You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
This <abbr class="dyn-abbr"><a href="#abbr_PP">PP</a></abbr> does not claim conformance to
993
993
any Protection Profile<a id="period_128" href="#period_128">. </a> </dd><p></p><dd>There are no <abbr class="dyn-abbr"><a href="#abbr_PP">PPs</a></abbr> or <abbr class="dyn-abbr"><a href="#abbr_PP">PP</a></abbr>-Modules that are allowed in a <abbr class="dyn-abbr"><a href="#abbr_PP-Configuration">PP-Configuration</a></abbr>
994
994
with this <abbr class="dyn-abbr"><a href="#abbr_PP">PP</a></abbr><a id="period_129" href="#period_129">. </a></dd><dt>Package Claim</dt><p></p><dd><ul><li>This <abbr class="dyn-abbr"><a href="#abbr_PP">PP</a></abbr> is
995
-
Functional Package for <abbr class="dyn-abbr"><a href="#abbr_TLS">TLS</a></abbr>, version 2.0 conformant<a id="period_130" href="#period_130">. </a></li><li>This <abbr class="dyn-abbr"><a href="#abbr_PP">PP</a></abbr> is
995
+
Functional Package for <abbr class="dyn-abbr"><a href="#abbr_TLS">TLS</a></abbr>, version 2.1 conformant<a id="period_130" href="#period_130">. </a></li><li>This <abbr class="dyn-abbr"><a href="#abbr_PP">PP</a></abbr> is
996
996
Functional Package for Secure Shell, version 2.0 conformant<a id="period_131" href="#period_131">. </a></li><li>This <abbr class="dyn-abbr"><a href="#abbr_PP">PP</a></abbr> is
997
997
Functional Package for X.509, version 1.0 conformant<a id="period_132" href="#period_132">. </a></li><li>This <abbr class="dyn-abbr"><a href="#abbr_PP">PP</a></abbr> is
998
998
Assurance Package for Flaw Remediation, version 1.0 conformant<a id="period_133" href="#period_133">. </a></li></ul></dd><p></p><dd>
2.0</a></span>, <span class="selectable-content" id="ftp-trp-tls"><abbr class="dyn-abbr"><a href="#abbr_TLS">TLS</a></abbr> as defined in the <a href="https://www.niap-ccevs.org/protectionprofiles/465">Functional Package for Transport Layer Security (TLS),
4182
4182
version
4183
-
2.0</a></span>] to </span>
4183
+
2.1</a></span>] to </span>
4184
4184
provide a <span class="refinement">trusted</span> communication path between itself and
4185
4185
[<i>remote <span class="refinement">subscribers and privileged</span></i>] users
[<b>selection</b>: <span class="selectable-content" id="_s_400">administrator</span>, <span class="selectable-content" id="_s_401"><abbr class="dyn-abbr"><a href="#abbr_CA">CA</a></abbr> operations staff</span>]</span></li><li style=""><span class="selectable-content" id="_s_402">an explicit TA database populated via a <abbr class="dyn-abbr"><a href="#abbr_TLS">TLS</a></abbr>-authenticated <abbr class="dyn-abbr"><a href="#abbr_EST">EST</a></abbr> <abbr class="dyn-abbr"><a href="#abbr_CA">CA</a></abbr>
9070
9070
certificate request in accordance with <abbr class="dyn-abbr"><a href="#abbr_RFC">RFC</a></abbr> 7030 section 4.1.2 and FCS_TLSC_EXT.2 (as defined in the <a href="https://www.niap-ccevs.org/protectionprofiles/465">Functional Package for Transport Layer Security (TLS),
The <abbr class="dyn-abbr"><a href="#abbr_TSF">TSF</a></abbr> shall authenticate <abbr class="dyn-abbr"><a href="#abbr_EST">EST</a></abbr> servers using X.509 certificates that chain to trust
[<b>selection</b>: <ul><li style=""><span class="selectable-content" id="_s_405"><abbr class="dyn-abbr"><a href="#abbr_HTTP">HTTP</a></abbr> basic authentication transported over <abbr class="dyn-abbr"><a href="#abbr_TLS">TLS</a></abbr> in accordance with <abbr class="dyn-abbr"><a href="#abbr_RFC">RFC</a></abbr> 7030
9085
9085
section 3.2.3 and FCS_TLSC_EXT.2 (as defined in the <a href="https://www.niap-ccevs.org/protectionprofiles/465">Functional Package for Transport Layer Security (TLS),
9086
9086
version
9087
-
2.0</a>)<a id="period_2429" href="#period_2429">. </a></span></li><li style=""><span class="selectable-content" id="_s_406"><abbr class="dyn-abbr"><a href="#abbr_HTTP">HTTP</a></abbr> digest authentication using a cryptographic hash algorithm in
9087
+
2.1</a>)<a id="period_2429" href="#period_2429">. </a></span></li><li style=""><span class="selectable-content" id="_s_406"><abbr class="dyn-abbr"><a href="#abbr_HTTP">HTTP</a></abbr> digest authentication using a cryptographic hash algorithm in
9088
9088
accordance with FCS_COP.1/HASH, transported over <abbr class="dyn-abbr"><a href="#abbr_TLS">TLS</a></abbr> in accordance with
9089
9089
<abbr class="dyn-abbr"><a href="#abbr_RFC">RFC</a></abbr> 7030 section 3.2.3 and FCS_TLSC_EXT.2 (as defined in the <a href="https://www.niap-ccevs.org/protectionprofiles/465">Functional Package for Transport Layer Security (TLS),
9090
9090
version
9091
-
2.0</a>)<a id="period_2430" href="#period_2430">. </a></span></li><li style=""><span class="selectable-content" id="_s_407">Certificate-based authentication in accordance with <abbr class="dyn-abbr"><a href="#abbr_RFC">RFC</a></abbr> 7030 section 3.3.2
9091
+
2.1</a>)<a id="period_2430" href="#period_2430">. </a></span></li><li style=""><span class="selectable-content" id="_s_407">Certificate-based authentication in accordance with <abbr class="dyn-abbr"><a href="#abbr_RFC">RFC</a></abbr> 7030 section 3.3.2
9092
9092
and FCS_TLSC_EXT.2 (as defined in the <a href="https://www.niap-ccevs.org/protectionprofiles/465">Functional Package for Transport Layer Security (TLS),
9093
9093
version
9094
-
2.0</a>) using
9094
+
2.1</a>) using
9095
9095
[<b>assignment</b>:
9096
9096
<span class="assignable-content">a pre-existing certificate authorized by the <abbr class="dyn-abbr"><a href="#abbr_EST">EST</a></abbr> server</span>]
accordance with <a href="#FCS_COP.1/Hash">FCS_COP.1/Hash</a> and <abbr class="dyn-abbr"><a href="#abbr_RFC">RFC</a></abbr> 7030 section 3.2.3;</span></li><li style=""><span class="selectable-content" id="_s_410"><abbr class="dyn-abbr"><a href="#abbr_TLS">TLS</a></abbr> certificate-based mutual authentication in accordance with
9197
9197
<abbr class="dyn-abbr"><a href="#abbr_RFC">RFC</a></abbr> 7030 section 3.3.2 and FCS_TLSS_EXT.1 (as defined in the <a href="https://www.niap-ccevs.org/protectionprofiles/465">Functional Package for Transport Layer Security (TLS),
The <abbr class="dyn-abbr"><a href="#abbr_TSF">TSF</a></abbr> shall authorize <abbr class="dyn-abbr"><a href="#abbr_EST">EST</a></abbr> clients based on [selection: the authenticated client
9202
9202
certificate is issued by the same issuer that asserts id-kp-cmcRA in its extended
<a href="#FCS_HTTPS_EXT.1">FCS_HTTPS_EXT.1</a> to establish a secure connection with an <abbr class="dyn-abbr"><a href="#abbr_EST">EST</a></abbr> client<a id="period_2461" href="#period_2461">. </a><br><br>
9212
9212
This <abbr class="dyn-abbr"><a href="#abbr_SFR">SFR</a></abbr> is included in the <abbr class="dyn-abbr"><a href="#abbr_ST">ST</a></abbr> if TODO<a id="period_2462" href="#period_2462">. </a>If this requirement is included in the <abbr class="dyn-abbr"><a href="#abbr_ST">ST</a></abbr>, the <abbr class="dyn-abbr"><a href="#abbr_ST">ST</a></abbr> author includes FCS_TLSS_EXT.1 (as defined in the <a href="https://www.niap-ccevs.org/protectionprofiles/465">Functional Package for Transport Layer Security (TLS),
For <a href="#FIA_ESTS_EXT.1.3">FIA_ESTS_EXT.1.3</a> as defined in <a href="https://www.niap-ccevs.org/protectionprofiles/511">Functional Package for X.509,
9216
9216
version
9217
9217
1.0</a>, the <abbr class="dyn-abbr"><a href="#abbr_ST">ST</a></abbr> author selects the method used to authenticate
The <abbr class="dyn-abbr"><a href="#abbr_TSF">TSF</a></abbr> shall <span class="refinement">use
9705
9705
[<b>selection</b>: <span class="selectable-content" id="ftp-itc-https"><abbr class="dyn-abbr"><a href="#abbr_HTTPS">HTTPS</a></abbr></span>, <span class="selectable-content" id="ftp-itc-ipsec"><abbr class="dyn-abbr"><a href="#abbr_IPsec">IPsec</a></abbr></span>, <span class="selectable-content" id="ftp-itc-tls"><abbr class="dyn-abbr"><a href="#abbr_TLS">TLS</a></abbr> as defined in the <a href="https://www.niap-ccevs.org/protectionprofiles/465">Functional Package for Transport Layer Security (TLS),
9706
9706
version
9707
-
2.0</a></span>, <span class="selectable-content" id="ftp-itc-ssh"><abbr class="dyn-abbr"><a href="#abbr_SSH">SSH</a></abbr> as defined in the <a href="https://www.niap-ccevs.org/protectionprofiles/515">Functional Package for Secure Shell (SSH),
9707
+
2.1</a></span>, <span class="selectable-content" id="ftp-itc-ssh"><abbr class="dyn-abbr"><a href="#abbr_SSH">SSH</a></abbr> as defined in the <a href="https://www.niap-ccevs.org/protectionprofiles/515">Functional Package for Secure Shell (SSH),
2.0</a><a id="period_2609" href="#period_2609">. </a> If the <abbr class="dyn-abbr"><a href="#abbr_ST">ST</a></abbr> author selects <abbr class="dyn-abbr"><a href="#abbr_TLS">TLS</a></abbr>, the <abbr class="dyn-abbr"><a href="#abbr_TSF">TSF</a></abbr> shall be validated against the <a href="https://www.niap-ccevs.org/protectionprofiles/465">Functional Package for Transport Layer Security (TLS),
0 commit comments