Blue Coat Secure Web Gateway Virtual Appliance

Certificate #3077

Webpage information

Status historical
Historical reason Moved to historical list due to sunsetting
Validation dates 11.12.2017 , 20.12.2017 , 13.11.2019 , 16.02.2021 , 27.05.2022
Standard FIPS 140-2
Security level 1
Type Software
Embodiment Multi-Chip Stand Alone
Caveat When operated in FIPS mode
Exceptions
  • Roles, Services, and Authentication: Level 2
  • Physical Security: N/A
  • Design Assurance: Level 3
  • Mitigation of Other Attacks: N/A
Description The Blue Coat ProxySG physical and virtual appliances are the core of Symantec’s Unified Security and Optimization solutions for business assurance. The appliances offer complete security and control of web traffic, providing rich policy constructs for threat protection, SSL traffic, authentication, filtering, data loss prevention and logging. SWG VA identifies malicious payloads and then filters, strips, blocks or replaces web content to mitigate risks and prevent data loss. The appliances also optimize web and internal application traffic for data, video, cloud and web applications.
Tested configurations
  • SGOS v6.7.2, SGOS v6.7.4, SGOS v6.7.4.601 and SGOS v6.7.5 on Vmware ESXi 6.0 running on a Dell PowerEdge R830 Server
Vendor Symantec, A Division of Broadcom
References

This certificate's webpage directly references 0 certificates, transitively this expands into 0 certificates.

Security policy

Symmetric Algorithms
AES, AES-128, AES-256, Triple-DES, TDES, HMAC, HMAC-SHA-256, HMAC-SHA-384
Asymmetric Algorithms
ECDH, ECDHE, ECDSA, ECC, DH, Diffie-Hellman, DHE
Hash functions
SHA-1, SHA-224, SHA-256, SHA-384, SHA-512, SHA384, MD5
Schemes
MAC, Key Agreement
Protocols
SSH, SSL, TLS, TLS 1.0, TLS 1.1, TLS 1.2
Randomness
DRBG, RNG
Libraries
Crypto Library v4.1.1
Elliptic Curves
P-256, P-384, P-521
Block cipher modes
ECB, CBC, CTR, CFB, GCM

Vendor
Broadcom, Microsoft

Security level
Level 1

Standards
FIPS 140-2, FIPS 201, FIPS 180-4, FIPS 198-1, FIPS 186-4, SP 800-38A, SP 800-38D, SP 800-38F, SP 800-67, SP 800-90A, SP 800-133, SP 800-52, PKCS1, PKCS#1, PKCS7, RFC 5288, X.509

File metadata

Title FIPS 140-2 Security Policy
Author Ian Hall
Creation date D:20220519140817-07'00'
Modification date D:20220519140817-07'00'
Pages 34
Creator Microsoft® Word for Microsoft 365
Producer Microsoft® Word for Microsoft 365

Heuristics

No heuristics are available for this certificate.

References

Loading...

Updates Feed

  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate was first processed.

Raw data

{
  "_type": "sec_certs.sample.fips.FIPSCertificate",
  "cert_id": 3077,
  "dgst": "4d934fe9163e483a",
  "heuristics": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.Heuristics",
    "algorithms": {
      "_type": "Set",
      "elements": [
        "RSA#2507",
        "CVL#1265",
        "SHS#3772",
        "DRBG#1541",
        "HMAC#3047",
        "CVL#1267",
        "HMAC#3046",
        "KTS#2446",
        "RSA#2506",
        "Triple-DES#2446",
        "AES#4596",
        "SHS#3773"
      ]
    },
    "cpe_matches": null,
    "direct_transitive_cves": null,
    "extracted_versions": {
      "_type": "Set",
      "elements": [
        "-"
      ]
    },
    "indirect_transitive_cves": null,
    "module_processed_references": {
      "_type": "sec_certs.sample.certificate.References",
      "directly_referenced_by": {
        "_type": "Set",
        "elements": [
          "3177"
        ]
      },
      "directly_referencing": null,
      "indirectly_referenced_by": {
        "_type": "Set",
        "elements": [
          "3177"
        ]
      },
      "indirectly_referencing": null
    },
    "module_prunned_references": {
      "_type": "Set",
      "elements": []
    },
    "policy_processed_references": {
      "_type": "sec_certs.sample.certificate.References",
      "directly_referenced_by": null,
      "directly_referencing": null,
      "indirectly_referenced_by": null,
      "indirectly_referencing": null
    },
    "policy_prunned_references": {
      "_type": "Set",
      "elements": []
    },
    "related_cves": null,
    "verified_cpe_matches": null
  },
  "pdf_data": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.PdfData",
    "keywords": {
      "asymmetric_crypto": {
        "ECC": {
          "ECC": {
            "ECC": 1
          },
          "ECDH": {
            "ECDH": 17,
            "ECDHE": 1
          },
          "ECDSA": {
            "ECDSA": 1
          }
        },
        "FF": {
          "DH": {
            "DH": 17,
            "DHE": 1,
            "Diffie-Hellman": 2
          }
        }
      },
      "certification_process": {},
      "cipher_mode": {
        "CBC": {
          "CBC": 10
        },
        "CFB": {
          "CFB": 2
        },
        "CTR": {
          "CTR": 2
        },
        "ECB": {
          "ECB": 2
        },
        "GCM": {
          "GCM": 2
        }
      },
      "cplc_data": {},
      "crypto_engine": {},
      "crypto_library": {
        "Generic": {
          "Crypto Library v4.1.1": 1
        }
      },
      "crypto_protocol": {
        "SSH": {
          "SSH": 59
        },
        "TLS": {
          "SSL": {
            "SSL": 1
          },
          "TLS": {
            "TLS": 53,
            "TLS 1.0": 1,
            "TLS 1.1": 2,
            "TLS 1.2": 3
          }
        }
      },
      "crypto_scheme": {
        "KA": {
          "Key Agreement": 4
        },
        "MAC": {
          "MAC": 1
        }
      },
      "device_model": {},
      "ecc_curve": {
        "NIST": {
          "P-256": 6,
          "P-384": 2,
          "P-521": 2
        }
      },
      "eval_facility": {},
      "fips_cert_id": {
        "Cert": {
          "#1": 1
        }
      },
      "fips_certlike": {
        "Certlike": {
          "AES 128, 192": 1,
          "AES-128": 2,
          "AES-256": 3,
          "HMAC-SHA-1": 2,
          "HMAC-SHA-1 128": 2,
          "HMAC-SHA-1-96": 2,
          "HMAC-SHA-256": 2,
          "HMAC-SHA-384": 2,
          "PKCS#1": 2,
          "PKCS1": 4,
          "PKCS7": 2,
          "SHA- 512": 1,
          "SHA-1": 6,
          "SHA-224": 4,
          "SHA-256": 9,
          "SHA-384": 5,
          "SHA-512": 4,
          "SHA384": 1
        }
      },
      "fips_security_level": {
        "Level": {
          "Level 1": 5
        }
      },
      "hash_function": {
        "MD": {
          "MD5": {
            "MD5": 1
          }
        },
        "SHA": {
          "SHA1": {
            "SHA-1": 6
          },
          "SHA2": {
            "SHA-224": 4,
            "SHA-256": 9,
            "SHA-384": 5,
            "SHA-512": 4,
            "SHA384": 1
          }
        }
      },
      "ic_data_group": {},
      "javacard_api_const": {},
      "javacard_packages": {},
      "javacard_version": {},
      "os_name": {},
      "pq_crypto": {},
      "randomness": {
        "PRNG": {
          "DRBG": 27
        },
        "RNG": {
          "RNG": 2
        }
      },
      "side_channel_analysis": {},
      "standard_id": {
        "FIPS": {
          "FIPS 140-2": 22,
          "FIPS 180-4": 2,
          "FIPS 186-4": 2,
          "FIPS 198-1": 2,
          "FIPS 201": 2
        },
        "NIST": {
          "SP 800-133": 2,
          "SP 800-38A": 1,
          "SP 800-38D": 1,
          "SP 800-38F": 2,
          "SP 800-52": 1,
          "SP 800-67": 1,
          "SP 800-90A": 9
        },
        "PKCS": {
          "PKCS#1": 1,
          "PKCS1": 2,
          "PKCS7": 1
        },
        "RFC": {
          "RFC 5288": 1
        },
        "X509": {
          "X.509": 4
        }
      },
      "symmetric_crypto": {
        "AES_competition": {
          "AES": {
            "AES": 9,
            "AES-128": 2,
            "AES-256": 3
          }
        },
        "DES": {
          "3DES": {
            "TDES": 1,
            "Triple-DES": 4
          }
        },
        "constructions": {
          "MAC": {
            "HMAC": 5,
            "HMAC-SHA-256": 1,
            "HMAC-SHA-384": 1
          }
        }
      },
      "tee_name": {},
      "tls_cipher_suite": {},
      "vendor": {
        "Broadcom": {
          "Broadcom": 38
        },
        "Microsoft": {
          "Microsoft": 2
        }
      },
      "vulnerability": {}
    },
    "policy_metadata": {
      "/Author": "Ian Hall",
      "/CreationDate": "D:20220519140817-07\u002700\u0027",
      "/Creator": "Microsoft\u00ae Word for Microsoft 365",
      "/ModDate": "D:20220519140817-07\u002700\u0027",
      "/Producer": "Microsoft\u00ae Word for Microsoft 365",
      "/Title": "FIPS 140-2 Security Policy",
      "pdf_file_size_bytes": 924326,
      "pdf_hyperlinks": {
        "_type": "Set",
        "elements": [
          "mailto:[email protected]",
          "mailto:[email protected]",
          "http://www.broadcom.com/",
          "http://csrc.nist.gov/groups/STM/cmvp/documents/140-1/140val-all.htm",
          "https://techdocs.broadcom.com/us/en/symantec-security-software/web-and-network-security/proxysg/6-7.html",
          "http://csrc.nist.gov/groups/STM/cmvp"
        ]
      },
      "pdf_is_encrypted": false,
      "pdf_number_of_pages": 34
    }
  },
  "state": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.InternalState",
    "module_download_ok": true,
    "module_extract_ok": true,
    "policy_convert_ok": true,
    "policy_download_ok": true,
    "policy_extract_ok": true,
    "policy_json_hash": null,
    "policy_pdf_hash": "714f32c31804687ec7c595a9a59aad71601bdc830d5c90f703234de1feb69e3d",
    "policy_txt_hash": "8f4d5ab92616efc65da3015ca3de365d0f7f7e64a914428c73b1ae906c8066c5"
  },
  "web_data": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.WebData",
    "caveat": "When operated in FIPS mode",
    "certificate_pdf_url": "https://csrc.nist.gov/CSRC/media/projects/cryptographic-module-validation-program/documents/certificates/FIPS140ConsolidatedCertDec2017.pdf",
    "date_sunset": null,
    "description": "The Blue Coat ProxySG physical and virtual appliances are the core of Symantec\u2019s Unified Security and Optimization solutions for business assurance. The appliances offer complete security and control of web traffic, providing rich policy constructs for threat protection, SSL traffic, authentication, filtering, data loss prevention and logging. SWG VA identifies malicious payloads and then filters, strips, blocks or replaces web content to mitigate risks and prevent data loss. The appliances also optimize web and internal application traffic for data, video, cloud and web applications.",
    "embodiment": "Multi-Chip Stand Alone",
    "exceptions": [
      "Roles, Services, and Authentication: Level 2",
      "Physical Security: N/A",
      "Design Assurance: Level 3",
      "Mitigation of Other Attacks: N/A"
    ],
    "fw_versions": null,
    "historical_reason": "Moved to historical list due to sunsetting",
    "hw_versions": null,
    "level": 1,
    "mentioned_certs": {},
    "module_name": "Blue Coat Secure Web Gateway Virtual Appliance",
    "module_type": "Software",
    "revoked_link": null,
    "revoked_reason": null,
    "standard": "FIPS 140-2",
    "status": "historical",
    "sw_versions": "6.7.2, 6.7.4, 6.7.4.601, 6.7.5",
    "tested_conf": [
      "SGOS v6.7.2, SGOS v6.7.4, SGOS v6.7.4.601 and SGOS v6.7.5 on Vmware ESXi 6.0 running on a Dell PowerEdge R830 Server"
    ],
    "validation_history": [
      {
        "_type": "sec_certs.sample.fips.FIPSCertificate.ValidationHistoryEntry",
        "date": "2017-12-11",
        "lab": "Acumen Security",
        "validation_type": "Initial"
      },
      {
        "_type": "sec_certs.sample.fips.FIPSCertificate.ValidationHistoryEntry",
        "date": "2017-12-20",
        "lab": "Acumen Security",
        "validation_type": "Update"
      },
      {
        "_type": "sec_certs.sample.fips.FIPSCertificate.ValidationHistoryEntry",
        "date": "2019-11-13",
        "lab": "Acumen Security",
        "validation_type": "Update"
      },
      {
        "_type": "sec_certs.sample.fips.FIPSCertificate.ValidationHistoryEntry",
        "date": "2021-02-16",
        "lab": "Acumen Security",
        "validation_type": "Update"
      },
      {
        "_type": "sec_certs.sample.fips.FIPSCertificate.ValidationHistoryEntry",
        "date": "2022-05-27",
        "lab": "Acumen Security",
        "validation_type": "Update"
      }
    ],
    "vendor": "Symantec, A Division of Broadcom",
    "vendor_url": "http://www.broadcom.com"
  }
}