|
1103 | 1103 | <depends on-incl="sfr-fau-gen-1"/> |
1104 | 1104 | <f-element id="fau-stg-5e1"> |
1105 | 1105 | <title> |
1106 | | - The TSF shall [<h:i>overwrite the oldest stored audit records</h:i>] if the audit data storage is full. |
| 1106 | + The TSF shall optionally notify the administrator or user that storage is full and |
| 1107 | + [<h:i>overwrite the oldest stored audit records</h:i>] if the audit data storage is full. |
1107 | 1108 | </title> |
1108 | 1109 | <note role="application"> |
1109 | 1110 | This SFR must be included in the ST if FAU_GEN.1 is claimed. |
|
7944 | 7945 | <Tests> |
7945 | 7946 | The evaluator shall perform the following test:<h:p/> |
7946 | 7947 | The evaluator shall attempt to overwrite or modify the platform firmware without invoking one of |
7947 | | - the update mechanisms specified in FPT_TUD_EXT.1 (e.g., using a modified Linux boot loader such |
7948 | | - as GRUB that attempts to write to the memory where platform firmware is stored). The test succeeds |
| 7948 | + the update mechanisms specified in FPT_TUD_EXT.1. The test succeeds |
7949 | 7949 | if the attempts to overwrite platform firmware fail. The evaluator shall attempt at least three |
7950 | 7950 | such tests--one that attempts to overwrite the first platform firmware that executes after boot, |
7951 | 7951 | one that targets the secure update mechanism (if implemented), and one that targets firmware |
|
8017 | 8017 | <selectable id="sel-rot2-hash">computation and verification of a hash by trusted code/data</selectable> |
8018 | 8018 | <selectable id="sel-rot2-digsig">verification of a digital signature by trusted code/data</selectable> |
8019 | 8019 | <selectable>measurement and verification by trusted code/data</selectable> |
8020 | | - <selectable><h:mark>measurement and verification by an on-platform dedicated security component</h:mark></selectable> |
8021 | | - <selectable><h:mark>measurement and verification by an off-platform entity</h:mark></selectable> |
| 8020 | + <selectable><h:mark>measurement by an on-platform dedicated security component and verification by an off-platform entity</h:mark></selectable> |
8022 | 8021 | </selectables>.<h:mark>(see Issues 79 and 80)</h:mark> |
8023 | 8022 | </title> |
8024 | 8023 | <ext-comp-def-title> |
|
8035 | 8034 | Otherwise, integrity must be extended through cryptographic means: either through hashes |
8036 | 8035 | or digital signatures computed and verified by firmware that is trusted because it has |
8037 | 8036 | previously had its integrity verified or is itself a Root of Trust. Verification can be performed |
8038 | | - by TOE components such as management controllers or non-TOE trusted entities.<h:p/> |
| 8037 | + by TOE components such as management controllers or non-TOE trusted entities such as remote verifiers.<h:p/> |
8039 | 8038 | If "<h:i>computation and verification of a hash by trusted code/data</h:i>" is selected, then FCS_COP.1/Hash must be claimed.<h:p/> |
8040 | 8039 | If "<h:i>verification of a digital signature by trusted code/data</h:i>" is selected, then FCS_COP.1/SigVer must be claimed. |
8041 | 8040 | </note> |
8042 | 8041 | </f-element> |
8043 | 8042 | <f-element id="fpt-rot-ext-2e2"> |
8044 | 8043 | <title>The TOE shall take the following actions if an integrity check specified in FPT_ROT_EXT.2.1 fails: |
8045 | 8044 | <h:ol type="1"> |
8046 | | - <h:li>Halt,</h:li> |
| 8045 | + <h:li>Stop all execution, or</h:li> |
8047 | 8046 | <h:li>Notify an |
8048 | 8047 | <selectables> |
8049 | 8048 | <selectable id="sel-rot2-admin-notify">Administrator</selectable> |
|
8054 | 8053 | <selectable><assignable>other notification method(s)</assignable></selectable> |
8055 | 8054 | </selectables>, and</h:li> |
8056 | 8055 | <h:li><selectables linebreak="yes" onlyone="yes"> |
8057 | | - <selectable>Stop all execution and shut down</selectable> |
| 8056 | + <selectable>Stop all execution</selectable> |
| 8057 | + <selectable>Shut down, or</selectable> |
8058 | 8058 | <selectable id="sel-rot2-recovery">Initiate a recovery process as specified in FPT_RVR_EXT.1</selectable> |
8059 | 8059 | </selectables><h:br/> |
8060 | 8060 | <selectables linebreak="yes" onlyone="yes"> |
|
0 commit comments