Connectra

Certificate #1474

Webpage information

Status historical
Historical reason RNG SP800-131A Revision 1 Transition
Validation dates 28.12.2010
Standard FIPS 140-2
Security level 1
Type Firmware
Embodiment Multi-Chip Stand Alone
Caveat When operated in FIPS mode
Exceptions
  • Roles, Services, and Authentication: Level 2
  • Design Assurance: Level 3
  • Tested: Connectra-1 3070 General Purpose Computer with Check Point SecurePlatform Operating System, version NGX R66.1 hotfix 1
Description Check Point Connectra that unifies SSL VPN, IPSec VPN, and integrated intrusion prevention for secure connectivity for mobile and remote workers while protecting enterprise networks and endpoints from external threats. Connectra includes centralized management and DynamicID SMS authentication.
Version (Firmware) NGX R66.1 with hotfix 1
Vendor Check Point Software Technologies Ltd.
References

This certificate's webpage directly references 0 certificates, transitively this expands into 0 certificates.

Security policy

Symmetric Algorithms
AES, CAST, DES, 3DES, TDES, Triple-DES, HMAC
Asymmetric Algorithms
Diffie-Hellman, DH, DSA
Hash functions
SHA-1, SHA1, MD5
Schemes
MAC, Key exchange, Key Exchange, Key Agreement, Key agreement
Protocols
SSH, SSL, TLS, TLS v1.0, IKE, IPsec, VPN
Randomness
PRNG, RNG
Block cipher modes
CBC

Security level
Level 1, level 1, level 3

Standards
FIPS 140-2, FIPS PUB 197, FIPS 46-3, FIPS 198, FIPS 180-2, PKCS#1, RFC 2104, RFC 2404, RFC 2246

File metadata

Title Microsoft Word - CheckPointConnectraSecurity PolicyV1.08.doc
Author kwong
Creation date D:20101214204123-05'00'
Modification date D:20101214204132-05'00'
Pages 36
Creator Microsoft Word - CheckPointConnectraSecurity PolicyV1.08.doc
Producer ScanSoft PDF Create! 7

Heuristics

No heuristics are available for this certificate.

References

No references are available for this certificate.

Updates Feed

  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate was first processed.

Raw data

{
  "_type": "sec_certs.sample.fips.FIPSCertificate",
  "cert_id": 1474,
  "dgst": "3a047b4a81effb2c",
  "heuristics": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.Heuristics",
    "algorithms": {
      "_type": "Set",
      "elements": [
        "RNG#756",
        "AES#1458",
        "SHS#1319",
        "AES#1369",
        "HMAC#802",
        "Triple-DES#984",
        "RSA#670",
        "RSA#713",
        "HMAC#855",
        "Triple-DES#944",
        "SHS#1251"
      ]
    },
    "cpe_matches": null,
    "direct_transitive_cves": null,
    "extracted_versions": {
      "_type": "Set",
      "elements": [
        "66.1"
      ]
    },
    "indirect_transitive_cves": null,
    "module_processed_references": {
      "_type": "sec_certs.sample.certificate.References",
      "directly_referenced_by": null,
      "directly_referencing": null,
      "indirectly_referenced_by": null,
      "indirectly_referencing": null
    },
    "module_prunned_references": {
      "_type": "Set",
      "elements": []
    },
    "policy_processed_references": {
      "_type": "sec_certs.sample.certificate.References",
      "directly_referenced_by": null,
      "directly_referencing": null,
      "indirectly_referenced_by": null,
      "indirectly_referencing": null
    },
    "policy_prunned_references": {
      "_type": "Set",
      "elements": []
    },
    "related_cves": null,
    "verified_cpe_matches": null
  },
  "pdf_data": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.PdfData",
    "keywords": {
      "asymmetric_crypto": {
        "FF": {
          "DH": {
            "DH": 2,
            "Diffie-Hellman": 7
          },
          "DSA": {
            "DSA": 1
          }
        }
      },
      "certification_process": {},
      "cipher_mode": {
        "CBC": {
          "CBC": 3
        }
      },
      "cplc_data": {},
      "crypto_engine": {},
      "crypto_library": {},
      "crypto_protocol": {
        "IKE": {
          "IKE": 37
        },
        "IPsec": {
          "IPsec": 2
        },
        "SSH": {
          "SSH": 2
        },
        "TLS": {
          "SSL": {
            "SSL": 7
          },
          "TLS": {
            "TLS": 41,
            "TLS v1.0": 1
          }
        },
        "VPN": {
          "VPN": 14
        }
      },
      "crypto_scheme": {
        "KA": {
          "Key Agreement": 1,
          "Key agreement": 1
        },
        "KEX": {
          "Key Exchange": 1,
          "Key exchange": 1
        },
        "MAC": {
          "MAC": 1
        }
      },
      "device_model": {},
      "ecc_curve": {},
      "eval_facility": {},
      "fips_cert_id": {
        "Cert": {
          "#1": 1,
          "#1251": 1,
          "#1319": 1,
          "#1369": 1,
          "#1458": 1,
          "#670": 1,
          "#713": 1,
          "#756": 1,
          "#802": 1,
          "#855": 1,
          "#944": 1,
          "#984": 1
        }
      },
      "fips_certlike": {
        "Certlike": {
          "AES (128": 1,
          "HMAC-SHA-1": 1,
          "HMAC-SHA-1 (20": 1,
          "HMAC-SHA-1-96": 2,
          "PKCS#1": 3,
          "SHA-1": 5,
          "SHA1": 1,
          "\u2013 PKCS#1": 1
        }
      },
      "fips_security_level": {
        "Level": {
          "Level 1": 5,
          "level 1": 2,
          "level 3": 1
        }
      },
      "hash_function": {
        "MD": {
          "MD5": {
            "MD5": 2
          }
        },
        "SHA": {
          "SHA1": {
            "SHA-1": 5,
            "SHA1": 1
          }
        }
      },
      "ic_data_group": {},
      "javacard_api_const": {},
      "javacard_packages": {},
      "javacard_version": {},
      "os_name": {},
      "pq_crypto": {},
      "randomness": {
        "PRNG": {
          "PRNG": 6
        },
        "RNG": {
          "RNG": 1
        }
      },
      "side_channel_analysis": {},
      "standard_id": {
        "FIPS": {
          "FIPS 140-2": 31,
          "FIPS 180-2": 1,
          "FIPS 198": 1,
          "FIPS 46-3": 1,
          "FIPS PUB 197": 1
        },
        "PKCS": {
          "PKCS#1": 2
        },
        "RFC": {
          "RFC 2104": 1,
          "RFC 2246": 1,
          "RFC 2404": 1
        }
      },
      "symmetric_crypto": {
        "AES_competition": {
          "AES": {
            "AES": 4
          },
          "CAST": {
            "CAST": 2
          }
        },
        "DES": {
          "3DES": {
            "3DES": 1,
            "TDES": 3,
            "Triple-DES": 3
          },
          "DES": {
            "DES": 1
          }
        },
        "constructions": {
          "MAC": {
            "HMAC": 5
          }
        }
      },
      "tee_name": {},
      "tls_cipher_suite": {},
      "vendor": {},
      "vulnerability": {}
    },
    "policy_metadata": {
      "/Author": "kwong",
      "/CreationDate": "D:20101214204123-05\u002700\u0027",
      "/Creator": "Microsoft Word - CheckPointConnectraSecurity PolicyV1.08.doc",
      "/ModDate": "D:20101214204132-05\u002700\u0027",
      "/Producer": "ScanSoft PDF Create! 7",
      "/Title": "Microsoft Word - CheckPointConnectraSecurity PolicyV1.08.doc",
      "pdf_file_size_bytes": 1971356,
      "pdf_hyperlinks": {
        "_type": "Set",
        "elements": []
      },
      "pdf_is_encrypted": false,
      "pdf_number_of_pages": 36
    }
  },
  "state": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.InternalState",
    "module_download_ok": true,
    "module_extract_ok": true,
    "policy_convert_ok": true,
    "policy_download_ok": true,
    "policy_extract_ok": true,
    "policy_json_hash": null,
    "policy_pdf_hash": "3c745c289eb5878416af03ea648cd9217dd54265ec9c6892280649b86f2b2b0d",
    "policy_txt_hash": "be42fb4b76a6a4b68391fc699c158766467ef93195dd4c83afcd10a72a7f9c22"
  },
  "web_data": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.WebData",
    "caveat": "When operated in FIPS mode",
    "certificate_pdf_url": "https://csrc.nist.gov/CSRC/media/projects/cryptographic-module-validation-program/documents/certificates/140crt1474.pdf",
    "date_sunset": null,
    "description": "Check Point Connectra that unifies SSL VPN, IPSec VPN, and integrated intrusion prevention for secure connectivity for mobile and remote workers while protecting enterprise networks and endpoints from external threats. Connectra includes centralized management and DynamicID SMS authentication.",
    "embodiment": "Multi-Chip Stand Alone",
    "exceptions": [
      "Roles, Services, and Authentication: Level 2",
      "Design Assurance: Level 3",
      "Tested: Connectra-1 3070 General Purpose Computer with Check Point SecurePlatform Operating System, version NGX R66.1 hotfix 1"
    ],
    "fw_versions": "NGX R66.1 with hotfix 1",
    "historical_reason": "RNG SP800-131A Revision 1 Transition",
    "hw_versions": null,
    "level": 1,
    "mentioned_certs": {},
    "module_name": "Connectra",
    "module_type": "Firmware",
    "revoked_link": null,
    "revoked_reason": null,
    "standard": "FIPS 140-2",
    "status": "historical",
    "sw_versions": null,
    "tested_conf": null,
    "validation_history": [
      {
        "_type": "sec_certs.sample.fips.FIPSCertificate.ValidationHistoryEntry",
        "date": "2010-12-28",
        "lab": "CYGNACOM SOLUTIONS INC",
        "validation_type": "Initial"
      }
    ],
    "vendor": "Check Point Software Technologies Ltd.",
    "vendor_url": "http://www.checkpoint.com"
  }
}