[CygnaCom Solutions logo]
Login    Contact Us   
  Products   Services   Corporate   Labs   Careers
Search
Security Testing and Evaluation Labs
 
 
Security Evaluation Laboratory
 
Overview (pdf)
 
Common Criteria
 
Evaluated Products
 
More Information...
 
CC Assurance Index
 
CC Function Index
 
 
Cryptographic Equipment Assessment Laboratory
Careers
 
Contact Us


Entrust Home
Security Testing
 

Security Testing and Evaluation Labs

Security Evaluation Laboratory (SEL)


NSA : PKI Certification Authority PP

Sponsor:National Security Agency
Assurance Level:EAL3+
Status:Completed

This Protection Profile describes a minimum set of Information Technology (IT) security requirements that must be implemented by any MISSI CMI assurance level Certification Authority operating in the MISSI Certificate Management Infrastructure.

The primary goal of this document is to map as directly as possible the US Department of Defense X.509 Certificate Policy requirements [USDOD_CP] to the latest version of the Common Criteria (CC). Hence, the primary source documents for this Protection Profile are the US Department of Defense X.509 Certificate Policy, draft, Version 0.9.1 [USDOD_CP], and the Certification Practices Statement for the Certificate Management Infrastructure of the Defense Information Infrastructure, draft, Version 0.2 [CPS].

The TOE is a Certification Authority (CA) that complies with US DOD CP. The general term CA refers to the following entities:

  • Policy Approving Authority (PAA)
  • Policy Creation Authority (PCA)
  • Certification Authority (CA)
  • Indirect Certification Revocation List Authority (ICRLA)
For the purposes of this Protection Profile, the TOE will be restricted to the specific form of the term CA, which is an administrative entity with the responsibility for issuing certificates and CRLs for end entities/Registration Authorities (RAs), and not for other generic Certificate Authorities.

The TOE is a CA software application (with a database) that depends on an OS for performing Identification & Authentication (and access control) and a cryptomodule for performing cryptographic services. Although the PP is written for the CA system, it only includes the functional/assurance components of the CA software application because assumptions were made to reflect that the CA application relies on the OS and cryptomodule to perform other services.

The CA will be of any MISSI CMI assurance level, and the differing requirements for the different assurance levels will be specified. The MISSI CMI assurance level defined here for the CA is associated with the US DOD Certificate Policy and is different from the Common Criteria notion of assurance. To distinguish the two notions of assurance, this document hereafter refers to the assurance level associated with the US DOD Certificate Policy as "MISSI CMI assurance level". For more information on MISSI CMI assurance levels, see Section 2.3.

Back to SEL Main Page

 
 
   Privacy Statement    Legal    Contact Us