Comparing certificates Experimental feature

You are comparing two certificates. By default, only differing attributes are shown. Use the button below to show/hide all attributes.

Showing only differing attributes.
FortiMail 7.4
CCEVS-VR-VID-11462-2024
IBM Enterprise PKCS#11 (EP11) Firmware identifier '2b638e8e' (4768)
BSI-DSZ-CC-1094-2019
name FortiMail 7.4 IBM Enterprise PKCS#11 (EP11) Firmware identifier '2b638e8e' (4768)
category Network and Network-Related Devices and Systems Other Devices and Systems
scheme US DE
status active archived
not_valid_after 26.07.2026 02.08.2024
not_valid_before 26.07.2024 02.08.2019
cert_link https://www.commoncriteriaportal.org/nfs/ccpfiles/files/epfiles/st_vid11454-ci.pdf https://www.commoncriteriaportal.org/nfs/ccpfiles/files/epfiles/1094c_pdf.pdf
report_link https://www.commoncriteriaportal.org/nfs/ccpfiles/files/epfiles/st_vid11454-vr.pdf https://www.commoncriteriaportal.org/nfs/ccpfiles/files/epfiles/1094a_pdf.pdf
st_link https://www.commoncriteriaportal.org/nfs/ccpfiles/files/epfiles/st_vid11454-st.pdf https://www.commoncriteriaportal.org/nfs/ccpfiles/files/epfiles/1094b_pdf.pdf
manufacturer Fortinet, Inc. IBM Corporation
manufacturer_web https://www.fortinet.com/ https://www.ibm.com
security_level {} EAL4
dgst 1fe3789bf4090221 1f2b1fe6f29f21b7
heuristics/cert_id CCEVS-VR-VID-11462-2024 BSI-DSZ-CC-1094-2019
heuristics/cert_lab US BSI
heuristics/cpe_matches cpe:2.3:a:fortinet:fortimail:7.4.3:*:*:*:*:*:*:*, cpe:2.3:a:fortinet:fortimail:7.4.2:*:*:*:*:*:*:*, cpe:2.3:a:fortinet:fortimail:7.4.0:*:*:*:*:*:*:*, cpe:2.3:a:fortinet:fortimail:7.4.1:*:*:*:*:*:*:* {}
heuristics/related_cves CVE-2021-32591, CVE-2023-45582 {}
heuristics/extracted_sars ASE_TSS.1, ADV_FSP.1, ALC_CMC.1, ASE_INT.1, ASE_SPD.1, ASE_OBJ.1, AVA_VAN.1, ATE_IND.1, ALC_CMS.1, AGD_OPE.1, ASE_REQ.1, ASE_CCL.1, ASE_ECD.1, AGD_PRE.1 {}
heuristics/extracted_versions 7.4 4768, 11
heuristics/report_references/directly_referencing {} BSI-DSZ-CC-1002-2018
heuristics/report_references/indirectly_referencing {} BSI-DSZ-CC-1002-2018
heuristics/scheme_data
heuristics/protection_profiles 89f2a255423f4a20 {}
protection_profile_links https://www.commoncriteriaportal.org/nfs/ccpfiles/files/ppfiles/CPP_ND_V2.2E.pdf {}
pdf_data/cert_filename st_vid11454-ci.pdf 1094c_pdf.pdf
pdf_data/cert_keywords/cc_cert_id
  • US:
    • CCEVS-VR-VID11454-2024: 1
  • DE:
    • BSI-DSZ-CC-1094-2019: 1
pdf_data/cert_keywords/cc_security_level
  • EAL:
    • EAL 2: 1
    • EAL 4: 1
pdf_data/cert_keywords/eval_facility
  • Leidos:
    • Leidos: 1
pdf_data/cert_keywords/standard_id
  • ISO:
    • ISO/IEC 15408: 2
    • ISO/IEC 18045: 2
  • PKCS:
    • PKCS#11: 1
pdf_data/cert_metadata
  • /Producer: WeasyPrint 62.3
  • /Title: FortiMail 7.4
  • pdf_file_size_bytes: 131509
  • pdf_hyperlinks: {}
  • pdf_is_encrypted: False
  • pdf_number_of_pages: 1
  • /Author: Bundesamt für Sicherheit in der Informationstechnik
  • /CreationDate: D:20190826112423+02'00'
  • /Creator: Writer
  • /Keywords: "Common Criteria, Certification, Zertifizierung, IBM Enterprise PKCS#11 (EP11) Firmware identifier 2b638e8e"
  • /ModDate: D:20190906121520+02'00'
  • /Producer: LibreOffice 6.1
  • /Subject: Urkunde, Zertifikat
  • /Title: Certification Report BSI-DSZ-CC-1094-2019
  • pdf_file_size_bytes: 368630
  • pdf_hyperlinks: {}
  • pdf_is_encrypted: False
  • pdf_number_of_pages: 1
pdf_data/report_filename st_vid11454-vr.pdf 1094a_pdf.pdf
pdf_data/report_frontpage
  • DE:
  • US:
    • cert_id: CCEVS-VR-VID11462-2024
    • cert_item: Cisco Catalyst 9200/9200L Series Switches 17.12
    • cert_lab: US NIAP
  • DE:
    • cc_security_level: Common Criteria Part 3 conformant EAL 4
    • cc_version: Product specific Security Target Common Criteria Part 2 extended
    • cert_id: BSI-DSZ-CC-1094-2019
    • cert_item: IBM Enterprise PKCS#11 (EP11) Firmware identifier '2b638e8e' (4768
    • cert_lab: BSI
    • developer: IBM Research & Development Germany
    • match_rules: ['(BSI-DSZ-CC-.+?) (?:for|For) (.+?) from (.*)']
    • ref_protection_profiles: None
  • US:
pdf_data/report_keywords/cc_cert_id
  • US:
    • CCEVS-VR-VID11462-2024: 1
  • DE:
    • BSI-DSZ-CC-1002-2018: 2
    • BSI-DSZ-CC-1094-2019: 14
  • NL:
    • CC-1002-2018: 1
pdf_data/report_keywords/cc_security_level
  • EAL:
    • EAL 1: 1
    • EAL 2: 3
    • EAL 4: 5
pdf_data/report_keywords/cc_sar
  • ALC:
    • ALC_FLR: 1
pdf_data/report_keywords/vendor
  • Cisco:
    • Cisco: 26
    • Cisco Systems, Inc: 4
pdf_data/report_keywords/eval_facility
  • Gossamer:
    • Gossamer Security: 4
  • atsec:
    • atsec: 3
pdf_data/report_keywords/symmetric_crypto
  • AES_competition:
    • AES:
      • AES: 1
      • AES-128: 1
  • AES_competition:
    • AES:
      • AES: 3
  • DES:
    • 3DES:
      • TDES: 3
pdf_data/report_keywords/asymmetric_crypto
  • ECC:
    • ECDH:
      • ECDH: 4
    • ECDSA:
      • ECDSA: 5
  • FF:
    • DSA:
      • DSA: 4
pdf_data/report_keywords/hash_function
  • SHA:
    • SHA2:
      • SHA-2: 1
  • SHA:
    • SHA1:
      • SHA-1: 2
    • SHA2:
      • SHA-2: 1
      • SHA-224: 1
      • SHA-256: 4
      • SHA-384: 1
      • SHA-512: 1
      • SHA256: 4
pdf_data/report_keywords/crypto_scheme
  • MAC:
    • MAC: 1
pdf_data/report_keywords/crypto_protocol
  • IPsec:
    • IPsec: 4
  • SSH:
    • SSH: 3
pdf_data/report_keywords/randomness
  • PRNG:
    • DRBG: 1
  • RNG:
    • RNG: 1
  • TRNG:
    • TRNG: 2
pdf_data/report_keywords/cipher_mode
  • CBC:
    • CBC: 3
  • ECB:
    • ECB: 2
pdf_data/report_keywords/ecc_curve
  • NIST:
    • secp256k1: 2
pdf_data/report_keywords/technical_report_id
  • BSI:
    • BSI 7148: 1
    • BSI TR-02102: 1
pdf_data/report_keywords/standard_id
  • X509:
    • X.509: 1
  • BSI:
    • AIS 20: 2
    • AIS 32: 1
    • AIS 38: 1
  • FIPS:
    • FIPS 180-4: 1
    • FIPS 186-4: 9
    • FIPS 197: 1
    • FIPS 46-3: 1
  • ISO:
    • ISO/IEC 15408: 4
    • ISO/IEC 17065: 2
    • ISO/IEC 18045: 4
  • NIST:
    • NIST SP 800-38A: 2
    • NIST SP 800-90A: 1
  • PKCS:
    • PKCS#1: 1
    • PKCS#11: 14
  • RFC:
    • RFC 3447: 1
    • RFC 5639: 3
  • X509:
    • X.509: 1
pdf_data/report_keywords/certification_process
  • ConfidentialDocument:
    • BOE) for documentation files, Version 1, 2017-07-14, IBM (confidential document) Configuration list from git, Charlotte part; Version 1, Date 2019-03-14, IBM (confidential: 1
    • Notes for the configuration list from git, Charlotte part; Version 1, Date 2019-03-14, IBM (confidential document) Hardware configuration list for IBM 4765 and 4767 EP11 HSMs, Version 1.0, 2017- 08-31, IBM: 1
    • Report, Version 2, 2019-07-10, Final Evaluation Technical Report, atsec information security GmbH (confidential document) [8] Configuration lists for the TOE: Configuration list of static content measured by SHA256: 1
    • Version 1.0, 2016- 12-12, IBM (confidential document) EP11 configuration list BOE, Version 1, 2019-03-27, IBM (confidential document) EP11 configuration: 1
    • being maintained, is not given any longer. In particular, prior to the dissemination of confidential documentation and information related to the TOE or resulting from the evaluation and certification: 1
pdf_data/report_metadata
pdf_data/st_filename st_vid11454-st.pdf 1094b_pdf.pdf
pdf_data/st_keywords/cc_protection_profile_id
  • BSI:
    • BSI-CC-PP-0045-2009: 1
pdf_data/st_keywords/cc_security_level
  • EAL:
    • EAL 4: 1
    • EAL4: 3
pdf_data/st_keywords/cc_sar
  • ADV:
    • ADV_FSP.1: 1
  • AGD:
    • AGD_OPE.1: 1
    • AGD_PRE.1: 1
  • ALC:
    • ALC_CMC.1: 1
    • ALC_CMS.1: 1
  • ASE:
    • ASE_CCL.1: 1
    • ASE_ECD.1: 1
    • ASE_INT.1: 1
    • ASE_OBJ.1: 1
    • ASE_REQ.1: 1
    • ASE_SPD.1: 1
    • ASE_TSS.1: 1
  • ATE:
    • ATE_IND.1: 1
  • AVA:
    • AVA_VAN: 1
    • AVA_VAN.1: 1
pdf_data/st_keywords/cc_sfr
  • FAU:
    • FAU_GEN.1: 5
    • FAU_GEN.1.1: 1
    • FAU_GEN.1.2: 1
    • FAU_GEN.2: 5
    • FAU_GEN.2.1: 1
    • FAU_STG_EXT.1: 6
    • FAU_STG_EXT.1.1: 1
    • FAU_STG_EXT.1.2: 1
    • FAU_STG_EXT.1.3: 1
  • FCS:
    • FCS_CKM.1: 6
    • FCS_CKM.1.1: 1
    • FCS_CKM.2: 6
    • FCS_CKM.2.1: 1
    • FCS_CKM.4: 6
    • FCS_CKM.4.1: 1
    • FCS_COP: 26
    • FCS_COP.1: 4
    • FCS_NTP_EXT.1: 1
    • FCS_NTP_EXT.1.4: 1
    • FCS_RBG_EXT.1: 7
    • FCS_RBG_EXT.1.1: 1
    • FCS_RBG_EXT.1.2: 1
    • FCS_SSHC_EXT.1: 1
    • FCS_SSHS_EXT.1: 9
    • FCS_SSHS_EXT.1.1: 1
    • FCS_SSHS_EXT.1.3: 1
    • FCS_SSHS_EXT.1.4: 1
    • FCS_SSHS_EXT.1.5: 1
    • FCS_SSHS_EXT.1.6: 1
    • FCS_SSHS_EXT.1.7: 1
    • FCS_SSHS_EXT.1.8: 1
    • FCS_TLSC_EXT.1: 7
    • FCS_TLSC_EXT.1.1: 1
    • FCS_TLSC_EXT.1.2: 1
    • FCS_TLSC_EXT.1.3: 1
    • FCS_TLSC_EXT.1.4: 1
    • FCS_TLSC_EXT.2: 7
    • FCS_TLSC_EXT.2.1: 1
    • FCS_TLSC_EXT.2.3: 2
    • FCS_TLSS_EXT.1: 7
    • FCS_TLSS_EXT.1.1: 1
    • FCS_TLSS_EXT.1.2: 1
    • FCS_TLSS_EXT.1.3: 1
    • FCS_TLSS_EXT.1.4: 1
  • FIA:
    • FIA_AFL.1: 10
    • FIA_AFL.1.1: 1
    • FIA_AFL.1.2: 1
    • FIA_PMG_EXT.1: 7
    • FIA_PMG_EXT.1.1: 1
    • FIA_UAU.7: 5
    • FIA_UAU.7.1: 1
    • FIA_UAU_EXT.2: 6
    • FIA_UAU_EXT.2.1: 1
    • FIA_UIA_EXT.1: 6
    • FIA_UIA_EXT.1.1: 1
    • FIA_UIA_EXT.1.2: 1
  • FMT:
    • FMT_MOF: 11
    • FMT_MOF.1: 2
    • FMT_MTD: 11
    • FMT_MTD.1: 2
    • FMT_SMF.1: 6
    • FMT_SMF.1.1: 1
    • FMT_SMR.2: 5
    • FMT_SMR.2.1: 1
    • FMT_SMR.2.2: 1
    • FMT_SMR.2.3: 1
  • FPT:
    • FPT_APW_EXT.1: 6
    • FPT_APW_EXT.1.1: 1
    • FPT_APW_EXT.1.2: 1
    • FPT_SKP_EXT.1: 7
    • FPT_SKP_EXT.1.1: 1
    • FPT_STM_EXT: 1
    • FPT_STM_EXT.1: 5
    • FPT_STM_EXT.1.1: 1
    • FPT_STM_EXT.1.2: 1
    • FPT_TST_EXT.1: 6
    • FPT_TST_EXT.1.1: 1
    • FPT_TUD_EXT.1: 6
    • FPT_TUD_EXT.1.1: 1
    • FPT_TUD_EXT.1.2: 1
    • FPT_TUD_EXT.1.3: 1
  • FTA:
    • FTA_SSL.3: 5
    • FTA_SSL.3.1: 1
    • FTA_SSL.4: 5
    • FTA_SSL.4.1: 1
    • FTA_SSL_EXT.1: 6
    • FTA_SSL_EXT.1.1: 1
    • FTA_TAB.1: 6
    • FTA_TAB.1.1: 1
  • FTP:
    • FTP_ITC.1: 7
    • FTP_ITC.1.1: 1
    • FTP_ITC.1.2: 1
    • FTP_ITC.1.3: 1
    • FTP_TRP: 5
    • FTP_TRP.1: 3
pdf_data/st_keywords/cc_claims
  • A:
    • A.COMPONENTS_RUNNING: 1
    • A.VS_ISOLATION: 1
    • A.VS_REGULAR_UPDATES: 1
    • A.VS_TRUSTED_ADMINISTRATOR: 1
  • OE:
    • OE.COMPONENTS_RUNNING: 1
    • OE.VM_CONFIGURATION: 1
pdf_data/st_keywords/vendor
  • STMicroelectronics:
    • STM: 4
pdf_data/st_keywords/symmetric_crypto
  • AES_competition:
    • AES:
      • AES: 17
      • AES-256: 1
  • constructions:
    • MAC:
      • HMAC: 1
      • HMAC-SHA-256: 4
      • HMAC-SHA-384: 2
  • AES_competition:
    • AES:
      • AES: 13
  • DES:
    • 3DES:
      • TDEA: 1
      • TDES: 8
  • constructions:
    • MAC:
      • CMAC: 2
      • HMAC: 7
  • miscellaneous:
    • SEED:
      • SEED: 1
pdf_data/st_keywords/asymmetric_crypto
  • ECC:
    • ECC:
      • ECC: 7
    • ECDH:
      • ECDH: 1
      • ECDHE: 2
    • ECDSA:
      • ECDSA: 12
  • FF:
    • DH:
      • DH: 1
      • DHE: 2
      • Diffie-Hellman: 2
    • DSA:
      • DSA: 3
  • ECC:
    • ECC:
      • ECC: 1
    • ECDH:
      • ECDH: 5
    • ECDSA:
      • ECDSA: 8
    • ECIES:
      • ECIES: 1
  • FF:
    • DH:
      • DH: 4
      • Diffie-Hellman: 2
    • DSA:
      • DSA: 12
  • RSA:
    • RSA 2048: 1
pdf_data/st_keywords/hash_function
  • SHA:
    • SHA1:
      • SHA-1: 3
    • SHA2:
      • SHA-256: 9
      • SHA-384: 4
      • SHA-512: 4
  • RIPEMD:
    • RIPEMD-160: 1
  • SHA:
    • SHA1:
      • SHA-1: 7
    • SHA2:
      • SHA-224: 5
      • SHA-256: 14
      • SHA-384: 4
      • SHA-512: 4
pdf_data/st_keywords/crypto_scheme
  • KA:
    • Key Agreement: 1
  • MAC:
    • MAC: 7
  • KA:
    • Key Agreement: 2
    • Key agreement: 1
  • KEX:
    • Key Exchange: 1
  • MAC:
    • MAC: 10
pdf_data/st_keywords/crypto_protocol
  • IPsec:
    • IPsec: 2
  • SSH:
    • SSH: 59
  • TLS:
    • DTLS:
      • DTLS: 2
    • SSL:
      • SSL: 2
      • SSL 2.0: 1
      • SSL 3.0: 1
    • TLS:
      • TLS: 89
      • TLS 1.0: 1
      • TLS 1.1: 4
      • TLS 1.2: 3
      • TLSv1.1: 1
  • TLS:
    • SSL:
      • SSL: 1
pdf_data/st_keywords/randomness
  • PRNG:
    • DRBG: 12
  • RNG:
    • RBG: 2
    • RNG: 4
  • PRNG:
    • DRBG: 2
  • RNG:
    • RNG: 19
  • TRNG:
    • TRNG: 5
pdf_data/st_keywords/cipher_mode
  • CBC:
    • CBC: 6
  • GCM:
    • GCM: 8
  • CBC:
    • CBC: 6
  • ECB:
    • ECB: 4
pdf_data/st_keywords/ecc_curve
  • NIST:
    • P-256: 24
    • P-384: 24
    • P-521: 24
    • secp256r1: 3
    • secp384r1: 3
    • secp521r1: 3
  • NIST:
    • P-192: 8
    • P-224: 8
    • P-256: 8
    • P-384: 8
    • P-521: 8
pdf_data/st_keywords/tls_cipher_suite
  • TLS:
    • TLS_DHE_RSA_WITH_AES_128_CBC_SHA: 3
    • TLS_DHE_RSA_WITH_AES_128_CBC_SHA256: 3
    • TLS_DHE_RSA_WITH_AES_256_CBC_SHA: 3
    • TLS_DHE_RSA_WITH_AES_256_CBC_SHA256: 3
    • TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA: 3
    • TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA256: 3
    • TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256: 3
    • TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA: 3
    • TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA384: 3
    • TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384: 3
    • TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256: 3
    • TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256: 3
    • TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384: 3
    • TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384: 3
pdf_data/st_keywords/crypto_library
  • OpenSSL:
    • OpenSSL: 1
pdf_data/st_keywords/side_channel_analysis
  • FI:
    • Malfunction: 3
    • malfunction: 2
  • SCA:
    • side-channel: 1
pdf_data/st_keywords/standard_id
  • FIPS:
    • FIPS 140-3: 1
    • FIPS PUB 186-4: 10
  • ISO:
    • ISO/IEC 14888-3: 1
    • ISO/IEC 18031:2011: 4
    • ISO/IEC 9796-2: 2
  • NIST:
    • NIST SP 800-56A: 1
    • SP 800-90A: 5
  • PKCS:
    • PKCS #1: 2
  • RFC:
    • RFC 2818: 4
    • RFC 2986: 2
    • RFC 3268: 6
    • RFC 3526: 11
    • RFC 4252: 1
    • RFC 4253: 2
    • RFC 4346: 2
    • RFC 4492: 6
    • RFC 5077: 5
    • RFC 5246: 8
    • RFC 5280: 5
    • RFC 5289: 24
    • RFC 6125: 2
    • RFC 6960: 2
  • X509:
    • X.509: 18
  • BSI:
    • AIS 31: 1
  • FIPS:
    • FIPS 140-2: 3
    • FIPS 180-4: 1
    • FIPS 186-4: 1
    • FIPS 197: 4
  • ISO:
    • ISO/IEC 18031:2011: 1
  • PKCS:
    • PKCS 11: 1
    • PKCS#11: 158
    • PKCS1: 14
    • PKCS11: 1
    • PKCS12: 1
  • RFC:
    • RFC 3394: 1
    • RFC 3447: 12
    • RFC 5649: 1
    • RFC 8017: 1
  • X509:
    • X.509: 6
pdf_data/st_keywords/certification_process
  • OutOfScope:
    • extent specified by the security functional requirements: TLS, HTTPS, SSH. The features below are out of scope. Table 2: Excluded Functionality Feature Description Email security system (antivirus, antispam: 3
    • out of scope: 3
pdf_data/st_metadata
  • /Author: Leidos
  • /CreationDate: D:20240726143512-04'00'
  • /Creator: Microsoft® Word 2019
  • /ModDate: D:20240726143512-04'00'
  • /Producer: Microsoft® Word 2019
  • /Subject: Third Party Protected Information
  • /Title: Fortinet FortiMail ST
  • pdf_file_size_bytes: 717669
  • pdf_hyperlinks: https://support.fortinet.com/
  • pdf_is_encrypted: False
  • pdf_number_of_pages: 50
  • /Author: Visegrady, Tamas <tvi (at) zurich.ibm.com>
  • /CreationDate: D:20190320220000+01'00'
  • /Creator: IBM Research --- Zurich and IBM Boeblingen/Poughkeepsie
  • /Keywords: IBM 4768 (hw. 00LV498PLH (3)); PCIeCC; XCP, Enterprise PKCS11 (EP11)
  • /ModDate: D:20190320220000+01'00'
  • /PTEX.Fullbanner: This is pdfTeX, Version 3.14159265-2.6-1.40.19 (TeX Live 2018/TeX Live for SUSE Linux) kpathsea version 6.3.0
  • /Producer: pdfTeX
  • /Subject: Security Policy [rev. 288]
  • /Title: IBM Enterprise PKCS11(on 4768) Security Target (EAL 4 )
  • /Trapped: /False
  • pdf_file_size_bytes: 841608
  • pdf_hyperlinks: {}
  • pdf_is_encrypted: False
  • pdf_number_of_pages: 53
state/cert/convert_garbage True False
state/cert/pdf_hash Different Different
state/cert/txt_hash Different Different
state/report/pdf_hash Different Different
state/report/txt_hash Different Different
state/st/pdf_hash Different Different
state/st/txt_hash Different Different