Comparing certificates Experimental feature

You are comparing two certificates. By default, only differing attributes are shown. Use the button below to show/hide all attributes.

Showing only differing attributes.
Voice Stream Interceptor (VSI)
SERTIT-072
Citrix MetaFrame Presentation Server 4.0
CRP219
name Voice Stream Interceptor (VSI) Citrix MetaFrame Presentation Server 4.0
category Other Devices and Systems Access Control Devices and Systems
scheme NO UK
not_valid_after 21.06.2022 05.03.2013
not_valid_before 21.06.2017 01.08.2005
report_link https://www.commoncriteriaportal.org/nfs/ccpfiles/files/epfiles/CR%20SERTIT-072_1.PDF https://www.commoncriteriaportal.org/nfs/ccpfiles/files/epfiles/CRP219.pdf
st_link https://www.commoncriteriaportal.org/nfs/ccpfiles/files/epfiles/SV000073-Voice-Stream-Interceptor-Security-Target-Lite.pdf https://www.commoncriteriaportal.org/nfs/ccpfiles/files/epfiles/LFS_T488_Citrix_ST_V10.pdf
manufacturer Saab Danmark AS Citrix Systems, Inc.
manufacturer_web https://saabgroup.com https://www.citrix.com
security_level EAL5+, ALC_FLR.3 EAL2
dgst 28228ddc7cba794e 7da57a5dc5ab73a9
heuristics/cert_id SERTIT-072 CRP219
heuristics/extracted_sars ATE_COV.2, ADV_TDS.4, ALC_FLR.3, AVA_VAN.4, ALC_TAT.2 AGD_ADM.1, ATE_FUN.1, AVA_VLA.1, ALC_FLR.2, ADV_FSP.1, ATE_COV.1, AVA_SOF.1, ADV_RCR.1, ADV_SPM.1, ADV_HLD.1, AGD_USR.1, ATE_IND.2
heuristics/extracted_versions - 4.0
heuristics/scheme_data
  • category: Other Devices and Systems
  • certification_date: 21.06.2017
  • developer: SAAB Danmark A/S
  • enhanced:
    • category: Other Devices and Systems
    • cert_id: SERTIT-072
    • certification_date: 21.06.2017
    • description: Saab Voice Stream Interceptor (VSI) is a software security product providing secure domain separation between voice with different classification level. VSI has very few requirements to the underlying platform and can be installed on a Common Criteria approved Linux Operating System with IPsec tunnel and Trusted Platform Module (TPM). VSI supports standardized Voice over IP (VoIP) communication and is used for VoIP clients. The VoIP client user application is completely separated from VSI and does not require being trusted for the secure separation of classified voice. The separation between the VoIP client user application and VSI gives the possibility to change or upgrade the user application and still maintain a secure domain separation of classified voice by an unchanged VSI. From an users point of view the VoIP client containing VSI can both be used for classified (RED) and lower classified or non-classified (BLACK) voice communication. In this way, a conversation can start as non-classified and during the conversation be switched to a classified conversation. Operational modes on radio based communication are supported in this way. It is also possible to listen to both BLACK and RED voice at the same time. VSI also controls the suppression of RED incoming voice stream to the VoIP client, such that while sending BLACK voice the possible pickup and cross talk via the speaker to the microphone is eliminated. During authorized configuration the suppression functionality can either be enabled or disabled depending on the required operational procedure. Saab provides the Secure Tacticall VoIP client, where VSI has been integrated into a user friendly end product and can be used in a secure RED/BLACK system solution.
    • developer: SAAB Danmark A/S
    • documents: frozendict({'cert': [frozendict({'href': 'https://sertit.no/getfile.php/135133-1607953045/SERTIT/Sertifikater/2017/72/C%20SERTIT-072.pdf'})], 'target': [frozendict({'href': 'https://sertit.no/getfile.php/135136-1607953047/SERTIT/Sertifikater/2017/72/SV000073-Voice-Stream-Interceptor-Security-Target-Lite.pdf'}), frozendict({'href': 'https://sertit.no/getfile.php/137492-1633083420/SERTIT/Sertifikater/2017/72/SV000073-Voice-Stream-Interceptor-Security-Target-Lite-2.pdf'})], 'report': [frozendict({'href': 'https://sertit.no/getfile.php/135139-1607953051/SERTIT/Sertifikater/2017/72/CR%20SERTIT-072_1.PDF'})], 'maintenance': [frozendict({'href': 'https://sertit.no/getfile.php/137486-1633083312/SERTIT/Sertifikater/2017/72/SERTIT-072%20MR%20v%201.0.pdf'})]})
    • evaluation_facility: NTT Com Security (Norway) AS
    • level: EAL 5
    • mutual_recognition: CCRA, SOG-IS
    • product: Stock no. SV000071, Version 1
    • sponsor: Norwegian Defence Logistics Organization Naval System
  • product: Voice Stream Interceptor
  • url: https://sertit.no/certified-products/product-archive/voice-stream-interceptor
maintenance_updates
pdf_data/report_filename CR SERTIT-072_1.PDF CRP219.pdf
pdf_data/report_keywords/cc_cert_id
  • NO:
    • SERTIT-072: 6
  • UK:
    • CERTIFICATION REPORT No. P219: 1
pdf_data/report_keywords/cc_security_level
  • EAL:
    • EAL 2: 1
    • EAL 2 augmented: 1
    • EAL 4: 1
    • EAL 5: 28
    • EAL 5 augmented: 26
    • EAL1: 1
    • EAL5: 1
    • EAL7: 1
  • EAL:
    • EAL2: 4
    • EAL2 augmented: 3
pdf_data/report_keywords/cc_sar
  • ADV:
    • ADV_TDS.4: 1
  • ALC:
    • ALC_FLR: 3
    • ALC_FLR.3: 25
    • ALC_TAT.2: 1
  • ATE:
    • ATE_COV.2: 1
  • AVA:
    • AVA_VAN.4: 2
  • ALC:
    • ALC_FLR.2: 3
pdf_data/report_keywords/cc_sfr
  • FAU:
    • FAU_GEN.1: 1
  • FDP:
    • FDP_IFC.1: 1
  • FMT:
    • FMT_MSA.1: 1
    • FMT_MSA.3: 1
    • FMT_SMR.1: 1
  • FPT:
    • FPT_FLS.1: 1
    • FPT_STM.1: 1
    • FPT_TST.1: 1
  • FTP:
    • FTP_TRP.1: 1
  • FTP:
    • FTP_ITC.1: 1
    • FTP_ITC.2: 1
pdf_data/report_keywords/cc_claims
  • O:
    • O.BLACK_VOICE_STREAM: 1
    • O.STREAM_SETUP: 1
  • OE:
    • OE.PREVENT_ACCESS: 2
    • OE.TRUSTED_RELEASE: 1
pdf_data/report_keywords/vendor
  • Microsoft:
    • Microsoft: 16
pdf_data/report_keywords/hash_function
  • SHA:
    • SHA2:
      • SHA256: 2
pdf_data/report_keywords/crypto_protocol
  • VPN:
    • VPN: 6
  • IPsec:
    • IPsec: 3
  • TLS:
    • SSL:
      • SSL: 2
    • TLS:
      • TLS: 8
pdf_data/report_keywords/crypto_library
  • OpenSSL:
    • OpenSSL: 1
pdf_data/report_keywords/standard_id
  • CC:
    • CCMB-2012-09-004: 1
  • ISO:
    • ISO/IEC 15408: 8
  • CC:
    • CCIMB-2004-01-001: 1
    • CCIMB-2004-01-002: 1
    • CCIMB-2004-01-003: 1
    • CCIMB-2004-01-004: 1
pdf_data/report_metadata
  • /Author: holthj-NSM-PC0709,44FD1973A6,CZC41336S0,CZC41336S0
  • /CreationDate: D:20170816091149+02'00'
  • /Creator: PixEdit Version 8.0.6.4, SN 357-92834-02, Nasjonal sikkerhetsmyndighet,(6A3791DF44),www.pixedit.com
  • /ModDate: D:20170816091149+02'00'
  • /Producer: Techsoft PixEdit Version 8.0.6.4, SN 357-92834-02, Nasjonal sikkerhetsmyndighet
  • /Subject: 385678 340600 VEDLEGG01
  • pdf_file_size_bytes: 7954615
  • pdf_hyperlinks: {}
  • pdf_is_encrypted: False
  • pdf_number_of_pages: 24
  • /Author: racook
  • /CreationDate: D:20050906112345Z
  • /Creator: LFS T488 CITRIX_V40_CertRep_P219_10 - Microsoft Word
  • /ModDate: D:20131119172038Z
  • /Producer: Acrobat PDFWriter 5.0 for Windows NT
  • /Title: LFS T488 CITRIX_V40_CertRep_P219_10.doc
  • pdf_file_size_bytes: 1021419
  • pdf_hyperlinks: {}
  • pdf_is_encrypted: False
  • pdf_number_of_pages: 20
pdf_data/st_filename SV000073-Voice-Stream-Interceptor-Security-Target-Lite.pdf LFS_T488_Citrix_ST_V10.pdf
pdf_data/st_keywords/cc_cert_id
  • NO:
    • SERTIT-072: 1
pdf_data/st_keywords/cc_security_level
  • EAL:
    • EAL 5: 1
    • EAL5: 1
  • EAL:
    • EAL2: 8
    • EAL2 augmented: 2
    • EAL2+: 1
pdf_data/st_keywords/cc_sar
  • ALC:
    • ALC_FLR.3: 1
  • ACM:
    • ACM_CAP.2: 2
  • ADO:
    • ADO_DEL.1: 2
    • ADO_IGS.1: 2
  • ADV:
    • ADV_FSP.1: 2
    • ADV_HLD.1: 2
    • ADV_RCR.1: 2
    • ADV_SPM.1: 2
  • AGD:
    • AGD_ADM.1: 2
    • AGD_USR.1: 2
  • ALC:
    • ALC_FLR.2: 7
  • ATE:
    • ATE_COV.1: 2
    • ATE_FUN.1: 2
    • ATE_IND.2: 2
  • AVA:
    • AVA_SOF.1: 2
    • AVA_VLA.1: 3
pdf_data/st_keywords/cc_sfr
  • FAU:
    • FAU_GEN.1: 6
    • FAU_GEN.1.1: 1
    • FAU_GEN.1.2: 1
  • FDP:
    • FDP_IFC: 2
    • FDP_IFC.1: 20
    • FDP_IFC.1.1: 3
    • FDP_IFF: 2
    • FDP_IFF.1: 22
    • FDP_IFF.1.1: 3
    • FDP_IFF.1.2: 3
    • FDP_IFF.1.3: 3
    • FDP_IFF.1.4: 3
    • FDP_IFF.1.5: 3
    • FDP_ITC.1: 1
  • FMT:
    • FMT_MSA: 2
    • FMT_MSA.1: 4
    • FMT_MSA.3: 12
    • FMT_MSA.3.1: 1
    • FMT_MSA.3.2: 1
    • FMT_SMR.1: 4
  • FPT:
    • FPT_FLS: 2
    • FPT_FLS.1: 6
    • FPT_FLS.1.1: 1
    • FPT_STM.1: 4
    • FPT_TST: 2
    • FPT_TST.1: 5
    • FPT_TST.1.1: 1
    • FPT_TST.1.2: 1
    • FPT_TST.1.3: 1
  • FTP:
    • FTP_TRP: 2
    • FTP_TRP.1: 6
    • FTP_TRP.1.1: 1
    • FTP_TRP.1.2: 1
    • FTP_TRP.1.3: 1
  • FCS:
    • FCS_CKM.1: 11
    • FCS_CKM.1.1: 1
    • FCS_CKM.2: 9
    • FCS_CKM.2.1: 2
    • FCS_CKM.4: 16
    • FCS_CKM.4.1: 2
    • FCS_COP.1: 21
    • FCS_COP.1.1: 3
  • FDP:
    • FDP_ACC.1: 23
    • FDP_ACF.1: 16
    • FDP_IFC.1: 3
    • FDP_ITT.1: 17
    • FDP_ITT.1.1: 2
    • FDP_RIP.1: 6
    • FDP_RIP.1.1: 1
  • FIA:
    • FIA_AFL.1: 5
    • FIA_AFL.1.1: 1
    • FIA_AFL.1.2: 1
    • FIA_ATD.1: 12
    • FIA_ATD.1.1: 1
    • FIA_UAU: 1
    • FIA_UAU.2: 11
    • FIA_UAU.2.1: 2
    • FIA_UID.1: 1
    • FIA_UID.2: 10
    • FIA_UID.2.1: 2
  • FMT:
    • FMT_MOF.1: 14
    • FMT_MOF.1.1: 2
    • FMT_MSA.1: 11
    • FMT_MSA.1.1: 1
    • FMT_MSA.2: 12
    • FMT_MSA.2.1: 1
    • FMT_MSA.3: 9
    • FMT_MSA.3.1: 1
    • FMT_MSA.3.2: 1
    • FMT_SMF: 1
    • FMT_SMF.1: 16
    • FMT_SMF.1.1: 1
    • FMT_SMR.1: 21
    • FMT_SMR.1.1: 1
    • FMT_SMR.1.2: 1
  • FPT:
    • FPT_AMT.1: 6
    • FPT_AMT.1.1: 1
    • FPT_ITT.1: 15
    • FPT_ITT.1.1: 2
    • FPT_RVM.1: 12
    • FPT_RVM.1.1: 1
    • FPT_SEP.1: 2
    • FPT_SEP.1.1: 1
    • FPT_SEP.1.2: 1
    • FPT_TST.1: 6
    • FPT_TST.1.1: 1
    • FPT_TST.1.2: 1
    • FPT_TST.1.3: 1
  • FTP:
    • FTP_ITC: 1
    • FTP_ITC.1: 1
    • FTP_ITC.2: 9
    • FTP_ITC.2.1: 1
    • FTP_ITC.2.2: 1
    • FTP_ITC.2.3: 1
pdf_data/st_keywords/cc_claims
  • A:
    • A.SECURE_IP: 4
    • A.SECURE_LOCATION: 3
    • A.SECURE_OS: 5
    • A.TRUSTED_VPN: 4
  • O:
    • O.BLACK_VOICE_STREAM: 9
    • O.RED_VOICE_STREAM: 6
    • O.STREAM_SETUP: 6
  • OE:
    • OE.ACOUSTIC_FEEDBACK: 3
    • OE.ENVIRONMENTAL: 4
    • OE.EVALUATED_OS: 7
    • OE.INSTRUCTED_ADMIN: 9
    • OE.INSTRUCTED_USERS: 7
    • OE.LOG_ACCESS: 4
    • OE.PREVENT_ACCESS: 7
    • OE.READ_LOG: 4
    • OE.SECURE_IP: 4
    • OE.SECURE_LOCATION: 6
    • OE.TRUSTED_REGISTRAR: 3
    • OE.TRUSTED_RELEASE: 8
  • OT:
    • OT.LOG: 8
    • OT.ROBUST: 6
    • OT.SANITY_CHECK: 10
    • OT.SELECTOR: 10
    • OT.SEND: 8
    • OT.SUBSTITUTION: 9
    • OT.SUPPRESS: 7
  • SA:
    • SA.VOICE_STREAM_CLASSIFICATION: 4
  • T:
    • T.CORRUPT_FORMAT: 3
    • T.CORRUPT_STREAM: 3
    • T.NETWORK_INTEGRITY: 3
    • T.SETUP: 4
    • T.TERMINAL_INTEGRITY: 4
    • T.WRONG_LABEL: 4
  • A:
    • A.APP_: 1
    • A.APP_CONFIG: 1
    • A.PUBLISHED_: 1
    • A.SMARTCARD: 1
    • A.THIRD_PARTY_: 1
    • A.TRUSTADMIN: 1
    • A.USER_: 1
  • OE:
    • OE.CERTIFICATES: 3
    • OE.CLIENT_: 1
    • OE.CLIENT_PHYSICAL: 1
    • OE.CLIENT_TPSW: 3
    • OE.IPSEC: 8
    • OE.LIMIT_AUT: 1
    • OE.LIMIT_AUTH: 2
    • OE.MALWARE_: 1
    • OE.MALWARE_PROT: 1
    • OE.MALWARE_PROTECT: 2
    • OE.MEMORY: 4
    • OE.OS_CONFIG: 2
    • OE.OS_CONFIG_: 2
    • OE.OS_CONFIG_CLIENT: 2
    • OE.OS_CONFIG_SERVER: 2
    • OE.PASSWORD: 1
    • OE.PASSWORD_: 1
    • OE.PASSWORD_SETUP: 1
    • OE.SECURE_: 1
    • OE.SECURE_EN: 1
    • OE.SECURE_ENCRYPTION: 2
    • OE.SERVER_: 1
    • OE.SERVER_PHYSICAL: 2
    • OE.SERVER_TH: 1
    • OE.SERVER_THIRD_: 1
    • OE.SERVER_THIRD_PARTY_SW: 1
    • OE.SESSION_K: 1
    • OE.SESSION_KEYS: 3
    • OE.TRUSTED_: 1
    • OE.TRUSTED_OPS: 2
  • OSP:
    • OSP.CRYPTO: 4
  • OT:
    • OT.APPS_: 1
    • OT.APPS_AVAIL: 2
    • OT.AUTHENTIC_: 4
    • OT.AUTHENTIC_CLIENT: 1
    • OT.AUTHENTIC_SERVER: 1
    • OT.CONF: 3
    • OT.CONF_: 1
    • OT.CONF_CLIENT: 2
    • OT.CUTPASTE: 1
    • OT.CUT_PASTE: 2
    • OT.DRIVES: 3
    • OT.GATE_ALLO: 1
    • OT.GATE_ALLOW: 2
    • OT.INTEG: 3
    • OT.INTEG_: 1
    • OT.INTEG_CLIENT: 2
    • OT.SECURE_ENC: 1
    • OT.SECURE_ENCRYP: 1
    • OT.SECURE_ENCRYPTION: 2
  • T:
    • T.AUTHENTIC: 4
    • T.AVAIL: 4
    • T.MISDIRECT: 2
    • T.MOD_CONF: 4
    • T.MOD_HW_CLIENT: 1
    • T.MOD_HW_SERVER: 1
pdf_data/st_keywords/vendor
  • Microsoft:
    • Microsoft: 19
pdf_data/st_keywords/symmetric_crypto
  • DES:
    • 3DES:
      • 3DES: 6
      • TripleDES: 4
pdf_data/st_keywords/crypto_scheme
  • KEX:
    • Key Exchange: 3
  • MAC:
    • MAC: 1
pdf_data/st_keywords/crypto_protocol
  • IPsec:
    • IPsec: 2
  • VPN:
    • VPN: 14
  • TLS:
    • SSL:
      • SSL: 6
    • TLS:
      • TLS: 34
pdf_data/st_keywords/standard_id
  • FIPS:
    • FIPS 140: 3
    • FIPS 140-1: 1
    • FIPS 140-2: 3
    • FIPS 186-2: 1
    • FIPS140: 10
    • FIPS140-1: 2
    • FIPS140-2: 2
  • RFC:
    • RFC 2246: 3
    • RFC 2412: 1
    • RFC 2451: 1
pdf_data/st_keywords/certification_process
  • OutOfScope:
    • The TOE comprises the sample deployment as described below. All other configurations are out of scope of the evaluation. The deployment uses the Secure Gateway to provide TLS encryption between a TLS-: 1
    • out of scope: 2
    • the TOE. Note: The Windows operating system provides the function that authenticates users. This is out of scope of the TOE, so there are no mechanisms requiring assessment. Version 1.0 Page 35 of 56 July 2005: 1
pdf_data/st_metadata
  • /Author: Arne Stig Peters
  • /CreationDate: D:20170815121252+02'00'
  • /Creator: Microsoft® Word 2010
  • /ModDate: D:20170815121252+02'00'
  • /Producer: Microsoft® Word 2010
  • pdf_file_size_bytes: 1265855
  • pdf_hyperlinks: {}
  • pdf_is_encrypted: False
  • pdf_number_of_pages: 34
  • /CreationDate: 9:9 7/25/2005
  • /Creator: Windows NT 4.0
  • /Producer: GNU Ghostscript 7.05
  • /Title: Untitled Document
  • pdf_file_size_bytes: 328607
  • pdf_hyperlinks: {}
  • pdf_is_encrypted: False
  • pdf_number_of_pages: 56
state/report/pdf_hash Different Different
state/report/txt_hash Different Different
state/st/pdf_hash Different Different
state/st/txt_hash Different Different