Skip to content

Commit 82a29ad

Browse files
committed
Deploying to gh-pages from @ f652944 🚀
1 parent a38bdf1 commit 82a29ad

File tree

6 files changed

+3366
-1079
lines changed

6 files changed

+3366
-1079
lines changed

index.html

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,5 +1,5 @@
11
<html><head><title>Listing</title></head><body>
2-
Fri Aug 15 17:35:31 UTC 2025
2+
Tue Aug 19 15:41:28 UTC 2025
33
<br/><ol>
44
<li><a href='.'>.</a></li>
55
<li><a href='./master/pdf_count.svg'>./master/pdf_count.svg</a></li>

master/certauth-release-linkable.html

Lines changed: 10 additions & 10 deletions
Original file line numberDiff line numberDiff line change
@@ -992,7 +992,7 @@ <h1 class="indexable" data-level="1" id="Conformance_Claims">2 Conformance Claim
992992
This <abbr class="dyn-abbr"><a href="#abbr_PP">PP</a></abbr> does not claim conformance to
993993
any Protection Profile<a id="period_128" href="#period_128">. </a> </dd><p></p><dd>There are no <abbr class="dyn-abbr"><a href="#abbr_PP">PPs</a></abbr> or <abbr class="dyn-abbr"><a href="#abbr_PP">PP</a></abbr>-Modules that are allowed in a <abbr class="dyn-abbr"><a href="#abbr_PP-Configuration">PP-Configuration</a></abbr>
994994
with this <abbr class="dyn-abbr"><a href="#abbr_PP">PP</a></abbr><a id="period_129" href="#period_129">. </a></dd><dt>Package Claim</dt><p></p><dd><ul><li>This <abbr class="dyn-abbr"><a href="#abbr_PP">PP</a></abbr> is
995-
Functional Package for <abbr class="dyn-abbr"><a href="#abbr_TLS">TLS</a></abbr>, version 2.0 conformant<a id="period_130" href="#period_130">. </a></li><li>This <abbr class="dyn-abbr"><a href="#abbr_PP">PP</a></abbr> is
995+
Functional Package for <abbr class="dyn-abbr"><a href="#abbr_TLS">TLS</a></abbr>, version 2.1 conformant<a id="period_130" href="#period_130">. </a></li><li>This <abbr class="dyn-abbr"><a href="#abbr_PP">PP</a></abbr> is
996996
Functional Package for Secure Shell, version 2.0 conformant<a id="period_131" href="#period_131">. </a></li><li>This <abbr class="dyn-abbr"><a href="#abbr_PP">PP</a></abbr> is
997997
Functional Package for X.509, version 1.0 conformant<a id="period_132" href="#period_132">. </a></li><li>This <abbr class="dyn-abbr"><a href="#abbr_PP">PP</a></abbr> is
998998
Assurance Package for Flaw Remediation, version 1.0 conformant<a id="period_133" href="#period_133">. </a></li></ul></dd><p></p><dd>
@@ -4180,7 +4180,7 @@ <h3 id="ftp" class="indexable" data-level="3">5.1.10 Class: Trusted Path/Channel
41804180
version
41814181
2.0</a></span>, <span class="selectable-content" id="ftp-trp-tls"><abbr class="dyn-abbr"><a href="#abbr_TLS">TLS</a></abbr> as defined in the <a href="https://www.niap-ccevs.org/protectionprofiles/465">Functional Package for Transport Layer Security (TLS),
41824182
version
4183-
2.0</a></span>] to </span>
4183+
2.1</a></span>] to </span>
41844184
provide a <span class="refinement">trusted</span> communication path between itself and
41854185
[<i>remote <span class="refinement">subscribers and privileged</span></i>] users
41864186
that is logically distinct from other
@@ -9069,7 +9069,7 @@ <h2 id="optional-reqs" class="indexable" data-level="2">A.1 Strictly Optional R
90699069
[<b>selection</b>: <span class="selectable-content" id="_s_400">administrator</span>, <span class="selectable-content" id="_s_401"><abbr class="dyn-abbr"><a href="#abbr_CA">CA</a></abbr> operations staff</span>]</span></li><li style=""><span class="selectable-content" id="_s_402">an explicit TA database populated via a <abbr class="dyn-abbr"><a href="#abbr_TLS">TLS</a></abbr>-authenticated <abbr class="dyn-abbr"><a href="#abbr_EST">EST</a></abbr> <abbr class="dyn-abbr"><a href="#abbr_CA">CA</a></abbr>
90709070
certificate request in accordance with <abbr class="dyn-abbr"><a href="#abbr_RFC">RFC</a></abbr> 7030 section 4.1.2 and FCS_TLSC_EXT.2 (as defined in the <a href="https://www.niap-ccevs.org/protectionprofiles/465">Functional Package for Transport Layer Security (TLS),
90719071
version
9072-
2.0</a>)
9072+
2.1</a>)
90739073
</span></li></ul>]<a id="period_2427" href="#period_2427">. </a> </div></div>
90749074
<div class="element"><div class="reqid" id="FIA_ESTC_EXT.1.3"><a href="#FIA_ESTC_EXT.1.3" class="abbr">FIA_ESTC_EXT.1.3</a></div><div class="reqdesc">
90759075
The <abbr class="dyn-abbr"><a href="#abbr_TSF">TSF</a></abbr> shall authenticate <abbr class="dyn-abbr"><a href="#abbr_EST">EST</a></abbr> servers using X.509 certificates that chain to trust
@@ -9084,14 +9084,14 @@ <h2 id="optional-reqs" class="indexable" data-level="2">A.1 Strictly Optional R
90849084
[<b>selection</b>: <ul><li style=""><span class="selectable-content" id="_s_405"><abbr class="dyn-abbr"><a href="#abbr_HTTP">HTTP</a></abbr> basic authentication transported over <abbr class="dyn-abbr"><a href="#abbr_TLS">TLS</a></abbr> in accordance with <abbr class="dyn-abbr"><a href="#abbr_RFC">RFC</a></abbr> 7030
90859085
section 3.2.3 and FCS_TLSC_EXT.2 (as defined in the <a href="https://www.niap-ccevs.org/protectionprofiles/465">Functional Package for Transport Layer Security (TLS),
90869086
version
9087-
2.0</a>)<a id="period_2429" href="#period_2429">. </a></span></li><li style=""><span class="selectable-content" id="_s_406"><abbr class="dyn-abbr"><a href="#abbr_HTTP">HTTP</a></abbr> digest authentication using a cryptographic hash algorithm in
9087+
2.1</a>)<a id="period_2429" href="#period_2429">. </a></span></li><li style=""><span class="selectable-content" id="_s_406"><abbr class="dyn-abbr"><a href="#abbr_HTTP">HTTP</a></abbr> digest authentication using a cryptographic hash algorithm in
90889088
accordance with FCS_COP.1/HASH, transported over <abbr class="dyn-abbr"><a href="#abbr_TLS">TLS</a></abbr> in accordance with
90899089
<abbr class="dyn-abbr"><a href="#abbr_RFC">RFC</a></abbr> 7030 section 3.2.3 and FCS_TLSC_EXT.2 (as defined in the <a href="https://www.niap-ccevs.org/protectionprofiles/465">Functional Package for Transport Layer Security (TLS),
90909090
version
9091-
2.0</a>)<a id="period_2430" href="#period_2430">. </a></span></li><li style=""><span class="selectable-content" id="_s_407">Certificate-based authentication in accordance with <abbr class="dyn-abbr"><a href="#abbr_RFC">RFC</a></abbr> 7030 section 3.3.2
9091+
2.1</a>)<a id="period_2430" href="#period_2430">. </a></span></li><li style=""><span class="selectable-content" id="_s_407">Certificate-based authentication in accordance with <abbr class="dyn-abbr"><a href="#abbr_RFC">RFC</a></abbr> 7030 section 3.3.2
90929092
and FCS_TLSC_EXT.2 (as defined in the <a href="https://www.niap-ccevs.org/protectionprofiles/465">Functional Package for Transport Layer Security (TLS),
90939093
version
9094-
2.0</a>) using
9094+
2.1</a>) using
90959095
[<b>assignment</b>:
90969096
<span class="assignable-content">a pre-existing certificate authorized by the <abbr class="dyn-abbr"><a href="#abbr_EST">EST</a></abbr> server</span>]
90979097
</span></li></ul>]<a id="period_2431" href="#period_2431">. </a> </div></div>
@@ -9196,7 +9196,7 @@ <h2 id="optional-reqs" class="indexable" data-level="2">A.1 Strictly Optional R
91969196
accordance with <a href="#FCS_COP.1/Hash">FCS_COP.1/Hash</a> and <abbr class="dyn-abbr"><a href="#abbr_RFC">RFC</a></abbr> 7030 section 3.2.3;</span></li><li style=""><span class="selectable-content" id="_s_410"><abbr class="dyn-abbr"><a href="#abbr_TLS">TLS</a></abbr> certificate-based mutual authentication in accordance with
91979197
<abbr class="dyn-abbr"><a href="#abbr_RFC">RFC</a></abbr> 7030 section 3.3.2 and FCS_TLSS_EXT.1 (as defined in the <a href="https://www.niap-ccevs.org/protectionprofiles/465">Functional Package for Transport Layer Security (TLS),
91989198
version
9199-
2.0</a>)<a id="period_2457" href="#period_2457">. </a></span></li></ul>]<a id="period_2458" href="#period_2458">. </a> </div></div>
9199+
2.1</a>)<a id="period_2457" href="#period_2457">. </a></span></li></ul>]<a id="period_2458" href="#period_2458">. </a> </div></div>
92009200
<div class="element"><div class="reqid" id="FIA_ESTS_EXT.1.3"><a href="#FIA_ESTS_EXT.1.3" class="abbr">FIA_ESTS_EXT.1.3</a></div><div class="reqdesc">
92019201
The <abbr class="dyn-abbr"><a href="#abbr_TSF">TSF</a></abbr> shall authorize <abbr class="dyn-abbr"><a href="#abbr_EST">EST</a></abbr> clients based on [selection: the authenticated client
92029202
certificate is issued by the same issuer that asserts id-kp-cmcRA in its extended
@@ -9211,7 +9211,7 @@ <h2 id="optional-reqs" class="indexable" data-level="2">A.1 Strictly Optional R
92119211
<a href="#FCS_HTTPS_EXT.1">FCS_HTTPS_EXT.1</a> to establish a secure connection with an <abbr class="dyn-abbr"><a href="#abbr_EST">EST</a></abbr> client<a id="period_2461" href="#period_2461">. </a><br><br>
92129212
This <abbr class="dyn-abbr"><a href="#abbr_SFR">SFR</a></abbr> is included in the <abbr class="dyn-abbr"><a href="#abbr_ST">ST</a></abbr> if TODO<a id="period_2462" href="#period_2462">. </a>If this requirement is included in the <abbr class="dyn-abbr"><a href="#abbr_ST">ST</a></abbr>, the <abbr class="dyn-abbr"><a href="#abbr_ST">ST</a></abbr> author includes FCS_TLSS_EXT.1 (as defined in the <a href="https://www.niap-ccevs.org/protectionprofiles/465">Functional Package for Transport Layer Security (TLS),
92139213
version
9214-
2.0</a>)<a id="period_2463" href="#period_2463">. </a><br><br>
9214+
2.1</a>)<a id="period_2463" href="#period_2463">. </a><br><br>
92159215
For <a href="#FIA_ESTS_EXT.1.3">FIA_ESTS_EXT.1.3</a> as defined in <a href="https://www.niap-ccevs.org/protectionprofiles/511">Functional Package for X.509,
92169216
version
92179217
1.0</a>, the <abbr class="dyn-abbr"><a href="#abbr_ST">ST</a></abbr> author selects the method used to authenticate
@@ -9704,7 +9704,7 @@ <h2 id="optional-reqs" class="indexable" data-level="2">A.1 Strictly Optional R
97049704
The <abbr class="dyn-abbr"><a href="#abbr_TSF">TSF</a></abbr> shall <span class="refinement">use
97059705
[<b>selection</b>: <span class="selectable-content" id="ftp-itc-https"><abbr class="dyn-abbr"><a href="#abbr_HTTPS">HTTPS</a></abbr></span>, <span class="selectable-content" id="ftp-itc-ipsec"><abbr class="dyn-abbr"><a href="#abbr_IPsec">IPsec</a></abbr></span>, <span class="selectable-content" id="ftp-itc-tls"><abbr class="dyn-abbr"><a href="#abbr_TLS">TLS</a></abbr> as defined in the <a href="https://www.niap-ccevs.org/protectionprofiles/465">Functional Package for Transport Layer Security (TLS),
97069706
version
9707-
2.0</a></span>, <span class="selectable-content" id="ftp-itc-ssh"><abbr class="dyn-abbr"><a href="#abbr_SSH">SSH</a></abbr> as defined in the <a href="https://www.niap-ccevs.org/protectionprofiles/515">Functional Package for Secure Shell (SSH),
9707+
2.1</a></span>, <span class="selectable-content" id="ftp-itc-ssh"><abbr class="dyn-abbr"><a href="#abbr_SSH">SSH</a></abbr> as defined in the <a href="https://www.niap-ccevs.org/protectionprofiles/515">Functional Package for Secure Shell (SSH),
97089708
version
97099709
2.0</a></span>] to</span>
97109710
provide a <span class="refinement">trusted</span>
@@ -9743,7 +9743,7 @@ <h2 id="optional-reqs" class="indexable" data-level="2">A.1 Strictly Optional R
97439743
version
97449744
2.0</a><a id="period_2609" href="#period_2609">. </a> If the <abbr class="dyn-abbr"><a href="#abbr_ST">ST</a></abbr> author selects <abbr class="dyn-abbr"><a href="#abbr_TLS">TLS</a></abbr>, the <abbr class="dyn-abbr"><a href="#abbr_TSF">TSF</a></abbr> shall be validated against the <a href="https://www.niap-ccevs.org/protectionprofiles/465">Functional Package for Transport Layer Security (TLS),
97459745
version
9746-
2.0</a><a id="period_2610" href="#period_2610">. </a><br><br>
9746+
2.1</a><a id="period_2610" href="#period_2610">. </a><br><br>
97479747
This requirement implies that not only are communications protected when they
97489748
are initially established, but also on resumption after an interruption<a id="period_2611" href="#period_2611">. </a>It may be
97499749
the case that some part of the <abbr class="dyn-abbr"><a href="#abbr_TOE">TOE</a></abbr> setup involves manually setting up tunnels to

0 commit comments

Comments
 (0)