SUSE Linux Enterprise Server 15, SP4

Known vulnerabilities detected

Our automated heuristics have identified vulnerabilities that may be associated with this certificate. See the CVEs section for details.

CSV information

Status active
Valid from 24.02.2026
Valid until 24.02.2031
Scheme 🇩🇪 DE
Manufacturer SUSE Software Solutions Germany GmbH
Category Other Devices and Systems
Security level
Protection profiles

Heuristics summary

Certificate ID: BSI-DSZ-CC-1248-2026

Certificate

Extracted keywords

Security level
EAL 4, EAL 2, EAL 4 augmented
Security Assurance Requirements (SAR)
ALC_FLR.3, ALC_FLR
Protection profiles
BSI-CC-PP-0067-2010
Certificates
BSI-DSZ-CC-1248-2026

Standards
ISO/IEC 15408, ISO/IEC 18045

File metadata

Title Certificate BSI-DSZ-CC-1248-2026
Subject "Common Criteria, Certification, Zertifizierung, Linux-basiertes Betriebssystem, Operating System Protection Profile, Virtualization"
Keywords """Common Criteria, Certification, Zertifizierung, Linux-basiertes Betriebssystem, Operating System Protection Profile, Virtualization"""
Author Federal Office for Information Security
Pages 1

Certification report

Extracted keywords

Symmetric Algorithms
AES, HMAC
Asymmetric Algorithms
ECDH, ECDSA, ECC, DH
Hash functions
SHA256, SHA-256, SHA-384, SHA-512, SHA-2, PBKDF2
Schemes
MAC, Key Exchange, Key Agreement
Protocols
SSHv2, SSH, SSL, TLS, IKEv1, IKEv2, IKE, IPsec, VPN
Randomness
RNG
Libraries
OpenSSL
Elliptic Curves
P-256, P-384, P-521
Block cipher modes
CBC, CTR, GCM, CCM, XTS

Security level
EAL 4, EAL 2, EAL 1, EAL4+, EAL 4 augmented
Security Assurance Requirements (SAR)
ALC_FLR.3, ALC_FLR
Security Functional Requirements (SFR)
FCS_RNG.1, FIA_AFL.1, FIA_UAU.7, FTP_ITC_EXT.1, FTP_ITC.1
Protection profiles
BSI-CC-PP-0067-2010, BSI-CC-PP-0067-
Certificates
BSI-DSZ-CC-1248-2026
Evaluation facilities
atsec

Vulnerabilities
CVE-2024-28956
Certification process
being maintained, is not given any longer. In particular, prior to the dissemination of confidential documentation and information related to the TOE or resulting from the evaluation and certification, GmbH [6] Final Evaluation Technical Report, Version 3, 2026-02-20, atsec information security GmbH (confidential document) [7] Operating System Protection Profile, Version 2.0, 01 June 2010, BSI-CC-PP-0067- 2010, OSPP, Version 2.0, 28 May 2010 [8] MASTER CM List, 2026-02-20, SUSE Software Solutions Germany GmbH (confidential document) [9] Common Criteria EAL4+ Evaluated Configuration Guide for SUSE LINUX Enterprise Server 15 SP4, GmbH [10] Linux Specification High-level design, 2024-10-24, SUSE Software Solutions Germany GmbH (confidential document) 7 specifically • AIS 1, Version 14, Durchführung der Ortsbesichtigung in der Entwicklungsumgebung

Standards
FIPS180-4, FIPS197, FIPS 186-5, FIPS198-1, PKCS#1, AIS 20, AIS 1, AIS 14, AIS 19, AIS 23, AIS 32, RFC8017, RFC4253, RFC4252, RFC8332, RFC5656, RFC 4344, RFC5647, RFC2104, RFC4251, RFC6668, RFC7296, RFC3447, RFC7427, RFC4754, RFC3526, RFC4868, RFC3602, RFC5930, RFC3686, RFC5282, RFC4309, RFC5116, RFC4106, RFC4303, RFC2898, ISO/IEC 15408, ISO/IEC 18045, ISO/IEC 17065
Technical reports
BSI TR-02102

File metadata

Title Certification Report BSI-DSZ-CC-1248-2026
Subject "Common Criteria, Certification, Zertifizierung, Linux-basiertes Betriebssystem, Operating System Protection Profile, Virtualization"
Keywords """Common Criteria, Certification, Zertifizierung, Linux-basiertes Betriebssystem, Operating System Protection Profile, Virtualization"""
Author Federal Office for Information Security
Pages 32

Frontpage

Certificate ID BSI-DSZ-CC-1248-2026
Certified item SUSE Linux Enterprise Server 15 SP4
Certification lab BSI
Developer SUSE Software Solutions Germany GmbH

Security target

Extracted keywords

Symmetric Algorithms
AES128, AES256, AES, AES-256, Triple-DES, HMAC, CMAC
Asymmetric Algorithms
ECDSA, ECC, Diffie-Hellman, DH, DSA
Hash functions
SHA-1, SHA-256, SHA-384, SHA-512, SHA256, SHA384, SHA512, SHA-2, PBKDF2
Schemes
MAC, Key Exchange
Protocols
SSHv2, SSH, SSL, TLS, IKEv2, IKE, IKEv1, IPsec, VPN
Randomness
DRBG, RNG
Libraries
OpenSSL
Elliptic Curves
curve P-256, curve P-384, curve P-521, P-256, P-384, P-521
Block cipher modes
CBC, CTR, GCM, CCM, XTS

Security level
EAL4, EAL4 augmented
Claims
O.AUDITING, O.CRYPTO, O.DISCRETIONARY, O.NETWORK, O.SUBJECT, O.MANAGE, O.TRUSTED_CHANNEL, O.COMP, O.ROLE, O.REMOTE_AUDIT, O.ANALYZE_AUDIT, O.CP, T.ACCESS, T.RESTRICT, T.IA, T.INFOFLOW, T.COMM, T.ROLE, T.UNOBSERVED_AUDIT, A.CONNECT, A.PHYSICAL, A.MANAGE, A.AUTHUSER, A.TRAINEDUSER, A.DETECT, A.PEER, A.IT, A.KEYS, OE.ADMIN, OE.REMOTE, OE.INFO_PROTECT, OE.INSTALL, OE.MAINTENANCE, OE.PHYSICAL, OE.RECOVER, OE.TRUSTED, OE.IT
Security Assurance Requirements (SAR)
ALC_FLR.3, ASE_CCL.1
Security Functional Requirements (SFR)
FAU_GEN.1, FAU_GEN.2, FAU_SAR.1, FAU_SAR.2, FAU_SAR.3, FAU_SEL.1, FAU_STG.1, FAU_STG.3, FAU_STG.4, FAU_GEN, FAU_GEN.1.1, FAU_GEN.1.2, FAU_GEN.2.1, FAU_SAR.1.1, FAU_SAR.1.2, FAU_SAR.2.1, FAU_SAR.3.1, FAU_SEL.1.1, FAU_STG.1.1, FAU_STG.1.2, FAU_STG.3.1, FAU_STG.4.1, FCS_RNG.1, FCS_CKM.1, FCS_CKM.2, FCS_CKM.4, FCS_COP.1, FCS_RNG, FCS_RNG.1.1, FCS_RNG.1.2, FCS_CKM.1.1, FCS_CKM.2.1, FCS_CKM.4.1, FCS_COP.1.1, FDP_CDP, FDP_CDP.1, FDP_ACC.1, FDP_ACF.1, FDP_IFC.2, FDP_IFF.1, FDP_ITC.2, FDP_RIP.2, FDP_RIP.3, FDP_ACC.2, FDP_ETC.2, FDP_IFC.1, FDP_CDP.1.1, FDP_UCT, FDP_ACC.1.1, FDP_ACF.1.1, FDP_ACF.1.2, FDP_ACF.1.3, FDP_ACF.1.4, FDP_IFC.2.1, FDP_IFC.2.2, FDP_IFF.1.1, FDP_IFF.1.2, FDP_IFF.1.3, FDP_IFF.1.4, FDP_IFF.1.5, FDP_ITC.2.1, FDP_ITC.2.2, FDP_ITC.2.3, FDP_ITC.2.4, FDP_ITC.2.5, FDP_RIP.2.1, FDP_RIP.3.1, FDP_ACC.2.1, FDP_ACC.2.2, FDP_ETC.2.1, FDP_ETC.2.2, FDP_ETC.2.3, FDP_ETC.2.4, FDP_ITC.1, FIA_AFL.1, FIA_ATD.1, FIA_SOS.1, FIA_UAU.1, FIA_UAU.5, FIA_UAU.7, FIA_UID.1, FIA_USB.2, FIA_UID.2, FIA_AFL.1.1, FIA_AFL.1.2, FIA_ATD.1.1, FIA_SOS.1.1, FIA_UAU.1.1, FIA_UAU.1.2, FIA_UAU.5.1, FIA_UAU.5.2, FIA_UAU.7.1, FIA_UID.1.1, FIA_UID.1.2, FIA_USB.2.1, FIA_USB.2.2, FIA_USB.2.3, FIA_USB.2.4, FIA_UID.2.1, FMT_MSA.3, FMT_MSA.1, FMT_MTD.1, FMT_MSA.4, FMT_REV.1, FMT_SMF.1, FMT_SMR.1, FMT_MSA.3.1, FMT_MSA.3.2, FMT_MSA.1.1, FMT_MTD.1.1, FMT_MSA.4.1, FMT_REV.1.1, FMT_REV.1.2, FMT_SMF.1.1, FMT_SMR.1.1, FMT_SMR.1.2, FPT_STM.1, FPT_TDC.1, FPT_STM.1.1, FPT_TDC.1.1, FPT_TDC.1.2, FTA_SSL.1, FTA_SSL.2, FTA_SSL.1.1, FTA_SSL.1.2, FTA_SSL.2.1, FTA_SSL.2.2, FTP_ITC.1, FTP_ITC.1.1, FTP_ITC.1.2, FTP_ITC.1.3
Certificates
BSI-DSZ-CC-1248
Evaluation facilities
atsec

Certification process
out of scope, PAT) for simple as well as more complex protocols. This mechanism is out of scope for the evaluation, as Port Address Translation (PAT) for simple as well as more complex protocols. This mechanism is out of scope for the evaluation. Furthermore, packet mangling support is provided with NFTables which is also, DAC mechanism but may be supplemented by further restrictions. These additional restrictions are out of scope for this evaluation. Examples of objects which are accessible to users that cannot be used to store

Standards
FIPS 140-3, FIPS PUB 186-3, FIPS PUB 186-5, FIPS PUB 186-4, FIPS197, AIS 20, AIS 31, RFC 2460, RFC 3484, RFC 3542, RFC 4213, RFC4253, RFC4306, RFC5656, RFC7296, RFC2409, RFC3526, RFC4753, RFC5114, RFC6954, RFC5647, RFC6668, RFC4252, RFC3602, RFC4307, RFC4301, RFC4303, RFC4309, RFC4106, RFC 791, RFC 793, RFC 768, RFC 792, RFC 4253, RFC 4252
Technical reports
BSI TR-02102

File metadata

Title Security Target for SUSE Linux Enterprise Server 15 SP4 including KVM virtualization (version 4.0 as of 2026-02-20)
Subject Security Target, Common Criteria, Linux Distribution
Keywords "Security Target, Common Criteria, Linux Distribution"
Author SUSE Software Solutions Germany GmbH
Pages 115

Heuristics

Automated inference - use with caution

All attributes shown in this section (e.g., links between certificates, products, vendors, and known CVEs) are generated by automated heuristics and have not been reviewed by humans. These methods can produce false positives or false negatives and should not be treated as definitive without independent verification. For details on our data sources and inference methods, see our methodology. If you believe any information here is inaccurate or harmful, please submit feedback.

Certificate ID

BSI-DSZ-CC-1248-2026

Extracted SARs

ALC_FLR.3, ASE_CCL.1

Related CVEs

ID Links Severity CVSS Score Published on
Base score
CVE-2002-20001
C N
HIGH 7.5 11.11.2021
CVE-2018-17962
C N
HIGH 7.5 09.10.2018
CVE-2019-18897
C N
HIGH 7.8 02.03.2020
CVE-2019-18901
C N
MEDIUM 5.5 02.03.2020
CVE-2019-18902
C N
CRITICAL 9.8 02.03.2020
CVE-2019-18903
C N
CRITICAL 9.8 02.03.2020
CVE-2020-8013
C N
LOW 2.5 02.03.2020
CVE-2022-27239
C N
HIGH 7.8 27.04.2022
CVE-2023-23005
C N
MEDIUM 5.5 01.03.2023
CVE-2026-31431
C N
HIGH 7.8 22.04.2026
Showing 5 out of 10.

Scheme data

Cert Id BSI-DSZ-CC-1248-2026
Product SUSE Linux Enterprise Server 15, SP4
Vendor SUSE Software Solutions Germany GmbH
Certification Date 24.02.2026
Category Operating systems
Url https://www.bsi.bund.de/SharedDocs/Zertifikate_CC/CC/Betriebssysteme/1248.html
Enhanced
Product SUSE Linux Enterprise Server 15, SP4
Applicant SUSE Software Solutions Germany GmbH Frankenstraße 146 90461 Nürnberg
Evaluation Facility atsec information security GmbH
Protection Profile Operating System Protection Profile, Version 2.0, 01 June 2010, BSI-CC-PP-0067-2010; OSPP Extended Package – Virtualization, Version 2.0, 28 May 2010; OSPP Extended Package – Advanced Audit, Version 2.0, 28 May 2010; OSPP Extended Package – Advanced Management, Version 2.0, 28 May 2010;
Certification Date 24.02.2026
Expiration Date 23.02.2031
Report Link https://www.bsi.bund.de/SharedDocs/Downloads/DE/BSI/Zertifizierung/Reporte/Reporte1200/1248a_pdf.pdf?__blob=publicationFile&v=2
Target Link https://www.bsi.bund.de/SharedDocs/Downloads/DE/BSI/Zertifizierung/Reporte/Reporte1200/1248b_pdf.pdf?__blob=publicationFile&v=2
Cert Link https://www.bsi.bund.de/SharedDocs/Downloads/DE/BSI/Zertifizierung/Reporte/Reporte1200/1248c_pdf.pdf?__blob=publicationFile&v=2
Description SUSE Linux Enterprise Server is a highly-configurable Linux-based operating system which has been developed to provide a good level of security as required in commercial environments. It also meets all requirements of the Operating System Protection Profile, together with the extended packages for Virtualization, Advanced Management and Advanced Audit.

References

No references are available for this certificate.

Updates Feed

  • The certificate data changed.
  • The certificate data changed.
  • The certificate was first processed.

Raw data

{
  "_type": "sec_certs.sample.cc.CCCertificate",
  "category": "Other Devices and Systems",
  "cert_link": "https://www.commoncriteriaportal.org/nfs/ccpfiles/files/epfiles/1248c_pdf.pdf",
  "dgst": "bb7f45e5dbacf3d8",
  "heuristics": {
    "_type": "sec_certs.sample.cc_eucc_common.Heuristics",
    "annotated_references": null,
    "cert_id": "BSI-DSZ-CC-1248-2026",
    "cert_lab": [
      "BSI"
    ],
    "cpe_matches": {
      "_type": "Set",
      "elements": [
        "cpe:2.3:o:suse:linux_enterprise_server:15:sp6:*:*:-:-:*:*",
        "cpe:2.3:o:suse:linux_enterprise_server:15:sp5:*:*:-:sap:*:*",
        "cpe:2.3:o:suse:linux_enterprise_server:15:sp7:*:*:-:-:*:*",
        "cpe:2.3:o:suse:linux_enterprise_server:15:sp4:*:*:ltss:-:*:*",
        "cpe:2.3:o:suse:linux_enterprise_server:15:sp5:*:*:-:-:*:*",
        "cpe:2.3:o:suse:linux_enterprise_server:15:sp4:*:*:*:*:*:*",
        "cpe:2.3:o:suse:linux_enterprise_server:15:sp4:*:*:-:-:*:*",
        "cpe:2.3:o:suse:linux_enterprise_server:15:sp5:*:*:*:*:*:*",
        "cpe:2.3:o:suse:linux_enterprise_server:15:sp7:*:*:-:sap:*:*",
        "cpe:2.3:o:suse:linux_enterprise_server:15:sp5:*:*:ltss:-:*:*",
        "cpe:2.3:o:suse:linux_enterprise_server:15:sp6:*:*:-:sap:*:*",
        "cpe:2.3:o:suse:linux_enterprise_server:15:sp6:*:*:ltss:-:*:*",
        "cpe:2.3:o:suse:linux_enterprise_server:15:sp4:*:*:-:sap:*:*"
      ]
    },
    "direct_transitive_cves": null,
    "eal": "EAL4+",
    "extracted_sars": {
      "_type": "Set",
      "elements": [
        {
          "_type": "sec_certs.sample.sar.SAR",
          "family": "ALC_FLR",
          "level": 3
        },
        {
          "_type": "sec_certs.sample.sar.SAR",
          "family": "ASE_CCL",
          "level": 1
        }
      ]
    },
    "extracted_versions": {
      "_type": "Set",
      "elements": [
        "15"
      ]
    },
    "indirect_transitive_cves": null,
    "next_certificates": null,
    "prev_certificates": null,
    "protection_profiles": {
      "_type": "Set",
      "elements": [
        "70cdc8b0cf910af7"
      ]
    },
    "related_cves": {
      "_type": "Set",
      "elements": [
        "CVE-2022-27239",
        "CVE-2020-8013",
        "CVE-2026-31431",
        "CVE-2023-23005",
        "CVE-2019-18901",
        "CVE-2018-17962",
        "CVE-2002-20001",
        "CVE-2019-18897",
        "CVE-2019-18903",
        "CVE-2019-18902"
      ]
    },
    "report_references": {
      "_type": "sec_certs.sample.certificate.References",
      "directly_referenced_by": null,
      "directly_referencing": null,
      "indirectly_referenced_by": null,
      "indirectly_referencing": null
    },
    "scheme_data": {
      "category": "Operating systems",
      "cert_id": "BSI-DSZ-CC-1248-2026",
      "certification_date": "2026-02-24",
      "enhanced": {
        "applicant": "SUSE Software Solutions Germany GmbH Frankenstra\u00dfe 146 90461 N\u00fcrnberg",
        "cert_link": "https://www.bsi.bund.de/SharedDocs/Downloads/DE/BSI/Zertifizierung/Reporte/Reporte1200/1248c_pdf.pdf?__blob=publicationFile\u0026v=2",
        "certification_date": "2026-02-24",
        "description": "SUSE Linux Enterprise Server is a highly-configurable Linux-based operating system which has been developed to provide a good level of security as required in commercial environments. It also meets all requirements of the Operating System Protection Profile, together with the extended packages for Virtualization, Advanced Management and Advanced Audit.",
        "evaluation_facility": "atsec information security GmbH",
        "expiration_date": "2031-02-23",
        "product": "SUSE Linux Enterprise Server 15, SP4",
        "protection_profile": "Operating System Protection Profile, Version 2.0, 01 June 2010, BSI-CC-PP-0067-2010; OSPP Extended Package \u2013 Virtualization, Version 2.0, 28 May 2010; OSPP Extended Package \u2013 Advanced Audit, Version 2.0, 28 May 2010; OSPP Extended Package \u2013 Advanced Management, Version 2.0, 28 May 2010;",
        "report_link": "https://www.bsi.bund.de/SharedDocs/Downloads/DE/BSI/Zertifizierung/Reporte/Reporte1200/1248a_pdf.pdf?__blob=publicationFile\u0026v=2",
        "target_link": "https://www.bsi.bund.de/SharedDocs/Downloads/DE/BSI/Zertifizierung/Reporte/Reporte1200/1248b_pdf.pdf?__blob=publicationFile\u0026v=2"
      },
      "product": "SUSE Linux Enterprise Server 15, SP4",
      "url": "https://www.bsi.bund.de/SharedDocs/Zertifikate_CC/CC/Betriebssysteme/1248.html",
      "vendor": "SUSE Software Solutions Germany GmbH"
    },
    "st_references": {
      "_type": "sec_certs.sample.certificate.References",
      "directly_referenced_by": null,
      "directly_referencing": null,
      "indirectly_referenced_by": null,
      "indirectly_referencing": null
    },
    "verified_cpe_matches": null
  },
  "maintenance_updates": {
    "_type": "Set",
    "elements": []
  },
  "manufacturer": "SUSE Software Solutions Germany GmbH",
  "manufacturer_web": "https://www.suse.com/",
  "name": "SUSE Linux Enterprise Server 15, SP4",
  "not_valid_after": "2031-02-24",
  "not_valid_before": "2026-02-24",
  "pdf_data": {
    "_type": "sec_certs.sample.cc_eucc_common.PdfData",
    "cert_filename": "1248c_pdf.pdf",
    "cert_frontpage": null,
    "cert_keywords": {
      "asymmetric_crypto": {},
      "cc_cert_id": {
        "DE": {
          "BSI-DSZ-CC-1248-2026": 1
        }
      },
      "cc_claims": {},
      "cc_protection_profile_id": {
        "BSI": {
          "BSI-CC-PP-0067-2010": 1
        }
      },
      "cc_sar": {
        "ALC": {
          "ALC_FLR": 1,
          "ALC_FLR.3": 1
        }
      },
      "cc_security_level": {
        "EAL": {
          "EAL 2": 1,
          "EAL 4": 1,
          "EAL 4 augmented": 1
        }
      },
      "cc_sfr": {},
      "certification_process": {},
      "cipher_mode": {},
      "cplc_data": {},
      "crypto_engine": {},
      "crypto_library": {},
      "crypto_protocol": {},
      "crypto_scheme": {},
      "device_model": {},
      "ecc_curve": {},
      "eval_facility": {},
      "hash_function": {},
      "ic_data_group": {},
      "javacard_api_const": {},
      "javacard_packages": {},
      "javacard_version": {},
      "os_name": {},
      "pq_crypto": {},
      "randomness": {},
      "side_channel_analysis": {},
      "standard_id": {
        "ISO": {
          "ISO/IEC 15408": 2,
          "ISO/IEC 18045": 2
        }
      },
      "symmetric_crypto": {},
      "technical_report_id": {},
      "tee_name": {},
      "tls_cipher_suite": {},
      "vendor": {},
      "vulnerability": {}
    },
    "cert_metadata": {
      "/Author": "Federal Office for Information Security",
      "/Keywords": "\"\"\"Common Criteria, Certification, Zertifizierung, Linux-basiertes Betriebssystem, Operating System Protection Profile, Virtualization\"\"\"",
      "/Subject": "\"Common Criteria, Certification, Zertifizierung, Linux-basiertes Betriebssystem, Operating System Protection Profile, Virtualization\"",
      "/Title": "Certificate BSI-DSZ-CC-1248-2026",
      "pdf_file_size_bytes": 237904,
      "pdf_hyperlinks": {
        "_type": "Set",
        "elements": []
      },
      "pdf_is_encrypted": false,
      "pdf_number_of_pages": 1
    },
    "report_filename": "1248a_pdf.pdf",
    "report_frontpage": {
      "DE": {
        "cc_security_level": "Common Criteria Part 3 conformant EAL 4 augmented by ALC_FLR.3 valid until: 23 February 2031",
        "cc_version": "PP conformant Common Criteria Part 2 extended",
        "cert_id": "BSI-DSZ-CC-1248-2026",
        "cert_item": "SUSE Linux Enterprise Server 15 SP4",
        "cert_lab": "BSI",
        "developer": "SUSE Software Solutions Germany GmbH",
        "match_rules": [
          "(BSI-DSZ-CC-.+?) (?:for|For) (.+?) from (.*)"
        ],
        "ref_protection_profiles": "Operating System Protection Profile, Version 2.0, 01 June 2010, BSI-CC-PP-0067-2010, OSPP Extended Package \u2013 Virtualization, Version 2.0, 28 May 2010, OSPP Extended Package \u2013 Advanced Audit, Version 2.0, 28 May 2010, OSPP Extended Package \u2013 Advanced Management, Version 2.0, 28 May 2010"
      }
    },
    "report_keywords": {
      "asymmetric_crypto": {
        "ECC": {
          "ECC": {
            "ECC": 1
          },
          "ECDH": {
            "ECDH": 2
          },
          "ECDSA": {
            "ECDSA": 6
          }
        },
        "FF": {
          "DH": {
            "DH": 3
          }
        }
      },
      "cc_cert_id": {
        "DE": {
          "BSI-DSZ-CC-1248-2026": 18
        }
      },
      "cc_claims": {},
      "cc_protection_profile_id": {
        "BSI": {
          "BSI-CC-PP-0067-": 1,
          "BSI-CC-PP-0067-2010": 2
        }
      },
      "cc_sar": {
        "ALC": {
          "ALC_FLR": 3,
          "ALC_FLR.3": 4
        }
      },
      "cc_security_level": {
        "EAL": {
          "EAL 1": 1,
          "EAL 2": 3,
          "EAL 4": 5,
          "EAL 4 augmented": 3,
          "EAL4+": 2
        }
      },
      "cc_sfr": {
        "FCS": {
          "FCS_RNG.1": 1
        },
        "FIA": {
          "FIA_AFL.1": 1,
          "FIA_UAU.7": 1
        },
        "FTP": {
          "FTP_ITC.1": 1,
          "FTP_ITC_EXT.1": 1
        }
      },
      "certification_process": {
        "ConfidentialDocument": {
          "GmbH [10] Linux Specification High-level design, 2024-10-24, SUSE Software Solutions Germany GmbH (confidential document) 7 specifically \u2022 AIS 1, Version 14, Durchf\u00fchrung der Ortsbesichtigung in der Entwicklungsumgebung": 1,
          "GmbH [6] Final Evaluation Technical Report, Version 3, 2026-02-20, atsec information security GmbH (confidential document) [7] Operating System Protection Profile, Version 2.0, 01 June 2010, BSI-CC-PP-0067- 2010, OSPP": 1,
          "Version 2.0, 28 May 2010 [8] MASTER CM List, 2026-02-20, SUSE Software Solutions Germany GmbH (confidential document) [9] Common Criteria EAL4+ Evaluated Configuration Guide for SUSE LINUX Enterprise Server 15 SP4": 1,
          "being maintained, is not given any longer. In particular, prior to the dissemination of confidential documentation and information related to the TOE or resulting from the evaluation and certification": 1
        }
      },
      "cipher_mode": {
        "CBC": {
          "CBC": 1
        },
        "CCM": {
          "CCM": 1
        },
        "CTR": {
          "CTR": 3
        },
        "GCM": {
          "GCM": 4
        },
        "XTS": {
          "XTS": 2
        }
      },
      "cplc_data": {},
      "crypto_engine": {},
      "crypto_library": {
        "OpenSSL": {
          "OpenSSL": 1
        }
      },
      "crypto_protocol": {
        "IKE": {
          "IKE": 12,
          "IKEv1": 2,
          "IKEv2": 11
        },
        "IPsec": {
          "IPsec": 9
        },
        "SSH": {
          "SSH": 10,
          "SSHv2": 1
        },
        "TLS": {
          "SSL": {
            "SSL": 1
          },
          "TLS": {
            "TLS": 1
          }
        },
        "VPN": {
          "VPN": 1
        }
      },
      "crypto_scheme": {
        "KA": {
          "Key Agreement": 1
        },
        "KEX": {
          "Key Exchange": 1
        },
        "MAC": {
          "MAC": 1
        }
      },
      "device_model": {},
      "ecc_curve": {
        "NIST": {
          "P-256": 8,
          "P-384": 8,
          "P-521": 8
        }
      },
      "eval_facility": {
        "atsec": {
          "atsec": 3
        }
      },
      "hash_function": {
        "PBKDF": {
          "PBKDF2": 2
        },
        "SHA": {
          "SHA2": {
            "SHA-2": 1,
            "SHA-256": 4,
            "SHA-384": 3,
            "SHA-512": 2,
            "SHA256": 1
          }
        }
      },
      "ic_data_group": {},
      "javacard_api_const": {},
      "javacard_packages": {},
      "javacard_version": {},
      "os_name": {},
      "pq_crypto": {},
      "randomness": {
        "RNG": {
          "RNG": 3
        }
      },
      "side_channel_analysis": {},
      "standard_id": {
        "BSI": {
          "AIS 1": 1,
          "AIS 14": 1,
          "AIS 19": 1,
          "AIS 20": 2,
          "AIS 23": 1,
          "AIS 32": 1
        },
        "FIPS": {
          "FIPS 186-5": 5,
          "FIPS180-4": 7,
          "FIPS197": 2,
          "FIPS198-1": 2
        },
        "ISO": {
          "ISO/IEC 15408": 4,
          "ISO/IEC 17065": 2,
          "ISO/IEC 18045": 4
        },
        "PKCS": {
          "PKCS#1": 1
        },
        "RFC": {
          "RFC 4344": 1,
          "RFC2104": 1,
          "RFC2898": 1,
          "RFC3447": 1,
          "RFC3526": 1,
          "RFC3602": 1,
          "RFC3686": 1,
          "RFC4106": 1,
          "RFC4251": 1,
          "RFC4252": 2,
          "RFC4253": 4,
          "RFC4303": 1,
          "RFC4309": 1,
          "RFC4754": 1,
          "RFC4868": 2,
          "RFC5116": 2,
          "RFC5282": 2,
          "RFC5647": 2,
          "RFC5656": 2,
          "RFC5930": 1,
          "RFC6668": 1,
          "RFC7296": 6,
          "RFC7427": 1,
          "RFC8017": 1,
          "RFC8332": 1
        }
      },
      "symmetric_crypto": {
        "AES_competition": {
          "AES": {
            "AES": 10
          }
        },
        "constructions": {
          "MAC": {
            "HMAC": 12
          }
        }
      },
      "technical_report_id": {
        "BSI": {
          "BSI TR-02102": 1
        }
      },
      "tee_name": {},
      "tls_cipher_suite": {},
      "vendor": {},
      "vulnerability": {
        "CVE": {
          "CVE-2024-28956": 1
        }
      }
    },
    "report_metadata": {
      "/Author": "Federal Office for Information Security",
      "/Keywords": "\"\"\"Common Criteria, Certification, Zertifizierung, Linux-basiertes Betriebssystem, Operating System Protection Profile, Virtualization\"\"\"",
      "/Subject": "\"Common Criteria, Certification, Zertifizierung, Linux-basiertes Betriebssystem, Operating System Protection Profile, Virtualization\"",
      "/Title": "Certification Report BSI-DSZ-CC-1248-2026",
      "pdf_file_size_bytes": 412428,
      "pdf_hyperlinks": {
        "_type": "Set",
        "elements": []
      },
      "pdf_is_encrypted": false,
      "pdf_number_of_pages": 32
    },
    "st_filename": "1248b_pdf.pdf",
    "st_frontpage": null,
    "st_keywords": {
      "asymmetric_crypto": {
        "ECC": {
          "ECC": {
            "ECC": 1
          },
          "ECDSA": {
            "ECDSA": 20
          }
        },
        "FF": {
          "DH": {
            "DH": 3,
            "Diffie-Hellman": 19
          },
          "DSA": {
            "DSA": 2
          }
        }
      },
      "cc_cert_id": {
        "DE": {
          "BSI-DSZ-CC-1248": 1
        }
      },
      "cc_claims": {
        "A": {
          "A.AUTHUSER": 3,
          "A.CONNECT": 5,
          "A.DETECT": 3,
          "A.IT": 3,
          "A.KEYS": 3,
          "A.MANAGE": 5,
          "A.PEER": 6,
          "A.PHYSICAL": 4,
          "A.TRAINEDUSER": 3
        },
        "O": {
          "O.ANALYZE_AUDIT": 5,
          "O.AUDITING": 15,
          "O.COMP": 31,
          "O.CP": 17,
          "O.CRYPTO": 18,
          "O.DISCRETIONARY": 11,
          "O.MANAGE": 26,
          "O.NETWORK": 12,
          "O.REMOTE_AUDIT": 8,
          "O.ROLE": 17,
          "O.SUBJECT": 11,
          "O.TRUSTED_CHANNEL": 5
        },
        "OE": {
          "OE.ADMIN": 6,
          "OE.INFO_PROTECT": 9,
          "OE.INSTALL": 4,
          "OE.IT": 4,
          "OE.MAINTENANCE": 3,
          "OE.PHYSICAL": 3,
          "OE.RECOVER": 4,
          "OE.REMOTE": 4,
          "OE.TRUSTED": 5
        },
        "T": {
          "T.ACCESS": 25,
          "T.COMM": 4,
          "T.IA": 6,
          "T.INFOFLOW": 4,
          "T.RESTRICT": 3,
          "T.ROLE": 6,
          "T.UNOBSERVED_AUDIT": 4
        }
      },
      "cc_protection_profile_id": {},
      "cc_sar": {
        "ALC": {
          "ALC_FLR.3": 4
        },
        "ASE": {
          "ASE_CCL.1": 17
        }
      },
      "cc_security_level": {
        "EAL": {
          "EAL4": 3,
          "EAL4 augmented": 1
        }
      },
      "cc_sfr": {
        "FAU": {
          "FAU_GEN": 2,
          "FAU_GEN.1": 12,
          "FAU_GEN.1.1": 1,
          "FAU_GEN.1.2": 1,
          "FAU_GEN.2": 6,
          "FAU_GEN.2.1": 1,
          "FAU_SAR.1": 9,
          "FAU_SAR.1.1": 1,
          "FAU_SAR.1.2": 1,
          "FAU_SAR.2": 6,
          "FAU_SAR.2.1": 1,
          "FAU_SAR.3": 7,
          "FAU_SAR.3.1": 1,
          "FAU_SEL.1": 9,
          "FAU_SEL.1.1": 1,
          "FAU_STG.1": 12,
          "FAU_STG.1.1": 1,
          "FAU_STG.1.2": 1,
          "FAU_STG.3": 8,
          "FAU_STG.3.1": 1,
          "FAU_STG.4": 9,
          "FAU_STG.4.1": 1
        },
        "FCS": {
          "FCS_CKM.1": 56,
          "FCS_CKM.1.1": 5,
          "FCS_CKM.2": 23,
          "FCS_CKM.2.1": 2,
          "FCS_CKM.4": 16,
          "FCS_CKM.4.1": 1,
          "FCS_COP.1": 25,
          "FCS_COP.1.1": 2,
          "FCS_RNG": 2,
          "FCS_RNG.1": 24,
          "FCS_RNG.1.1": 2,
          "FCS_RNG.1.2": 3
        },
        "FDP": {
          "FDP_ACC.1": 37,
          "FDP_ACC.1.1": 3,
          "FDP_ACC.2": 19,
          "FDP_ACC.2.1": 2,
          "FDP_ACC.2.2": 2,
          "FDP_ACF.1": 41,
          "FDP_ACF.1.1": 5,
          "FDP_ACF.1.2": 5,
          "FDP_ACF.1.3": 5,
          "FDP_ACF.1.4": 5,
          "FDP_CDP": 5,
          "FDP_CDP.1": 14,
          "FDP_CDP.1.1": 2,
          "FDP_ETC.2": 7,
          "FDP_ETC.2.1": 1,
          "FDP_ETC.2.2": 1,
          "FDP_ETC.2.3": 1,
          "FDP_ETC.2.4": 1,
          "FDP_IFC.1": 9,
          "FDP_IFC.2": 19,
          "FDP_IFC.2.1": 2,
          "FDP_IFC.2.2": 2,
          "FDP_IFF.1": 18,
          "FDP_IFF.1.1": 2,
          "FDP_IFF.1.2": 2,
          "FDP_IFF.1.3": 2,
          "FDP_IFF.1.4": 2,
          "FDP_IFF.1.5": 2,
          "FDP_ITC.1": 1,
          "FDP_ITC.2": 17,
          "FDP_ITC.2.1": 2,
          "FDP_ITC.2.2": 2,
          "FDP_ITC.2.3": 2,
          "FDP_ITC.2.4": 2,
          "FDP_ITC.2.5": 2,
          "FDP_RIP.2": 13,
          "FDP_RIP.2.1": 1,
          "FDP_RIP.3": 13,
          "FDP_RIP.3.1": 1,
          "FDP_UCT": 1
        },
        "FIA": {
          "FIA_AFL.1": 9,
          "FIA_AFL.1.1": 1,
          "FIA_AFL.1.2": 1,
          "FIA_ATD.1": 20,
          "FIA_ATD.1.1": 2,
          "FIA_SOS.1": 8,
          "FIA_SOS.1.1": 1,
          "FIA_UAU.1": 12,
          "FIA_UAU.1.1": 1,
          "FIA_UAU.1.2": 1,
          "FIA_UAU.5": 10,
          "FIA_UAU.5.1": 1,
          "FIA_UAU.5.2": 1,
          "FIA_UAU.7": 6,
          "FIA_UAU.7.1": 1,
          "FIA_UID.1": 14,
          "FIA_UID.1.1": 1,
          "FIA_UID.1.2": 1,
          "FIA_UID.2": 8,
          "FIA_UID.2.1": 1,
          "FIA_USB.2": 7,
          "FIA_USB.2.1": 1,
          "FIA_USB.2.2": 1,
          "FIA_USB.2.3": 1,
          "FIA_USB.2.4": 1
        },
        "FMT": {
          "FMT_MSA.1": 48,
          "FMT_MSA.1.1": 5,
          "FMT_MSA.3": 49,
          "FMT_MSA.3.1": 7,
          "FMT_MSA.3.2": 7,
          "FMT_MSA.4": 6,
          "FMT_MSA.4.1": 1,
          "FMT_MTD.1": 142,
          "FMT_MTD.1.1": 21,
          "FMT_REV.1": 15,
          "FMT_REV.1.1": 2,
          "FMT_REV.1.2": 2,
          "FMT_SMF.1": 34,
          "FMT_SMF.1.1": 1,
          "FMT_SMR.1": 43,
          "FMT_SMR.1.1": 1,
          "FMT_SMR.1.2": 1
        },
        "FPT": {
          "FPT_STM.1": 8,
          "FPT_STM.1.1": 1,
          "FPT_TDC.1": 22,
          "FPT_TDC.1.1": 2,
          "FPT_TDC.1.2": 2
        },
        "FTA": {
          "FTA_SSL.1": 7,
          "FTA_SSL.1.1": 1,
          "FTA_SSL.1.2": 1,
          "FTA_SSL.2": 7,
          "FTA_SSL.2.1": 1,
          "FTA_SSL.2.2": 1
        },
        "FTP": {
          "FTP_ITC.1": 10,
          "FTP_ITC.1.1": 1,
          "FTP_ITC.1.2": 1,
          "FTP_ITC.1.3": 1
        }
      },
      "certification_process": {
        "OutOfScope": {
          "DAC mechanism but may be supplemented by further restrictions. These additional restrictions are out of scope for this evaluation. Examples of objects which are accessible to users that cannot be used to store": 1,
          "PAT) for simple as well as more complex protocols. This mechanism is out of scope for the evaluation": 1,
          "as Port Address Translation (PAT) for simple as well as more complex protocols. This mechanism is out of scope for the evaluation. Furthermore, packet mangling support is provided with NFTables which is also": 1,
          "out of scope": 3
        }
      },
      "cipher_mode": {
        "CBC": {
          "CBC": 2
        },
        "CCM": {
          "CCM": 6
        },
        "CTR": {
          "CTR": 3
        },
        "GCM": {
          "GCM": 7
        },
        "XTS": {
          "XTS": 3
        }
      },
      "cplc_data": {},
      "crypto_engine": {},
      "crypto_library": {
        "OpenSSL": {
          "OpenSSL": 7
        }
      },
      "crypto_protocol": {
        "IKE": {
          "IKE": 19,
          "IKEv1": 1,
          "IKEv2": 19
        },
        "IPsec": {
          "IPsec": 3
        },
        "SSH": {
          "SSH": 55,
          "SSHv2": 8
        },
        "TLS": {
          "SSL": {
            "SSL": 30
          },
          "TLS": {
            "TLS": 3
          }
        },
        "VPN": {
          "VPN": 1
        }
      },
      "crypto_scheme": {
        "KEX": {
          "Key Exchange": 6
        },
        "MAC": {
          "MAC": 1
        }
      },
      "device_model": {},
      "ecc_curve": {
        "NIST": {
          "P-256": 4,
          "P-384": 4,
          "P-521": 4,
          "curve P-256": 2,
          "curve P-384": 2,
          "curve P-521": 2
        }
      },
      "eval_facility": {
        "atsec": {
          "atsec": 118
        }
      },
      "hash_function": {
        "PBKDF": {
          "PBKDF2": 5
        },
        "SHA": {
          "SHA1": {
            "SHA-1": 2
          },
          "SHA2": {
            "SHA-2": 6,
            "SHA-256": 4,
            "SHA-384": 4,
            "SHA-512": 4,
            "SHA256": 1,
            "SHA384": 1,
            "SHA512": 1
          }
        }
      },
      "ic_data_group": {},
      "javacard_api_const": {},
      "javacard_packages": {},
      "javacard_version": {},
      "os_name": {},
      "pq_crypto": {},
      "randomness": {
        "PRNG": {
          "DRBG": 1
        },
        "RNG": {
          "RNG": 11
        }
      },
      "side_channel_analysis": {},
      "standard_id": {
        "BSI": {
          "AIS 20": 1,
          "AIS 31": 1
        },
        "FIPS": {
          "FIPS 140-3": 4,
          "FIPS PUB 186-3": 2,
          "FIPS PUB 186-4": 1,
          "FIPS PUB 186-5": 3,
          "FIPS197": 2
        },
        "RFC": {
          "RFC 2460": 1,
          "RFC 3484": 1,
          "RFC 3542": 1,
          "RFC 4213": 1,
          "RFC 4252": 4,
          "RFC 4253": 3,
          "RFC 768": 1,
          "RFC 791": 2,
          "RFC 792": 1,
          "RFC 793": 1,
          "RFC2409": 2,
          "RFC3526": 3,
          "RFC3602": 3,
          "RFC4106": 4,
          "RFC4252": 6,
          "RFC4253": 12,
          "RFC4301": 4,
          "RFC4303": 5,
          "RFC4306": 4,
          "RFC4307": 5,
          "RFC4309": 4,
          "RFC4753": 2,
          "RFC5114": 3,
          "RFC5647": 2,
          "RFC5656": 4,
          "RFC6668": 2,
          "RFC6954": 3,
          "RFC7296": 5
        }
      },
      "symmetric_crypto": {
        "AES_competition": {
          "AES": {
            "AES": 20,
            "AES-256": 1,
            "AES128": 1,
            "AES256": 1
          }
        },
        "DES": {
          "3DES": {
            "Triple-DES": 1
          }
        },
        "constructions": {
          "MAC": {
            "CMAC": 2,
            "HMAC": 9
          }
        }
      },
      "technical_report_id": {
        "BSI": {
          "BSI TR-02102": 1
        }
      },
      "tee_name": {},
      "tls_cipher_suite": {},
      "vendor": {},
      "vulnerability": {}
    },
    "st_metadata": {
      "/Author": "SUSE Software Solutions Germany GmbH",
      "/Keywords": "\"Security Target, Common Criteria, Linux Distribution\"",
      "/Subject": "Security Target, Common Criteria, Linux Distribution",
      "/Title": "Security Target for SUSE Linux Enterprise Server 15 SP4 including KVM virtualization (version 4.0 as of 2026-02-20)",
      "pdf_file_size_bytes": 1384949,
      "pdf_hyperlinks": {
        "_type": "Set",
        "elements": [
          "http://tools.ietf.org/html/rfc6668",
          "http://tools.ietf.org/html/rfc4252",
          "http://csrc.nist.gov/publications/fips/fips197/fips-197.pdf",
          "http://tools.ietf.org/html/rfc5114",
          "http://tools.ietf.org/html/rfc4253",
          "http://www.ietf.org/rfc/rfc4106.txt",
          "http://tools.ietf.org/html/rfc4306",
          "http://tools.ietf.org/html/rfc4303",
          "http://www.commoncriteriaportal.org/files/ccfiles/CCPART1V3.1R5.pdf",
          "http://www.ietf.org/rfc/rfc7296.txt",
          "http://tools.ietf.org/html/rfc3526",
          "http://tools.ietf.org/html/rfc4307",
          "http://tools.ietf.org/html/rfc4301",
          "http://tools.ietf.org/html/rfc2409",
          "http://tools.ietf.org/html/rfc4753",
          "http://www.ietf.org/rfc/rfc6954.txt",
          "http://www.commoncriteriaportal.org/files/ccfiles/CCPART3V3.1R5.pdf",
          "http://tools.ietf.org/html/rfc5647",
          "http://tools.ietf.org/html/rfc3602",
          "http://tools.ietf.org/html/rfc5656",
          "http://www.ietf.org/rfc/rfc4309.txt",
          "http://www.commoncriteriaportal.org/files/ccfiles/CCPART2V3.1R5.pdf"
        ]
      },
      "pdf_is_encrypted": false,
      "pdf_number_of_pages": 115
    }
  },
  "protection_profile_links": {
    "_type": "Set",
    "elements": [
      "https://www.commoncriteriaportal.org/nfs/ccpfiles/files/ppfiles/pp0067b_pdf.pdf"
    ]
  },
  "report_link": "https://www.commoncriteriaportal.org/nfs/ccpfiles/files/epfiles/1248a_pdf.pdf",
  "scheme": "DE",
  "security_level": {
    "_type": "Set",
    "elements": []
  },
  "st_link": "https://www.commoncriteriaportal.org/nfs/ccpfiles/files/epfiles/1248b_pdf.pdf",
  "state": {
    "_type": "sec_certs.sample.cc_eucc_common.InternalState",
    "cert": {
      "_type": "sec_certs.sample.document_state.DocumentState",
      "convert_ok": true,
      "download_ok": true,
      "extract_ok": true,
      "json_hash": null,
      "source_hash": "c39091789ae96c8875516403d64a43cff6d56b9130be17de87776a51480e8b50",
      "txt_hash": "1d49e85a6840ea107cfca697460db6ede8a3d88376d00ad4fb87445ca0e2c777"
    },
    "report": {
      "_type": "sec_certs.sample.document_state.DocumentState",
      "convert_ok": true,
      "download_ok": true,
      "extract_ok": true,
      "json_hash": null,
      "source_hash": "21c82608fb37da7096e67418df034845d6f27335703024ecabb16fc2fc30a117",
      "txt_hash": "6829d123115e63dcfa06d878c6e43b48ab27fb831538836aca25dd60f6937a30"
    },
    "st": {
      "_type": "sec_certs.sample.document_state.DocumentState",
      "convert_ok": true,
      "download_ok": true,
      "extract_ok": true,
      "json_hash": null,
      "source_hash": "e9adaefed8794230e331825d0eba0ba0483e982b4074cae59398e49258d25855",
      "txt_hash": "48c8292f024ac1e285266ea13ddd1666d577624a15c555712f05e9203b083462"
    }
  },
  "status": "active"
}