Comparing certificates Experimental feature

You are comparing two certificates. By default, only differing attributes are shown. Use the button below to show/hide all attributes.

Showing only differing attributes.
Employee Express (EmplX) Security Module v1.0 (Build SVR 2.0)
ISCB-5-RPT-C019-CR-v1a
Citrix Presentation Server 4.5
CRP241
name Employee Express (EmplX) Security Module v1.0 (Build SVR 2.0) Citrix Presentation Server 4.5
category Other Devices and Systems Access Control Devices and Systems
scheme MY UK
not_valid_after 04.11.2016 05.03.2013
not_valid_before 04.11.2011 01.07.2007
report_link https://www.commoncriteriaportal.org/nfs/ccpfiles/files/epfiles/ISCB-5-RPT-C019-CR-v1a.pdf https://www.commoncriteriaportal.org/nfs/ccpfiles/files/epfiles/CRP241.pdf
st_link https://www.commoncriteriaportal.org/nfs/ccpfiles/files/epfiles/MYWave%20EAL2%20Security%20Target%20(EmplX%20Security%20Module)%20v1.0.pdf https://www.commoncriteriaportal.org/nfs/ccpfiles/files/epfiles/LFS-T528_citrix_ST%20v2.0.pdf
manufacturer MYwave Sdn Bhd Citrix Systems, Inc.
manufacturer_web https://www.mywave.biz https://www.citrix.com
security_level EAL2 EAL2+, ALC_FLR.2
dgst 111e346581566c73 9f78a9b594d9b0d2
heuristics/cert_id ISCB-5-RPT-C019-CR-v1a CRP241
heuristics/indirect_transitive_cves {} CVE-2014-4700, CVE-2016-6493, CVE-2016-4810
heuristics/extracted_sars ASE_CCL.1, ATE_FUN.1, ASE_OBJ.2, ALC_CMS.2, ASE_INT.1, ASE_REQ.2, AGD_PRE.1, ATE_IND.2, ASE_ECD.1, AVA_VAN.2, ADV_TDS.1, ASE_SPD.1, ALC_CMC.2, ADV_FSP.2, ATE_COV.1, AGD_OPE.1, ALC_DEL.1, ASE_TSS.1, ADV_ARC.1 ADV_HLD.1, AVA_VLA.1, AGD_ADM.1, ATE_IND.2, ALC_FLR.2, ADV_RCR.1, ATE_COV.1, AVA_SOF.1, ATE_FUN.1, AGD_USR.1, ADV_SPM.1, ADV_FSP.1
heuristics/extracted_versions 1.0, 2.0 4.5
heuristics/report_references/directly_referenced_by {} CRP257
heuristics/report_references/indirectly_referenced_by {} CRP282, CRP257, CRP281
heuristics/scheme_data
  • cert_no: 2011-018-C019
  • certification_date: 04.11.2011
  • developer: MYwave Sdn Bhd
  • enhanced:
    • assurance_level: EAL2
    • category: Other Devices and Systems
    • cert_id: C019
    • certification_date: 04.11.2011
    • developer: Yip Hon Choong 1-3-21, Krystal Point Corporate Park,Jalan Tun Dr Awang,11900 Bayan Lepas, Pulau Pinang MALAYSIA URL: http://www.mywave.bizEmail: [email protected]:+ 604 6403 117
    • expiration_date: 04.11.2016
    • mutual_recognition: CCRA
    • product: Employee Express (EmplX) Security Module
    • report_link: https://iscb.cybersecurity.my/resources/document/mycc/mycpr/C019/ISCB-5-RPT-C019-CR-v1a.pdf
    • scope: The Target of Evaluation (TOE), Employee Express (EmplX) Security Module v1.0 (Build SVR 2.0) is a PHP module of EmplX Human Resource Management Systems (HRMS) web application hosted on a web server. It is designed to be used as a core security controlling module for a web-based application environment. The TOE provides core security functionality such as authentication, access control, secure communications and application security management. All http requests to the web server will be meditated by the TOE before allowing access to the rest of the EmplX HRMS. The security functionality that is within the scope of the evaluation includes: Access control – EmplX Security Module manages access control based on user IDs, user roles and access control lists. It maintains access control lists (ACLs) for each object within an organisation. Each ACL maps users and roles to the operations that they are permitted to perform on the object. Organisation Management – EmplX Security Module provides strict controls on organisation management. Only Super Administrators can manage the creation, modification and destruction of an organisation. Users and Supervisors can only operate within their organisation. Identification and Authentication – each user is required to successfully identified using user ID and authenticated using password before any interaction with protected resources within EmplX HRMS is permitted. Security Management - EmplX Security Module provides functions that allow management of the TOE and its security functions. It restricts access to the management functions based on the role of the user. Secure Communications - EmplX Security Module is able to protect the user data from disclosure and modification when it is sent from users' browser to the EmplX HRMS using the secure SSL channel.
    • status: Archive
    • target_link: https://iscb.cybersecurity.my/resources/document/mycc/mycpr/C019/MYWave%20EAL2%20Security%20Target%20(EmplX%20Security%20Module)%20v1.0.pdf
    • type: Specialist software module designed to be used as a core security controlling module for a web-based application environment
  • expiration_date: 04.11.2016
  • level: EAL2
  • product: Employee Express (EmplX) Security Module
  • recognition: CCRA
  • url: https://iscb.cybersecurity.my/index.php/certification/product-certification/mycc/archived-certified-products-and-systems/submission-view/153
pdf_data/report_filename ISCB-5-RPT-C019-CR-v1a.pdf CRP241.pdf
pdf_data/report_keywords/cc_cert_id
  • MY:
    • ISCB-5-RPT-C019-CR-v1a: 30
  • UK:
    • CRP241: 1
pdf_data/report_keywords/cc_security_level
  • EAL:
    • EAL 2: 1
    • EAL2: 10
  • EAL:
    • EAL2: 4
    • EAL2 augmented: 3
pdf_data/report_keywords/cc_sar
  • ALC:
    • ALC_FLR.2: 3
pdf_data/report_keywords/cc_sfr
  • FCS:
    • FCS_COP.1: 1
  • FDP:
    • FDP_ACC.1: 1
    • FDP_ACF.1.1: 1
    • FDP_ACF.1.3: 1
  • FIA:
    • FIA_UAU.2: 1
    • FIA_UID.2: 1
  • FMT:
    • FMT_MSA.1: 1
    • FMT_MSA.3: 1
    • FMT_MTD: 4
    • FMT_SMF.1: 1
    • FMT_SMR.1: 1
  • FTP:
    • FTP_TRP.1.1: 1
    • FTP_TRP.1.3: 1
  • FTP:
    • FTP_ITC.1: 1
    • FTP_ITC.2: 1
pdf_data/report_keywords/vendor
  • Broadcom:
    • Broadcom: 1
  • Microsoft:
    • Microsoft: 29
pdf_data/report_keywords/hash_function
  • SHA:
    • SHA2:
      • SHA-2: 2
      • SHA-224: 1
      • SHA-256: 2
      • SHA-384: 1
      • SHA-512: 1
pdf_data/report_keywords/crypto_protocol
  • TLS:
    • SSL:
      • SSL: 4
    • TLS:
      • TLS: 1
  • IPsec:
    • IPsec: 3
  • TLS:
    • SSL:
      • SSL: 1
    • TLS:
      • TLS: 8
pdf_data/report_keywords/standard_id
  • FIPS:
    • FIPS 180-2: 2
  • ISO:
    • ISO/IEC 18045: 2
    • ISO/IEC15408: 2
  • CC:
    • CCMB-2005-08-001: 1
    • CCMB-2005-08-002: 1
    • CCMB-2005-08-003: 1
    • CCMB-2005-08-004: 1
  • FIPS:
    • FIPS 140-1: 1
    • FIPS 140-2: 1
pdf_data/report_metadata
  • /Author: Zie
  • /CreationDate: D:20111109153418+08'00'
  • /Creator: PScript5.dll Version 5.2
  • /ModDate: D:20111109153418+08'00'
  • /Producer: Acrobat Distiller 8.3.1 (Windows)
  • /Title: Microsoft Word - ISCB-5-RPT-C019-CR-v1a _web_
  • pdf_file_size_bytes: 330254
  • pdf_hyperlinks: {}
  • pdf_is_encrypted: True
  • pdf_number_of_pages: 30
  • /CreationDate: D:20070802100755+01'00'
  • /ModDate: D:20070802100755+01'00'
  • /Producer: Acrobat Distiller 6.0 (Windows)
  • /Title: untitled
  • pdf_file_size_bytes: 411222
  • pdf_hyperlinks: {}
  • pdf_is_encrypted: False
  • pdf_number_of_pages: 22
pdf_data/st_filename MYWave EAL2 Security Target (EmplX Security Module) v1.0.pdf LFS-T528_citrix_ST v2.0.pdf
pdf_data/st_keywords/cc_security_level
  • EAL:
    • EAL2: 9
  • EAL:
    • EAL2: 8
    • EAL2 augmented: 2
    • EAL2+: 1
pdf_data/st_keywords/cc_sar
  • ADV:
    • ADV_ARC.1: 1
    • ADV_FSP.2: 1
    • ADV_TDS.1: 1
  • AGD:
    • AGD_OPE.1: 1
    • AGD_PRE.1: 1
  • ALC:
    • ALC_CMC.2: 1
    • ALC_CMS.2: 1
    • ALC_DEL.1: 1
  • ASE:
    • ASE_CCL.1: 4
    • ASE_ECD.1: 1
    • ASE_INT.1: 4
    • ASE_OBJ.2: 4
    • ASE_REQ.2: 4
    • ASE_SPD.1: 4
    • ASE_TSS.1: 4
  • ATE:
    • ATE_COV.1: 1
    • ATE_FUN.1: 1
    • ATE_IND.2: 1
  • AVA:
    • AVA_VAN.2: 1
  • ACM:
    • ACM_CAP.2: 2
  • ADO:
    • ADO_DEL.1: 2
    • ADO_IGS.1: 2
  • ADV:
    • ADV_FSP.1: 2
    • ADV_HLD.1: 2
    • ADV_RCR.1: 2
    • ADV_SPM.1: 2
  • AGD:
    • AGD_ADM.1: 2
    • AGD_USR.1: 2
  • ALC:
    • ALC_FLR.2: 7
  • ATE:
    • ATE_COV.1: 2
    • ATE_FUN.1: 2
    • ATE_IND.2: 2
  • AVA:
    • AVA_SOF.1: 2
    • AVA_VLA.1: 3
pdf_data/st_keywords/cc_sfr
  • FCS:
    • FCS_CKM.1: 3
    • FCS_CKM.4: 3
    • FCS_COP: 1
    • FCS_COP.1: 4
    • FCS_COP.1.1: 1
  • FDP:
    • FDP_ACC: 2
    • FDP_ACC.1: 11
    • FDP_ACC.1.1: 1
    • FDP_ACF: 2
    • FDP_ACF.1: 6
    • FDP_ACF.1.1: 1
    • FDP_ACF.1.2: 1
    • FDP_ACF.1.3: 1
    • FDP_ACF.1.4: 1
    • FDP_IFC.1: 2
    • FDP_IFF: 2
    • FDP_ITC.1: 2
    • FDP_ITC.2: 2
  • FIA:
    • FIA_UAU: 2
    • FIA_UAU.1: 1
    • FIA_UAU.2: 4
    • FIA_UAU.2.1: 1
    • FIA_UID: 2
    • FIA_UID.1: 4
    • FIA_UID.2: 5
    • FIA_UID.2.1: 1
  • FMT:
    • FMT_MSA: 2
    • FMT_MSA.1: 6
    • FMT_MSA.1.1: 1
    • FMT_MSA.3: 7
    • FMT_MSA.3.1: 1
    • FMT_MSA.3.2: 1
    • FMT_MTD: 25
    • FMT_SMF: 1
    • FMT_SMF.1: 19
    • FMT_SMF.1.1: 1
    • FMT_SMR: 2
    • FMT_SMR.1: 17
    • FMT_SMR.1.1: 1
    • FMT_SMR.1.2: 1
  • FTP:
    • FTP_TRP.1: 5
    • FTP_TRP.1.1: 1
    • FTP_TRP.1.2: 1
    • FTP_TRP.1.3: 1
  • FCS:
    • FCS_CKM.1: 12
    • FCS_CKM.1.1: 1
    • FCS_CKM.2: 10
    • FCS_CKM.2.1: 2
    • FCS_CKM.4: 25
    • FCS_CKM.4.1: 3
    • FCS_COP.1: 21
    • FCS_COP.1.1: 3
    • FCS_ITC.2: 1
  • FDP:
    • FDP_ACC.1: 23
    • FDP_ACF.1: 16
    • FDP_IFC.1: 3
    • FDP_ITC.1: 2
    • FDP_ITC.2: 2
    • FDP_ITT.1: 17
    • FDP_ITT.1.1: 2
    • FDP_RIP.1: 6
    • FDP_RIP.1.1: 1
  • FIA:
    • FIA_AFL.1: 5
    • FIA_AFL.1.1: 1
    • FIA_AFL.1.2: 1
    • FIA_ATD.1: 12
    • FIA_ATD.1.1: 1
    • FIA_UAU: 1
    • FIA_UAU.2: 11
    • FIA_UAU.2.1: 2
    • FIA_UID.1: 1
    • FIA_UID.2: 10
    • FIA_UID.2.1: 2
  • FMT:
    • FMT_MOF.1: 14
    • FMT_MOF.1.1: 2
    • FMT_MSA.1: 11
    • FMT_MSA.1.1: 1
    • FMT_MSA.2: 12
    • FMT_MSA.2.1: 1
    • FMT_MSA.3: 9
    • FMT_MSA.3.1: 1
    • FMT_MSA.3.2: 1
    • FMT_SMF.1: 17
    • FMT_SMF.1.1: 1
    • FMT_SMR.1: 21
    • FMT_SMR.1.1: 1
    • FMT_SMR.1.2: 1
  • FPT:
    • FPT_AMT.1: 6
    • FPT_AMT.1.1: 1
    • FPT_ITT.1: 15
    • FPT_ITT.1.1: 2
    • FPT_RVM.1: 12
    • FPT_RVM.1.1: 1
    • FPT_SEP.1: 2
    • FPT_SEP.1.1: 1
    • FPT_SEP.1.2: 1
    • FPT_TST.1: 6
    • FPT_TST.1.1: 1
    • FPT_TST.1.2: 1
    • FPT_TST.1.3: 1
  • FTP:
    • FTP_ITC: 1
    • FTP_ITC.1: 1
    • FTP_ITC.2: 9
    • FTP_ITC.2.1: 1
    • FTP_ITC.2.2: 1
    • FTP_ITC.2.3: 1
pdf_data/st_keywords/cc_claims
  • A:
    • A.ADMIN: 2
    • A.DATABASE: 2
    • A.ENVIRONMENT: 2
    • A.MANAGEMENT: 2
    • A.NETWORK: 2
    • A.PATCH: 1
    • A.PHYSICAL: 2
    • A.SSL_CONFIG: 2
  • O:
    • O.ACCESS: 4
    • O.COMM: 3
    • O.MANAGE: 3
    • O.ORGANISATION: 3
    • O.PASSWORD: 3
    • O.USER: 5
  • OE:
    • OE.ADMIN: 2
    • OE.DATABASE: 2
    • OE.ENVIRONMENT: 2
    • OE.MANAGEMENT: 2
    • OE.NETWORK: 2
    • OE.PATCH: 2
    • OE.PHYSICAL: 2
    • OE.SSL_CONFIG: 2
  • T:
    • T.ACCESS: 2
    • T.COMM: 1
    • T.MANAGEMENT: 2
    • T.ORGANISATION: 3
    • T.PASSWORD: 2
  • A:
    • A.APP_: 1
    • A.APP_CONFIG: 1
    • A.PUBLISHED_: 1
    • A.SMARTCARD: 1
    • A.THIRD_PARTY_: 1
    • A.TRUSTADMIN: 1
    • A.USER_: 1
  • OE:
    • OE.CERTIFICATES: 3
    • OE.CLIENT_: 1
    • OE.CLIENT_PHYSICAL: 1
    • OE.CLIENT_TPSW: 3
    • OE.IPSEC: 8
    • OE.LIMIT_AUT: 1
    • OE.LIMIT_AUTH: 2
    • OE.MALWARE_: 1
    • OE.MALWARE_PROT: 1
    • OE.MALWARE_PROTECT: 2
    • OE.MEMORY: 4
    • OE.OS_CONFIG: 2
    • OE.OS_CONFIG_: 2
    • OE.OS_CONFIG_CLIENT: 2
    • OE.OS_CONFIG_SERVER: 2
    • OE.PASSWORD: 1
    • OE.PASSWORD_: 1
    • OE.PASSWORD_SETUP: 1
    • OE.SECURE_: 1
    • OE.SECURE_EN: 1
    • OE.SECURE_ENCRYPTION: 2
    • OE.SERVER_: 1
    • OE.SERVER_PHYSICAL: 2
    • OE.SERVER_TH: 1
    • OE.SERVER_THIRD_: 1
    • OE.SERVER_THIRD_PARTY_SW: 1
    • OE.SESSION_K: 1
    • OE.SESSION_KEYS: 2
    • OE.TRUSTED_: 1
    • OE.TRUSTED_OPS: 2
  • OSP:
    • OSP.CRYPTO: 4
  • OT:
    • OT.APPS_: 1
    • OT.APPS_AVAIL: 2
    • OT.AUTHENTIC_: 4
    • OT.AUTHENTIC_CLIENT: 1
    • OT.AUTHENTIC_SERVER: 1
    • OT.CONF: 3
    • OT.CONF_: 1
    • OT.CONF_CLIENT: 2
    • OT.CUTPASTE: 1
    • OT.CUT_PASTE: 2
    • OT.DRIVES: 3
    • OT.GATE_ALLO: 1
    • OT.GATE_ALLOW: 2
    • OT.INTEG: 3
    • OT.INTEG_: 1
    • OT.INTEG_CLIENT: 2
    • OT.SECURE_ENC: 1
    • OT.SECURE_ENCRYP: 1
    • OT.SECURE_ENCRYPTION: 2
  • T:
    • T.AUTHENTIC: 4
    • T.AVAIL: 4
    • T.MISDIRECT: 2
    • T.MOD_CONF: 4
    • T.MOD_HW_CLIENT: 1
    • T.MOD_HW_SERVER: 1
pdf_data/st_keywords/vendor
  • Microsoft:
    • Microsoft: 22
pdf_data/st_keywords/symmetric_crypto
  • DES:
    • 3DES:
      • 3DES: 3
      • TripleDES: 4
pdf_data/st_keywords/crypto_scheme
  • KEX:
    • Key Exchange: 3
pdf_data/st_keywords/crypto_protocol
  • TLS:
    • SSL:
      • SSL: 8
    • TLS:
      • TLS: 1
  • TLS:
    • SSL:
      • SSL: 3
    • TLS:
      • TLS: 29
pdf_data/st_keywords/standard_id
  • FIPS:
    • FIPS 140: 3
    • FIPS 140-1: 1
    • FIPS 140-2: 3
    • FIPS 186-2: 1
    • FIPS140: 13
    • FIPS140-1: 2
  • RFC:
    • RFC 2246: 3
    • RFC 2412: 1
    • RFC 2451: 1
pdf_data/st_keywords/certification_process
  • OutOfScope:
    • The TOE comprises the sample deployment as described below. All other configurations are out of scope of the evaluation. The deployment uses the Secure Gateway to provide TLS encryption between a TLS-: 1
    • out of scope: 2
    • the TOE. Note: The Windows operating system provides the function that authenticates users. This is out of scope of the TOE, so there are no mechanisms requiring assessment. Page 36 of 58 Version 2.0 Ref: 1
pdf_data/st_metadata
  • /Author: Zie
  • /CreationDate: D:20111109153646+08'00'
  • /Creator: PScript5.dll Version 5.2
  • /ModDate: D:20111109153646+08'00'
  • /Producer: Acrobat Distiller 8.3.1 (Windows)
  • /Title: Microsoft Word - MYWave EAL2 Security Target _EmplX Security Module_ v1.0
  • pdf_file_size_bytes: 307957
  • pdf_hyperlinks: {}
  • pdf_is_encrypted: True
  • pdf_number_of_pages: 37
  • /Author: Administrator
  • /CreationDate: D:20070725145948Z
  • /Creator: PScript5.dll Version 5.2
  • /ModDate: D:20070802101448+01'00'
  • /Producer: GPL Ghostscript 8.15
  • /Title: Microsoft Word - 056 Citrix ST V2.0 - 24-07-07.doc
  • pdf_file_size_bytes: 273312
  • pdf_hyperlinks: {}
  • pdf_is_encrypted: False
  • pdf_number_of_pages: 58
state/report/pdf_hash Different Different
state/report/txt_hash Different Different
state/st/pdf_hash Different Different
state/st/txt_hash Different Different