto_scheme": {},
"device_model": {},
"ecc_curve": {},
"eval_facility": {},
"hash_function": {},
"ic_data_group": {},
"javacard_api_const": {},
"javacard_packages": {},
"javacard_version": {},
"os_name": {},
"pq_crypto": {},
"randomness": {},
"side_channel_analysis": {},
"standard_id": {
"ISO": {
"ISO/IEC 15408": 2,
"ISO/IEC 18045": 2
}
},
"symmetric_crypto": {},
"technical_report_id": {},
"tee_name": {},
"tls_cipher_suite": {},
"vendor": {},
"vulnerability": {}
},
"cert_metadata": {
"/Author": "Federal Office for Information Security",
"/Keywords": "\"\"\"Common Criteria, Certification, Zertifizierung, Linux-basiertes Betriebssystem, Operating System Protection Profile, Virtualization\"\"\"",
"/Subject": "\"Common Criteria, Certification, Zertifizierung, Linux-basiertes Betriebssystem, Operating System Protection Profile, Virtualization\"",
"/Title": "Certificate BSI-DSZ-CC-1248-2026",
"pdf_file_size_bytes": 237904,
"pdf_hyperlinks": {
"_type": "Set",
"elements": []
},
"pdf_is_encrypted": false,
"pdf_number_of_pages": 1
},
"report_filename": "1248a_pdf.pdf",
"report_frontpage": {
"DE": {
"cc_security_level": "Common Criteria Part 3 conformant EAL 4 augmented by ALC_FLR.3 valid until: 23 February 2031",
"cc_version": "PP conformant Common Criteria Part 2 extended",
"cert_id": "BSI-DSZ-CC-1248-2026",
"cert_item": "SUSE Linux Enterprise Server 15 SP4",
"cert_lab": "BSI",
"developer": "SUSE Software Solutions Germany GmbH",
"match_rules": [
"(BSI-DSZ-CC-.+?) (?:for|For) (.+?) from (.*)"
],
"ref_protection_profiles": "Operating System Protection Profile, Version 2.0, 01 June 2010, BSI-CC-PP-0067-2010, OSPP Extended Package \u2013 Virtualization, Version 2.0, 28 May 2010, OSPP Extended Package \u2013 Advanced Audit, Version 2.0, 28 May 2010, OSPP Extended Package \u2013 Advanced Management, Version 2.0, 28 May 2010"
}
},
"report_keywords": {
"asymmetric_crypto": {
"ECC": {
"ECC": {
"ECC": 1
},
"ECDH": {
"ECDH": 2
},
"ECDSA": {
"ECDSA": 6
}
},
"FF": {
"DH": {
"DH": 3
}
}
},
"cc_cert_id": {
"DE": {
"BSI-DSZ-CC-1248-2026": 18
}
},
"cc_claims": {},
"cc_protection_profile_id": {
"BSI": {
"BSI-CC-PP-0067-": 1,
"BSI-CC-PP-0067-2010": 2
}
},
"cc_sar": {
"ALC": {
"ALC_FLR": 3,
"ALC_FLR.3": 4
}
},
"cc_security_level": {
"EAL": {
"EAL 1": 1,
"EAL 2": 3,
"EAL 4": 5,
"EAL 4 augmented": 3,
"EAL4+": 2
}
},
"cc_sfr": {
"FCS": {
"FCS_RNG.1": 1
},
"FIA": {
"FIA_AFL.1": 1,
"FIA_UAU.7": 1
},
"FTP": {
"FTP_ITC.1": 1,
"FTP_ITC_EXT.1": 1
}
},
"certification_process": {
"ConfidentialDocument": {
"GmbH [10] Linux Specification High-level design, 2024-10-24, SUSE Software Solutions Germany GmbH (confidential document) 7 specifically \u2022 AIS 1, Version 14, Durchf\u00fchrung der Ortsbesichtigung in der Entwicklungsumgebung": 1,
"GmbH [6] Final Evaluation Technical Report, Version 3, 2026-02-20, atsec information security GmbH (confidential document) [7] Operating System Protection Profile, Version 2.0, 01 June 2010, BSI-CC-PP-0067- 2010, OSPP": 1,
"Version 2.0, 28 May 2010 [8] MASTER CM List, 2026-02-20, SUSE Software Solutions Germany GmbH (confidential document) [9] Common Criteria EAL4+ Evaluated Configuration Guide for SUSE LINUX Enterprise Server 15 SP4": 1,
"being maintained, is not given any longer. In particular, prior to the dissemination of confidential documentation and information related to the TOE or resulting from the evaluation and certification": 1
}
},
"cipher_mode": {
"CBC": {
"CBC": 1
},
"CCM": {
"CCM": 1
},
"CTR": {
"CTR": 3
},
"GCM": {
"GCM": 4
},
"XTS": {
"XTS": 2
}
},
"cplc_data": {},
"crypto_engine": {},
"crypto_library": {
"OpenSSL": {
"OpenSSL": 1
}
},
"crypto_protocol": {
"IKE": {
"IKE": 12,
"IKEv1": 2,
"IKEv2": 11
},
"IPsec": {
"IPsec": 9
},
"SSH": {
"SSH": 10,
"SSHv2": 1
},
"TLS": {
"SSL": {
"SSL": 1
},
"TLS": {
"TLS": 1
}
},
"VPN": {
"VPN": 1
}
},
"crypto_scheme": {
"KA": {
"Key Agreement": 1
},
"KEX": {
"Key Exchange": 1
},
"MAC": {
"MAC": 1
}
},
"device_model": {},
"ecc_curve": {
"NIST": {
"P-256": 8,
"P-384": 8,
"P-521": 8
}
},
"eval_facility": {
"atsec": {
"atsec": 3
}
},
"hash_function": {
"PBKDF": {
"PBKDF2": 2
},
"SHA": {
"SHA2": {
"SHA-2": 1,
"SHA-256": 4,
"SHA-384": 3,
"SHA-512": 2,
"SHA256": 1
}
}
},
"ic_data_group": {},
"javacard_api_const": {},
"javacard_packages": {},
"javacard_version": {},
"os_name": {},
"pq_crypto": {},
"randomness": {
"RNG": {
"RNG": 3
}
},
"side_channel_analysis": {},
"standard_id": {
"BSI": {
"AIS 1": 1,
"AIS 14": 1,
"AIS 19": 1,
"AIS 20": 2,
"AIS 23": 1,
"AIS 32": 1
},
"FIPS": {
"FIPS 186-5": 5,
"FIPS180-4": 7,
"FIPS197": 2,
"FIPS198-1": 2
},
"ISO": {
"ISO/IEC 15408": 4,
"ISO/IEC 17065": 2,
"ISO/IEC 18045": 4
},
"PKCS": {
"PKCS#1": 1
},
"RFC": {
"RFC 4344": 1,
"RFC2104": 1,
"RFC2898": 1,
"RFC3447": 1,
"RFC3526": 1,
"RFC3602": 1,
"RFC3686": 1,
"RFC4106": 1,
"RFC4251": 1,
"RFC4252": 2,
"RFC4253": 4,
"RFC4303": 1,
"RFC4309": 1,
"RFC4754": 1,
"RFC4868": 2,
"RFC5116": 2,
"RFC5282": 2,
"RFC5647": 2,
"RFC5656": 2,
"RFC5930": 1,
"RFC6668": 1,
"RFC7296": 6,
"RFC7427": 1,
"RFC8017": 1,
"RFC8332": 1
}
},
"symmetric_crypto": {
"AES_competition": {
"AES": {
"AES": 10
}
},
"constructions": {
"MAC": {
"HMAC": 12
}
}
},
"technical_report_id": {
"BSI": {
"BSI TR-02102": 1
}
},
"tee_name": {},
"tls_cipher_suite": {},
"vendor": {},
"vulnerability": {
"CVE": {
"CVE-2024-28956": 1
}
}
},
"report_metadata": {
"/Author": "Federal Office for Information Security",
"/Keywords": "\"\"\"Common Criteria, Certification, Zertifizierung, Linux-basiertes Betriebssystem, Operating System Protection Profile, Virtualization\"\"\"",
"/Subject": "\"Common Criteria, Certification, Zertifizierung, Linux-basiertes Betriebssystem, Operating System Protection Profile, Virtualization\"",
"/Title": "Certification Report BSI-DSZ-CC-1248-2026",
"pdf_file_size_bytes": 412428,
"pdf_hyperlinks": {
"_type": "Set",
"elements": []
},
"pdf_is_encrypted": false,
"pdf_number_of_pages": 32
},
"st_filename": "1248b_pdf.pdf",
"st_frontpage": null,
"st_keywords": {
"asymmetric_crypto": {
"ECC": {
"ECC": {
"ECC": 1
},
"ECDSA": {
"ECDSA": 20
}
},
"FF": {
"DH": {
"DH": 3,
"Diffie-Hellman": 19
},
"DSA": {
"DSA": 2
}
}
},
"cc_cert_id": {
"DE": {
"BSI-DSZ-CC-1248": 1
}
},
"cc_claims": {
"A": {
"A.AUTHUSER": 3,
"A.CONNECT": 5,
"A.DETECT": 3,
"A.IT": 3,
"A.KEYS": 3,
"A.MANAGE": 5,
"A.PEER": 6,
"A.PHYSICAL": 4,
"A.TRAINEDUSER": 3
},
"O": {
"O.ANALYZE_AUDIT": 5,
"O.AUDITING": 15,
"O.COMP": 31,
"O.CP": 17,
"O.CRYPTO": 18,
"O.DISCRETIONARY": 11,
"O.MANAGE": 26,
"O.NETWORK": 12,
"O.REMOTE_AUDIT": 8,
"O.ROLE": 17,
"O.SUBJECT": 11,
"O.TRUSTED_CHANNEL": 5
},
"OE": {
"OE.ADMIN": 6,
"OE.INFO_PROTECT": 9,
"OE.INSTALL": 4,
"OE.IT": 4,
"OE.MAINTENANCE": 3,
"OE.PHYSICAL": 3,
"OE.RECOVER": 4,
"OE.REMOTE": 4,
"OE.TRUSTED": 5
},
"T": {
"T.ACCESS": 25,
"T.COMM": 4,
"T.IA": 6,
"T.INFOFLOW": 4,
"T.RESTRICT": 3,
"T.ROLE": 6,
"T.UNOBSERVED_AUDIT": 4
}
},
"cc_protection_profile_id": {},
"cc_sar": {
"ALC": {
"ALC_FLR.3": 4
},
"ASE": {
"ASE_CCL.1": 17
}
},
"cc_security_level": {
"EAL": {
"EAL4": 3,
"EAL4 augmented": 1
}
},
"cc_sfr": {
"FAU": {
"FAU_GEN": 2,
"FAU_GEN.1": 12,
"FAU_GEN.1.1": 1,
"FAU_GEN.1.2": 1,
"FAU_GEN.2": 6,
"FAU_GEN.2.1": 1,
"FAU_SAR.1": 9,
"FAU_SAR.1.1": 1,
"FAU_SAR.1.2": 1,
"FAU_SAR.2": 6,
"FAU_SAR.2.1": 1,
"FAU_SAR.3": 7,
"FAU_SAR.3.1": 1,
"FAU_SEL.1": 9,
"FAU_SEL.1.1": 1,
"FAU_STG.1": 12,
"FAU_STG.1.1": 1,
"FAU_STG.1.2": 1,
"FAU_STG.3": 8,
"FAU_STG.3.1": 1,
"FAU_STG.4": 9,
"FAU_STG.4.1": 1
},
"FCS": {
"FCS_CKM.1": 56,
"FCS_CKM.1.1": 5,
"FCS_CKM.2": 23,
"FCS_CKM.2.1": 2,
"FCS_CKM.4": 16,
"FCS_CKM.4.1": 1,
"FCS_COP.1": 25,
"FCS_COP.1.1": 2,
"FCS_RNG": 2,
"FCS_RNG.1": 24,
"FCS_RNG.1.1": 2,
"FCS_RNG.1.2": 3
},
"FDP": {
"FDP_ACC.1": 37,
"FDP_ACC.1.1": 3,
"FDP_ACC.2": 19,
"FDP_ACC.2.1": 2,
"FDP_ACC.2.2": 2,
"FDP_ACF.1": 41,
"FDP_ACF.1.1": 5,
"FDP_ACF.1.2": 5,
"FDP_ACF.1.3": 5,
"FDP_ACF.1.4": 5,
"FDP_CDP": 5,
"FDP_CDP.1": 14,
"FDP_CDP.1.1": 2,
"FDP_ETC.2": 7,
"FDP_ETC.2.1": 1,
"FDP_ETC.2.2": 1,
"FDP_ETC.2.3": 1,
"FDP_ETC.2.4": 1,
"FDP_IFC.1": 9,
"FDP_IFC.2": 19,
"FDP_IFC.2.1": 2,
"FDP_IFC.2.2": 2,
"FDP_IFF.1": 18,
"FDP_IFF.1.1": 2,
"FDP_IFF.1.2": 2,
"FDP_IFF.1.3": 2,
"FDP_IFF.1.4": 2,
"FDP_IFF.1.5": 2,
"FDP_ITC.1": 1,
"FDP_ITC.2": 17,
"FDP_ITC.2.1": 2,
"FDP_ITC.2.2": 2,
"FDP_ITC.2.3": 2,
"FDP_ITC.2.4": 2,
"FDP_ITC.2.5": 2,
"FDP_RIP.2": 13,
"FDP_RIP.2.1": 1,
"FDP_RIP.3": 13,
"FDP_RIP.3.1": 1,
"FDP_UCT": 1
},
"FIA": {
"FIA_AFL.1": 9,
"FIA_AFL.1.1": 1,
"FIA_AFL.1.2": 1,
"FIA_ATD.1": 20,
"FIA_ATD.1.1": 2,
"FIA_SOS.1": 8,
"FIA_SOS.1.1": 1,
"FIA_UAU.1": 12,
"FIA_UAU.1.1": 1,
"FIA_UAU.1.2": 1,
"FIA_UAU.5": 10,
"FIA_UAU.5.1": 1,
"FIA_UAU.5.2": 1,
"FIA_UAU.7": 6,
"FIA_UAU.7.1": 1,
"FIA_UID.1": 14,
"FIA_UID.1.1": 1,
"FIA_UID.1.2": 1,
"FIA_UID.2": 8,
"FIA_UID.2.1": 1,
"FIA_USB.2": 7,
"FIA_USB.2.1": 1,
"FIA_USB.2.2": 1,
"FIA_USB.2.3": 1,
"FIA_USB.2.4": 1
},
"FMT": {
"FMT_MSA.1": 48,
"FMT_MSA.1.1": 5,
"FMT_MSA.3": 49,
"FMT_MSA.3.1": 7,
"FMT_MSA.3.2": 7,
"FMT_MSA.4": 6,
"FMT_MSA.4.1": 1,
"FMT_MTD.1": 142,
"FMT_MTD.1.1": 21,
"FMT_REV.1": 15,
"FMT_REV.1.1": 2,
"FMT_REV.1.2": 2,
"FMT_SMF.1": 34,
"FMT_SMF.1.1": 1,
"FMT_SMR.1": 43,
"FMT_SMR.1.1": 1,
"FMT_SMR.1.2": 1
},
"FPT": {
"FPT_STM.1": 8,
"FPT_STM.1.1": 1,
"FPT_TDC.1": 22,
"FPT_TDC.1.1": 2,
"FPT_TDC.1.2": 2
},
"FTA": {
"FTA_SSL.1": 7,
"FTA_SSL.1.1": 1,
"FTA_SSL.1.2": 1,
"FTA_SSL.2": 7,
"FTA_SSL.2.1": 1,
"FTA_SSL.2.2": 1
},
"FTP": {
"FTP_ITC.1": 10,
"FTP_ITC.1.1": 1,
"FTP_ITC.1.2": 1,
"FTP_ITC.1.3": 1
}
},
"certification_process": {
"OutOfScope": {
"DAC mechanism but may be supplemented by further restrictions. These additional restrictions are out of scope for this evaluation. Examples of objects which are accessible to users that cannot be used to store": 1,
"PAT) for simple as well as more complex protocols. This mechanism is out of scope for the evaluation": 1,
"as Port Address Translation (PAT) for simple as well as more complex protocols. This mechanism is out of scope for the evaluation. Furthermore, packet mangling support is provided with NFTables which is also": 1,
"out of scope": 3
}
},
"cipher_mode": {
"CBC": {
"CBC": 2
},
"CCM": {
"CCM": 6
},
"CTR": {
"CTR": 3
},
"GCM": {
"GCM": 7
},
"XTS": {
"XTS": 3
}
},
"cplc_data": {},
"crypto_engine": {},
"crypto_library": {
"OpenSSL": {
"OpenSSL": 7
}
},
"crypto_protocol": {
"IKE": {
"IKE": 19,
"IKEv1": 1,
"IKEv2": 19
},
"IPsec": {
"IPsec": 3
},
"SSH": {
"SSH": 55,
"SSHv2": 8
},
"TLS": {
"SSL": {
"SSL": 30
},
"TLS": {
"TLS": 3
}
},
"VPN": {
"VPN": 1
}
},
"crypto_scheme": {
"KEX": {
"Key Exchange": 6
},
"MAC": {
"MAC": 1
}
},
"device_model": {},
"ecc_curve": {
"NIST": {
"P-256": 4,
"P-384": 4,
"P-521": 4,
"curve P-256": 2,
"curve P-384": 2,
"curve P-521": 2
}
},
"eval_facility": {
"atsec": {
"atsec": 118
}
},
"hash_function": {
"PBKDF": {
"PBKDF2": 5
},
"SHA": {
"SHA1": {
"SHA-1": 2
},
"SHA2": {
"SHA-2": 6,
"SHA-256": 4,
"SHA-384": 4,
"SHA-512": 4,
"SHA256": 1,
"SHA384": 1,
"SHA512": 1
}
}
},
"ic_data_group": {},
"javacard_api_const": {},
"javacard_packages": {},
"javacard_version": {},
"os_name": {},
"pq_crypto": {},
"randomness": {
"PRNG": {
"DRBG": 1
},
"RNG": {
"RNG": 11
}
},
"side_channel_analysis": {},
"standard_id": {
"BSI": {
"AIS 20": 1,
"AIS 31": 1
},
"FIPS": {
"FIPS 140-3": 4,
"FIPS PUB 186-3": 2,
"FIPS PUB 186-4": 1,
"FIPS PUB 186-5": 3,
"FIPS197": 2
},
"RFC": {
"RFC 2460": 1,
"RFC 3484": 1,
"RFC 3542": 1,
"RFC 4213": 1,
"RFC 4252": 4,
"RFC 4253": 3,
"RFC 768": 1,
"RFC 791": 2,
"RFC 792": 1,
"RFC 793": 1,
"RFC2409": 2,
"RFC3526": 3,
"RFC3602": 3,
"RFC4106": 4,
"RFC4252": 6,
"RFC4253": 12,
"RFC4301": 4,
"RFC4303": 5,
"RFC4306": 4,
"RFC4307": 5,
"RFC4309": 4,
"RFC4753": 2,
"RFC5114": 3,
"RFC5647": 2,
"RFC5656": 4,
"RFC6668": 2,
"RFC6954": 3,
"RFC7296": 5
}
},
"symmetric_crypto": {
"AES_competition": {
"AES": {
"AES": 20,
"AES-256": 1,
"AES128": 1,
"AES256": 1
}
},
"DES": {
"3DES": {
"Triple-DES": 1
}
},
"constructions": {
"MAC": {
"CMAC": 2,
"HMAC": 9
}
}
},
"technical_report_id": {
"BSI": {
"BSI TR-02102": 1
}
},
"tee_name": {},
"tls_cipher_suite": {},
"vendor": {},
"vulnerability": {}
},
"st_metadata": {
"/Author": "SUSE Software Solutions Germany GmbH",
"/Keywords": "\"Security Target, Common Criteria, Linux Distribution\"",
"/Subject": "Security Target, Common Criteria, Linux Distribution",
"/Title": "Security Target for SUSE Linux Enterprise Server 15 SP4 including KVM virtualization (version 4.0 as of 2026-02-20)",
"pdf_file_size_bytes": 1384949,
"pdf_hyperlinks": {
"_type": "Set",
"elements": [
"http://tools.ietf.org/html/rfc6668",
"http://tools.ietf.org/html/rfc4252",
"http://csrc.nist.gov/publications/fips/fips197/fips-197.pdf",
"http://tools.ietf.org/html/rfc5114",
"http://tools.ietf.org/html/rfc4253",
"http://www.ietf.org/rfc/rfc4106.txt",
"http://tools.ietf.org/html/rfc4306",
"http://tools.ietf.org/html/rfc4303",
"http://www.commoncriteriaportal.org/files/ccfiles/CCPART1V3.1R5.pdf",
"http://www.ietf.org/rfc/rfc7296.txt",
"http://tools.ietf.org/html/rfc3526",
"http://tools.ietf.org/html/rfc4307",
"http://tools.ietf.org/html/rfc4301",
"http://tools.ietf.org/html/rfc2409",
"http://tools.ietf.org/html/rfc4753",
"http://www.ietf.org/rfc/rfc6954.txt",
"http://www.commoncriteriaportal.org/files/ccfiles/CCPART3V3.1R5.pdf",
"http://tools.ietf.org/html/rfc5647",
"http://tools.ietf.org/html/rfc3602",
"http://tools.ietf.org/html/rfc5656",
"http://www.ietf.org/rfc/rfc4309.txt",
"http://www.commoncriteriaportal.org/files/ccfiles/CCPART2V3.1R5.pdf"
]
},
"pdf_is_encrypted": false,
"pdf_number_of_pages": 115
}
},
"protection_profile_links": {
"_type": "Set",
"elements": [
"https://www.commoncriteriaportal.org/nfs/ccpfiles/files/ppfiles/pp0067b_pdf.pdf"
]
},
"report_link": "https://www.commoncriteriaportal.org/nfs/ccpfiles/files/epfiles/1248a_pdf.pdf",
"scheme": "DE",
"security_level": {
"_type": "Set",
"elements": []
},
"st_link": "https://www.commoncriteriaportal.org/nfs/ccpfiles/files/epfiles/1248b_pdf.pdf",
"state": {
"_type": "sec_certs.sample.cc_eucc_common.InternalState",
"cert": {
"_type": "sec_certs.sample.document_state.DocumentState",
"convert_ok": true,
"download_ok": true,
"extract_ok": true,
"json_hash": null,
"source_hash": "c39091789ae96c8875516403d64a43cff6d56b9130be17de87776a51480e8b50",
"txt_hash": "1d49e85a6840ea107cfca697460db6ede8a3d88376d00ad4fb87445ca0e2c777"
},
"report": {
"_type": "sec_certs.sample.document_state.DocumentState",
"convert_ok": true,
"download_ok": true,
"extract_ok": true,
"json_hash": null,
"source_hash": "21c82608fb37da7096e67418df034845d6f27335703024ecabb16fc2fc30a117",
"txt_hash": "6829d123115e63dcfa06d878c6e43b48ab27fb831538836aca25dd60f6937a30"
},
"st": {
"_type": "sec_certs.sample.document_state.DocumentState",
"convert_ok": true,
"download_ok": true,
"extract_ok": true,
"json_hash": null,
"source_hash": "e9adaefed8794230e331825d0eba0ba0483e982b4074cae59398e49258d25855",
"txt_hash": "48c8292f024ac1e285266ea13ddd1666d577624a15c555712f05e9203b083462"
}
},
"status": "active"
}