This page was not yet optimized for use on mobile devices.
PP-Module for Authentication Servers Version 2.0
Profile details
| Status | active |
|---|---|
| Valid from | 10.03.2026 |
| Scheme | πΊπΈ US |
| Category | Network and Network-Related Devices and Systems |
| Security level |
Certification report
certification report could not be downloaded, no link is available.
Protection profile
Extracted keywords
Symmetric Algorithms
HMACAsymmetric Algorithms
ECDSAHash functions
SHA-512, SHA-384, PBKDF, PBKDF2Protocols
SSH, TLS, TLS 1.0, TLS 1.1, DTLS, DTLS 1.2, DTLS 1.0, IKE, IPsec, VPNRandomness
RBGClaims
T.FALSE_ENDPOINTS, T.INVALID_USERS, T.UNAUTHORIZED_ADMINISTRATOR_ACCESS, T.UNDETECTED_ACTIVITY, T.WEAK_AUTHENTICATION_ENDPOINTS, T.UNTRUSTED_COMMUNICATION_CHANNELS, A.RP_FEDERATION, OE.RP_FEDERATION, OE.REQUIRE_AUTHSecurity Assurance Requirements (SAR)
ATE_IND.1Security Functional Requirements (SFR)
FAU_GEN, FAU_GEN.1, FAU_STG.1, FCO_NRO.1, FCO_NRR.1, FCO_NRO.1.2, FCO_NRO.1.3, FCO_NRO, FCO_NRR.1.1, FCO_NRR.1.2, FCO_NRR.1.3, FCO_NRR, FCS_STG_EXT, FCS_TLS_EXT.1.1, FCS_TLSC_EXT.1.1, FCS_STG_EXT.1, FCS_CKM.3, FCS_CKM.3.1, FCS_CKM, FCS_TLSS_EXT.1, FCS_TLSS_EXT.2, FCS_RBG.1, FCS_TLSS_EXT, FCS_STG_EXT.1.1, FCS_COP, FCS_PSK_EXT.3.4, FCS_COP.1, FCS_NTP_EXT.1, FIA_HOTP_EXT, FIA_PSK_EXT, FIA_TOTP_EXT, FIA_XCU_EXT.2.1, FIA_XCU_EXT.1.1, FIA_AFL, FIA_UAU.6, FIA_HOTP_EXT.1, FIA_TOTP_EXT.1, FIA_AFL.1, FIA_UAU.6.1, FIA_UAU, FIA_PSK_EXT.3, FIA_PSK_EXT.2, FIA_PSK_EXT.1, FIA_HOTP_EXT.1.1, FIA_HOTP_EXT.1.3, FIA_HOTP_EXT.1.4, FIA_HOTP_EXT.1.5, FIA_HOTP_EXT.1.6, FIA_HOTP_EXT.1.7, FIA_HOTP_EXT.1.8, FIA_TOTP_EXT.1.7, FIA_PSK_EXT.2.1, FIA_PSK_EXT.3.2, FIA_PSK_EXT.3.3, FIA_PSK_EXT.3.4, FIA_PSK_EXT.3.1, FIA_PSK_EXT.3.5, FIA_PSK_EXT.3.6, FIA_PSK_EXT.3.7, FIA_TOTP_EXT.1.1, FIA_TOTP_EXT.1.2, FIA_TOTP_EXT.1.3, FIA_TOTP_EXT.1.4, FIA_TOTP_EXT.1.5, FIA_TOTP_EXT.1.6, FIA_TOTP_EXT.1.8, FIA_HOTP_EXT.1.2, FIA_PSK_EXT.1.1, FIA_PSK_EXT.1.2, FIA_TOTP_EXT.1.9, FMT_SMF, FMT_SMF.1, FPT_SKP_EXT.1, FTA_TSE.1, FTA_TSE.1.1, FTA_TSE, FTP_ITC, FTP_ITC.1Certification process
out of scope, between the relying party and the TOE. Federation protocols that only support bearer assertions are out of scope for this PP-Module. Relying Party (RP) An entity that relies upon the subscriberβs authenticatorsStandards
NIST SP 800-132, NIST SP 800-63B, RFC 8603, RFC 5216, RFC 5881, RFC 8996, RFC 2865, RFC 6733, RFC 6614, RFC 7360, RFC 6347, RFC 4226, RFC 6238, ISO/IEC 15408, X.509, CCMB-2022-11-001, CCMB-2022-11-002, CCMB-2022-11-003, CCMB-2022-11-005, CCMB-2022-11-006References
No references are available for this protection profile.
-
The protection profile was first processed.
{
"_id": "a947fb2b0c6cc328",
"_type": "sec_certs.sample.protection_profile.ProtectionProfile",
"dgst": "a947fb2b0c6cc328",
"heuristics": {
"_type": "sec_certs.sample.protection_profile.ProtectionProfile.Heuristics"
},
"pdf_data": {
"_type": "sec_certs.sample.protection_profile.ProtectionProfile.PdfData",
"pp_filename": "",
"pp_keywords": {
"asymmetric_crypto": {
"ECC": {
"ECDSA": {
"ECDSA": 1
}
}
},
"cc_cert_id": {},
"cc_claims": {
"A": {
"A.RP_FEDERATION": 3
},
"OE": {
"OE.REQUIRE_AUTH": 2,
"OE.RP_FEDERATION": 3
},
"T": {
"T.FALSE_ENDPOINTS": 2,
"T.INVALID_USERS": 2,
"T.UNAUTHORIZED_ADMINISTRATOR_ACCESS": 2,
"T.UNDETECTED_ACTIVITY": 1,
"T.UNTRUSTED_COMMUNICATION_CHANNELS": 1,
"T.WEAK_AUTHENTICATION_ENDPOINTS": 1
}
},
"cc_protection_profile_id": {},
"cc_sar": {
"ATE": {
"ATE_IND.1": 1
}
},
"cc_security_level": {},
"cc_sfr": {
"FAU": {
"FAU_GEN": 12,
"FAU_GEN.1": 4,
"FAU_STG.1": 1
},
"FCO": {
"FCO_NRO": 2,
"FCO_NRO.1": 6,
"FCO_NRO.1.2": 1,
"FCO_NRO.1.3": 1,
"FCO_NRR": 1,
"FCO_NRR.1": 6,
"FCO_NRR.1.1": 1,
"FCO_NRR.1.2": 1,
"FCO_NRR.1.3": 1
},
"FCS": {
"FCS_CKM": 2,
"FCS_CKM.3": 10,
"FCS_CKM.3.1": 1,
"FCS_COP": 1,
"FCS_COP.1": 3,
"FCS_NTP_EXT.1": 1,
"FCS_PSK_EXT.3.4": 1,
"FCS_RBG.1": 20,
"FCS_STG_EXT": 4,
"FCS_STG_EXT.1": 13,
"FCS_STG_EXT.1.1": 2,
"FCS_TLSC_EXT.1.1": 1,
"FCS_TLSS_EXT": 1,
"FCS_TLSS_EXT.1": 10,
"FCS_TLSS_EXT.2": 9,
"FCS_TLS_EXT.1.1": 3
},
"FIA": {
"FIA_AFL": 8,
"FIA_AFL.1": 4,
"FIA_HOTP_EXT": 12,
"FIA_HOTP_EXT.1": 13,
"FIA_HOTP_EXT.1.1": 2,
"FIA_HOTP_EXT.1.2": 1,
"FIA_HOTP_EXT.1.3": 2,
"FIA_HOTP_EXT.1.4": 6,
"FIA_HOTP_EXT.1.5": 4,
"FIA_HOTP_EXT.1.6": 4,
"FIA_HOTP_EXT.1.7": 3,
"FIA_HOTP_EXT.1.8": 2,
"FIA_PSK_EXT": 20,
"FIA_PSK_EXT.1": 29,
"FIA_PSK_EXT.1.1": 1,
"FIA_PSK_EXT.1.2": 1,
"FIA_PSK_EXT.2": 10,
"FIA_PSK_EXT.2.1": 5,
"FIA_PSK_EXT.3": 10,
"FIA_PSK_EXT.3.1": 4,
"FIA_PSK_EXT.3.2": 4,
"FIA_PSK_EXT.3.3": 5,
"FIA_PSK_EXT.3.4": 4,
"FIA_PSK_EXT.3.5": 2,
"FIA_PSK_EXT.3.6": 2,
"FIA_PSK_EXT.3.7": 3,
"FIA_TOTP_EXT": 10,
"FIA_TOTP_EXT.1": 13,
"FIA_TOTP_EXT.1.1": 2,
"FIA_TOTP_EXT.1.2": 2,
"FIA_TOTP_EXT.1.3": 2,
"FIA_TOTP_EXT.1.4": 6,
"FIA_TOTP_EXT.1.5": 4,
"FIA_TOTP_EXT.1.6": 4,
"FIA_TOTP_EXT.1.7": 4,
"FIA_TOTP_EXT.1.8": 4,
"FIA_TOTP_EXT.1.9": 1,
"FIA_UAU": 1,
"FIA_UAU.6": 7,
"FIA_UAU.6.1": 1,
"FIA_XCU_EXT.1.1": 2,
"FIA_XCU_EXT.2.1": 1
},
"FMT": {
"FMT_SMF": 8,
"FMT_SMF.1": 2
},
"FPT": {
"FPT_SKP_EXT.1": 2
},
"FTA": {
"FTA_TSE": 1,
"FTA_TSE.1": 5,
"FTA_TSE.1.1": 1
},
"FTP": {
"FTP_ITC": 8,
"FTP_ITC.1": 6
}
},
"certification_process": {
"OutOfScope": {
"between the relying party and the TOE. Federation protocols that only support bearer assertions are out of scope for this PP-Module. Relying Party (RP) An entity that relies upon the subscriber\u2019s authenticators": 1,
"out of scope": 1
}
},
"cipher_mode": {},
"cplc_data": {},
"crypto_engine": {},
"crypto_library": {},
"crypto_protocol": {
"IKE": {
"IKE": 1
},
"IPsec": {
"IPsec": 12
},
"SSH": {
"SSH": 1
},
"TLS": {
"DTLS": {
"DTLS": 20,
"DTLS 1.0": 1,
"DTLS 1.2": 1
},
"TLS": {
"TLS": 56,
"TLS 1.0": 1,
"TLS 1.1": 1
}
},
"VPN": {
"VPN": 3
}
},
"crypto_scheme": {},
"device_model": {},
"ecc_curve": {},
"eval_facility": {},
"hash_function": {
"PBKDF": {
"PBKDF": 4,
"PBKDF2": 1
},
"SHA": {
"SHA2": {
"SHA-384": 5,
"SHA-512": 6
}
}
},
"ic_data_group": {},
"javacard_api_const": {},
"javacard_packages": {},
"javacard_version": {},
"os_name": {},
"pq_crypto": {},
"randomness": {
"RNG": {
"RBG": 7
}
},
"side_channel_analysis": {},
"standard_id": {
"CC": {
"CCMB-2022-11-001": 1,
"CCMB-2022-11-002": 1,
"CCMB-2022-11-003": 1,
"CCMB-2022-11-005": 1,
"CCMB-2022-11-006": 1
},
"ISO": {
"ISO/IEC 15408": 2
},
"NIST": {
"NIST SP 800-132": 1,
"NIST SP 800-63B": 1
},
"RFC": {
"RFC 2865": 2,
"RFC 4226": 2,
"RFC 5216": 2,
"RFC 5881": 2,
"RFC 6238": 2,
"RFC 6347": 1,
"RFC 6614": 3,
"RFC 6733": 2,
"RFC 7360": 4,
"RFC 8603": 1,
"RFC 8996": 5
},
"X509": {
"X.509": 16
}
},
"symmetric_crypto": {
"constructions": {
"MAC": {
"HMAC": 4
}
}
},
"technical_report_id": {},
"tee_name": {},
"tls_cipher_suite": {},
"vendor": {},
"vulnerability": {}
},
"pp_metadata": {
"/CreationDate": "D:20260310130123+00\u002700\u0027",
"/Creator": "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) HeadlessChrome/145.0.0.0 Safari/537.36",
"/ModDate": "D:20260310130123+00\u002700\u0027",
"/Producer": "Skia/PDF m145",
"/Title": "PP-Module for Authentication Servers",
"pdf_file_size_bytes": 3528784,
"pdf_hyperlinks": {
"_type": "Set",
"elements": [
"https://www.niap-ccevs.org/protectionprofiles/465",
"http://www.commoncriteriaportal.org/files/ccfiles/CC2022PART3R1.pdf",
"http://www.commoncriteriaportal.org/files/ccfiles/CC2022PART2R1.pdf",
"http://www.commoncriteriaportal.org/files/ccfiles/CC2022PART5R1.pdf",
"http://www.commoncriteriaportal.org/files/ccfiles/CC2022PART4R1.pdf",
"http://www.commoncriteriaportal.org/files/ccfiles/CEM2022R1.pdf",
"https://www.niap-ccevs.org/protectionprofiles/524",
"https://www.commoncriteriaportal.org/files/ccfiles/CC2022PART1R1.pdf",
"https://www.niap-ccevs.org/protectionprofiles/511"
]
},
"pdf_is_encrypted": false,
"pdf_number_of_pages": 68
},
"report_filename": null,
"report_keywords": null,
"report_metadata": null
},
"scheme_metadata": {
"cc_version": "CC:2022",
"pp_short_name": "MOD_AUTHSVR_V2.0",
"pp_sponsor_id": "NIAP",
"pp_transition": null,
"predecessor": "MOD_AUTHSVR_V1.0",
"source_scheme": "US",
"successor": null
},
"state": {
"_type": "sec_certs.sample.protection_profile.ProtectionProfile.InternalState",
"pp": {
"_type": "sec_certs.sample.document_state.DocumentState",
"convert_ok": true,
"download_ok": true,
"extract_ok": true,
"json_hash": null,
"source_hash": "22b71cc5abb656d05d7490bc1e7213256b618a161f2cd5bc7d58a2a9dc0252d1",
"txt_hash": "8b2b4226b1b06f6a520995ed251bd90fc877d260cdaeb1d215b1fbc78c872998"
},
"report": {
"_type": "sec_certs.sample.document_state.DocumentState",
"convert_ok": false,
"download_ok": false,
"extract_ok": false,
"json_hash": null,
"source_hash": null,
"txt_hash": null
}
},
"web_data": {
"_type": "sec_certs.sample.protection_profile.ProtectionProfile.WebData",
"category": "Network and Network-Related Devices and Systems",
"is_collaborative": false,
"maintenances": [],
"name": "PP-Module for Authentication Servers Version 2.0",
"not_valid_after": null,
"not_valid_before": "2026-03-10",
"pp_link": "https://www.niap-ccevs.org/api/file/get_public_file/?file_id=37720",
"report_link": null,
"scheme": "US",
"security_level": {
"_type": "Set",
"elements": []
},
"status": "active",
"version": "2.0"
}
}