|
5581 | 5581 | comparison of the DN, the evaluator shall change a single bit in the DN (preferably, in an Object Identifier |
5582 | 5582 | (OID) in the DN) and verify that the IKEv2 authentication fails. To demonstrate a comparison of DN values, |
5583 | 5583 | the evaluator shall change any one of the four DN values and verify that the IKEv2 authentication fails.</test> |
5584 | | - <test>[conditional] If the TOE supports both IPv4 and IPv6 and supports IP address identifier types, the |
5585 | | - evaluator must repeat test 1 and 2 with both IPv4 address identifiers and IPv6 identifiers. Additionally, |
5586 | | - the evaluator shall verify that the TOE verifies that the IP header matches the identifiers by setting the |
5587 | | - presented identifiers and the reference identifier with the same IP address that differs from the actual IP |
5588 | | - address of the peer in the <test>[conditional] If, according to the TSS, the TOE performs comparisons between the peer’s ID |
5589 | | - payload and the peer’s certificate, the evaluator shall repeat the following test for each combination of |
5590 | | - supported identifier typeIP headers and verifying that the IKEv2 authentication fails.</test> |
5591 | | -s and supported certificate fields (as above). The evaluator shall configure the |
5592 | | - peer to present a different ID payload than the field in the peer’s presented certificate and verify that the |
5593 | | - TOE fails to authenticate the IKE peer.</test> |
| 5584 | + <test>[conditional] If the TOE supports both IPv4 and IPv6 and supports IP address identifier types, the evaluator |
| 5585 | + must repeat test 1 and 2 with both IPv4 address identifiers and IPv6 identifiers. Additionally, the evaluator |
| 5586 | + shall verify that the TOE verifies that the IP header matches the identifiers by setting the presented identifiers |
| 5587 | + and the reference identifier with the same IP address that differs from the actual IP address of the peer in the |
| 5588 | + IP headers and verifying that the IKE authentication fails.</test> |
| 5589 | + <test>[conditional] If, according to the TSS, the TOE performs comparisons between the peer’s ID payload and the |
| 5590 | + peer’s certificate, the evaluator shall repeat the following test for each combination of supported identifier |
| 5591 | + types and supported certificate fields (as above). The evaluator shall configure the peer to present a different |
| 5592 | + ID payload than the field in the peer’s presented certificate and verify that the TOE fails to authenticate the IKE peer.</test> |
5594 | 5593 | </testlist> |
5595 | 5594 | </Tests> |
5596 | 5595 | </aactivity> |
|
0 commit comments