Comparing certificates Experimental feature

You are comparing two certificates. By default, only differing attributes are shown. Use the button below to show/hide all attributes.

Showing only differing attributes.
FortiManager Appliances running Firmware 5.2.4
383-4-359
PalmSecure SDK Version 24 Premium
BSI-DSZ-CC-0511-2008
name FortiManager Appliances running Firmware 5.2.4 PalmSecure SDK Version 24 Premium
category Network and Network-Related Devices and Systems Biometric Systems and Devices
scheme CA DE
not_valid_after 11.07.2021 01.09.2019
not_valid_before 11.07.2016 30.12.2008
cert_link https://www.commoncriteriaportal.org/nfs/ccpfiles/files/epfiles/383-4-359%20ct%20v1.0e.docx
report_link https://www.commoncriteriaportal.org/nfs/ccpfiles/files/epfiles/383-4-359%20CR%20v1.0.pdf https://www.commoncriteriaportal.org/nfs/ccpfiles/files/epfiles/0511a.pdf
st_link https://www.commoncriteriaportal.org/nfs/ccpfiles/files/epfiles/383-4-359%20ST_NDPP_US_FortiManager_v1_0.pdf https://www.commoncriteriaportal.org/nfs/ccpfiles/files/epfiles/0511b.pdf
manufacturer Fortinet, Inc. Fujitsu Limited
manufacturer_web https://www.fortinet.com/ https://www.fujitsu.com/
security_level {} EAL2
dgst edf97c0da86bc11a ca5a5c3b72c34bc3
heuristics/cert_id 383-4-359 BSI-DSZ-CC-0511-2008
heuristics/cert_lab [] BSI
heuristics/cpe_matches cpe:2.3:a:fortinet:fortimanager:5.2.4:*:*:*:*:*:*:* {}
heuristics/related_cves CVE-2018-13375, CVE-2021-32597, CVE-2019-17654, CVE-2018-1354, CVE-2020-9289, CVE-2019-17657, CVE-2018-1360, CVE-2021-24017, CVE-2018-1351, CVE-2018-1355, CVE-2021-24016, CVE-2021-32589, CVE-2021-36170, CVE-2018-1353 {}
heuristics/extracted_sars ASE_OBJ.2, AGD_OPE.1, AGD_PRE.1, ASE_ECD.1, ATE_IND.1, AVA_VAN.1, ASE_CCL.1, ASE_REQ.2, ALC_CMC.1, ADV_FSP.1, ALC_CMS.1, ASE_INT.1, ASE_TSS.1 ADV_TDS.6, AGD_OPE.1, APE_SPD.1, ASE_ECD.1, ADV_FSP.2, APE_OBJ.2, ALC_TAT.3, APE_CCL.1, ALC_DEL.1, ADV_IMP.2, ALC_CMS.2, ATE_COV.1, ADV_ARC.1, AVA_VAN.2, ASE_SPD.1, ASE_INT.1, ASE_OBJ.2, APE_INT.1, ASE_CCL.1, ASE_REQ.2, APE_ECD.1, APE_REQ.2, ATE_IND.2, ADV_SPM.1, ALC_FLR.3, ASE_TSS.1, ALC_LCD.2, ATE_FUN.1, ALC_DVS.2, AGD_PRE.1, ADV_INT.3, ALC_CMC.2, ATE_DPT.4
heuristics/extracted_versions 5.2.4 24
heuristics/protection_profiles ac9abe3d5c5a31f0 {}
protection_profile_links https://www.commoncriteriaportal.org/nfs/ccpfiles/files/ppfiles/pp_nd_v1.1.pdf {}
pdf_data/cert_filename 383-4-359 ct v1.0e.docx
pdf_data/report_filename 383-4-359 CR v1.0.pdf 0511a.pdf
pdf_data/report_frontpage
  • DE:
  • CA:
  • DE:
    • cert_id: BSI-DSZ-CC-0511-2008
    • cert_item: PalmSecure SDK Version 24 Premium
    • cert_lab: BSI
    • developer: Fujitsu Limited
    • match_rules: ['(BSI-DSZ-CC-.+?) (?:for|For) (.+?) from (.*)']
  • CA:
pdf_data/report_keywords/cc_cert_id
  • CA:
    • 383-4-359: 1
  • DE:
    • BSI-DSZ-CC-0511-2008: 16
pdf_data/report_keywords/cc_security_level
  • EAL:
    • EAL 1: 1
    • EAL 2: 3
    • EAL 4: 1
    • EAL 7: 1
    • EAL1: 6
    • EAL2: 4
    • EAL3: 4
    • EAL4: 4
    • EAL5: 6
    • EAL6: 3
    • EAL7: 4
pdf_data/report_keywords/cc_sar
  • ADV:
    • ADV_ARC: 1
    • ADV_ARC.1: 1
    • ADV_FSP: 1
    • ADV_FSP.1: 1
    • ADV_FSP.2: 1
    • ADV_FSP.3: 1
    • ADV_FSP.4: 1
    • ADV_FSP.5: 1
    • ADV_FSP.6: 1
    • ADV_IMP: 1
    • ADV_IMP.1: 1
    • ADV_IMP.2: 1
    • ADV_INT: 1
    • ADV_INT.1: 1
    • ADV_INT.2: 1
    • ADV_INT.3: 1
    • ADV_SPM: 1
    • ADV_SPM.1: 1
    • ADV_TDS: 1
    • ADV_TDS.1: 1
    • ADV_TDS.2: 1
    • ADV_TDS.3: 1
    • ADV_TDS.4: 1
    • ADV_TDS.5: 1
    • ADV_TDS.6: 1
  • AGD:
    • AGD_OPE: 1
    • AGD_OPE.1: 1
    • AGD_PRE: 1
    • AGD_PRE.1: 1
  • ALC:
    • ALC_CMC: 1
    • ALC_CMC.1: 1
    • ALC_CMC.2: 1
    • ALC_CMC.3: 1
    • ALC_CMC.4: 1
    • ALC_CMC.5: 1
    • ALC_CMS: 1
    • ALC_CMS.1: 1
    • ALC_CMS.2: 1
    • ALC_CMS.3: 1
    • ALC_CMS.4: 1
    • ALC_CMS.5: 1
    • ALC_DEL: 1
    • ALC_DEL.1: 1
    • ALC_DVS: 1
    • ALC_DVS.1: 1
    • ALC_DVS.2: 1
    • ALC_FLR: 1
    • ALC_FLR.1: 1
    • ALC_FLR.2: 1
    • ALC_FLR.3: 1
    • ALC_LCD.1: 1
    • ALC_LCD.2: 1
    • ALC_TAT: 1
    • ALC_TAT.1: 1
    • ALC_TAT.2: 1
    • ALC_TAT.3: 1
  • APE:
    • APE_CCL.1: 1
    • APE_ECD.1: 1
    • APE_INT.1: 1
    • APE_OBJ.1: 1
    • APE_OBJ.2: 1
    • APE_REQ.1: 1
    • APE_REQ.2: 1
    • APE_SPD.1: 1
  • ASE:
    • ASE_CCL: 1
    • ASE_CCL.1: 1
    • ASE_ECD: 1
    • ASE_ECD.1: 1
    • ASE_INT: 1
    • ASE_INT.1: 1
    • ASE_OBJ: 1
    • ASE_OBJ.1: 1
    • ASE_OBJ.2: 1
    • ASE_REQ.1: 1
    • ASE_REQ.2: 1
    • ASE_SPD: 1
    • ASE_SPD.1: 1
    • ASE_TSS: 1
    • ASE_TSS.1: 1
    • ASE_TSS.2: 1
  • ATE:
    • ATE_COV: 1
    • ATE_COV.1: 1
    • ATE_COV.2: 1
    • ATE_COV.3: 1
    • ATE_DPT: 1
    • ATE_DPT.1: 1
    • ATE_DPT.2: 1
    • ATE_DPT.3: 1
    • ATE_DPT.4: 1
    • ATE_FUN: 1
    • ATE_FUN.1: 1
    • ATE_FUN.2: 1
    • ATE_IND: 1
    • ATE_IND.1: 1
    • ATE_IND.2: 1
    • ATE_IND.3: 1
  • AVA:
    • AVA_VAN: 2
    • AVA_VAN.1: 1
    • AVA_VAN.2: 1
    • AVA_VAN.3: 1
    • AVA_VAN.4: 1
    • AVA_VAN.5: 1
pdf_data/report_keywords/cc_claims
  • OE:
    • OE.ADMINISTRATION: 1
    • OE.AUDIT_REACTION: 1
    • OE.AUTHADMIN: 1
    • OE.ENROLMENT: 1
    • OE.ENVIRONMENT: 1
    • OE.FALLBACK: 1
    • OE.PHYSICAL: 1
    • OE.ROLES_AND_ACCESS: 1
pdf_data/report_keywords/vendor
  • Microsoft:
    • Microsoft: 7
pdf_data/report_keywords/eval_facility
  • SRC:
    • SRC Security Research & Consulting: 3
pdf_data/report_keywords/crypto_protocol
  • SSH:
    • SSH: 3
pdf_data/report_keywords/technical_report_id
  • BSI:
    • BSI 7125: 2
    • BSI 7148: 1
    • BSI 7149: 1
pdf_data/report_keywords/standard_id
  • FIPS:
    • FIPS 140-2: 4
  • ISO:
    • ISO/IEC 17025:2005: 1
pdf_data/report_keywords/certification_process
  • ConfidentialDocument:
    • 8] Evaluation Technical Report, Version 1.1, 24.11.2008, SRC Security Research & Consulting GmbH, (confidential document) [9] Security guide (PalmSecureTM Version 24 Premium), Fujitsu, First edition, September 2008 [10: 1
  • OutOfScope:
    • out of scope: 1
    • tests at the ITSEF excepting such tests which are related to functions or parameters which are out of scope of the evaluation (functions regarding enrolment and identification, parameters regarding threshold: 1
pdf_data/report_metadata
  • /Author: White, Debra E.
  • /Company: CSEC
  • /CreationDate: D:20160906142349-04'00'
  • /Creator: Acrobat PDFMaker 11 for Word
  • /ModDate: D:20160906142413-04'00'
  • /Producer: Adobe PDF Library 11.0
  • /SourceModified: D:20160906182312
  • /Title: 383-4-XXX CR v0.1
  • pdf_file_size_bytes: 414359
  • pdf_hyperlinks: mailto:[email protected]
  • pdf_is_encrypted: False
  • pdf_number_of_pages: 16
  • /Author: Bundesamt für Sicherheit in der Informationstechnik
  • /CreationDate: D:20090202084856+01'00'
  • /Creator: Writer
  • /Keywords: "Common Criteria, Certification, Zertifizierung, PalmSecure SDK Version 24 Premium, Fujitsu Limited"
  • /ModDate: D:20090202150925+01'00'
  • /Producer: StarOffice 8
  • /Subject: Common Criteria Certification
  • /Title: Certification Report BSI-DSZ-CC-0511-2008
  • pdf_file_size_bytes: 922937
  • pdf_hyperlinks: http://www.bsi.bund.de/
  • pdf_is_encrypted: False
  • pdf_number_of_pages: 34
pdf_data/st_filename 383-4-359 ST_NDPP_US_FortiManager_v1_0.pdf 0511b.pdf
pdf_data/st_keywords/cc_cert_id
  • DE:
    • BSI-DSZ-CC-0511: 2
pdf_data/st_keywords/cc_protection_profile_id
  • BSI:
    • BSI-PP-0016: 2
pdf_data/st_keywords/cc_security_level
  • EAL:
    • EAL2: 6
pdf_data/st_keywords/cc_sar
  • ADV:
    • ADV_FSP.1: 1
  • AGD:
    • AGD_OPE.1: 1
    • AGD_PRE.1: 1
  • ALC:
    • ALC_CMC.1: 1
    • ALC_CMS.1: 1
  • ASE:
    • ASE_CCL.1: 1
    • ASE_ECD.1: 1
    • ASE_INT.1: 1
    • ASE_OBJ.2: 1
    • ASE_REQ.2: 1
    • ASE_TSS.1: 1
  • ATE:
    • ATE_IND.1: 1
  • AVA:
    • AVA_VAN.1: 1
  • ADV:
    • ADV_ARC.1: 1
    • ADV_FSP.2: 1
    • ADV_SPM.1: 1
    • ADV_TDS: 1
  • AGD:
    • AGD_OPE.1: 1
    • AGD_PRE.1: 1
  • ALC:
    • ALC_CMC.2: 1
    • ALC_CMS.2: 1
    • ALC_DEL.1: 1
  • ASE:
    • ASE_CCL.1: 1
    • ASE_ECD.1: 1
    • ASE_INT.1: 1
    • ASE_OBJ.2: 1
    • ASE_REQ.2: 1
    • ASE_SPD.1: 1
    • ASE_TSS.1: 1
  • ATE:
    • ATE_COV.1: 1
    • ATE_FUN: 1
    • ATE_FUN.1: 1
    • ATE_IND: 1
    • ATE_IND.2: 1
  • AVA:
    • AVA_VAN.2: 1
pdf_data/st_keywords/cc_sfr
  • FAU:
    • FAU_GEN: 7
    • FAU_GEN.1: 5
    • FAU_GEN.1.1: 1
    • FAU_GEN.1.2: 1
    • FAU_GEN.2: 4
    • FAU_GEN.2.1: 1
    • FAU_STG: 2
    • FAU_STG.1: 1
    • FAU_STG_EXT: 2
    • FAU_STG_EXT.1: 8
    • FAU_STG_EXT.1.1: 2
  • FCS:
    • FCS_CKM: 2
    • FCS_CKM.1: 6
    • FCS_CKM.1.1: 3
    • FCS_CKM.4: 1
    • FCS_CKM_EXT: 1
    • FCS_CKM_EXT.4: 9
    • FCS_CKM_EXT.4.1: 2
    • FCS_COP.1: 23
    • FCS_COP.1.1: 4
    • FCS_RBG_EXT.1: 9
    • FCS_RBG_EXT.1.1: 2
    • FCS_RBG_EXT.1.2: 2
    • FCS_TLS_EXT.1: 11
    • FCS_TLS_EXT.1.1: 2
  • FDP:
    • FDP_ITC.1: 1
    • FDP_ITC.2: 1
    • FDP_RIP.2: 4
    • FDP_RIP.2.1: 1
  • FIA:
    • FIA_PMG_EXT: 1
    • FIA_PMG_EXT.1: 8
    • FIA_PMG_EXT.1.1: 2
    • FIA_SOS: 1
    • FIA_UAU: 3
    • FIA_UAU.1: 5
    • FIA_UAU.7: 5
    • FIA_UAU.7.1: 1
    • FIA_UAU_EXT: 1
    • FIA_UAU_EXT.2: 9
    • FIA_UAU_EXT.2.1: 2
    • FIA_UIA_EXT: 1
    • FIA_UIA_EXT.1: 10
    • FIA_UIA_EXT.1.1: 2
    • FIA_UIA_EXT.1.2: 2
    • FIA_UID: 1
    • FIA_UID.1: 2
  • FMT:
    • FMT_MTD.1: 5
    • FMT_MTD.1.1: 1
    • FMT_SMF.1: 5
    • FMT_SMF.1.1: 1
    • FMT_SMR.2: 5
    • FMT_SMR.2.1: 1
    • FMT_SMR.2.2: 1
    • FMT_SMR.2.3: 1
  • FPT:
    • FPT_APW_EXT.1: 8
    • FPT_APW_EXT.1.1: 2
    • FPT_APW_EXT.1.2: 2
    • FPT_PTD: 3
    • FPT_SKP_EXT.1: 8
    • FPT_SKP_EXT.1.1: 2
    • FPT_SSP.1: 1
    • FPT_SSP.2: 1
    • FPT_STM.1: 3
    • FPT_STM.1.1: 1
    • FPT_TST: 1
    • FPT_TST.1: 1
    • FPT_TST_EXT: 2
    • FPT_TST_EXT.1: 7
    • FPT_TST_EXT.1.1: 2
    • FPT_TUD_EXT.1: 6
    • FPT_TUD_EXT.1.1: 2
    • FPT_TUD_EXT.1.2: 2
    • FPT_TUD_EXT.1.3: 2
  • FTA:
    • FTA_SSL: 1
    • FTA_SSL.3: 3
    • FTA_SSL.3.1: 1
    • FTA_SSL.4: 4
    • FTA_SSL.4.1: 1
    • FTA_SSL_EXT.1: 8
    • FTA_SSL_EXT.1.1: 2
    • FTA_TAB.1: 7
    • FTA_TAB.1.1: 1
  • FTP:
    • FTP_ITC.1: 5
    • FTP_ITC.1.1: 1
    • FTP_ITC.1.2: 1
    • FTP_ITC.1.3: 1
    • FTP_TRP.1: 4
    • FTP_TRP.1.1: 1
    • FTP_TRP.1.2: 1
    • FTP_TRP.1.3: 1
  • FDP:
    • FDP_ACC.1: 1
    • FDP_ACF.1: 1
    • FDP_RIP: 2
    • FDP_RIP.1: 1
    • FDP_RIP.2: 7
  • FIA:
    • FIA_ATD.1: 1
    • FIA_UAU: 4
    • FIA_UAU.1: 1
    • FIA_UAU.2: 4
    • FIA_UAU.3: 8
    • FIA_UID: 2
    • FIA_UID.1: 2
    • FIA_UID.2: 5
  • FPT:
    • FPT_RPL: 3
    • FPT_RPL.1: 10
pdf_data/st_keywords/cc_claims
  • A:
    • A.NO_GENERAL_PURPOSE: 1
    • A.PHYSICAL: 1
    • A.TRUSTED_ADMIN: 1
  • O:
    • O.DISPLAY_BANNER: 1
    • O.PROTECTED_COMMUNICA: 1
    • O.RESIDUAL_INFORMATION_: 1
    • O.SESSION_LOCK: 1
    • O.SYSTEM_MONITORING: 1
    • O.TOE_ADMINISTRATION: 1
    • O.TSF_SELF_TEST: 1
    • O.VERIFIABLE_UPDATES: 1
  • OE:
    • OE.NO_GENERAL_PURPOSE: 1
    • OE.PHYSICAL: 1
    • OE.TRUSTED_ADMIN: 1
  • T:
    • T.ADMIN_ERROR: 1
    • T.TSF_FAILURE: 1
    • T.UNAUTHORIZED_ACCESS: 1
    • T.UNAUTHORIZED_UPDATE: 1
    • T.UNDETECTED_ACTIONS: 1
    • T.USER_DATA_REUSE: 1
  • A:
    • A.ADMINISTRATION: 4
    • A.AUDIT_REACTION: 4
    • A.AUTHADMIN: 4
    • A.ENROLMENT: 4
    • A.ENVIRONMENT: 4
    • A.FALLBACK: 4
    • A.PHYSICAL: 5
    • A.ROLES_AND_ACCESS: 4
  • O:
    • O.BIO_VERIFCATION: 1
    • O.BIO_VERIFICATION: 9
    • O.NO_REPRODUCE: 8
    • O.RESIDUAL: 5
    • O.RESIDUAL_CAPTURE: 6
  • OE:
    • OE.ADMINISTRATION: 5
    • OE.AUDIT_REACKTION: 1
    • OE.AUDIT_REACTION: 17
    • OE.AUTHADMIN: 9
    • OE.ENROLMENT: 5
    • OE.ENVIRONMENT: 5
    • OE.FALLBACK: 3
    • OE.PHYSICAL: 5
    • OE.ROLES_AND_ACCESS: 9
  • OSP:
    • OSP.FAR: 7
    • OSP.USERLIMIT: 4
  • T:
    • T.BRUTEFORCE: 5
    • T.MODIFY_ASSETS: 7
    • T.REPRODUCE: 5
    • T.RESIDUAL: 9
    • T.ROLES: 8
pdf_data/st_keywords/symmetric_crypto
  • AES_competition:
    • AES:
      • AES: 11
      • AES-128: 3
      • AES128: 1
      • AES256: 1
  • DES:
    • 3DES:
      • 3DES: 1
  • constructions:
    • MAC:
      • CMAC: 1
      • HMAC: 4
pdf_data/st_keywords/asymmetric_crypto
  • FF:
    • DH:
      • DH: 5
      • Diffie-Hellman: 2
pdf_data/st_keywords/hash_function
  • SHA:
    • SHA1:
      • SHA-1: 4
    • SHA2:
      • SHA-256: 2
      • SHA256: 3
pdf_data/st_keywords/crypto_scheme
  • KA:
    • Key Agreement: 1
pdf_data/st_keywords/crypto_protocol
  • IPsec:
    • IPsec: 1
  • SSH:
    • SSH: 2
  • TLS:
    • SSL:
      • SSL: 1
    • TLS:
      • TLS: 31
      • TLS 1.0: 1
      • TLS 1.1: 4
      • TLS 1.2: 3
pdf_data/st_keywords/randomness
  • PRNG:
    • DRBG: 5
  • RNG:
    • RBG: 5
    • RNG: 2
pdf_data/st_keywords/cipher_mode
  • CBC:
    • CBC: 2
  • CTR:
    • CTR: 2
pdf_data/st_keywords/tls_cipher_suite
  • TLS:
    • TLS_DHE_RSA_WITH_AES_128_CBC_SHA: 2
    • TLS_DHE_RSA_WITH_AES_256_CBC_SHA: 1
    • TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA256: 1
    • TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256: 1
    • TLS_RSA_WITH_AES_128_CBC_SHA: 4
    • TLS_RSA_WITH_AES_128_CBC_SHA256: 1
    • TLS_RSA_WITH_AES_256_CBC_SHA: 1
pdf_data/st_keywords/standard_id
  • FIPS:
    • FIPS 140-2: 12
    • FIPS 186-2: 1
    • FIPS 186-3: 1
    • FIPS PUB 140-2: 2
    • FIPS PUB 186-2: 3
    • FIPS PUB 186-3: 3
    • FIPS PUB 197: 2
  • NIST:
    • NIST SP 800-38A: 1
    • NIST SP 800-56B: 1
    • NIST SP 800-90A: 2
    • NIST SP 800-90B: 1
    • SP 800-56B: 1
  • PKCS:
    • PKCS#1: 1
  • RFC:
    • RFC 2346: 1
    • RFC 2818: 2
    • RFC 4346: 3
    • RFC 5246: 3
pdf_data/st_keywords/certification_process
  • OutOfScope:
    • Biometric Identification is not addressed within this ST. Furthermore the enrolment process is out of scope of this ST and it is assumed that all authorized users have been enrolled. Last but not least a: 1
    • a mechanism for audit review of the TOE audit logs. As mentioned before all auditing aspects are out of scope of the TOE. • Transmission / Storage: The environment cares for a secure communication and storing: 1
    • higher error rates of those systems are only two of them. The biometric identification process is out of scope of this ST. Please see [BEM] or [BPT] for further explanations. 1.5.2 Wording in context of Common: 1
    • out of scope: 5
    • the BIR to a name or some other "real-life" identification of a user is up to the application and out of scope of the TOE. VERSION 1.0 Security Target for PalmSecure 14.September 2008 All Rights Reserved: 1
    • user identity from the TOE. As mentioned before the specific connection to the Portal Service is out of scope of the TOE and depends on the overall application using the PalmSecure Library. • Auditing: The: 1
pdf_data/st_metadata
  • /Author: Fujitsu
  • /Company: Fujitsu
  • /CreationDate: D:20090105144849+09'00'
  • /Creator: Word 用 Acrobat PDFMaker 8.1
  • /Keywords: authentication,biometric,identification,verification
  • /ModDate: D:20090105145458+09'00'
  • /Producer: Acrobat Distiller 8.1.0 (Windows)
  • /SourceModified: D:20090105054723
  • /Subject: PalmSecure SDK
  • /Title: Security Target for PalmSecure
  • pdf_file_size_bytes: 707424
  • pdf_hyperlinks: http://www.bsi.bund.de/
  • pdf_is_encrypted: True
  • pdf_number_of_pages: 59
state/cert/convert_garbage True False
state/cert/download_ok True False
state/cert/pdf_hash Different Different
state/report/pdf_hash Different Different
state/report/txt_hash Different Different
state/st/pdf_hash Different Different
state/st/txt_hash Different Different