Kaseya US Sales, LLC Virtual System Administrator Cryptographic Module Software Version: 1.0
|
|
|
- Douglas Floyd
- 10 years ago
- Views:
Transcription
1 Kaseya US Sales, LLC Virtual System Administrator Cryptographic Module Software Version: 1.0 FIPS Non-Proprietary Security Policy FIPS Security Level: 1 Document Version: 1.0 Prepared for: Prepared by: Kaseya US Sales, LLC 901 N. Glebe Road, Suite 1010 Arlington, VA United States of America Corsec Security, Inc Lee Jackson Memorial Hwy, Suite 220 Fairfax, VA United States of America Phone: +1 (415) Phone: +1 (703)
2 Table of Contents 1 INTRODUCTION PURPOSE REFERENCES DOCUMENT ORGANIZATION KASEYA VSACM OVERVIEW Virtual System Administrator Server Virtual System Administrator Agent SECURITY VSA Server Security Agent Security MODULE SPECIFICATION MODULE INTERFACES ROLES, SERVICES, AND AUTHENTICATION Crypto Officer Role User Role PHYSICAL SECURITY OPERATIONAL ENVIRONMENT CRYPTOGRAPHIC KEY MANAGEMENT EMI/EMC SELF-TESTS DESIGN ASSURANCE MITIGATION OF OTHER ATTACKS SECURE OPERATION INITIAL SETUP CRYPTO OFFICER GUIDANCE Initialization Management Non-Approved Mode of Operation USER GUIDANCE ACRONYMS Table of Figures FIGURE 1 KASEYA VIRTUAL SYSTEM ADMINISTRATOR SYSTEM OVERVIEW... 7 FIGURE 2 LOGICAL BLOCK DIAGRAM... 8 FIGURE 3 GPC BLOCK DIAGRAM... 9 List of Tables TABLE 1 SECURITY LEVEL PER FIPS SECTION... 8 TABLE 2 FIPS LOGICAL INTERFACES TABLE 3 MAPPING OF CRYPTO OFFICER ROLE S SERVICES TO INPUTS, OUTPUTS, CSPS (CRITICAL SECURITY PARAMETER), AND TYPE OF ACCESS TABLE 4 MAPPING OF USER ROLE S SERVICES TO INPUTS, OUTPUTS, CSPS, AND TYPE OF ACCESS TABLE 5 FIPS-APPROVED ALGORITHM IMPLEMENTATIONS TABLE 6 LIST OF CRYPTOGRAPHIC KEYS, CRYPTOGRAPHIC KEY COMPONENTS, AND CSPS TABLE 7 POWER-UP TESTS AND DESCRIPTIONS TABLE 8 CONDITIONAL TESTS AND DESCRIPTIONS TABLE 9 CRITICAL FUNCTION TESTS AND DESCRIPTIONS Virtual System Administrator Cryptographic Module Page 2 of 21
3 TABLE 10 ACRONYMS Virtual System Administrator Cryptographic Module Page 3 of 21
4 1 Introduction 1.1 Purpose This is a non-proprietary Cryptographic Module Security Policy for the Virtual System Administrator Cryptographic Module from Kaseya US Sales, LLC. This Security Policy describes how the Virtual System Administrator Cryptographic Module meets the security requirements of FIPS (Federal Information Processing Standards) and how to run the module in a secure FIPS mode. This policy was prepared as part of the Level 1 FIPS validation of the module. FIPS (Federal Information Processing Standards Publication Security Requirements for Cryptographic Modules) details the U.S. and Canadian Government requirements for cryptographic modules. More information about the FIPS standard and validation program is available on the Cryptographic Module Validation Program (CMVP) website, which is maintained by National Institute of Standards and Technology (NIST) and Communication Security Establishment Canada (CSEC): The Virtual System Administrator Cryptographic Module (VSACM) is referred to in this document as the Kaseya VSACM, crypto module, or the module. 1.2 References This document deals only with operations and capabilities of the module in the technical terms of a FIPS cryptographic module security policy. More information is available on the module from the following sources: The Kaseya website contains information on the full line of products from Kaseya. The CMVP website ( contains contact information for answers to technical or sales-related questions for the module. 1.3 Document Organization The Security Policy document is one document in a FIPS Submission Package provided to the Cryptographic Module Testing Laboratory. In addition to this document, the Submission Package contains: Vendor Evidence document Finite State Model Other supporting documentation as additional references This Security Policy and the other validation submission documentation were produced by Corsec Security, Inc. under contract to Kaseya. With the exception of this Non-Proprietary Security Policy, the FIPS Validation Documentation is proprietary to Kaseya and is releasable only under appropriate non-disclosure agreements. For access to these documents, please contact Kaseya. Kaseya Virtual System Administrator Cryptographic Module Page 4 of 21
5 2 Kaseya VSACM 2.1 Overview Kaseya was founded with the goal of simplifying and automating Information Technology (IT) management, providing a single congruent and highly integrated solution which covers an ever-expanding set of IT management tasks. The Kaseya Virtual System Administrator (VSA) product is intended to satisfy this goal, providing automated, secure remote monitoring, management, and protection of IT resources. The Kaseya Virtual System Administrator provides an IT automation framework allowing IT managers to proactively monitor, manage, maintain, and protect distributed IT resources using a single, integrated webbased interface. The services offered by Kaseya Virtual System Administrator are ever-broadening; as IT management services needs increase, so do the tools and services provided by the framework. In addition, the number of managed endpoints, which in this context are individual machines (laptops, desktops, servers, etc.), is also rapidly expanding. The current number of managed endpoints supported is approximately 20,000; however, Kaseya is moving quickly towards the ability to manage an unlimited number of endpoints Virtual System Administrator Server The VSA Server is the central management component of the Kaseya Virtual System Administrator. As shown in Figure 1, the VSA Server includes the following components: KServer, which is the main Kaseya management application Microsoft IIS 1 ASP 2 framework Microsoft SQL 3 server, which communicates with a database through OLEDB (Object Linking and Embedding Database) and ODBC (Open Database Connectivity) Administrator authentication functionality implemented in JavaScript The primary VSA Server administrative interface is provided via a web-based application, allowing remote access to the majority of administrative services. The web pages for the web-based Graphical User Interface (GUI) are served to administrator workstations via HTTP 4 or HTTPS 5. In addition, the VSA also provides an API 6, allowing third-party application integration. The API exposes the majority of the actions and functionality available from the web GUI. The KServer component contains the core set of VSA Server functionality, providing policy configuration and deployment to the Agents, who then use the policies to automatically manage their host endpoint. By using the management interfaces provided by the KServer component the following Kaseya Virtual System Administrator management services are realized: Endpoint policy creation and deployment Endpoint monitoring and auditing Automatic Agent deployment for new endpoints Endpoint antivirus and malware management Endpoint patch management 1 Internet Information Services 2 Active Server Pages 3 Structured Query Language 4 Hypertext Transfer Protocol 5 Hypertext Transfer Protocol Secure 6 Application Programming Interface Kaseya Virtual System Administrator Cryptographic Module Page 5 of 21
6 Endpoint performance management The KServer component also allows an operator to perform real-time audits, virus scans, and management actions such as manually setting up tasks for individual Agents Virtual System Administrator Agent The Kaseya Virtual System Administrator Agents are software applications installed on the managed endpoints (Macintosh, Windows, or Linux-based General Purpose Computer (GPC)) and servers. Agents are the components which enact the endpoint management activities driven by VSA Server activities. The Agent management activities driven by the VSA Server typically include the following: Automated software patching Automated network policy enforcement Automated antivirus scans and definition updates Automated data backup and recovery Automated system inventory, monitoring, and reporting Remote control services All Agent activities are driven by policies or requested tasks generated on the Virtual System Administrator Server; however, the Agent must first connect to the VSA Server. The VSA Server component acts solely as a server and will never initiate a connection to the Agent. 2.2 Security The Kaseya Virtual System Administrator includes security functionality which provides both confidentiality and data authentication techniques to securely manage endpoints. This security functionality is described at a high-level in the following two sections VSA Server Security The VSA Server uses security functionality over two different interfaces: (1) a TCP/IP 7 connection to securely communicate with and authenticate to the Agents and (2) the administrator HTTP/HTTPS interface which requires authentication: Agent-to-VSA Server communication: All data sent between the VSA Server and Agents is sent via Transmission Control Protocol (TCP). Before the data is sent, Agents are first authenticated to the VSA Server using a proprietary shared secret-based authentication mechanism which incorporates Secure Hashing Algorithm (SHA-256). Authenticated data is sent encrypted using the Advanced Encryption Standard (AES) block cipher within the VSA Server or Agent host computer and then sent over the TCP connection. In general, the data will consist of Agent control input, IT management policies, and Agent reporting data. Administrator Authentication: Services on the VSA Server can be accessed either locally or remotely. In order to securely authenticate an operator, the VSA Server uses a proprietary authentication mechanism incorporating the SHA-256. Within this mechanism, passwords entered on the Administrator PC (Personal Computer) are SHA-256 hashed before they are output. This ensures that the passwords are never output; only secure hashes of the passwords are output. 7 Transmission Control Protocol/Internet Protocol Kaseya Virtual System Administrator Cryptographic Module Page 6 of 21
7 2.2.2 Agent Security Agents communicate securely with the VSA Server over a TCP/IP port (default TCP port is 5721). The security provided over this interface is provided by a Kaseya-proprietary protocol which utilizes AES to provide confidentiality and authentication of the Agents to the VSA Server. Authentication: Authentication is provided via a proprietary shared secret-based authentication mechanism which incorporates SHA-256. Confidential Communication: All communications provided between the Agent and VSA Server are encrypted using AES, which is implemented by the Kaseya VSA Cryptographic Module. Figure 1 provides an overview of the VSA system components and configuration, while Figure 2 below provides a logical diagram of the VSACM. Note that the cryptographic boundary is depicted in each figure with a red dotted line. Administrator PC Workstation w/ Agent VSA Server Web browser Agent Kaseya VSA Cryptographic Module TCP (Kaseya proprietary protocol) Kserver Kaseya VSA Cryptographic Module HTTP/HTTPS GPC Operating System Operating System ASP framework Microsoft SQL Server Database Microsoft IIS Microsoft Windows Operating System OLEDB/ODBC Microsoft SQL Server Microsoft Windows Operating System Figure 1 Kaseya Virtual System Administrator System Overview Kaseya Virtual System Administrator Cryptographic Module Page 7 of 21
8 Cryptographic Boundary Kaseya HMAC Value File Kaseya VSA Cryptographic Library Kaseya Wrapper Library Application Figure 2 Logical Block Diagram The Virtual System Administrator Cryptographic Module is validated at the following FIPS Section levels: Table 1 Security Level Per FIPS Section Section Section Title Level 1 Cryptographic Module Specification 1 2 Cryptographic Module Ports and Interfaces 1 3 Roles, Services, and Authentication 1 4 Finite State Model 1 5 Physical Security N/A 6 Operational Environment 1 7 Cryptographic Key Management 1 8 EMI/EMC Self-tests 1 10 Design Assurance 1 11 Mitigation of Other Attacks N/A 8 EMI/EMC Electromagnetic Interference / Electromagnetic Compatibility Kaseya Virtual System Administrator Cryptographic Module Page 8 of 21
9 2.3 Module Specification The Virtual System Administrator Cryptographic Module is a software-only module that meets overall level 1 FIPS requirements. The logical cryptographic boundary of the Virtual System Administrator Cryptographic Module is defined as the following per operating platform: Windows 7: Kaseya VSA Cryptographic Library (libkacm.dll, libkacm_ksrv.dll), Windows 2008: Kaseya VSA Cryptographi Library Server Edition (libkacm.dll, libkacm_ksrv.dll) Mac OS X: Kaseya VSA Cryptographic Library (libkacm.dylib) Linux RHEL 9 5.5: Kaseya VSA Cryptographic Library (libkacm.so.1) 2.4 Module Interfaces The module supports the physical interfaces of a GPC, including the integrated circuits of the system board, the CPU (Central Processing Unit), network adapters, RAM (Random Access Memory), hard disk, device case, power supply, and fans. Other devices may be attached to the GPC, such as a display monitor, keyboard, mouse, printer, or storage media. See Figure 3 for a standard GPC block diagram. Figure 3 GPC Block Diagram 9 RHEL Red Hat Enterprise Linux Kaseya Virtual System Administrator Cryptographic Module Page 9 of 21
10 The modules interfaces are provided by the logical API supported by Kaseya Cryptographic Library, which provides the data input, data output, control input, and status output logical interfaces defined by FIPS These logical interfaces are shown in Figure 3 above. The mapping of logical interfaces to the physical ports of the GPC is provided in Table 2 below Table 2 FIPS Logical Interfaces FIPS Logical Interface Data Input Data Output Control Input Status Output Physical Interface USB ports (keyboard, mouse, data), network ports, serial ports, SCSI/SATA ports, DVD drive Monitor, USB ports, network ports, serial ports, SCSI/SATA ports, audio ports, DVD drive USB ports (keyboard, mouse), network ports, serial ports, power switch Monitor, network ports, serial ports, Audio Logical Interface Description Arguments for library functions that specify plaintext data, ciphertext, digital signatures, cryptographic keys (plaintext or encrypted), initialization vectors, and passwords that are to be input to and processed by the cryptographic module. Arguments for library functions that receive plaintext data, ciphertext data, digital signatures, cryptographic keys (plaintext or encrypted), and initialization vectors from the cryptographic module. Arguments for library functions that initiate and control the operation of the module, such as arguments that specify commands and control data (e.g., algorithms, algorithm modes, digest type, or module settings). Function return codes, error codes, or output arguments that receive status information used to indicate the status of the cryptographic module. 2.5 Roles, Services, and Authentication The module does not support authentication; all roles are implicitly assumed. There are two roles in the module (as required by FIPS 140-2) that operators may assume: a Crypto Officer role and a User role Crypto Officer Role The Crypto Officer role has the ability to initialize and terminate the module. Descriptions of the services available to the Crypto Officer role are provided in the table below. Table 3 Mapping of Crypto Officer Role s Services to Inputs, Outputs, CSPs (Critical Security Parameter), and Type of Access Crypto Enable Service Description Input Output CSP and Type of Access Initiates Power-on Self-Tests. All other functions will not execute until this service has been invoked and successfully returns. API Command Status None Kaseya Virtual System Administrator Cryptographic Module Page 10 of 21
11 Service Description Input Output CSP and Type of Access Crypto Disable Disables the crypto services; Crypto Enable will need to be invoked to re-enable them. API Command Status None User Role The User role has the ability to perform basic cryptographic operations such as encrypt, decrypt, generate random, and hash. Descriptions of the services available to the User role are provided in the table below. Table 4 Mapping of User Role s Services to Inputs, Outputs, CSPs, and Type of Access Service Description Input Output CSP and Type of Access Generate Random Zeroize Encrypt File Decrypt File Encrypt Buffer Decrypt Buffer Create a random number of a specified bit length. Overwrites a CSP that was sent into the crypto module by a previous call. Zeroes will be written in the memory location that held the CSP and then the memory is freed. Encrypts the specified file using AES 256-bit in CTR (Counter) mode and writes the encrypted data into an output file. Decrypts the specified file and writes the plaintext data into an output file. Encrypts an input buffer of data using AES 256-bit CTR mode and writes the encrypted data into an output buffer. Decrypts an input buffer of data and writes the decrypted data into an output buffer. Size Random Read DRBG Seed, V, and key Memory Address Plaintext File, Key Encrypted File, Key Buffer, Key Encrypted Buffer, Key None Encrypted File Plaintext File Encrypted Buffer Plaintext Buffer Write All CSPs Read AES Key Read AES Key Read AES Key Read AES Key Kaseya Virtual System Administrator Cryptographic Module Page 11 of 21
12 Hash File Service Description Input Output CSP and Type of Access Hashes the specified file using SHA-256 and returns the hash result in an output file. File Hash None Hash Buffer Hashes an input buffer using SHA-256 and returns the hash result in an output buffer. Buffer Hash None Key Wrap Key Unwrap HMAC File HMAC SHA-256 Buffer Error Data Parameter Validation Crypto Module Integrity Check Encrypts a specified key in accordance with the AES Key Wrap specification. Decrypts a specified key in accordance with the AES Key Wrap specification. Create an HMAC hash for a specified file using HMAC SHA-256. Set stream buffer using HMAC SHA-256 Provide error notifications. Verify the provided parameters for a given function are valid. Verify the software integrity of the crypto module. Get File Descriptors Opens the given file name and returns their associated file descriptors Initialize Cipher Context Clean Up Cipher Context Stream Based Encryption Stream Based Decryption Initialize AES Stream Cipher Finalize AES Stream Cipher Stream cipher encryption Stream cipher decryption Key Encryption Key, Key Key Encryption Key, Encrypted Key HMAC key, file Data API Command Data Parameter HMAC, HMAC Key File Data Encrypted Key Key Hash Buffer data, Status Status Status Status File Descriptors Status, Ciphertext Read AES Key Read, Execute AES KEK Read AES Key Read, Execute AES KEK Read HMAC Key Read HMAC Key None None Read HMAC Key None Data Status None Data Data Status, Ciphertext Status, Plaintext Data Read AES Key Read AES Key Read AES Key Kaseya Virtual System Administrator Cryptographic Module Page 12 of 21
13 In addition to the above services, the Show Status and Self-tests services are also available to both roles; neither service has any access to any CSPs Non-Approved Services When the module is operating in the non-approved mode of operation (described in Section 3.2.3), the following additional service is available to the operator of the module, which uses the non-approved AES- CBC mode. This service is only available in the non-approved mode of operation. Encrypt and Decrypt with AES-CBC Mode 2.6 Physical Security Virtual System Administrator Cryptographic Module is a software-only module. For the purposes of FIPS 140-2, the module is defined as a multiple-chip standalone cryptographic module, which is reflective of the GPC on which the module is installed. As a result, physical security is not applicable. 2.7 Operational Environment The Virtual System Administrator Cryptographic Module was tested and found to be compliant with FIPS requirements on the following platforms: MAC OS X v10.6.8, Windows 7 (32-bit and 64-bit), Windows Server 2008, and Red Hat Enterprise Linux 5.5 (32-bit and 64-bit) Kaseya affirms that the module also executes in its FIPS-Approved manner (as described in this Security Policy) on other Operating Systems that are binary-compatible to those on which the module was tested; however no assurance can be made as to the correct operation of the module under these operational environments: Microsoft Windows NT, 2000, XP, XP Pro, 2003, 2003 R2, Vista, 2008, 2008 R2, 7 Apple Mac OS X version or above SuSE Linux Enterprise 10 and 11, Red Hat Enterprise Linux 5.4/5.5, Ubuntu , and OpenSuSE 2.8 Cryptographic Key Management The module implements the FIPS-Approved algorithms listed in Table 5 below. Table 5 FIPS-Approved Algorithm Implementations Algorithm Certificate Number AES ECB 10, CTR 11 modes; 256-bit keys (DRBG Implementation) 1989 AES ECB, CTR modes; 256-bit keys (VSACM Implementation) 1988 SHA HMAC-SHA Electronic Code Book 11 Counter Kaseya Virtual System Administrator Cryptographic Module Page 13 of 21
14 SP A CTR_DRBG 185 The module provides the following non-fips-approved algorithm, which is not allowed for use in a FIPS- Approved mode of operation: AES-CBC (non-compliant) Additionally, the following algorithm is allowed in the FIPS-Approved mode for key wrapping: AES (Cert. #1989, key wrapping) The module supports the critical security parameters listed in Table 6 below. Table 6 List of Cryptographic Keys, Cryptographic Key Components, and CSPs Key Type AES Key Generation / Input Generated Within the Physical Boundary; Input Electronically in Plaintext via API Call AES KEK Generated Within the Physical Boundary; Input Electronically in Plaintext via API Call HMAC Key Generated Within the Physical Boundary; Input Electronically in Plaintext via API Call DRBG Seed DRBG V Value DRBG key Value Generated Within the Physical Boundary; Input Electronically Generated Within the Physical Boundary; Input Electronically Generated Within the Physical Boundary; Input Electronically Output Storage Zeroization Use Wrapped via AES KEK 12 N/A N/A Never Never Never Plaintext in volatile memory Plaintext in volatile memory Plaintext in volatile memory Plaintext in volatile memory Plaintext in volatile memory Plaintext in volatile memory By calling the Zeroize function in the API By calling the Zeroize function in the API By calling the Zeroize function in the API Zeroize function; Module reset Zeroize function; Module reset Zeroize function; Module reset Data confidentiality Wrapping AES Keys Keyed hashing Generate random values Used for SP CTR_DRBG Used for SP CTR_DRBG 12 KEK Key Encryption Key Kaseya Virtual System Administrator Cryptographic Module Page 14 of 21
15 2.9 EMI/EMC The test platforms used to perform operational testing comply with the EMI/EMC requirements of the FIPS standard Self-Tests The Virtual System Administrator Cryptographic Module performs all self-tests required by FIPS requirements at power-up. If the module encounters an error during a power-up or conditional self-test, the module will write the appropriate error message to an error log and then continue to unload itself from memory. In order to restart the module, the host system or calling application should be restarted. Should this operation fail to bring the module to an operational state, the module must be reinstalled following the directions in Section 3 of this Security Policy. See Table 7 for a description of all self-tests performed at power-up. Power-Up Test AES KAT 13 (VSACM Implementation) Table 7 Power-Up Tests and Descriptions Description Individual Known Answer Tests for VSACM AES implementation AES KAT (DRBG Implementation) Individual Known Answer Tests for DRBG AES implementation SHA-256 KAT HMAC-SHA-256 KAT SP A CTR_DRBG KAT Software Integrity Test Known Answer Test for SHA-256 Known Answer Test for HMAC-SHA-256 Known Answer Test for SP A CTR_DRBG HMAC SHA-256 verifications of the crypto module The Virtual System Administrator Cryptographic Module performs all conditional self-tests required by FIPS See Table 8 for a description of all conditional tests. Table 8 Conditional Tests and Descriptions Continuous DRBG Test Conditional Test Description Continuous test performed to ensure no two consecutively generated values are the same, which would indicate a DRBG failure The Kaseya VSACM implements the SP CTR_DRBG as its random number generator. This DRBG employs two critical functions which must also be tested on a regular basis to ensure the security of the SP DRBG. Therefore, the critical function tests listed in Table 9 are also implemented by the crypto module. Table 9 Critical Function Tests and Descriptions DRBG Instantiate Test DRBG Reseed Test Critical Function Test Description Test performed prior to instantiating a new DRBG. Test performed prior to instantiating a new DRBG 13 KAT Known Answer Test Kaseya Virtual System Administrator Cryptographic Module Page 15 of 21
16 or before reseeding an existing DRBG. If any of the above self-tests fail, the module will enter into an error state and no cryptographic services will be available Design Assurance A combination of Subversion (SVN), version 1.6.5, and Author-it Enterprise Authoring Platform (EAP) version 5.4 are used to provide configuration management for the Virtual System Administrator Cryptographic Module and related documentation. These software solutions provide access control, versioning, and logging Mitigation of Other Attacks The module has not been designed to mitigate any attacks beyond the scope of FIPS requirements. Kaseya Virtual System Administrator Cryptographic Module Page 16 of 21
17 3 Secure Operation The Virtual System Administrator Cryptographic Module meets Level 1 requirements for FIPS The sections below describe how to place and keep the module in FIPS-approved mode of operation. 3.1 Initial Setup The Virtual System Administrator Cryptographic Module does not require any additional configuration once it has been properly installed and initialized per the guidance provided in Section 3.2 below. 3.2 Crypto Officer Guidance The Virtual System Administrator Cryptographic Module is provided in the installation package of the Virtual System Administrator Server and Virtual System Administrator Agent. The module is installed onto a system during the installation of these products. The Crypto Officer is required to install the dynamic library components of the VSACM and their HMAC signature counter-parts in the same directory Initialization To place the module into FIPS mode, the calling application must invoke kacm_crypto_enable upon startup to initialize the VSACM. If being called through the Kaseya wrapper library, then kacm_start must be called upon startup. After FIPS mode has been enabled, the CO shall ensure that AES CBC mode is not used during operation. Use of this algorithm will cause the module to operate in a Non-Approved mode. See Section for further details Management The module is a cryptographic library and as such, the single-user of the module is the calling application. The application itself may service multiple operators, but the module itself will only provide services to the associated loading application. When providing service to a server, the server application makes the calls to the cryptographic module. Therefore, the server application is the single user of the cryptographic module, even when the server application is serving multiple clients. The operating system itself prevents operators from circumventing the single-user enforcement mechanism, as the module runs in separate instances Non-Approved Mode of Operation The Virtual System Administrator Cryptographic Module contains both an Approved and Non-Approved mode of operation. Instructions on how to place the module into an Approved mode of operation are available in Section To take the module out of an Approved mode of operation, the CO can call _kacm_crypto_disable. To operate the module in a Non-Approved mode of operation, the CO must do the following: 1. Call register_cipher() to register the AES-256 cipher 2. Call register_hash() to register the SHA-256 hash 3. Set two global variables pointing the chosen cipher and hash algorithms When operating in a Non-Approved mode, the module provides all cryptographic algorithms listed in Table 5 in a non-compliant form, with the addition of AES in CBC mode. Additionally, the services listed in Table 3 and Table 4 are available to the user of the module and can be run in a non-approved form. Section presents an additional service, which is available to the operator of the module only in the non-approved mode. AES can be used in CBC mode for encrypt and decrypt operations of files and buffers, in the non-approved mode. While operating in the non-approved mode, all module services are available to all operators with access to the module. Kaseya Virtual System Administrator Cryptographic Module Page 17 of 21
18 3.3 User Guidance No additional guidance is required for the User. Kaseya Virtual System Administrator Cryptographic Module Page 18 of 21
19 4 Acronyms Table 10 lists the acronyms used throughout this document. Table 10 Acronyms Acronym Definition API Application Programming Interface ASP Active Server Pages BIOS Basic Input/Output System CMVP Cryptographic Module Validation Program CPU Central Processing Unit CSEC Communications Security Establishment Canada CSP Critical Security Parameter CTR Counter DSA Digital Signature Algorithm DRBG Deterministic Random Bit Generator DVD Digital Video Disc EAP Enterprise Authoring Platform ECB Electronic Code Book EMC Electromagnetic Compatibility EMI Electromagnetic Interference FIPS Federal Information Processing Standards GPC General Purpose Computer GUI Graphical User Interface HDD Hard Disk Drive HMAC (Keyed-) Hash Message Authentication Code HTTP Hypertext Transfer Protocol HTTPS Hypertext Transfer Protocol Secure IIS Internet Information Services IP Internet Protocol IT Information Technology KAT Known Answer Test MAC Macintosh NIST National Institute of Standards and Technology NVLAP National Voluntary Laboratory Accreditation Program ODBC Open Database Connectivity Kaseya Virtual System Administrator Cryptographic Module Page 19 of 21
20 Acronym Definition OLEDB Object Linking and Embedding Database OS Operating System PC Personal Computer PCI Peripheral Component Interconnect PCIe Peripheral Component Interconnect Express RAM Random Access Memory RHEL Red Hat Enterprise Linux RSA Rivest Shamir and Adleman SATA Serial Advanced Technology Attachment SCSI Small Computer System Interface SHA Secure Hash Algorithm SQL Structured Query Language SVN SubVersion TCP Transmission Control Protocol TDES Triple Data Encryption Standard USB Universal Serial Bus VSA Virtual System Administrator VSACM Virtual System Administrator Cryptographic Module VSS Visual Source Safe Kaseya Virtual System Administrator Cryptographic Module Page 20 of 21
21 Prepared by: Corsec Security, Inc Lee Jackson Memorial Hwy, Suite 220 Fairfax, VA United States of America Phone: (703)
Symantec Corporation Symantec Enterprise Vault Cryptographic Module Software Version: 1.0.0.2
Symantec Corporation Symantec Enterprise Vault Cryptographic Module Software Version: 1.0.0.2 FIPS 140 2 Non Proprietary Security Policy FIPS Security Level: 1 Document Version: 1.1 Prepared for: Prepared
Accellion Secure File Transfer Cryptographic Module Security Policy Document Version 1.0. Accellion, Inc.
Accellion Secure File Transfer Cryptographic Module Security Policy Document Version 1.0 Accellion, Inc. December 24, 2009 Copyright Accellion, Inc. 2009. May be reproduced only in its original entirety
Pulse Secure, LLC. January 9, 2015
Pulse Secure Network Connect Cryptographic Module Version 2.0 Non-Proprietary Security Policy Document Version 1.1 Pulse Secure, LLC. January 9, 2015 2015 by Pulse Secure, LLC. All rights reserved. May
FIPS 140-2 Non- Proprietary Security Policy. McAfee SIEM Cryptographic Module, Version 1.0
FIPS 40-2 Non- Proprietary Security Policy McAfee SIEM Cryptographic Module, Version.0 Document Version.4 December 2, 203 Document Version.4 McAfee Page of 6 Prepared For: Prepared By: McAfee, Inc. 282
Nortel Networks, Inc. VPN Client Software (Software Version: 7_11.101) FIPS 140-2 Non-Proprietary Security Policy
Nortel Networks, Inc. VPN Client Software (Software Version: 7_11.101) FIPS 140-2 Non-Proprietary Security Policy Level 1 Validation Document Version 0.5 Prepared for: Prepared by: Nortel Networks, Inc.
VMware, Inc. VMware Java JCE (Java Cryptographic Extension) Module
VMware, Inc. VMware Java JCE (Java Cryptographic Extension) Module Software Version: 1.0 FIPS 140-2 Non-Proprietary Security Policy F I P S S E C U R I T Y L E V E L 1 D O C U M E N T V E R S I O N : 1.0
Secure Network Communications FIPS 140 2 Non Proprietary Security Policy
Secure Network Communications FIPS 140 2 Non Proprietary Security Policy 21 June 2010 Table of Contents Introduction Module Specification Ports and Interfaces Approved Algorithms Test Environment Roles
SecureDoc Disk Encryption Cryptographic Engine
SecureDoc Disk Encryption Cryptographic Engine FIPS 140-2 Non-Proprietary Security Policy Abstract: This document specifies Security Policy enforced by SecureDoc Cryptographic Engine compliant with the
13135 Lee Jackson Memorial Hwy., Suite 220 Fairfax, VA 22033 United States of America
VMware, Inc. VMware Kernel Cryptographic Module Software Version: 1.0 FIPS 140-2 Non-Proprietary Security Policy FIPS Security Level: 1 Document Version: 1.0 Prepared for: Prepared by: VMware, Inc. 3401
FIPS 140-2 Non-Proprietary Security Policy. IBM Internet Security Systems SiteProtector Cryptographic Module (Version 1.0)
FIPS 140-2 Non-Proprietary Security Policy IBM Internet Security Systems SiteProtector Document Version 2.3 August 5, 2010 Document Version 2.3 IBM Internet Security Systems Page 1 of 24 Prepared For:
SECUDE AG. FinallySecure Enterprise Cryptographic Module. FIPS 140-2 Security Policy
SECUDE AG FinallySecure Enterprise Cryptographic Module (SW Version: 1.0) FIPS 140-2 Security Policy Document Version 2.4 04/22/2010 Copyright SECUDE AG, 2010. May be reproduced only in its original entirety
Secure File Transfer Appliance Security Policy Document Version 1.9. Accellion, Inc.
Secure File Transfer Appliance Security Policy Document Version 1.9 Accellion, Inc. November 11, 2010 Copyright Accellion, Inc. 2010. May be reproduced only in its original entirety [without revision].
FIPS 140-2 Security Policy LogRhythm 6.0.4 Log Manager
FIPS 140-2 Security Policy LogRhythm 6.0.4 Log Manager LogRhythm 3195 Sterling Circle, Suite 100 Boulder CO, 80301 USA September 17, 2012 Document Version 1.0 Module Version 6.0.4 Page 1 of 23 Copyright
FIPS 140 2 Non Proprietary Security Policy: Kingston Technology DataTraveler DT4000 Series USB Flash Drive
FIPS 140 2 Non Proprietary Security Policy Kingston Technology Company, Inc. DataTraveler DT4000 G2 Series USB Flash Drive Document Version 1.8 December 3, 2014 Document Version 1.8 Kingston Technology
FIPS 140-2 Security Policy LogRhythm 6.0.4 or 6.3.4 Windows System Monitor Agent
FIPS 140-2 Security Policy LogRhythm 6.0.4 or 6.3.4 Windows System Monitor Agent LogRhythm, Inc. 4780 Pearl East Circle Boulder, CO 80301 May 1, 2015 Document Version 2.0 Module Versions 6.0.4 or 6.3.4
Northrop Grumman M5 Network Security SCS Linux Kernel Cryptographic Services. FIPS Security Policy Version 2.42. www.northropgrumman.
Northrop Grumman M5 Network Security SCS Linux Kernel Cryptographic Services FIPS Security Policy Version 2.42 www.northropgrumman.com/m5/ SCS Linux Kernel Cryptographic Services Security Policy Version
Symantec Mobility: Suite Server Cryptographic Module
FIPS 140-2 Non-Proprietary Security Policy Symantec Mobility: Suite Server Cryptographic Module Software Version 1.0 Document Version 1.4 February 10, 2016 Prepared For: Prepared By: Symantec Corporation
VASCO Data Security International, Inc. DIGIPASS GO-7. FIPS 140-2 Non-Proprietary Cryptographic Module Security Policy
VASCO Data Security International, Inc. DIGIPASS GO-7 FIPS 140-2 Non-Proprietary Cryptographic Module Security Policy Security Level: 2 Version: 1.7 Date: August 12, 2015 Copyright VASCO Data Security
SkyRecon Cryptographic Module (SCM)
SkyRecon Cryptographic Module (SCM) FIPS 140-2 Documentation: Security Policy Abstract This document specifies the security policy for the SkyRecon Cryptographic Module (SCM) as described in FIPS PUB 140-2.
Security Policy. Trapeze Networks
MP-422F Mobility Point Security Policy Trapeze Networks August 14, 2009 Copyright Trapeze Networks 2007. May be reproduced only in its original entirety [without revision]. TABLE OF CONTENTS 1. MODULE
FIPS 140-2 Security Policy. for Motorola, Inc. Motorola Wireless Fusion on Windows CE Cryptographic Module
FIPS 140-2 Security Policy for Motorola, Inc Motorola Wireless Fusion on Windows CE Cryptographic Module Hybrid Module Software Component Version: 3.00.0 Hardware Component Version: CX 55222 Document Version
SECURE USB FLASH DRIVE. Non-Proprietary Security Policy
SECURE USB FLASH DRIVE Non-Proprietary Security Policy FIPS 140-2 SECURITY POLICY VERSION 9 Page 1 of 10 Definitions and Acronyms AES Advanced Encryption Standard CBC Cipher Block Chaining CRC Cyclic Redundancy
FIPS 140-2 Non-Proprietary Security Policy. FIPS Security Level: 2 Document Version: 0.9
Bomgar Corporation B200 and B300 Remote Support Appliances Firmware Version: 3.2.2FIPS; Software Version: 10.6.2FIPS; Hardware Versions: B200, B300, and B300 r1 FIPS 140-2 Non-Proprietary Security Policy
FIPS 140 2 Non Proprietary Security Policy: IBM Internet Security Systems Proventia GX Series Security
FIPS 140 2 Non Proprietary Security Policy IBM Internet Security Systems Proventia GX Series Security Document Version 1.6 January 25, 2013 Document Version 1.6 IBM Internet Security Systems Page 1 of
FIPS 140 2 Non Proprietary Security Policy: IBM Internet Security Systems Proventia GX Series Security
FIPS 140 2 Non Proprietary Security Policy IBM Internet Security Systems Proventia GX Series Security Document Version 1.2 January 31, 2013 Document Version 1.2 IBM Internet Security Systems Page 1 of
FIPS 140-2 Level 1 Security Policy for Cisco Secure ACS FIPS Module
FIPS 140-2 Level 1 Security Policy for Cisco Secure ACS FIPS Module Contents Overview, page 1 Security Requirements, page 2 Cryptographic Module Specification, page 2 Cryptographic Module Ports and Interfaces,
Windows Server 2008 R2 Boot Manager Security Policy For FIPS 140-2 Validation
Boot Manager Security Policy Windows Server 2008 R2 Boot Manager Security Policy For FIPS 140-2 Validation v 1.3 6/8/11 1 INTRODUCTION... 1 1.1 Cryptographic Boundary for BOOTMGR... 1 2 SECURITY POLICY...
Cisco Telepresence C40, C60, and C90 Codecs (Firmware Version: TC5.0.2) (Hardware Version: v1) FIPS 140-2 Non-Proprietary Security Policy
Cisco Systems Cisco Telepresence C40, C60, and C90 Codecs (Firmware Version: TC5.0.2) (Hardware Version: v1) FIPS 140-2 Non-Proprietary Security Policy Level 2 Validation Document Version 1.0 2011 CISCO
1C - FIPS 140-2 Cisco VPN Client Security Policy
This document describes the Cisco VPN Client security policy. Introduction This non-proprietary cryptographic module security policy describes how version 3.6.5 of the Cisco software VPN Client meets the
FIPS 140-2 Security Policy
FIPS 140-2 Security Policy BlackBerry Cryptographic Library for Secure Work Space Version 1.0 Document Version 1.2 BlackBerry Security Certifications, Research In Motion 2013 BlackBerry Limited. All rights
RSA BSAFE. Crypto-C Micro Edition for MFP SW Platform (psos) Security Policy. Version 3.0.0.1, 3.0.0.2 October 22, 2012
RSA BSAFE Crypto-C Micro Edition for MFP SW Platform (psos) Security Policy Version 3.0.0.1, 3.0.0.2 October 22, 2012 Strong encryption technology for C/C++ developers Contact Information See our Web sites
HP LTO-6 Tape Drive Level 1 Security Policy
HP LTO-6 Tape Drive Level 1 Security Policy Version: 8 Revision Date: 1 October 2013 Hewlett Packard Company Copyright 2013 Hewlett-Packard Company This document may be freely reproduced and distributed
SNAPcell Security Policy Document Version 1.7. Snapshield
SNAPcell Security Policy Document Version 1.7 Snapshield July 12, 2005 Copyright Snapshield 2005. May be reproduced only in its original entirety [without revision]. TABLE OF CONTENTS 1. MODULE OVERVIEW...3
FIPS 140-2 Security Policy
Red Hat Enterprise Linux 6.2 dm-crypt Cryptographic Module v2.0 Version 1.4 Last Update: 2013-04-03 Contents 1 Cryptographic Module Specification...3 1.1 Description of Module...3 1.2 Description of Modes
OpenSSL FIPS 140-2 Security Policy Version 1.2.4
OpenSSL FIPS Object Module Version 1.2.4 By the Open Source Software Institute http://www.oss-institute.org/ OpenSSL FIPS 140-2 Security Policy Version 1.2.4 June 12, 2012 Copyright Notice Copyright 2003-2012
FIPS 140-2 Security Policy 3Com Embedded Firewall PCI Cards
FIPS 140-2 Security Policy 3Com Embedded Firewall PCI Cards 3Com Corporation 5403 Betsy Ross Drive Santa Clara, CA 95054 USA February 24, 2006 Revision Version 0.4 Page 1 of 15 1. Introduction The following
Blue Coat Systems, Inc. Secure Web Gateway Virtual Appliance-V100 Software Version: 6.5.2.8. FIPS 140-2 Non-Proprietary Security Policy
Blue Coat Systems, Inc. Secure Web Gateway Virtual Appliance-V100 Software Version: 6.5.2.8 FIPS 140-2 Non-Proprietary Security Policy FIPS Security Level: 1 Document Version: 0.5 Prepared for: Prepared
TANDBERG MXP Codec (Firmware Version: F6.0) FIPS 140-2 Non-Proprietary Security Policy
TANDBERG Telecom AS TANDBERG MXP Codec (Firmware Version: F6.0) FIPS 140-2 Non-Proprietary Security Policy Level 1 Validation Document Version 1.3 Prepared for: Prepared by: TANDBERG Telecom AS Corsec
Certicom Security for Government Suppliers developing client-side products to meet the US Government FIPS 140-2 security requirement
certicom application notes Certicom Security for Government Suppliers developing client-side products to meet the US Government FIPS 140-2 security requirement THE PROBLEM How can vendors take advantage
JUNOS-FIPS-L2 Cryptographic Module Security Policy Document Version 1.3
JUNOS-FIPS-L2 Cryptographic Module Security Policy Document Version 1.3 Juniper Networks January 10, 2007 Copyright Juniper Networks 2007. May be reproduced only in its original entirety [without revision].
Secure Computing Corporation Secure Firewall (Sidewinder) 2150E (Hardware Version: 2150 with SecureOS v7.0.1.01)
Secure Computing Corporation Secure Firewall (Sidewinder) 2150E (Hardware Version: 2150 with SecureOS v7.0.1.01) FIPS 140-2 Non-Proprietary Security Policy Level 2 Validation Document Version 1.1 Prepared
NitroGuard Intrusion Prevention System Version 8.0.0.20080605 and 8.2.0 Security Policy
NitroGuard Intrusion Prevention System Version 8.0.0.20080605 and 8.2.0 Security Policy FIPS 140-2 Level 2 Validation Model Numbers NS-IPS-620R-4C-B NS-IPS-1220R-6C-B NS-IPS-1220R-4C-2F-B NS-IPS-620R-4C-BFS
FIPS 140-2 SECURITY POLICY FOR
FIPS 140-2 SECURITY POLICY FOR SPECTRAGUARD ENTERPRISE SERVER August 31, 2011 FIPS 140-2 LEVEL-1 SECURITY POLICY FOR AIRTIGHT NETWORKS SPECTRAGUARD ENTERPRISE SERVER 1. Introduction This document describes
Network Security Services (NSS) Cryptographic Module Version 3.12.4
Network Security Services () Cryptographic Module Version 3.12.4 FIPS 140-2 Security Policy Level 1 Validation Wind River Systems, Inc. Version 1.2 Last Update: 2010-12-13 Table of Contents 1 Introduction...
Kaseya Server Instal ation User Guide June 6, 2008
Kaseya Server Installation User Guide June 6, 2008 About Kaseya Kaseya is a global provider of IT automation software for IT Solution Providers and Public and Private Sector IT organizations. Kaseya's
MOTOROLA MESSAGING SERVER SERVER AND MOTOROLA MYMAIL DESKTOP PLUS MODULE OVERVIEW. Security Policy REV 1.3, 10/2002
Security Policy MOTOROLA MESSAGING SERVER SERVER AND MOTOROLA MYMAIL DESKTOP PLUS ENCRYPTION DLL CRYPTOGRAPHIC MODULE REV 1.3, 10/2002 CONTENTS Module Overview... 1 Scope of Document... 2 Terms and Definitions...
Security Policy, DLP Cinema, Series 2 Enigma Link Decryptor
ISIONS DESCRIPTION ECO DATE APPROVED F Initial Release 2108109 06/02/10 Lee Armstrong Copyright 2010 by Texas Instruments.. Security Policy, DLP Cinema, Series 2 Enigma Link Decryptor The data in this
FIPS 140-2 Non-Proprietary Security Policy. FIPS Security Level: 2 Document Version: 0.7
Blue Coat Systems, Inc. ProxySG 9000 Series Models: SG9000-20, SG9000-20B, SG9000-30, SG9000-40 Hardware Version: 090-02840, 090-02839, 090-02984, 090-02985, 090-02841, 090-02842, 090-02845, 090-02846
MOTOROLA ACCOMPLI 009 PERSONAL COMMUNICATOR MODULE OVERVIEW SCOPE OF DOCUMENT. Security Policy REV 1.2, 10/2002
Security Policy MOTOROLA ACCOMPLI 009 PERSONAL COMMUNICATOR ENCRYPTION SERVICES MODULE REV 1.2, 10/2002 CONTENTS Module Overview... 1 Scope of Document... 1 Terms and Definitions... 2 Security Level...
Cisco Catalyst 3560-X and 3750-X Switches FIPS 140-2 Level 2 Non-Proprietary Security Policy
Cisco Catalyst 3560-X and 3750-X Switches FIPS 140-2 Level 2 Non-Proprietary Security Policy Overall Level 2 Validation Version 0.54 April 25, 2012 Introduction... 3 References... 3 FIPS 140-2 Submission
Security Policy for FIPS 140 2 Validation
BitLocker Windows OS Loader Security Policy for FIPS 140 2 Validation BitLocker Windows OS Loader (winload) in Microsoft Windows 8.1 Enterprise Windows Server 2012 R2 Windows Storage Server 2012 R2 Surface
Security Policy for Oracle Advanced Security Option Cryptographic Module
Security Policy for Oracle Advanced Security Option Cryptographic Module Version 1.0 September 1999 Prepared by Oracle Corporation A. Scope of Document This document describes the security policy for the
McAfee Firewall Enterprise 8.3.1
Configuration Guide Revision A McAfee Firewall Enterprise 8.3.1 FIPS 140-2 The McAfee Firewall Enterprise FIPS 140-2 Configuration Guide, version 8.3.1, provides instructions for setting up McAfee Firewall
Non-Proprietary Security Policy for the FIPS 140-2 Level 1 Validated Fortress Secure Client Software Version 3.1
Non-Proprietary Security Policy for the FIPS 140-2 Level 1 Validated Fortress Secure Client Software Version 3.1 (Document Version 1.01) June 2007 Prepared by the Fortress Technologies, Inc., Government
HEWLETT PACKARD TIPPINGPOINT. FIPS 140 2 NON PROPRIETARY SECURITY POLICY HP TippingPoint Security Management System
HEWLETT PACKAD TIPPINGPOINT FIPS 140 2 NON POPIETAY SECUITY POLICY HP TippingPoint Security Management System Level 1 Validation Firmware Version: 3.2.0.8312.3 Document Version: 1.03 Page 1 of 31 FIPS
McAfee Firewall Enterprise 8.2.1
Configuration Guide FIPS 140 2 Revision A McAfee Firewall Enterprise 8.2.1 The McAfee Firewall Enterprise FIPS 140 2 Configuration Guide, version 8.2.1, provides instructions for setting up McAfee Firewall
Safeguarding Data Using Encryption. Matthew Scholl & Andrew Regenscheid Computer Security Division, ITL, NIST
Safeguarding Data Using Encryption Matthew Scholl & Andrew Regenscheid Computer Security Division, ITL, NIST What is Cryptography? Cryptography: The discipline that embodies principles, means, and methods
FIPS 140-2 Non-Proprietary Security Policy. FIPS Security Level: 2 Document Version: 1.9. 1201 Winterson Road Linthicum, MD 21090
Ciena Corporation 565/5100/5200 Advanced Services Platform FW Version: 11.2 and 11.21 HW Versions: 565 Chassis (NT0H50DAE5 REV 004), Backplane SP Card (NT0H5066E5 Rev 04), QOTR/E Card (NT0H25BAE5 Rev 2),
A COMPARISON OF THE SECURITY REQUIREMENTS FOR CRYPTOGRAPHIC MODULES IN FIPS 140-1 AND FIPS 140-2
NIST Special Publication 800-29 A COMPARISON OF THE SECURITY REQUIREMENTS FOR CRYPTOGRAPHIC MODULES IN FIPS 140-1 AND FIPS 140-2 Ray Snouffer Annabelle Lee Arch Oldehoeft Security Technology Group Computer
Kaseya IT Automation Framework
Kaseya Kaseya IT Automation Framework An Integrated solution designed for reducing complexity while increasing productivity for IT Professionals and Managed Service Providers. The powerful, web-based automation
Acano solution. Security Considerations. August 2015 76-1026-01-E
Acano solution Security Considerations August 2015 76-1026-01-E Contents Contents 1 Introduction... 3 2 Acano Secure Development Lifecycle... 3 3 Acano Security Points... 4 Acano solution: Security Consideration
Security Policy: Key Management Facility Crypto Card (KMF CC)
Security Policy: Key Management Facility Crypto Card (KMF CC) Version 2.12.2 2/7/11 1.0 Introduction 3 1.1 Scope 3 1.2 Overview 3 1.3 KMF CC Implementation 4 1.4 KMF CC HW/SW version numbers 4 1.5 KMF
User Guide. FIPS Mode. For use with epolicy Orchestrator 4.6.x Software
User Guide FIPS Mode For use with epolicy Orchestrator 4.6.x Software COPYRIGHT Copyright 2013 McAfee, Inc. Do not copy without permission. TRADEMARK ATTRIBUTIONS McAfee, the McAfee logo, McAfee Active
Sonus Networks, Inc. SBC 5110 and 5210 Session Border Controllers Hardware Version: SBC 5110 and SBC 5210 Firmware Version: 4.0
Sonus Networks, Inc. SBC 5110 and 5210 Session Border Controllers Hardware Version: SBC 5110 and SBC 5210 Firmware Version: 4.0 FIPS 140-2 Non-Proprietary Security Policy FIPS Security Level: 1 Document
SyncThru TM Web Admin Service Administrator Manual
SyncThru TM Web Admin Service Administrator Manual 2007 Samsung Electronics Co., Ltd. All rights reserved. This administrator's guide is provided for information purposes only. All information included
LAB FORWARD. WITH PROService RMS TECHNOLOGY, ARCHITECTURE AND SECURITY INFORMATION FOR IT PROFESSIONALS
LAB FORWARD WITH PROService RMS TECHNOLOGY, ARCHITECTURE AND SECURITY INFORMATION FOR IT PROFESSIONALS Medical diagnostics are a vital part of the modern healthcare system, and instrument uptime is critical
Guidance Regarding Skype and Other P2P VoIP Solutions
Guidance Regarding Skype and Other P2P VoIP Solutions Ver. 1.1 June 2012 Guidance Regarding Skype and Other P2P VoIP Solutions Scope This paper relates to the use of peer-to-peer (P2P) VoIP protocols,
SafeEnterprise TM ATM Encryptor II Model 600 FIPS 140-2 Level 3 Validation Non-Proprietary Security Policy
SafeEnterprise TM ATM Encryptor II Model 600 FIPS 140-2 Level 3 Validation Non-Proprietary Security Policy Hardware Models T1 RJ45 (901-11001-00x) E1 BNC (901-27001-00x) T3 BNC (901-37001-00x) E3 BNC (901-77001-00x)
Certification Report
Certification Report EAL 2+ Evaluation of Symantec Endpoint Protection Version 11.0 Issued by: Communications Security Establishment Canada Certification Body Canadian Common Criteria Evaluation and Certification
Cautions When Using BitLocker Drive Encryption on PRIMERGY
Cautions When Using BitLocker Drive Encryption on PRIMERGY July 2008 Fujitsu Limited Table of Contents Preface...3 1 Recovery mode...4 2 Changes in hardware configurations...5 3 Prior to hardware maintenance
Stratusphere. Architecture Overview
Stratusphere Architecture Overview Introduction This guide has been authored by experts at Liquidware Labs in order to provide an architecture overview of Liquidware Labs Stratusphere product, the leading
Alliance Key Manager Solution Brief
Alliance Key Manager Solution Brief KEY MANAGEMENT Enterprise Encryption Key Management On the road to protecting sensitive data assets, data encryption remains one of the most difficult goals. A major
Alliance AES Encryption for IBM i Solution Brief
Encryption & Tokenization Alliance AES Encryption for IBM i Solution Brief A Complete AES Encryption Solution Alliance AES Encryption for IBM i provides AES encryption for sensitive data everywhere it
Certification Report
Certification Report EAL 4+ Evaluation of Entrust Authority Security Manager and Security Manager Administration v8.1 SP1 Issued by: Communications Security Establishment Canada Certification Body Canadian
Client side. DESlock + Data Encryption
Data Encryption DESlock + is a simple-to-use encryption application for companies large and small. Take advantage of the optimized setup that speeds up the time to adoption for admins. The client side
Citrix MetaFrame XP Security Standards and Deployment Scenarios
Citrix MetaFrame XP Security Standards and Deployment Scenarios Including Common Criteria Information MetaFrame XP Server for Windows with Feature Release 3 Citrix Systems, Inc. Information in this document
Secure FTP Server (FIPS) v3.3 User Guide
Secure FTP Server (FIPS) v3.3 User Guide GlobalSCAPE, Inc. (GSB) Corporate Headquarters Address: 6000 Northwest Parkway, Suite 100 San Antonio, TX (USA) 78249 Sales: (210) 308-8267 Sales (Toll Free): (800)
enicq 5 System Administrator s Guide
Vermont Oxford Network enicq 5 Documentation enicq 5 System Administrator s Guide Release 2.0 Published November 2014 2014 Vermont Oxford Network. All Rights Reserved. enicq 5 System Administrator s Guide
Click to view Web Link, click Chapter 8, Click Web Link from left navigation, then click BIOS below Chapter 8 p. 395 Fig. 8-4.
Chapter 8 Objectives Chapter 8 Operating Systems and Utility Programs Identify the the types types of of system software Summarize the the startup process on on a a personal computer Describe the the functions
IT Networking and Security
elearning Course Outlines IT Networking and Security powered by Calibrate elearning Course Outline CompTIA A+ 801: Fundamentals of Computer Hardware/Software www.medallionlearning.com Fundamentals of Computer
Cryptographic and Security Testing Laboratory. Deputy Laboratory Director, CST Laboratory Manager
Cryptographic and Security Testing Laboratory Deputy Laboratory Director, CST Laboratory Manager About our Cryptographic and Security Testing Laboratory Bringing together a suite of conformance testing
OpenSSL FIPS 140-2 Security Policy Version 1.1.1b
OpenSSL FIPS Object Module Version 1.1.1 By the Open Source Software Institute http://www.oss-institute.org/ OpenSSL FIPS 140-2 Security Policy Version 1.1.1b January 29, 2007 Copyright Notice Copyright
FIPS 140-2 Documentation: Security Policy 05/06/2015 11:21 AM. Windows CE and Windows Mobile Operating System. Abstract
Windows CE and Windows Mobile Operating System Microsoft Windows CE, Windows Mobile, and Windows Embedded Handheld Enhanced Cryptographic Provider (RSAENH) (5.00.911762, 5.01.01603, 5.04.17228, 5.05.19202,
EAC Decision on Request for Interpretation 2008-03 (Operating System Configuration)
EAC Decision on Request for Interpretation 2008-03 (Operating System Configuration) 2002 VSS Volume1: 2.2.5.3, 4.1.1, 6.2.1.1, Volume2: 3.5 2005 VVSG Volume1: 2.1.5.2, 5.1.1, 7.2.1, Volume2: 3.5 Date:
7906G, 7911G, 7931G, 7941G, 7942G, 7945G, 7961G, 7961GE, 7962G, 7965G, 7970G, 7971G, 7971GE,
FIPS 140-2 Non-Proprietary Security Policy for the Cisco Unified IP Phone 7906G, 7911G, 7931G, 7941G, 7942G, 7945G, 7961G, 7961GE, 7962G, 7965G, 7970G, 7971G, 7971GE, and 7975G Introduction This is a non-proprietary
Lecture 6: Operating Systems and Utility Programs
Lecture 6: Operating Systems and Utility Programs Chapter 8 Objectives Identify the types of system software Summarize the startup process on a personal computer Summarize the features of several stand-alone
NetCrunch 6. AdRem. Network Monitoring Server. Document. Monitor. Manage
AdRem NetCrunch 6 Network Monitoring Server With NetCrunch, you always know exactly what is happening with your critical applications, servers, and devices. Document Explore physical and logical network
CimTrak Integrity & Compliance Suite 2.0.6.19
CimTrak Integrity & Compliance Suite 2.0.6.19 Master Repository Management Console App Server File System Agent Network Device Agent Command Line Utility Ping Utility Proxy Utility FTP Repository Interface
Security Policy Revision Date: 23 April 2009
Security Policy Revision Date: 23 April 2009 Remote Desktop Support Version 3.2.1 or later for Windows Version 3.1.2 or later for Linux and Mac 4 ISL Light Security Policy This section describes the procedure
Certification Report
Certification Report EAL 2+ Evaluation of Symantec Endpoint Protection Version 12.1.2 Issued by: Communications Security Establishment Canada Certification Body Canadian Common Criteria Evaluation and
BlackBerry Enterprise Service 10. Secure Work Space for ios and Android Version: 10.1.1. Security Note
BlackBerry Enterprise Service 10 Secure Work Space for ios and Android Version: 10.1.1 Security Note Published: 2013-06-21 SWD-20130621110651069 Contents 1 About this guide...4 2 What is BlackBerry Enterprise
Configuring Security Features of Session Recording
Configuring Security Features of Session Recording Summary This article provides information about the security features of Citrix Session Recording and outlines the process of configuring Session Recording
Intelligent Power Protector User manual extension for Microsoft Virtual architectures: Hyper-V 6.0 Manager Hyper-V Server (R1&R2)
Intelligent Power Protector User manual extension for Microsoft Virtual architectures: Hyper-V 6.0 Manager Hyper-V Server (R1&R2) Hyper-V Manager Hyper-V Server R1, R2 Intelligent Power Protector Main
Certification Report
Certification Report EAL 4 Evaluation of SecureDoc Disk Encryption Version 4.3C Issued by: Communications Security Establishment Certification Body Canadian Common Criteria Evaluation and Certification
SysPatrol - Server Security Monitor
SysPatrol Server Security Monitor User Manual Version 2.2 Sep 2013 www.flexense.com www.syspatrol.com 1 Product Overview SysPatrol is a server security monitoring solution allowing one to monitor one or
U.S. Federal Information Processing Standard (FIPS) and Secure File Transfer
IPSWITCH FILE TRANSFER WHITE PAPER U.S. Federal Information Processing Standard (FIPS) and Secure File Transfer www.ipswitchft.com FIPS 140-2 is a standard first published in 2001 by the U.S. National
A+ Guide to Software: Managing, Maintaining, and Troubleshooting, 5e. Chapter 3 Installing Windows
: Managing, Maintaining, and Troubleshooting, 5e Chapter 3 Installing Windows Objectives How to plan a Windows installation How to install Windows Vista How to install Windows XP How to install Windows
How To Protect Your Computer From Attack
FIPS PUB 140-2 CHANGE NOTICES (12-03-2002) FEDERAL INFORMATION PROCESSING STANDARDS PUBLICATION (Supercedes FIPS PUB 140-1, 1994 January 11) SECURITY REQUIREMENTS FOR CRYPTOGRAPHIC MODULES CATEGORY: COMPUTER
PC Business Banking. Technical Requirements
PC Business Banking Technical Requirements For PC Business Banking Version 7.0 March 2007 Application Overview PC Business Banking (PCBB) is Bank of New Zealand s banking platform for large business/corporate
