PP-Module for Authentication Servers Version 2.0

Profile details

Status active
Valid from 10.03.2026
Scheme πŸ‡ΊπŸ‡Έ US
Category Network and Network-Related Devices and Systems
Security level

Certification report

certification report could not be downloaded, no link is available.

Protection profile

Extracted keywords

Symmetric Algorithms
HMAC
Asymmetric Algorithms
ECDSA
Hash functions
SHA-512, SHA-384, PBKDF, PBKDF2
Protocols
SSH, TLS, TLS 1.0, TLS 1.1, DTLS, DTLS 1.2, DTLS 1.0, IKE, IPsec, VPN
Randomness
RBG

Claims
T.FALSE_ENDPOINTS, T.INVALID_USERS, T.UNAUTHORIZED_ADMINISTRATOR_ACCESS, T.UNDETECTED_ACTIVITY, T.WEAK_AUTHENTICATION_ENDPOINTS, T.UNTRUSTED_COMMUNICATION_CHANNELS, A.RP_FEDERATION, OE.RP_FEDERATION, OE.REQUIRE_AUTH
Security Assurance Requirements (SAR)
ATE_IND.1
Security Functional Requirements (SFR)
FAU_GEN, FAU_GEN.1, FAU_STG.1, FCO_NRO.1, FCO_NRR.1, FCO_NRO.1.2, FCO_NRO.1.3, FCO_NRO, FCO_NRR.1.1, FCO_NRR.1.2, FCO_NRR.1.3, FCO_NRR, FCS_STG_EXT, FCS_TLS_EXT.1.1, FCS_TLSC_EXT.1.1, FCS_STG_EXT.1, FCS_CKM.3, FCS_CKM.3.1, FCS_CKM, FCS_TLSS_EXT.1, FCS_TLSS_EXT.2, FCS_RBG.1, FCS_TLSS_EXT, FCS_STG_EXT.1.1, FCS_COP, FCS_PSK_EXT.3.4, FCS_COP.1, FCS_NTP_EXT.1, FIA_HOTP_EXT, FIA_PSK_EXT, FIA_TOTP_EXT, FIA_XCU_EXT.2.1, FIA_XCU_EXT.1.1, FIA_AFL, FIA_UAU.6, FIA_HOTP_EXT.1, FIA_TOTP_EXT.1, FIA_AFL.1, FIA_UAU.6.1, FIA_UAU, FIA_PSK_EXT.3, FIA_PSK_EXT.2, FIA_PSK_EXT.1, FIA_HOTP_EXT.1.1, FIA_HOTP_EXT.1.3, FIA_HOTP_EXT.1.4, FIA_HOTP_EXT.1.5, FIA_HOTP_EXT.1.6, FIA_HOTP_EXT.1.7, FIA_HOTP_EXT.1.8, FIA_TOTP_EXT.1.7, FIA_PSK_EXT.2.1, FIA_PSK_EXT.3.2, FIA_PSK_EXT.3.3, FIA_PSK_EXT.3.4, FIA_PSK_EXT.3.1, FIA_PSK_EXT.3.5, FIA_PSK_EXT.3.6, FIA_PSK_EXT.3.7, FIA_TOTP_EXT.1.1, FIA_TOTP_EXT.1.2, FIA_TOTP_EXT.1.3, FIA_TOTP_EXT.1.4, FIA_TOTP_EXT.1.5, FIA_TOTP_EXT.1.6, FIA_TOTP_EXT.1.8, FIA_HOTP_EXT.1.2, FIA_PSK_EXT.1.1, FIA_PSK_EXT.1.2, FIA_TOTP_EXT.1.9, FMT_SMF, FMT_SMF.1, FPT_SKP_EXT.1, FTA_TSE.1, FTA_TSE.1.1, FTA_TSE, FTP_ITC, FTP_ITC.1

Certification process
out of scope, between the relying party and the TOE. Federation protocols that only support bearer assertions are out of scope for this PP-Module. Relying Party (RP) An entity that relies upon the subscriber’s authenticators

Standards
NIST SP 800-132, NIST SP 800-63B, RFC 8603, RFC 5216, RFC 5881, RFC 8996, RFC 2865, RFC 6733, RFC 6614, RFC 7360, RFC 6347, RFC 4226, RFC 6238, ISO/IEC 15408, X.509, CCMB-2022-11-001, CCMB-2022-11-002, CCMB-2022-11-003, CCMB-2022-11-005, CCMB-2022-11-006

References

No references are available for this protection profile.

Processing updates

Feed
  • The protection profile was first processed.

Raw data

{
  "_id": "a947fb2b0c6cc328",
  "_type": "sec_certs.sample.protection_profile.ProtectionProfile",
  "dgst": "a947fb2b0c6cc328",
  "heuristics": {
    "_type": "sec_certs.sample.protection_profile.ProtectionProfile.Heuristics"
  },
  "pdf_data": {
    "_type": "sec_certs.sample.protection_profile.ProtectionProfile.PdfData",
    "pp_filename": "",
    "pp_keywords": {
      "asymmetric_crypto": {
        "ECC": {
          "ECDSA": {
            "ECDSA": 1
          }
        }
      },
      "cc_cert_id": {},
      "cc_claims": {
        "A": {
          "A.RP_FEDERATION": 3
        },
        "OE": {
          "OE.REQUIRE_AUTH": 2,
          "OE.RP_FEDERATION": 3
        },
        "T": {
          "T.FALSE_ENDPOINTS": 2,
          "T.INVALID_USERS": 2,
          "T.UNAUTHORIZED_ADMINISTRATOR_ACCESS": 2,
          "T.UNDETECTED_ACTIVITY": 1,
          "T.UNTRUSTED_COMMUNICATION_CHANNELS": 1,
          "T.WEAK_AUTHENTICATION_ENDPOINTS": 1
        }
      },
      "cc_protection_profile_id": {},
      "cc_sar": {
        "ATE": {
          "ATE_IND.1": 1
        }
      },
      "cc_security_level": {},
      "cc_sfr": {
        "FAU": {
          "FAU_GEN": 12,
          "FAU_GEN.1": 4,
          "FAU_STG.1": 1
        },
        "FCO": {
          "FCO_NRO": 2,
          "FCO_NRO.1": 6,
          "FCO_NRO.1.2": 1,
          "FCO_NRO.1.3": 1,
          "FCO_NRR": 1,
          "FCO_NRR.1": 6,
          "FCO_NRR.1.1": 1,
          "FCO_NRR.1.2": 1,
          "FCO_NRR.1.3": 1
        },
        "FCS": {
          "FCS_CKM": 2,
          "FCS_CKM.3": 10,
          "FCS_CKM.3.1": 1,
          "FCS_COP": 1,
          "FCS_COP.1": 3,
          "FCS_NTP_EXT.1": 1,
          "FCS_PSK_EXT.3.4": 1,
          "FCS_RBG.1": 20,
          "FCS_STG_EXT": 4,
          "FCS_STG_EXT.1": 13,
          "FCS_STG_EXT.1.1": 2,
          "FCS_TLSC_EXT.1.1": 1,
          "FCS_TLSS_EXT": 1,
          "FCS_TLSS_EXT.1": 10,
          "FCS_TLSS_EXT.2": 9,
          "FCS_TLS_EXT.1.1": 3
        },
        "FIA": {
          "FIA_AFL": 8,
          "FIA_AFL.1": 4,
          "FIA_HOTP_EXT": 12,
          "FIA_HOTP_EXT.1": 13,
          "FIA_HOTP_EXT.1.1": 2,
          "FIA_HOTP_EXT.1.2": 1,
          "FIA_HOTP_EXT.1.3": 2,
          "FIA_HOTP_EXT.1.4": 6,
          "FIA_HOTP_EXT.1.5": 4,
          "FIA_HOTP_EXT.1.6": 4,
          "FIA_HOTP_EXT.1.7": 3,
          "FIA_HOTP_EXT.1.8": 2,
          "FIA_PSK_EXT": 20,
          "FIA_PSK_EXT.1": 29,
          "FIA_PSK_EXT.1.1": 1,
          "FIA_PSK_EXT.1.2": 1,
          "FIA_PSK_EXT.2": 10,
          "FIA_PSK_EXT.2.1": 5,
          "FIA_PSK_EXT.3": 10,
          "FIA_PSK_EXT.3.1": 4,
          "FIA_PSK_EXT.3.2": 4,
          "FIA_PSK_EXT.3.3": 5,
          "FIA_PSK_EXT.3.4": 4,
          "FIA_PSK_EXT.3.5": 2,
          "FIA_PSK_EXT.3.6": 2,
          "FIA_PSK_EXT.3.7": 3,
          "FIA_TOTP_EXT": 10,
          "FIA_TOTP_EXT.1": 13,
          "FIA_TOTP_EXT.1.1": 2,
          "FIA_TOTP_EXT.1.2": 2,
          "FIA_TOTP_EXT.1.3": 2,
          "FIA_TOTP_EXT.1.4": 6,
          "FIA_TOTP_EXT.1.5": 4,
          "FIA_TOTP_EXT.1.6": 4,
          "FIA_TOTP_EXT.1.7": 4,
          "FIA_TOTP_EXT.1.8": 4,
          "FIA_TOTP_EXT.1.9": 1,
          "FIA_UAU": 1,
          "FIA_UAU.6": 7,
          "FIA_UAU.6.1": 1,
          "FIA_XCU_EXT.1.1": 2,
          "FIA_XCU_EXT.2.1": 1
        },
        "FMT": {
          "FMT_SMF": 8,
          "FMT_SMF.1": 2
        },
        "FPT": {
          "FPT_SKP_EXT.1": 2
        },
        "FTA": {
          "FTA_TSE": 1,
          "FTA_TSE.1": 5,
          "FTA_TSE.1.1": 1
        },
        "FTP": {
          "FTP_ITC": 8,
          "FTP_ITC.1": 6
        }
      },
      "certification_process": {
        "OutOfScope": {
          "between the relying party and the TOE. Federation protocols that only support bearer assertions are out of scope for this PP-Module. Relying Party (RP) An entity that relies upon the subscriber\u2019s authenticators": 1,
          "out of scope": 1
        }
      },
      "cipher_mode": {},
      "cplc_data": {},
      "crypto_engine": {},
      "crypto_library": {},
      "crypto_protocol": {
        "IKE": {
          "IKE": 1
        },
        "IPsec": {
          "IPsec": 12
        },
        "SSH": {
          "SSH": 1
        },
        "TLS": {
          "DTLS": {
            "DTLS": 20,
            "DTLS 1.0": 1,
            "DTLS 1.2": 1
          },
          "TLS": {
            "TLS": 56,
            "TLS 1.0": 1,
            "TLS 1.1": 1
          }
        },
        "VPN": {
          "VPN": 3
        }
      },
      "crypto_scheme": {},
      "device_model": {},
      "ecc_curve": {},
      "eval_facility": {},
      "hash_function": {
        "PBKDF": {
          "PBKDF": 4,
          "PBKDF2": 1
        },
        "SHA": {
          "SHA2": {
            "SHA-384": 5,
            "SHA-512": 6
          }
        }
      },
      "ic_data_group": {},
      "javacard_api_const": {},
      "javacard_packages": {},
      "javacard_version": {},
      "os_name": {},
      "pq_crypto": {},
      "randomness": {
        "RNG": {
          "RBG": 7
        }
      },
      "side_channel_analysis": {},
      "standard_id": {
        "CC": {
          "CCMB-2022-11-001": 1,
          "CCMB-2022-11-002": 1,
          "CCMB-2022-11-003": 1,
          "CCMB-2022-11-005": 1,
          "CCMB-2022-11-006": 1
        },
        "ISO": {
          "ISO/IEC 15408": 2
        },
        "NIST": {
          "NIST SP 800-132": 1,
          "NIST SP 800-63B": 1
        },
        "RFC": {
          "RFC 2865": 2,
          "RFC 4226": 2,
          "RFC 5216": 2,
          "RFC 5881": 2,
          "RFC 6238": 2,
          "RFC 6347": 1,
          "RFC 6614": 3,
          "RFC 6733": 2,
          "RFC 7360": 4,
          "RFC 8603": 1,
          "RFC 8996": 5
        },
        "X509": {
          "X.509": 16
        }
      },
      "symmetric_crypto": {
        "constructions": {
          "MAC": {
            "HMAC": 4
          }
        }
      },
      "technical_report_id": {},
      "tee_name": {},
      "tls_cipher_suite": {},
      "vendor": {},
      "vulnerability": {}
    },
    "pp_metadata": {
      "/CreationDate": "D:20260310130123+00\u002700\u0027",
      "/Creator": "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) HeadlessChrome/145.0.0.0 Safari/537.36",
      "/ModDate": "D:20260310130123+00\u002700\u0027",
      "/Producer": "Skia/PDF m145",
      "/Title": "PP-Module for Authentication Servers",
      "pdf_file_size_bytes": 3528784,
      "pdf_hyperlinks": {
        "_type": "Set",
        "elements": [
          "https://www.niap-ccevs.org/protectionprofiles/465",
          "http://www.commoncriteriaportal.org/files/ccfiles/CC2022PART3R1.pdf",
          "http://www.commoncriteriaportal.org/files/ccfiles/CC2022PART2R1.pdf",
          "http://www.commoncriteriaportal.org/files/ccfiles/CC2022PART5R1.pdf",
          "http://www.commoncriteriaportal.org/files/ccfiles/CC2022PART4R1.pdf",
          "http://www.commoncriteriaportal.org/files/ccfiles/CEM2022R1.pdf",
          "https://www.niap-ccevs.org/protectionprofiles/524",
          "https://www.commoncriteriaportal.org/files/ccfiles/CC2022PART1R1.pdf",
          "https://www.niap-ccevs.org/protectionprofiles/511"
        ]
      },
      "pdf_is_encrypted": false,
      "pdf_number_of_pages": 68
    },
    "report_filename": null,
    "report_keywords": null,
    "report_metadata": null
  },
  "scheme_metadata": {
    "cc_version": "CC:2022",
    "pp_short_name": "MOD_AUTHSVR_V2.0",
    "pp_sponsor_id": "NIAP",
    "pp_transition": null,
    "predecessor": "MOD_AUTHSVR_V1.0",
    "source_scheme": "US",
    "successor": null
  },
  "state": {
    "_type": "sec_certs.sample.protection_profile.ProtectionProfile.InternalState",
    "pp": {
      "_type": "sec_certs.sample.document_state.DocumentState",
      "convert_ok": true,
      "download_ok": true,
      "extract_ok": true,
      "json_hash": null,
      "source_hash": "22b71cc5abb656d05d7490bc1e7213256b618a161f2cd5bc7d58a2a9dc0252d1",
      "txt_hash": "8b2b4226b1b06f6a520995ed251bd90fc877d260cdaeb1d215b1fbc78c872998"
    },
    "report": {
      "_type": "sec_certs.sample.document_state.DocumentState",
      "convert_ok": false,
      "download_ok": false,
      "extract_ok": false,
      "json_hash": null,
      "source_hash": null,
      "txt_hash": null
    }
  },
  "web_data": {
    "_type": "sec_certs.sample.protection_profile.ProtectionProfile.WebData",
    "category": "Network and Network-Related Devices and Systems",
    "is_collaborative": false,
    "maintenances": [],
    "name": "PP-Module for Authentication Servers Version 2.0",
    "not_valid_after": null,
    "not_valid_before": "2026-03-10",
    "pp_link": "https://www.niap-ccevs.org/api/file/get_public_file/?file_id=37720",
    "report_link": null,
    "scheme": "US",
    "security_level": {
      "_type": "Set",
      "elements": []
    },
    "status": "active",
    "version": "2.0"
  }
}