Comparing certificates Experimental feature

You are comparing two certificates. By default, only differing attributes are shown. Use the button below to show/hide all attributes.

Showing only differing attributes.
Cisco cEdge Routers running IOS XE 17.12 with SD-WAN 20.12
654-LSS
NAVICS MLS Boundary Protection System Operational Software 01.00
BSI-DSZ-CC-1123-2023
name Cisco cEdge Routers running IOS XE 17.12 with SD-WAN 20.12 NAVICS MLS Boundary Protection System Operational Software 01.00
category Boundary Protection Devices and Systems Network and Network-Related Devices and Systems
scheme CA DE
not_valid_after 18.12.2029 13.03.2028
not_valid_before 18.12.2024 13.03.2023
cert_link https://www.commoncriteriaportal.org/nfs/ccpfiles/files/epfiles/654-LSS%20CT%20v1.0.pdf https://www.commoncriteriaportal.org/nfs/ccpfiles/files/epfiles/1123c_pdf.pdf
report_link https://www.commoncriteriaportal.org/nfs/ccpfiles/files/epfiles/654-LSS%20CR%20v1.0.pdf https://www.commoncriteriaportal.org/nfs/ccpfiles/files/epfiles/1123a_pdf.pdf
st_link https://www.commoncriteriaportal.org/nfs/ccpfiles/files/epfiles/654-LSS%20ST%20v1.2.pdf https://www.commoncriteriaportal.org/nfs/ccpfiles/files/epfiles/1123b_pdf.pdf
manufacturer Cisco Systems, Inc. Rohde&Schwarz SIT GmbH
manufacturer_web https://www.cisco.com https://rohde-schwaz.com
security_level EAL2+, ALC_FLR.2 EAL4+, AVA_VAN.4
dgst beb60ed58a76b232 b2dc6148fc77cdc3
heuristics/cert_id 654-LSS BSI-DSZ-CC-1123-2023
heuristics/cert_lab [] BSI
heuristics/extracted_sars ASE_INT.1, AVA_VAN.2, ADV_FSP.2, ASE_ECD.1, ASE_TSS.1, ASE_SPD.1, ALC_DEL.1, AGD_OPE.1, AGD_PRE.1, ALC_CMS.2, ADV_TDS.1, ATE_FUN.1, ATE_COV.1, ADV_ARC.1, ASE_OBJ.2, ALC_FLR.2, ASE_REQ.2, ALC_CMC.2, ATE_IND.2, ASE_CCL.1 ASE_INT.1, ALC_CMC.4, ASE_ECD.1, ADV_IMP.1, ATE_COV.2, ASE_TSS.1, ALC_TAT.1, ASE_SPD.1, ALC_DEL.1, ALC_LCD.1, AGD_OPE.1, AGD_PRE.1, ALC_CMS.4, ATE_FUN.1, ADV_ARC.1, ASE_OBJ.2, ADV_TDS.3, ATE_DPT.1, ASE_REQ.2, ALC_DVS.1, ADV_FSP.4, ATE_IND.2, AVA_VAN.4, ASE_CCL.1
heuristics/extracted_versions 17.12, 20.12 01.00
heuristics/scheme_data
  • certification_date: 18.12.2024
  • level: EAL 2+ (ALC_FLR.2)
  • product: Cisco cEdge Routers running IOS XE 17.12 with SD-WAN 20.12
  • vendor: Cisco Systems, Inc.
pdf_data/cert_filename 654-LSS CT v1.0.pdf 1123c_pdf.pdf
pdf_data/cert_keywords/cc_cert_id
  • CA:
    • 654-LSS: 1
  • DE:
    • BSI-DSZ-CC-1123-2023: 1
pdf_data/cert_keywords/cc_security_level
  • EAL:
    • EAL 2+: 1
  • EAL:
    • EAL 2: 1
    • EAL 4: 2
    • EAL 4 augmented: 1
pdf_data/cert_keywords/cc_sar
  • ALC:
    • ALC_FLR.2: 1
  • ALC:
    • ALC_FLR: 1
  • AVA:
    • AVA_VAN.4: 1
pdf_data/cert_keywords/vendor
  • Cisco:
    • Cisco: 1
    • Cisco Systems, Inc: 1
pdf_data/cert_keywords/eval_facility
  • Lightship:
    • Lightship Security: 1
pdf_data/cert_keywords/standard_id
  • ISO:
    • ISO/IEC 15408: 2
    • ISO/IEC 18045: 2
pdf_data/cert_metadata
  • /Author: Clark, Cory P.
  • /CreationDate: D:20241219134340-05'00'
  • /Creator: Microsoft® Word for Microsoft 365
  • /MSIP_Label_4dd2c6e0-f1e3-4cf2-bd0b-256ab4cff3af_ActionId: 03c3dcc6-6bfd-4194-a625-fb83b8d0389e
  • /MSIP_Label_4dd2c6e0-f1e3-4cf2-bd0b-256ab4cff3af_ContentBits: 1
  • /MSIP_Label_4dd2c6e0-f1e3-4cf2-bd0b-256ab4cff3af_Enabled: true
  • /MSIP_Label_4dd2c6e0-f1e3-4cf2-bd0b-256ab4cff3af_Method: Privileged
  • /MSIP_Label_4dd2c6e0-f1e3-4cf2-bd0b-256ab4cff3af_Name: UNCLASSIFIED
  • /MSIP_Label_4dd2c6e0-f1e3-4cf2-bd0b-256ab4cff3af_SetDate: 2023-05-16T11:46:20Z
  • /MSIP_Label_4dd2c6e0-f1e3-4cf2-bd0b-256ab4cff3af_SiteId: da9cbe40-ec1e-4997-afb3-17d87574571a
  • /ModDate: D:20241219134340-05'00'
  • /Producer: Microsoft® Word for Microsoft 365
  • pdf_file_size_bytes: 389504
  • pdf_hyperlinks: {}
  • pdf_is_encrypted: False
  • pdf_number_of_pages: 1
  • /Author: Bundesamt für Sicherheit in der Informationstechnik
  • /Keywords: "Common Criteria, Certification, Zertifizierung, bidirectional stateless packet filtering gateway, NAVICS MLS"
  • /Subject: Common Criteria, Certification, Zertifizierung, bidirectional stateless packet filtering gateway, NAVICS MLS
  • /Title: Certificate BSI-DSZ-CC-1123-2023
  • pdf_file_size_bytes: 228950
  • pdf_hyperlinks: {}
  • pdf_is_encrypted: False
  • pdf_number_of_pages: 1
pdf_data/report_filename 654-LSS CR v1.0.pdf 1123a_pdf.pdf
pdf_data/report_frontpage
  • DE:
  • CA:
  • DE:
    • cert_id: BSI-DSZ-CC-1123-2023
    • cert_item: NAVICS MLS Boundary Protection System Operational Software V01.00
    • cert_lab: BSI
    • developer: ROHDE & SCHWARZ SIT GmbH
    • match_rules: ['(BSI-DSZ-CC-.+?) (?:for|For) (.+?) from (.*)']
  • CA:
pdf_data/report_keywords/cc_cert_id
  • DE:
    • BSI-DSZ-CC-1123-2023: 12
pdf_data/report_keywords/cc_security_level
  • EAL:
    • EAL 2+: 1
  • EAL:
    • EAL 1: 1
    • EAL 2: 3
    • EAL 4: 8
    • EAL 4 augmented: 3
pdf_data/report_keywords/cc_sar
  • ALC:
    • ALC_FLR.2: 1
  • ALC:
    • ALC_FLR: 3
  • AVA:
    • AVA_VAN.4: 5
pdf_data/report_keywords/vendor
  • Cisco:
    • Cisco: 11
    • Cisco Systems, Inc: 2
pdf_data/report_keywords/eval_facility
  • Lightship:
    • Lightship Security: 1
  • DFKI:
    • DFKI: 2
pdf_data/report_keywords/symmetric_crypto
  • AES_competition:
    • AES:
      • AES: 4
  • constructions:
    • MAC:
      • CMAC: 11
pdf_data/report_keywords/hash_function
  • SHA:
    • SHA2:
      • SHA-256: 3
pdf_data/report_keywords/crypto_protocol
  • IPsec:
    • IPsec: 2
pdf_data/report_keywords/technical_report_id
  • BSI:
    • BSI 7148: 1
    • BSI TR-02102: 1
pdf_data/report_keywords/standard_id
  • ISO:
    • ISO/IEC 17025: 2
  • BSI:
    • AIS 1: 1
    • AIS 32: 1
  • FIPS:
    • FIPS PUB 197: 2
  • ISO:
    • ISO/IEC 15408: 4
    • ISO/IEC 17065: 2
    • ISO/IEC 18045: 4
  • NIST:
    • NIST SP 800-38B: 2
pdf_data/report_keywords/certification_process
  • ConfidentialDocument:
    • MLS Software V01.00 – ETR Summary, Deutsches Forschungszentrum für Künstliche Intelligenz GmbH (confidential document) [8] Configuration list for the TOE, Version 47.00, 29 November 2022, Configuration List NAVICS MLS: 1
    • Protection, Part Number 5416.2878.92 (confidential document) [9] Guidance documentation for the TOE: • R&S TF5900M Trusted Filter IP User Manual, Version 06: 1
    • being maintained, is not given any longer. In particular, prior to the dissemination of confidential documentation and information related to the TOE or resulting from the evaluation and certification: 1
  • OutOfScope:
    • out of scope: 1
    • the final product is shipped to the operator. This shipment and further installation is out of scope for this certification. 3. Security Policy The Security Policy is expressed by the set of Security: 1
pdf_data/report_metadata
pdf_data/st_filename 654-LSS ST v1.2.pdf 1123b_pdf.pdf
pdf_data/st_keywords/cc_security_level
  • EAL:
    • EAL2: 2
    • EAL2 augmented: 2
  • EAL:
    • EAL 4: 1
    • EAL 4 augmented: 1
    • EAL4: 4
    • EAL4 augmented: 3
pdf_data/st_keywords/cc_sar
  • ADV:
    • ADV_ARC.1: 2
    • ADV_FSP.2: 2
    • ADV_TDS.1: 2
  • AGD:
    • AGD_OPE.1: 2
    • AGD_PRE.1: 2
  • ALC:
    • ALC_CMC.2: 2
    • ALC_CMS.2: 2
    • ALC_DEL.1: 2
    • ALC_FLR.2: 4
  • ASE:
    • ASE_CCL.1: 1
    • ASE_ECD.1: 1
    • ASE_INT.1: 1
    • ASE_OBJ.2: 1
    • ASE_REQ.2: 1
    • ASE_SPD.1: 1
    • ASE_TSS.1: 1
  • ATE:
    • ATE_COV.1: 2
    • ATE_FUN.1: 2
    • ATE_IND.2: 2
  • AVA:
    • AVA_VAN.2: 2
  • ADV:
    • ADV_ARC.1: 1
    • ADV_FSP.4: 1
    • ADV_IMP.1: 1
    • ADV_TDS.3: 1
  • AGD:
    • AGD_OPE.1: 3
    • AGD_PRE.1: 1
  • ALC:
    • ALC_CMC.4: 1
    • ALC_CMS.4: 1
    • ALC_DEL.1: 1
    • ALC_DVS.1: 1
    • ALC_LCD.1: 1
    • ALC_TAT.1: 1
  • ASE:
    • ASE_CCL.1: 1
    • ASE_ECD.1: 1
    • ASE_INT.1: 1
    • ASE_OBJ.2: 1
    • ASE_REQ.2: 1
    • ASE_SPD.1: 1
    • ASE_TSS.1: 1
  • ATE:
    • ATE_COV.2: 1
    • ATE_DPT.1: 1
    • ATE_FUN.1: 1
    • ATE_IND.2: 1
  • AVA:
    • AVA_VAN.3: 2
    • AVA_VAN.4: 6
pdf_data/st_keywords/cc_sfr
  • FAU:
    • FAU_GEN: 4
    • FAU_GEN.1: 11
    • FAU_GEN.1.1: 1
    • FAU_GEN.1.2: 1
    • FAU_GEN.2: 7
    • FAU_GEN.2.1: 1
    • FAU_STG.1: 9
    • FAU_STG.1.1: 1
    • FAU_STG.1.2: 1
    • FAU_STG.4: 5
    • FAU_STG.4.1: 1
  • FCS:
    • FCS_CKM.1: 18
    • FCS_CKM.1.1: 1
    • FCS_CKM.2: 7
    • FCS_CKM.2.1: 1
    • FCS_CKM.4: 13
    • FCS_CKM.4.1: 1
    • FCS_COP.1: 15
    • FCS_RBG_EXT.1: 17
    • FCS_RBG_EXT.1.1: 2
    • FCS_RBG_EXT.1.2: 2
  • FDP:
    • FDP_ACC.1: 1
    • FDP_IFC.1: 12
    • FDP_IFC.1.1: 1
    • FDP_IFF.1: 8
    • FDP_IFF.1.1: 1
    • FDP_IFF.1.2: 1
    • FDP_IFF.1.3: 1
    • FDP_IFF.1.4: 1
    • FDP_IFF.1.5: 1
    • FDP_ITC.1: 4
    • FDP_ITC.2: 4
    • FDP_ITT.1: 12
    • FDP_ITT.1.1: 1
  • FIA:
    • FIA_AFL.1: 9
    • FIA_AFL.1.1: 1
    • FIA_AFL.1.2: 1
    • FIA_PMG_EXT: 3
    • FIA_PMG_EXT.1: 11
    • FIA_PMG_EXT.1.1: 2
    • FIA_UAU.1: 2
    • FIA_UAU.2: 9
    • FIA_UAU.2.1: 1
    • FIA_UAU.7: 6
    • FIA_UAU.7.1: 1
    • FIA_UID.1: 12
    • FIA_UID.1.1: 1
    • FIA_UID.1.2: 1
  • FMT:
    • FMT_MOF.1: 13
    • FMT_MOF.1.1: 2
    • FMT_MSA.1: 8
    • FMT_MSA.1.1: 1
    • FMT_MSA.3: 9
    • FMT_MTD.1: 5
    • FMT_MTD.1.1: 1
    • FMT_SMF.1: 13
    • FMT_SMF.1.1: 1
    • FMT_SMR.1: 2
    • FMT_SMR.2: 12
    • FMT_SMR.2.1: 1
    • FMT_SMR.2.2: 1
    • FMT_SMR.2.3: 1
  • FPT:
    • FPT_APW_EXT: 3
    • FPT_APW_EXT.1: 12
    • FPT_APW_EXT.1.1: 2
    • FPT_APW_EXT.1.2: 2
    • FPT_ITT: 1
    • FPT_ITT.1: 7
    • FPT_STM.1: 9
    • FPT_STM.1.1: 1
    • FPT_TST.1: 7
    • FPT_TST.1.1: 1
    • FPT_TST.1.2: 1
    • FPT_TST.1.3: 1
  • FTA:
    • FTA_SSL.1: 10
    • FTA_SSL.1.1: 2
    • FTA_SSL.1.2: 2
    • FTA_SSL.3: 9
    • FTA_SSL.4: 7
    • FTA_SSL.4.1: 1
    • FTA_TAB.1: 9
  • FTP:
    • FTP_TRP.1: 8
    • FTP_TRP.1.2: 1
    • FTP_TRP.1.3: 1
  • FCS:
    • FCS_CKM.1: 1
    • FCS_CKM.4: 4
    • FCS_COP.1: 9
    • FCS_COP.1.1: 1
  • FDP:
    • FDP_ACC.1: 2
    • FDP_IFC.1: 38
    • FDP_IFC.1.1: 3
    • FDP_IFF.1: 32
    • FDP_IFF.1.1: 3
    • FDP_IFF.1.2: 3
    • FDP_IFF.1.3: 3
    • FDP_IFF.1.4: 3
    • FDP_IFF.1.5: 4
    • FDP_ITC: 1
    • FDP_ITC.1: 11
    • FDP_ITC.1.1: 1
    • FDP_ITC.1.2: 1
    • FDP_ITC.1.3: 1
    • FDP_ITC.2: 3
    • FDP_ITT.1: 1
    • FDP_ITT.2: 8
    • FDP_ITT.2.1: 1
    • FDP_ITT.2.2: 1
    • FDP_ITT.4: 1
  • FMT:
    • FMT_MSA.3: 8
    • FMT_SMF.1: 19
    • FMT_SMF.1.1: 3
  • FPT:
    • FPT_FLS.1: 1
    • FPT_RCV.1: 7
    • FPT_RCV.1.1: 1
    • FPT_TDC.1: 1
pdf_data/st_keywords/cc_claims
  • A:
    • A.ADMIN: 3
    • A.CONNECTIONS: 3
    • A.LOCATE: 3
    • A.PHYSEC: 3
  • O:
    • O.ACCESS: 1
    • O.ACCESS_CONTRO: 1
    • O.ACCESS_CONTROL: 15
    • O.ACCESS_CONTROLL: 3
    • O.ACCES_CONTROL: 1
    • O.ADMIN: 9
    • O.AUDIT: 1
    • O.AUDIT_GEN: 10
    • O.AUDIT_VIEW: 4
    • O.DATA: 11
    • O.IDAUTH: 12
    • O.MEDIATE: 7
    • O.PROTECTED_COM: 1
    • O.PROTECTED_COMMS: 3
    • O.SELFPRO: 12
    • O.SELPRO: 1
    • O.TIME: 7
    • O.TOE_ADMINISTRA: 1
    • O.TOE_ADMINISTRATION: 2
    • O.VPN: 11
  • OE:
    • OE: 1
    • OE.ADMIN: 3
    • OE.CONNECTION: 2
    • OE.LOCATE: 3
    • OE.PHYSEC: 2
  • T:
    • T.ACCOUNTABIL: 1
    • T.ACCOUNTABILITY: 2
    • T.ASPO: 1
    • T.ASPOOF: 2
    • T.MEDI: 1
    • T.MEDIAT: 2
    • T.NETWO: 1
    • T.NETWORK_COMPROMISE: 2
    • T.NOAU: 1
    • T.NOAUTH: 2
    • T.VP: 1
    • T.VPN: 2
  • A:
    • A.H: 1
    • A.HIGHNETWORKSECURITY: 2
    • A.T: 2
    • A.TRUSTEDADMINISTRATORS: 2
    • A.TRUSTEDUSERS: 2
  • OE:
    • OE.HIGHNETWORKSECURITY: 5
    • OE.PROTECTEDTRANSMISSION: 3
    • OE.SECUREPLATFORM: 4
    • OE.SECURERULES: 5
    • OE.TRUSTEDADMINISTRATORS: 3
    • OE.TRUSTEDUSERS: 3
  • OT:
    • OT.S: 1
    • OT.SECURESTATE: 3
    • OT.T: 2
    • OT.TRUSTEDFILTERMANAGEMENT: 5
    • OT.TRUSTEDFILTERVOICE: 4
    • OT.V: 1
    • OT.VOICETERMINAL: 3
  • T:
    • T.D: 1
    • T.DISCLOSURE: 2
    • T.M: 1
    • T.MANIPULATION: 2
pdf_data/st_keywords/vendor
  • Cisco:
    • Cisco: 54
    • Cisco Systems, Inc: 6
pdf_data/st_keywords/eval_facility
  • DFKI:
    • DFKI: 20
pdf_data/st_keywords/symmetric_crypto
  • AES_competition:
    • AES:
      • AES: 14
      • AES-: 1
  • constructions:
    • MAC:
      • HMAC: 5
      • HMAC-SHA-256: 1
  • AES_competition:
    • AES:
      • AES: 6
      • AES-256: 2
  • constructions:
    • MAC:
      • CMAC: 51
pdf_data/st_keywords/hash_function
  • SHA:
    • SHA2:
      • SHA256: 1
pdf_data/st_keywords/crypto_scheme
  • KEX:
    • Key Exchange: 3
  • MAC:
    • MAC: 4
pdf_data/st_keywords/crypto_protocol
  • IKE:
    • IKE: 1
    • IKEv1: 1
    • IKEv2: 1
  • IPsec:
    • IPsec: 13
  • SSH:
    • SSH: 12
    • SSHv2: 9
  • TLS:
    • DTLS:
      • DTLS: 11
      • DTLS v1.2: 1
    • TLS:
      • TLS v1.2: 2
      • TLS v1.3: 2
  • VPN:
    • VPN: 20
pdf_data/st_keywords/randomness
  • PRNG:
    • DRBG: 6
  • RNG:
    • RBG: 3
pdf_data/st_keywords/cipher_mode
  • GCM:
    • GCM: 2
pdf_data/st_keywords/ecc_curve
  • NIST:
    • secp256r1: 7
pdf_data/st_keywords/tls_cipher_suite
  • TLS:
    • TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256: 2
    • TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384: 3
pdf_data/st_keywords/side_channel_analysis
  • SCA:
    • SPA: 5
pdf_data/st_keywords/standard_id
  • CC:
    • CCMB-2017-04-001: 1
    • CCMB-2017-04-002: 1
    • CCMB-2017-04-003: 1
    • CCMB-2017-04-004: 1
  • FIPS:
    • FIPS 198: 1
  • ISO:
    • ISO/IEC 18031:2011: 6
    • ISO/IEC 18033-3: 1
    • ISO/IEC 19772: 2
  • NIST:
    • SP 800-90A: 2
  • RFC:
    • RFC 6347: 2
    • RFC 791: 1
    • RFC 792: 1
    • RFC 793: 1
  • CC:
    • CCMB-2017-04-001: 1
    • CCMB-2017-04-002: 1
    • CCMB-2017-04-003: 1
  • FIPS:
    • FIPS PUB 197: 4
  • NIST:
    • NIST SP 800-38B: 4
pdf_data/st_keywords/certification_process
  • OutOfScope:
    • Defense (UTD) security features such as IPS, Cisco URL Filtering, AMP, and TLS/SSL proxy. This is out of scope for the evaluation. These services will be disabled by configuration settings. Cisco cEdge Routers: 1
    • UTD) security features such as IPS, Cisco URL Filtering, AMP, and TLS/SSL proxy. This is out of scope for the evaluation: 1
    • out of scope: 1
pdf_data/st_metadata
  • /Author: conan
  • /CreationDate: D:20241217081136-05'00'
  • /ModDate: D:20241217081136-05'00'
  • /Producer: Microsoft: Print To PDF
  • /Title: Microsoft Word - Cisco_cEdge_IOS-XE_17.12_SDWAN_20.12_EAL2_ST_v1.2 (1).docx
  • pdf_file_size_bytes: 1976947
  • pdf_hyperlinks: {}
  • pdf_is_encrypted: False
  • pdf_number_of_pages: 80
  • /Author: Jöckel Teresa 11SI-GS1
  • /Title: Security Target NAVICS MLS Boundary Protection System Operational Software
  • pdf_file_size_bytes: 1276404
  • pdf_hyperlinks: {}
  • pdf_is_encrypted: False
  • pdf_number_of_pages: 45
state/cert/convert_garbage True False
state/cert/pdf_hash Different Different
state/cert/txt_hash Different Different
state/report/pdf_hash Different Different
state/report/txt_hash Different Different
state/st/pdf_hash Different Different
state/st/txt_hash Different Different