Skip to content

Commit d48d891

Browse files
authored
Update gpcp.xml
Updates address issues 73 and 81 as well as a section flagged for future discussion. Changes are based on live edits from 7/17/2025 meeting.
1 parent c52ddfd commit d48d891

File tree

1 file changed

+8
-8
lines changed

1 file changed

+8
-8
lines changed

input/gpcp.xml

Lines changed: 8 additions & 8 deletions
Original file line numberDiff line numberDiff line change
@@ -1103,7 +1103,8 @@
11031103
<depends on-incl="sfr-fau-gen-1"/>
11041104
<f-element id="fau-stg-5e1">
11051105
<title>
1106-
The TSF shall [<h:i>overwrite the oldest stored audit records</h:i>] if the audit data storage is full.
1106+
The TSF shall optionally notify the administrator or user that storage is full and
1107+
[<h:i>overwrite the oldest stored audit records</h:i>] if the audit data storage is full.
11071108
</title>
11081109
<note role="application">
11091110
This SFR must be included in the ST if FAU_GEN.1 is claimed.
@@ -7944,8 +7945,7 @@
79447945
<Tests>
79457946
The evaluator shall perform the following test:<h:p/>
79467947
The evaluator shall attempt to overwrite or modify the platform firmware without invoking one of
7947-
the update mechanisms specified in FPT_TUD_EXT.1 (e.g., using a modified Linux boot loader such
7948-
as GRUB that attempts to write to the memory where platform firmware is stored). The test succeeds
7948+
the update mechanisms specified in FPT_TUD_EXT.1. The test succeeds
79497949
if the attempts to overwrite platform firmware fail. The evaluator shall attempt at least three
79507950
such tests--one that attempts to overwrite the first platform firmware that executes after boot,
79517951
one that targets the secure update mechanism (if implemented), and one that targets firmware
@@ -8017,8 +8017,7 @@
80178017
<selectable id="sel-rot2-hash">computation and verification of a hash by trusted code/data</selectable>
80188018
<selectable id="sel-rot2-digsig">verification of a digital signature by trusted code/data</selectable>
80198019
<selectable>measurement and verification by trusted code/data</selectable>
8020-
<selectable><h:mark>measurement and verification by an on-platform dedicated security component</h:mark></selectable>
8021-
<selectable><h:mark>measurement and verification by an off-platform entity</h:mark></selectable>
8020+
<selectable><h:mark>measurement by an on-platform dedicated security component and verification by an off-platform entity</h:mark></selectable>
80228021
</selectables>.<h:mark>(see Issues 79 and 80)</h:mark>
80238022
</title>
80248023
<ext-comp-def-title>
@@ -8035,15 +8034,15 @@
80358034
Otherwise, integrity must be extended through cryptographic means: either through hashes
80368035
or digital signatures computed and verified by firmware that is trusted because it has
80378036
previously had its integrity verified or is itself a Root of Trust. Verification can be performed
8038-
by TOE components such as management controllers or non-TOE trusted entities.<h:p/>
8037+
by TOE components such as management controllers or non-TOE trusted entities such as remote verifiers.<h:p/>
80398038
If "<h:i>computation and verification of a hash by trusted code/data</h:i>" is selected, then FCS_COP.1/Hash must be claimed.<h:p/>
80408039
If "<h:i>verification of a digital signature by trusted code/data</h:i>" is selected, then FCS_COP.1/SigVer must be claimed.
80418040
</note>
80428041
</f-element>
80438042
<f-element id="fpt-rot-ext-2e2">
80448043
<title>The TOE shall take the following actions if an integrity check specified in FPT_ROT_EXT.2.1 fails:
80458044
<h:ol type="1">
8046-
<h:li>Halt,</h:li>
8045+
<h:li>Stop all execution, or</h:li>
80478046
<h:li>Notify an
80488047
<selectables>
80498048
<selectable id="sel-rot2-admin-notify">Administrator</selectable>
@@ -8054,7 +8053,8 @@
80548053
<selectable><assignable>other notification method(s)</assignable></selectable>
80558054
</selectables>, and</h:li>
80568055
<h:li><selectables linebreak="yes" onlyone="yes">
8057-
<selectable>Stop all execution and shut down</selectable>
8056+
<selectable>Stop all execution</selectable>
8057+
<selectable>Shut down, or</selectable>
80588058
<selectable id="sel-rot2-recovery">Initiate a recovery process as specified in FPT_RVR_EXT.1</selectable>
80598059
</selectables><h:br/>
80608060
<selectables linebreak="yes" onlyone="yes">

0 commit comments

Comments
 (0)