Comparing certificates Experimental feature

You are comparing two certificates. By default, only differing attributes are shown. Use the button below to show/hide all attributes.

Showing only differing attributes.
Web Bytes Xilnex Framework version 3.0
ISCB-5-RPT-C030-CR-v1a
SCAN S3 Security Manager Console Release 14556 (v2.0) integrated with Scan S3 Agent (v2.0.1.6.2)
ISCB-5-RPT-C050-CR-v1
name Web Bytes Xilnex Framework version 3.0 SCAN S3 Security Manager Console Release 14556 (v2.0) integrated with Scan S3 Agent (v2.0.1.6.2)
category Other Devices and Systems Access Control Devices and Systems
not_valid_after 16.02.2017 09.07.2019
not_valid_before 16.02.2012 09.07.2014
report_link https://www.commoncriteriaportal.org/nfs/ccpfiles/files/epfiles/ISCB-5-RPT-C030-CR-v1a.pdf https://www.commoncriteriaportal.org/nfs/ccpfiles/files/epfiles/ISCB-5-RPT-C050-CR-v1.pdf
st_link https://www.commoncriteriaportal.org/nfs/ccpfiles/files/epfiles/Web%20Bytes%20EAL1%20Security%20Target%20(Xilnex%20Framework)%20v1.1.pdf https://www.commoncriteriaportal.org/nfs/ccpfiles/files/epfiles/2014-04-14-ST-SCANS_S3-v2.7.pdf
manufacturer Web Bytes Sdn Bhd Scan Associates Berhad
manufacturer_web https://www.webbytes.com.my https://www.scan-associates.net/
security_level EAL1 EAL2
dgst 0136a64efd2140e4 a7b3c98ebbb51b0c
heuristics/cert_id ISCB-5-RPT-C030-CR-v1a ISCB-5-RPT-C050-CR-v1
heuristics/extracted_sars ASE_CCL.1, AGD_PRE.1, ALC_CMC.1, AGD_OPE.1, ATE_IND.1, ASE_INT.1, ASE_ECD.1, ASE_OBJ.1, ASE_REQ.1, ALC_CMS.1, ASE_TSS.1, AVA_VAN.1, ADV_FSP.1 ASE_CCL.1, ATE_FUN.1, ASE_OBJ.2, ALC_CMS.2, ASE_INT.1, ASE_REQ.2, AGD_PRE.1, ATE_IND.2, ASE_ECD.1, AVA_VAN.2, ADV_TDS.1, ASE_SPD.1, ALC_CMC.2, ADV_FSP.2, ATE_COV.1, AGD_OPE.1, ALC_DEL.1, ASE_TSS.1, ADV_ARC.1
heuristics/extracted_versions 3.0 2.0.1.6.2, 2.0
heuristics/scheme_data
  • cert_no: 2012-002-C030
  • certification_date: 16.02.2012
  • developer: Web Bytes Sdn Bhd
  • enhanced:
    • assurance_level: EAL1
    • category: Other Devices and Systems
    • cert_id: C030
    • certification_date: 16.02.2012
    • developer: Ooi Boon-Sheng Unit 1-2-33, Kompleks Mayang Mall,Jalan Mayang Pasir 1,11950 Bayan Baru,Pulau Pinang MALAYSIA URL: http://www.webbytes.com.myEmail: [email protected]:+ 6012 472 9615Fax:+ 604 611 0162
    • expiration_date: 16.02.2017
    • mutual_recognition: CCRA
    • product: Web Bytes Xilnex Framework version 3.0
    • report_link: https://iscb.cybersecurity.my/resources/document/mycc/mycpr/C030/ISCB-5-RPT-C030-CR-v1a.pdf
    • scope: Web Bytes Xilnex Framework Version 3.0 is a distribution and synchronization platform which distributes subscribed applications to multiple clients as well performs data synchronisation between all the clients in the same group. The TOE comprises of two primary components as follows: Client Software. The client software that installs directly on each user's PC which operates the daily process and update based on the user activities. Server Software. The server software that extends client software with secure communication, identification and authentication, and data synchronization. The security functions that the TOE provides include the following: Secure Transmission – All communications between the server and the client is through an SSL channel. It protects the user data from disclosure and modification. Access control – The TOE allows users to launch only the applications they subscribed to as well as accessing the database. The TOE will check the user ID and their organization ID to ensure the applications that the user is allowed to run. Identification and Authentication – Users will have to present their credentials to the server for identification and authentication before the user is allowed to launch the applications and access the user data at the backend and at the local cache. Encryption – Username and passwords are always hashed when they are being stored into the database and during authentication. Management – The TOE contains various management functions to ensure efficient and secure management of the TOE. The TOE maintains two roles, users and administrator, to ensure that the functions are restricted to only the TOE administrator.
    • status: Archive
    • target_link: https://iscb.cybersecurity.my/resources/document/mycc/mycpr/C030/Web%20Bytes%20EAL1%20Security%20Target%20(Xilnex%20Framework)%20v1.1.pdf
    • type: Distribution and synchronization platform
  • expiration_date: 16.02.2017
  • level: EAL1
  • product: Web Bytes Xilnex Framework version 3.0
  • recognition: CCRA
  • url: https://iscb.cybersecurity.my/index.php/certification/product-certification/mycc/archived-certified-products-and-systems/submission-view/152
  • cert_no: 2014-003-C050
  • certification_date: 09.07.2014
  • developer: Scan Associates Berhad
  • enhanced:
    • assurance_level: EAL2
    • category: Access Control Devices and System
    • cert_id: C050
    • certification_date: 09.07.2014
    • developer: Mohd Rizal Othman Scan Associates Berhad,Level 8, Menara Naluri,161-B, Jalan Ampang,50450 Kuala LumpurMalaysia URL: http://www.scan-associates.net/Email: [email protected]: +603 2166 0020Fax: +603 2166 1020
    • expiration_date: 09.07.2019
    • mutual_recognition: CCRA
    • product: SCAN S3 Security Manager Console Release 14556 (v2.0) integrated with Scan S3 Agent (v2.0.1.6.2)
    • report_link: https://iscb.cybersecurity.my/resources/document/mycc/mycpr/C050/ISCB-5-RPT-C050-CR-v1.pdf
    • scope: SCAN S3 SMC-AGENT is a Web-Based Application Access Control Management, which enable users to access their internal network resources securely through PKI implementation via soft-certificates, roaming certificates and smart cards. SCAN S3 SMC-AGENT is the combination of SCAN S3 SMC(Security Management Console), in which, the SCAN S3 SMC is define as the administration console for the operations SCAN S3 SMC-AGENT in the aspects of managing users and the access controls, thus, as for the SCAN S3 AGENT is the front-end interface for all users registered in the SCAN S3 SMC system, uses the interface as a secure platform in communicating with the protected resources govern by the security protection of SCAN S3 SMC-AGENT.With the new integration of software desktop that enable users to access the internal network resources, by inputting soft-certificate, roaming certificates orsmart cards through that application. The SCAN S3 SMCAGENTenables the organization to manage the overall security through a single framework that enables the defining and assignment or implementation of the following security functions in one system: Security Audit; The TOE will generate audit records for selected security events in several log files and categories. Authentication and Identification; TOE Administrator/smust login to SCAN S3 to identify themselves to the application together with the prompted (one of up to three) authentication means in order for them to gain access to the protected websites, using SCAN S3 AGENT software desktop. Cryptography; TOE has built-in feature of cryptography that bound to the operations of SCAN S3 AGENT at Users and Administrators workstation. Security Management; TOE Administrator/s has access to all TOE features, that applicable to be managed through web application portal hosted byTOE. User Data Protection; User/s data and credentials including TOE Administrator/s information is protected by ensuring that specific TOE Administrator/s that is assigned with roles and privileges can only access a specific web pages/portals and hence the data associated with the web pages/portal. Protection of the TSF; The security audit functions will generate audit records of events along with date and time of event. To ensure a reliable date and time, TOE enforce the time stamps to be taken from a reliable source from the environment.
    • status: Archive
    • target_link: https://iscb.cybersecurity.my/resources/document/mycc/mycpr/C050/2014-04-14-ST-SCANS_S3-v2.7.pdf
    • type: Web-Based Application Access Control Management, which enable users to access their internal network resources securely through PKI implementation via soft-certificates, roaming certificates and smart cards.
  • expiration_date: 09.07.2019
  • level: EAL2
  • product: SCAN S3 Security Manager Console Release 14556 (v2.0) integrated with Scan S3 Agent (v2.0.1.6.2)
  • recognition: CCRA
  • url: https://iscb.cybersecurity.my/index.php/certification/product-certification/mycc/archived-certified-products-and-systems/submission-view/66
pdf_data/report_filename ISCB-5-RPT-C030-CR-v1a.pdf ISCB-5-RPT-C050-CR-v1.pdf
pdf_data/report_keywords/cc_cert_id
  • MY:
    • ISCB-5-RPT-C030-CR-v1a: 29
  • MY:
    • ISCB-5-RPT-C050-CR-v1: 30
pdf_data/report_keywords/cc_security_level
  • EAL:
    • EAL 1: 1
    • EAL1: 11
  • EAL:
    • EAL 2: 2
    • EAL2: 8
pdf_data/report_keywords/cc_sar
  • ALC:
    • ALC_DEL: 1
pdf_data/report_keywords/cc_sfr
  • FCS:
    • FCS_CKM.1: 1
    • FCS_CKM.4: 1
    • FCS_COP.1: 1
  • FDP:
    • FDP_ACC.1: 1
    • FDP_ACF.1: 1
  • FIA:
    • FIA_AFL.1: 1
    • FIA_ATD.1: 1
    • FIA_UAU.2: 1
    • FIA_UID.2: 1
  • FMT:
    • FMT_ITT.1: 1
    • FMT_MSA.1: 1
    • FMT_MSA.3: 1
    • FMT_SMF.1: 1
    • FMT_SMR.1: 1
  • FAU:
    • FAU_GEN.3: 1
    • FAU_SAR.1: 1
    • FAU_STG.1: 1
  • FCS:
    • FCS_COP.1: 1
  • FDP:
    • FDP_ACC.1: 1
    • FDP_IFC.1: 1
  • FIA:
    • FIA_ATD.1: 1
    • FIA_UID.2: 1
  • FMT:
    • FMT_MOF.1: 1
    • FMT_MSA.1: 1
    • FMT_SMF.1: 1
  • FPT:
    • FPT_STM.2: 1
  • FTA:
    • FTA_SSL.1: 1
pdf_data/report_keywords/vendor
  • Microsoft:
    • Microsoft: 2
pdf_data/report_keywords/symmetric_crypto
  • AES_competition:
    • RC:
      • RC4: 4
pdf_data/report_keywords/hash_function
  • SHA:
    • SHA2:
      • SHA512: 2
pdf_data/report_keywords/crypto_protocol
  • TLS:
    • SSL:
      • SSL: 9
  • VPN:
    • VPN: 1
pdf_data/report_metadata
  • /Author: ISCB Department
  • /CreationDate: D:20140710161510+08'00'
  • /Creator: Microsoft® Word 2013
  • /Keywords: MyCB_TMP_002
  • /ModDate: D:20140710161510+08'00'
  • /Producer: Microsoft® Word 2013
  • /Subject: SCAN S3 Security Manager Console Release 14556 (v2.0) integrated with SCAN S3 Agent (v2.0.1.6.2)
  • /Title: C050 Certification Report
  • pdf_file_size_bytes: 704539
  • pdf_hyperlinks: mailto:[email protected], http://www.cybersecurity.my/mycc
  • pdf_is_encrypted: False
  • pdf_number_of_pages: 31
pdf_data/st_filename Web Bytes EAL1 Security Target (Xilnex Framework) v1.1.pdf 2014-04-14-ST-SCANS_S3-v2.7.pdf
pdf_data/st_keywords/cc_security_level
  • EAL:
    • EAL1: 9
  • EAL:
    • EAL2: 5
pdf_data/st_keywords/cc_sar
  • ADV:
    • ADV_FSP.1: 2
  • AGD:
    • AGD_OPE.1: 2
    • AGD_PRE.1: 2
  • ALC:
    • ALC_CMC.1: 2
    • ALC_CMS.1: 2
  • ASE:
    • ASE_CCL: 2
    • ASE_CCL.1: 2
    • ASE_ECD.1: 2
    • ASE_INT: 2
    • ASE_INT.1: 2
    • ASE_OBJ: 2
    • ASE_OBJ.1: 2
    • ASE_REQ: 2
    • ASE_REQ.1: 2
    • ASE_TSS: 2
    • ASE_TSS.1: 2
  • ATE:
    • ATE_IND.1: 2
  • AVA:
    • AVA_VAN.1: 2
  • ADV:
    • ADV_ARC.1: 1
    • ADV_FSP.2: 1
    • ADV_TDS.1: 1
  • AGD:
    • AGD_OPE.1: 1
    • AGD_PRE.1: 1
  • ALC:
    • ALC_CMC.2: 1
    • ALC_CMS.2: 1
    • ALC_DEL.1: 1
  • ASE:
    • ASE_CCL.1: 1
    • ASE_ECD.1: 1
    • ASE_INT.1: 1
    • ASE_OBJ.2: 1
    • ASE_REQ.2: 1
    • ASE_SPD.1: 1
    • ASE_TSS.1: 1
  • ATE:
    • ATE_COV.1: 1
    • ATE_FUN.1: 1
    • ATE_IND.2: 1
  • AVA:
    • AVA_VAN.2: 1
pdf_data/st_keywords/cc_sfr
  • FCS:
    • FCS_CKM.1: 13
    • FCS_CKM.2: 2
    • FCS_CKM.4: 10
    • FCS_CKM.4.1: 1
    • FCS_COP: 11
    • FCS_COP.1: 2
  • FDP:
    • FDP_ACC.1: 10
    • FDP_ACC.1.1: 1
    • FDP_ACF.1: 5
    • FDP_ACF.1.1: 1
    • FDP_ACF.1.2: 1
    • FDP_ACF.1.3: 1
    • FDP_ACF.1.4: 1
    • FDP_IFC.1: 2
    • FDP_IFF: 2
    • FDP_ITC.1: 6
    • FDP_ITC.2: 6
  • FIA:
    • FIA_AFL.1: 4
    • FIA_AFL.1.1: 1
    • FIA_AFL.1.2: 1
    • FIA_ATD.1: 3
    • FIA_ATD.1.1: 1
    • FIA_UAU.1: 1
    • FIA_UAU.2: 4
    • FIA_UAU.2.1: 1
    • FIA_UID.1: 5
    • FIA_UID.2: 6
    • FIA_UID.2.1: 1
  • FMT:
    • FMT_MSA.1: 6
    • FMT_MSA.1.1: 1
    • FMT_MSA.3: 7
    • FMT_MSA.3.1: 1
    • FMT_MSA.3.2: 1
    • FMT_SMF.1: 7
    • FMT_SMF.1.1: 1
    • FMT_SMR.1: 8
    • FMT_SMR.1.1: 1
    • FMT_SMR.1.2: 1
  • FPT:
    • FPT_ITT.1: 4
    • FPT_ITT.1.1: 1
  • FAU:
    • FAU_GEN: 1
    • FAU_GEN.1: 3
    • FAU_GEN.2: 2
    • FAU_GEN.2.1: 1
    • FAU_GEN.3: 11
    • FAU_GEN.3.1: 2
    • FAU_GEN.3.2: 2
    • FAU_SAR.1: 5
    • FAU_SAR.1.1: 1
    • FAU_SAR.1.2: 1
    • FAU_SAR.2: 2
    • FAU_SAR.2.1: 1
    • FAU_STG: 1
    • FAU_STG.1: 6
    • FAU_STG.1.1: 1
    • FAU_STG.1.2: 1
    • FAU_STG.3: 1
    • FAU_STG.4: 3
    • FAU_STG.4.1: 1
  • FCS:
    • FCS_CKM.1: 2
    • FCS_CKM.4: 1
    • FCS_COP: 1
    • FCS_COP.1: 4
    • FCS_COP.1.1: 1
  • FDP:
    • FDP_ACC.1: 7
    • FDP_ACC.1.1: 1
    • FDP_ACF.1: 4
    • FDP_ACF.1.1: 1
    • FDP_ACF.1.2: 1
    • FDP_ACF.1.3: 1
    • FDP_ACF.1.4: 1
    • FDP_IFC.1: 8
    • FDP_IFC.1.1: 1
    • FDP_IFF.1: 6
    • FDP_IFF.1.1: 2
    • FDP_IFF.1.2: 1
    • FDP_IFF.1.3: 1
    • FDP_IFF.1.4: 1
    • FDP_IFF.1.5: 1
    • FDP_ITC.1: 1
    • FDP_ITC.2: 1
  • FIA:
    • FIA_ATD.1: 5
    • FIA_ATD.1.1: 2
    • FIA_UAU.1: 2
    • FIA_UAU.2: 4
    • FIA_UAU.2.1: 1
    • FIA_UID.1: 3
    • FIA_UID.2: 5
    • FIA_UID.2.1: 1
    • FIA_USB.1: 4
    • FIA_USB.1.1: 1
    • FIA_USB.1.2: 1
  • FMT:
    • FMT_MOF.1: 4
    • FMT_MOF.1.1: 2
    • FMT_MSA.1: 5
    • FMT_MSA.1.1: 1
    • FMT_MSA.3: 5
    • FMT_MSA.3.1: 1
    • FMT_MSA.3.2: 1
    • FMT_MTD.1: 4
    • FMT_MTD.1.1: 1
    • FMT_SMF.1: 7
    • FMT_SMF.1.1: 1
    • FMT_SMR.1: 9
    • FMT_SMR.1.1: 1
    • FMT_SMR.1.2: 1
  • FPT:
    • FPT_STM: 1
    • FPT_STM.1: 1
    • FPT_STM.2: 9
    • FPT_STM.2.1: 2
  • FTA:
    • FTA_SSL.1: 3
    • FTA_SSL.1.1: 1
    • FTA_SSL.1.2: 1
pdf_data/st_keywords/cc_claims
  • OE:
    • OE.ADMIN: 1
    • OE.CERTIFICATES: 1
    • OE.DATABASE: 1
    • OE.ENVIRONMENT: 1
    • OE.INSTALL: 1
    • OE.NETWORK: 1
    • OE.PHYSICAL: 1
  • A:
    • A.ADMIN: 2
    • A.CONN: 2
    • A.FLOW: 2
    • A.MGMT: 2
    • A.PHY: 2
    • A.TIMEBACK: 2
    • A.USER: 2
  • O:
    • O.ACCESSLOG: 3
    • O.AUDIT: 3
    • O.CONFIG: 4
    • O.EXPLOIT: 4
    • O.NOAUTH: 3
  • OE:
    • OE.ADMIN: 3
    • OE.CONN: 3
    • OE.FLOW: 2
    • OE.MGMT: 3
    • OE.PHY: 2
    • OE.SOFTCERT: 2
    • OE.TIMEBACK: 2
    • OE.USER: 3
  • T:
    • T.ACCESSLOG: 2
    • T.AUDIT: 2
    • T.CONFIG: 2
    • T.EXPLOIT: 2
    • T.NOAUTH: 2
    • T.REMOTE: 2
    • T.SPOOF: 2
pdf_data/st_keywords/vendor
  • Microsoft:
    • Microsoft: 4
pdf_data/st_keywords/symmetric_crypto
  • AES_competition:
    • RC:
      • RC4: 7
pdf_data/st_keywords/hash_function
  • SHA:
    • SHA2:
      • SHA512: 3
pdf_data/st_keywords/crypto_protocol
  • TLS:
    • SSL:
      • SSL: 10
  • SSH:
    • SSH: 1
  • TLS:
    • TLS:
      • TLS: 1
  • VPN:
    • VPN: 6
pdf_data/st_keywords/standard_id
  • FIPS:
    • FIPS 140-1: 1
    • FIPS 180-2: 2
    • FIPS140-1: 1
  • RFC:
    • RFC 4345: 3
  • CC:
    • CCMB-2012-09-004: 1
  • X509:
    • X.509: 1
pdf_data/st_metadata
state/report/pdf_hash Different Different
state/report/txt_hash Different Different
state/st/pdf_hash Different Different
state/st/txt_hash Different Different