Comparing certificates Experimental feature

You are comparing two certificates. By default, only differing attributes are shown. Use the button below to show/hide all attributes.

Showing only differing attributes.
Voice Stream Interceptor (VSI)
SERTIT-072
Juniper Networks, Inc. Junos 12.1 X46 D20 for SRX Series Platforms
Certificate Number: 2015/90
name Voice Stream Interceptor (VSI) Juniper Networks, Inc. Junos 12.1 X46 D20 for SRX Series Platforms
category Other Devices and Systems Network and Network-Related Devices and Systems
scheme NO AU
not_valid_after 21.06.2022 24.04.2020
not_valid_before 21.06.2017 03.07.2015
report_link https://www.commoncriteriaportal.org/nfs/ccpfiles/files/epfiles/CR%20SERTIT-072_1.PDF https://www.commoncriteriaportal.org/nfs/ccpfiles/files/epfiles/CR_2015_90_Junos12.1%20X46%20D20_SRX.pdf
st_link https://www.commoncriteriaportal.org/nfs/ccpfiles/files/epfiles/SV000073-Voice-Stream-Interceptor-Security-Target-Lite.pdf https://www.commoncriteriaportal.org/nfs/ccpfiles/files/epfiles/ST_Junos12.1%20X46%20D20_SRX.pdf
manufacturer Saab Danmark AS Juniper Networks, Inc.
manufacturer_web https://saabgroup.com https://www.juniper.net/
security_level EAL5+, ALC_FLR.3 {}
dgst 28228ddc7cba794e 31f1985150107367
heuristics/cert_id SERTIT-072 Certificate Number: 2015/90
heuristics/cpe_matches {} cpe:2.3:o:juniper:junos:12.1:-:*:*:*:*:*:*
heuristics/related_cves {} CVE-2023-28979, CVE-2014-6380, CVE-2024-39511, CVE-2024-39556, CVE-2022-22243, CVE-2022-22162, CVE-2024-39514, CVE-2022-22214, CVE-2022-22173, CVE-2014-6379, CVE-2023-44194, CVE-2004-0468, CVE-2023-22391, CVE-2013-4689, CVE-2022-22197, CVE-2014-2713, CVE-2025-21590, CVE-2023-22395, CVE-2023-22406, CVE-2023-28962, CVE-2024-39528, CVE-2022-22244, CVE-2014-3819, CVE-2004-0230, CVE-2013-6014, CVE-2023-44201, CVE-2014-3816, CVE-2013-7313, CVE-2023-36843, CVE-2023-28963, CVE-2023-44182, CVE-2022-22245, CVE-2024-30380, CVE-2024-21594, CVE-2024-30397, CVE-2014-2712, CVE-2022-22215, CVE-2022-22220, CVE-2014-3818, CVE-2021-31362, CVE-2022-22246, CVE-2024-39549, CVE-2023-44175, CVE-2022-22181, CVE-2022-22163, CVE-2022-22224, CVE-2014-2714, CVE-2023-28964, CVE-2019-0036, CVE-2022-22241, CVE-2024-39517, CVE-2023-44197, CVE-2023-4481, CVE-2023-36842, CVE-2022-22208, CVE-2023-22407, CVE-2023-44184, CVE-2022-22242, CVE-2022-22238, CVE-2024-39555, CVE-2023-28975, CVE-2014-2711, CVE-2024-21591, CVE-2023-44185, CVE-2021-31372, CVE-2023-36841, CVE-2023-44178, CVE-2022-22156, CVE-2013-4686, CVE-2023-44186, CVE-2023-44176, CVE-2023-36839, CVE-2023-44177, CVE-2013-6618, CVE-2023-36840, CVE-2024-39558
heuristics/extracted_sars ATE_COV.2, ADV_TDS.4, ALC_FLR.3, AVA_VAN.4, ALC_TAT.2 ATE_IND.1, AVA_VAN.1, AGD_PRE.1, AGD_OPE.1, ALC_CMS.1, ALC_CMC.1, ADV_FSP.1
heuristics/extracted_versions - 12.1
heuristics/scheme_data
  • category: Other Devices and Systems
  • certification_date: 21.06.2017
  • developer: SAAB Danmark A/S
  • enhanced:
    • category: Other Devices and Systems
    • cert_id: SERTIT-072
    • certification_date: 21.06.2017
    • description: Saab Voice Stream Interceptor (VSI) is a software security product providing secure domain separation between voice with different classification level. VSI has very few requirements to the underlying platform and can be installed on a Common Criteria approved Linux Operating System with IPsec tunnel and Trusted Platform Module (TPM). VSI supports standardized Voice over IP (VoIP) communication and is used for VoIP clients. The VoIP client user application is completely separated from VSI and does not require being trusted for the secure separation of classified voice. The separation between the VoIP client user application and VSI gives the possibility to change or upgrade the user application and still maintain a secure domain separation of classified voice by an unchanged VSI. From an users point of view the VoIP client containing VSI can both be used for classified (RED) and lower classified or non-classified (BLACK) voice communication. In this way, a conversation can start as non-classified and during the conversation be switched to a classified conversation. Operational modes on radio based communication are supported in this way. It is also possible to listen to both BLACK and RED voice at the same time. VSI also controls the suppression of RED incoming voice stream to the VoIP client, such that while sending BLACK voice the possible pickup and cross talk via the speaker to the microphone is eliminated. During authorized configuration the suppression functionality can either be enabled or disabled depending on the required operational procedure. Saab provides the Secure Tacticall VoIP client, where VSI has been integrated into a user friendly end product and can be used in a secure RED/BLACK system solution.
    • developer: SAAB Danmark A/S
    • documents: frozendict({'cert': [frozendict({'href': 'https://sertit.no/getfile.php/135133-1607953045/SERTIT/Sertifikater/2017/72/C%20SERTIT-072.pdf'})], 'target': [frozendict({'href': 'https://sertit.no/getfile.php/135136-1607953047/SERTIT/Sertifikater/2017/72/SV000073-Voice-Stream-Interceptor-Security-Target-Lite.pdf'}), frozendict({'href': 'https://sertit.no/getfile.php/137492-1633083420/SERTIT/Sertifikater/2017/72/SV000073-Voice-Stream-Interceptor-Security-Target-Lite-2.pdf'})], 'report': [frozendict({'href': 'https://sertit.no/getfile.php/135139-1607953051/SERTIT/Sertifikater/2017/72/CR%20SERTIT-072_1.PDF'})], 'maintenance': [frozendict({'href': 'https://sertit.no/getfile.php/137486-1633083312/SERTIT/Sertifikater/2017/72/SERTIT-072%20MR%20v%201.0.pdf'})]})
    • evaluation_facility: NTT Com Security (Norway) AS
    • level: EAL 5
    • mutual_recognition: CCRA, SOG-IS
    • product: Stock no. SV000071, Version 1
    • sponsor: Norwegian Defence Logistics Organization Naval System
  • product: Voice Stream Interceptor
  • url: https://sertit.no/certified-products/product-archive/voice-stream-interceptor
heuristics/protection_profiles {} d7508f508083d040, ac9abe3d5c5a31f0
maintenance_updates
protection_profile_links {} https://www.commoncriteriaportal.org/nfs/ccpfiles/files/ppfiles/PP_ND_TFFWEP_V1.0.pdf, https://www.commoncriteriaportal.org/nfs/ccpfiles/files/ppfiles/pp_nd_v1.1.pdf
pdf_data/report_filename CR SERTIT-072_1.PDF CR_2015_90_Junos12.1 X46 D20_SRX.pdf
pdf_data/report_keywords/cc_cert_id
  • NO:
    • SERTIT-072: 6
  • AU:
    • Certification Report 2015/90: 1
  • FR:
    • Certification Report 2015/90: 1
pdf_data/report_keywords/cc_security_level
  • EAL:
    • EAL 2: 1
    • EAL 2 augmented: 1
    • EAL 4: 1
    • EAL 5: 28
    • EAL 5 augmented: 26
    • EAL1: 1
    • EAL5: 1
    • EAL7: 1
pdf_data/report_keywords/cc_sar
  • ADV:
    • ADV_TDS.4: 1
  • ALC:
    • ALC_FLR: 3
    • ALC_FLR.3: 25
    • ALC_TAT.2: 1
  • ATE:
    • ATE_COV.2: 1
  • AVA:
    • AVA_VAN.4: 2
pdf_data/report_keywords/cc_sfr
  • FAU:
    • FAU_GEN.1: 1
  • FDP:
    • FDP_IFC.1: 1
  • FMT:
    • FMT_MSA.1: 1
    • FMT_MSA.3: 1
    • FMT_SMR.1: 1
  • FPT:
    • FPT_FLS.1: 1
    • FPT_STM.1: 1
    • FPT_TST.1: 1
  • FTP:
    • FTP_TRP.1: 1
pdf_data/report_keywords/cc_claims
  • O:
    • O.BLACK_VOICE_STREAM: 1
    • O.STREAM_SETUP: 1
  • OE:
    • OE.PREVENT_ACCESS: 2
    • OE.TRUSTED_RELEASE: 1
pdf_data/report_keywords/hash_function
  • SHA:
    • SHA2:
      • SHA256: 2
  • MD:
    • MD5:
      • MD5: 1
pdf_data/report_keywords/crypto_protocol
  • VPN:
    • VPN: 6
  • IPsec:
    • IPsec: 1
  • TLS:
    • SSL:
      • SSL: 1
pdf_data/report_keywords/randomness
  • PRNG:
    • DRBG: 1
pdf_data/report_keywords/standard_id
  • CC:
    • CCMB-2012-09-004: 1
  • ISO:
    • ISO/IEC 15408: 8
pdf_data/report_metadata
  • /Author: holthj-NSM-PC0709,44FD1973A6,CZC41336S0,CZC41336S0
  • /CreationDate: D:20170816091149+02'00'
  • /Creator: PixEdit Version 8.0.6.4, SN 357-92834-02, Nasjonal sikkerhetsmyndighet,(6A3791DF44),www.pixedit.com
  • /ModDate: D:20170816091149+02'00'
  • /Producer: Techsoft PixEdit Version 8.0.6.4, SN 357-92834-02, Nasjonal sikkerhetsmyndighet
  • /Subject: 385678 340600 VEDLEGG01
  • pdf_file_size_bytes: 7954615
  • pdf_hyperlinks: {}
  • pdf_is_encrypted: False
  • pdf_number_of_pages: 24
  • /Author: ACA
  • /Company: Department of Defence
  • /CreationDate: D:20150709132128+10'00'
  • /Creator: Acrobat PDFMaker 9.0 for Word
  • /ModDate: D:20150709132132+10'00'
  • /Objective-Classification: [Inherited - Restricted]
  • /Objective-CreationStamp: D:20150703
  • /Objective-Id: R22670710
  • /Objective-IsApproved: 0
  • /Objective-IsPublished: 0
  • /Objective-ModificationStamp: D:20150709
  • /Objective-Owner: Caulfield, Terence (MR)(ASD)
  • /Objective-Parent: Certification
  • /Objective-Path: Objective Global Folder - PROD:Defence Business Units:Intelligence and Security Group:Defence Signals Directorate:DSD : Defence Signals Directorate (DSD):CISD:ASCS:CSPD:Evals:Australasn Certn Auth:Certification:Operations:AISEP Certification Records:EFS-T
  • /Objective-State: Being Edited
  • /Objective-Title: Junos 12.1 X46 D20.6 for SRX Series Platforms Certification Report Final
  • /Objective-Version: 0.6
  • /Objective-VersionNumber: 6
  • /Producer: Acrobat Distiller 9.0.0 (Windows)
  • /SourceModified: D:20150709032102
  • /Title:
  • pdf_file_size_bytes: 76775
  • pdf_hyperlinks: {}
  • pdf_is_encrypted: False
  • pdf_number_of_pages: 19
pdf_data/st_filename SV000073-Voice-Stream-Interceptor-Security-Target-Lite.pdf ST_Junos12.1 X46 D20_SRX.pdf
pdf_data/st_keywords/cc_cert_id
  • NO:
    • SERTIT-072: 1
pdf_data/st_keywords/cc_security_level
  • EAL:
    • EAL 5: 1
    • EAL5: 1
pdf_data/st_keywords/cc_sar
  • ALC:
    • ALC_FLR.3: 1
  • ADV:
    • ADV_FSP.1: 2
  • AGD:
    • AGD_OPE.1: 2
    • AGD_PRE.1: 2
  • ALC:
    • ALC_CMC.1: 2
    • ALC_CMS.1: 2
  • ATE:
    • ATE_IND.1: 2
  • AVA:
    • AVA_VAN.1: 2
pdf_data/st_keywords/cc_sfr
  • FAU:
    • FAU_GEN.1: 6
    • FAU_GEN.1.1: 1
    • FAU_GEN.1.2: 1
  • FDP:
    • FDP_IFC: 2
    • FDP_IFC.1: 20
    • FDP_IFC.1.1: 3
    • FDP_IFF: 2
    • FDP_IFF.1: 22
    • FDP_IFF.1.1: 3
    • FDP_IFF.1.2: 3
    • FDP_IFF.1.3: 3
    • FDP_IFF.1.4: 3
    • FDP_IFF.1.5: 3
    • FDP_ITC.1: 1
  • FMT:
    • FMT_MSA: 2
    • FMT_MSA.1: 4
    • FMT_MSA.3: 12
    • FMT_MSA.3.1: 1
    • FMT_MSA.3.2: 1
    • FMT_SMR.1: 4
  • FPT:
    • FPT_FLS: 2
    • FPT_FLS.1: 6
    • FPT_FLS.1.1: 1
    • FPT_STM.1: 4
    • FPT_TST: 2
    • FPT_TST.1: 5
    • FPT_TST.1.1: 1
    • FPT_TST.1.2: 1
    • FPT_TST.1.3: 1
  • FTP:
    • FTP_TRP: 2
    • FTP_TRP.1: 6
    • FTP_TRP.1.1: 1
    • FTP_TRP.1.2: 1
    • FTP_TRP.1.3: 1
  • FAU:
    • FAU_GEN.1: 6
    • FAU_GEN.1.1: 1
    • FAU_GEN.1.2: 1
    • FAU_GEN.2: 4
    • FAU_GEN.2.1: 1
    • FAU_STG_EXT.1: 5
    • FAU_STG_EXT.1.1: 1
  • FCS:
    • FCS_CKM.1: 9
    • FCS_CKM.1.1: 2
    • FCS_CKM_EXT.4: 5
    • FCS_CKM_EXT.4.1: 1
    • FCS_COP.1: 28
    • FCS_COP.1.1: 5
    • FCS_RBG_EXT.1: 4
    • FCS_SSH_EXT: 1
    • FCS_SSH_EXT.1: 5
    • FCS_SSH_EXT.1.2: 1
    • FCS_SSH_EXT.1.3: 1
    • FCS_SSH_EXT.1.4: 1
    • FCS_SSH_EXT.1.5: 1
    • FCS_SSH_EXT.1.6: 1
    • FCS_SSH_EXT.1.7: 1
  • FDP:
    • FDP_RIP.2: 5
    • FDP_RIP.2.1: 1
  • FIA:
    • FIA_PMG_EXT.1: 5
    • FIA_PMG_EXT.1.1: 1
    • FIA_PSK_EXT.1: 5
    • FIA_PSK_EXT.1.1: 1
    • FIA_PSK_EXT.1.2: 1
    • FIA_PSK_EXT.1.3: 1
    • FIA_UAU.7: 5
    • FIA_UAU.7.1: 1
    • FIA_UAU_EXT.2: 5
    • FIA_UAU_EXT.2.1: 1
    • FIA_UIA_EXT.1: 6
    • FIA_UIA_EXT.1.1: 1
    • FIA_UIA_EXT.1.2: 1
  • FMT:
    • FMT_MTD: 1
    • FMT_MTD.1: 4
    • FMT_MTD.1.1: 1
    • FMT_SMF.1: 5
    • FMT_SMF.1.1: 1
    • FMT_SMR.2: 4
    • FMT_SMR.2.1: 1
    • FMT_SMR.2.2: 1
    • FMT_SMR.2.3: 1
  • FPT:
    • FPT_APW_EXT.1: 4
    • FPT_APW_EXT.1.1: 1
    • FPT_APW_EXT.1.2: 1
    • FPT_SKP_EXT: 1
    • FPT_SKP_EXT.1: 4
    • FPT_SKP_EXT.1.1: 1
    • FPT_STM.1: 5
    • FPT_STM.1.1: 1
    • FPT_TST_EXT: 1
    • FPT_TST_EXT.1: 4
    • FPT_TST_EXT.1.1: 1
    • FPT_TUD_EXT.1: 5
    • FPT_TUD_EXT.1.1: 1
    • FPT_TUD_EXT.1.2: 1
    • FPT_TUD_EXT.1.3: 1
  • FTA:
    • FTA_SSL.3: 3
    • FTA_SSL.3.1: 1
    • FTA_SSL.4: 4
    • FTA_SSL_EXT.1: 6
    • FTA_SSL_EXT.1.1: 1
    • FTA_SSL_EXT.4.1: 1
    • FTA_TAB.1: 4
    • FTA_TAB.1.1: 1
  • FTP:
    • FTP_ITC: 1
    • FTP_ITC.1: 4
    • FTP_ITC.1.1: 1
    • FTP_ITC.1.2: 1
    • FTP_ITC.1.3: 1
    • FTP_TRP: 1
    • FTP_TRP.1: 3
    • FTP_TRP.1.1: 1
    • FTP_TRP.1.2: 1
    • FTP_TRP.1.3: 1
pdf_data/st_keywords/cc_claims
  • A:
    • A.SECURE_IP: 4
    • A.SECURE_LOCATION: 3
    • A.SECURE_OS: 5
    • A.TRUSTED_VPN: 4
  • O:
    • O.BLACK_VOICE_STREAM: 9
    • O.RED_VOICE_STREAM: 6
    • O.STREAM_SETUP: 6
  • OE:
    • OE.ACOUSTIC_FEEDBACK: 3
    • OE.ENVIRONMENTAL: 4
    • OE.EVALUATED_OS: 7
    • OE.INSTRUCTED_ADMIN: 9
    • OE.INSTRUCTED_USERS: 7
    • OE.LOG_ACCESS: 4
    • OE.PREVENT_ACCESS: 7
    • OE.READ_LOG: 4
    • OE.SECURE_IP: 4
    • OE.SECURE_LOCATION: 6
    • OE.TRUSTED_REGISTRAR: 3
    • OE.TRUSTED_RELEASE: 8
  • OT:
    • OT.LOG: 8
    • OT.ROBUST: 6
    • OT.SANITY_CHECK: 10
    • OT.SELECTOR: 10
    • OT.SEND: 8
    • OT.SUBSTITUTION: 9
    • OT.SUPPRESS: 7
  • SA:
    • SA.VOICE_STREAM_CLASSIFICATION: 4
  • T:
    • T.CORRUPT_FORMAT: 3
    • T.CORRUPT_STREAM: 3
    • T.NETWORK_INTEGRITY: 3
    • T.SETUP: 4
    • T.TERMINAL_INTEGRITY: 4
    • T.WRONG_LABEL: 4
  • A:
    • A.CONNECTIONS: 1
    • A.NO_GENERAL_PURPOSE: 1
    • A.PHYSICAL: 1
    • A.TRUSTED_ADMIN: 1
  • O:
    • O.ADDRESS_FILTERING: 2
    • O.DISPLAY_BANNER: 2
    • O.PORT_FILTERING: 2
    • O.PROTECTED_COMMUNICATIONS: 2
    • O.RELATED_CONNECTION_FILTERING: 2
    • O.RESIDUAL_INFORMATION_CLEARING: 2
    • O.SESSION_LOCK: 2
    • O.STATEFUL_INSPECTION: 2
    • O.SYSTEM_MONITORING: 2
    • O.TOE_ADMINISTRATION: 3
    • O.TSF_SELF_TEST: 2
    • O.VERIFIABLE_UPDATES: 2
  • OE:
    • OE.CONNECTIONS: 1
    • OE.NO_GENERAL_PURPOSE: 1
    • OE.PHYSICAL: 1
    • OE.TRUSTED_ADMIN: 1
  • T:
    • T.ADMIN_ERROR: 1
    • T.NETWORK_DISCLOSURE: 1
    • T.NETWORK_DOS: 1
    • T.NETWORK_MISUSE: 1
    • T.TSF_FAILURE: 1
    • T.UNAUTHORIZED_ACCESS: 1
    • T.UNAUTHORIZED_UPDATE: 1
    • T.UNDETECTED_ACTIONS: 1
    • T.USER_DATA_REUSE: 1
pdf_data/st_keywords/symmetric_crypto
  • AES_competition:
    • AES:
      • AES: 4
      • AES-: 2
  • DES:
    • 3DES:
      • TDEA: 1
    • DES:
      • DES: 1
  • constructions:
    • MAC:
      • HMAC: 6
pdf_data/st_keywords/asymmetric_crypto
  • ECC:
    • ECC:
      • ECC: 5
    • ECDSA:
      • ECDSA: 10
  • FF:
    • DH:
      • DH: 6
      • Diffie-Hellman: 2
    • DSA:
      • DSA: 4
pdf_data/st_keywords/hash_function
  • SHA:
    • SHA1:
      • SHA-1: 5
      • SHA1: 4
    • SHA2:
      • SHA-256: 2
      • SHA-384: 2
pdf_data/st_keywords/crypto_scheme
  • KEX:
    • Key Exchange: 2
    • Key exchange: 1
  • MAC:
    • MAC: 2
pdf_data/st_keywords/crypto_protocol
  • IPsec:
    • IPsec: 2
  • VPN:
    • VPN: 14
  • IKE:
    • IKE: 7
    • IKEv1: 12
    • IKEv2: 10
  • IPsec:
    • IPsec: 20
  • SSH:
    • SSH: 55
    • SSHv2: 6
  • TLS:
    • SSL:
      • SSL: 6
  • VPN:
    • VPN: 3
pdf_data/st_keywords/randomness
  • PRNG:
    • DRBG: 1
    • PRNG: 1
  • RNG:
    • RBG: 2
    • RNG: 5
pdf_data/st_keywords/cipher_mode
  • CBC:
    • CBC: 3
  • CCM:
    • CCM: 1
  • GCM:
    • GCM: 3
pdf_data/st_keywords/ecc_curve
  • NIST:
    • P-256: 2
    • P-384: 2
pdf_data/st_keywords/crypto_library
  • OpenSSL:
    • OpenSSL: 9
pdf_data/st_keywords/standard_id
  • FIPS:
    • FIPS PUB 186-2: 1
    • FIPS PUB 186-3: 2
    • FIPS PUB 197: 1
  • NIST:
    • NIST SP 800-38A: 1
    • NIST SP 800-38D: 1
    • SP 800-56A: 2
  • RFC:
    • RFC 2409: 2
    • RFC 2460: 2
    • RFC 3513: 2
    • RFC 3602: 2
    • RFC 4106: 2
    • RFC 4109: 2
    • RFC 4252: 1
    • RFC 4253: 2
    • RFC 4301: 2
    • RFC 4303: 1
    • RFC 4306: 2
    • RFC 4443: 2
    • RFC 4868: 4
    • RFC 4945: 1
    • RFC 5735: 2
    • RFC 6379: 1
    • RFC 768: 2
    • RFC 791: 1
    • RFC 792: 2
    • RFC 793: 2
    • RFC 959: 2
    • RFC4253: 2
pdf_data/st_keywords/certification_process
  • OutOfScope:
    • FTP), Secure Socket Layer (SSL) are out of scope. Document Version 1.11 @©Juniper Networks, Inc: 1
    • out of scope: 1
    • used to exchange information, Telnet, File Transfer Protocol (FTP), Secure Socket Layer (SSL) are out of scope. Document Version 1.11 @©Juniper Networks, Inc. Page 12 of 62 Security Target: 1
pdf_data/st_metadata
  • /Author: Arne Stig Peters
  • /CreationDate: D:20170815121252+02'00'
  • /Creator: Microsoft® Word 2010
  • /ModDate: D:20170815121252+02'00'
  • /Producer: Microsoft® Word 2010
  • pdf_file_size_bytes: 1265855
  • pdf_hyperlinks: {}
  • pdf_is_encrypted: False
  • pdf_number_of_pages: 34
  • /AAPL:Keywords: ['']
  • /Author:
  • /CreationDate: D:20150611045615Z00'00'
  • /Creator: Word
  • /Keywords:
  • /ModDate: D:20150611045615Z00'00'
  • /Producer: Mac OS X 10.9.5 Quartz PDFContext
  • /Subject:
  • /Title:
  • pdf_file_size_bytes: 769549
  • pdf_hyperlinks: {}
  • pdf_is_encrypted: False
  • pdf_number_of_pages: 62
state/report/pdf_hash Different Different
state/report/txt_hash Different Different
state/st/convert_garbage False True
state/st/pdf_hash Different Different
state/st/txt_hash Different Different