Amtliche Mitteilungen

Ordnungsmerkmale

erschienen in: <kes> 2004#6, Seite 44

Rubrik: BSI Forum

Schlagwort: Amtliche Mitteilungen

  1. Mit Datum 2004-09-24 wurde das Produkt "SafeGuardâ Easy 3.0 für Windowsâ 2000" der Firma Utimaco Safeware AG nach den CC zertifiziert. Das zusammenfassende Zertifikat wird im Folgenden abgedruckt.
  2. Mit Datum 2004-09-23 wurde das Produkt "Red Hat Enterprise Linux WS v. 3 U3" der Firma Red Hat Inc., gesponsert von der Firma Hewlett Packard (HP), nach den CC zertifiziert. Das zusammenfassende Zertifikat wird im Folgenden abgedruckt.
  3. Mit Datum 2004-09-23 wurde das Produkt "Red Hat Enterprise Linux AS v. 3 U3" der Firma Red Hat Inc., gesponsert von der Firma Hewlett Packard (HP), nach den CC zertifiziert. Das zusammenfassende Zertifikat wird im Folgenden abgedruckt.
  4. Mit Datum 2004-09-23 wurde das Produkt "SUSE Linux Enterprise Server 8 with service pack 3" der Firma SuSE Linux AG, gesponsert von der Firma Hewlett Packard (HP), nach den CC zertifiziert. Das zusammenfassende Zertifikat wird im Folgenden abgedruckt.
  5. Mit Datum vom 2004-09-23 wurde das Produkt "Renesas AE46C1 (HD65246C1) smartcard integrated circuit version 01" der Firma Renesas Technology Corporation nach den CC zertifiziert. Das zusammenfassende Zertifikat wird im Folgenden abgedruckt.
  6. Mit Datum vom 2004-09-16 wurde das Produkt "Philips P5CT072V0M and P5CC072V0M Secure Smart Card Controller" der Firma Philips Semiconductors GmbH Business Line Identification nach den CC zertifiziert. Das zusammenfassende Zertifikat wird im Folgenden abgedruckt.
  7. Mit Datum vom 2004-09-13 wurde das Produkt "Infineon Smart Card IC (Security Controller) SLE66CX322P with RSA2048 m1484b14 and m1484f18" der Firma Infineon Technologies AG nach den CC zertifiziert. Das zusammenfassende Zertifikat wird im Folgenden abgedruckt.
  8. Mit Datum vom 2004-09-08 wurde das Produkt "Philips P5CC036V0M Secure Smart Card Controller" der Firma Philips Semiconductors GmbH Business Line Identification nach den CC zertifiziert. Die zusammenfassende . Das zusammenfassende Zertifikat wird im Folgenden abgedruckt.
  9. Mit Datum vom 2004-09-06 wurde das Produkt "Philips P5CC009V0M Secure Smart Card Controller " der Firma Philips Semiconductors GmbH Business Line Identification nach den CC zertifiziert. Die zusammenfassende . Das zusammenfassende Zertifikat wird im Folgenden abgedruckt.
  10. Eine vollständige Liste aller zertifizierten Produkte sowie der in der Zertifizierung befindlichen Produkte erscheint vierteljährlich. Sie kann beim BSI angefordert oder unter [externer Link] www.bsi.bund.de/zertifiz/ heruntergeladen werden.
  11. Bis zur Veröffentlichung einer neuen Ausgabe dieser Druckschrift können weitere Produkte zertifiziert worden sein. Auskünfte hierüber erteilt das BSI unter +49 228 9582-111 (Infoline) oder sie können auf der o. g. Internetseite eingesehen werden.
  12. Im Vergleich zur letzten Ausgabe dieser amtlichen Mitteilungen ist inzwischen für folgende Produkte eine Zertifizierung beantragt worden:
    Antragsteller Produktname Produkttyp Zertifizierungs-ID
    IBM Corporation IBM Tivoli Access Manager Version 5.1 Access Management Application BSI-DSZ-CC-0285
    Microsoft Corporation Exchange Server 2003 E-Mail Server BSI-DSZ-CC-0284
    IBM Corporation IBM Tivoli Directory Server 6 LDAP Server BSI-DSZ-CC-0283
    Gemplus SA JavaCard Platform GXP3.2-E64PK-CC with GemSAFE V2 Digital Signature applet Smartcard als Signaturerstellungseinheit BSI-DSZ-CC-0281
    Fujitsu Siemens Computers GmbH KBPC "CC" S26381-K339-Vxxx PC Keyboard with Smartcard Reader (USB) BSI-DSZ-CC-0280
    IBM Corporation PR/SM on IBM zSeries 890 and 990 Operating System BSI-DSZ-CC-0279
    IBM Corporation PR/SM on IBM zSeries 890 and 990 Operating System BSI-DSZ-CC-0278
    Anmerkung:
  13. Mit Wirkung 2004-09-22 hat das BSI 15 neue IT-Grundschutz-Auditoren zertifiziert:
    Lizenz-Nummer Name des Auditors Kontaktinfos
    0125/2004 Roland Fröhlich Schindler Technik AG, 14199 Berlin, [externer Link] www.st-ag.de
    0126/2004 Matthias Ernst auf Anfrage
    0127/2004 Clemens Wanko TÜV Informationstechnik GmbH, 45141 Essen, [externer Link] www.tuvit.de
    0128/2004 Henning Boost CC Compunet, 12099 Berlin, [externer Link] www.compunet.de
    0129/2004 Frank Hanel Tele-Consulting, 71126 Gäufelden, [externer Link] www.tele-consulting.de
    0130/2004 Marian Kassovic SQS AG, 22767 Hamburg, [externer Link] www.sqs.de
    0131/2004 Michael Loos MAN Nutzfahrzeuge AG, 90441 Nürnberg, [externer Link] www.mn.man.de
    0132/2004 Holger Gerlach Gerlach Sicherheitsmanagement, 89231 Neu-Ulm, [externer Link] www.gerlach-sicherheit.de
    0133/2004 Stefan Morkovsky T-Systems GEI GmbH, 53111 Bonn, [externer Link] www.t-systems-itc-security.com
    0134/2004 Dr. Bernadetta Frenzel T-Systems GEI GmbH, 53111 Bonn, [externer Link] www.t-systems-itc-security.com
    0135/2004 Kay Schlüpmann Gesellschaft für Datenverarbeitung mbH, 42929 Wermelskirchen, [externer Link] www.gfd.de
    0136/2004 Jürgen Liebhäuser ::Microsec:: OHG, 90411 Nürnberg, [externer Link] www.microsec.de
    0137/2004 Dr. Sigrid Schumacher CSC Ploenzke AG, 80335 München, [externer Link] www.csc.com
    0138/2004 Thomas Grebe Geno Tec GmbH IT Managementberatung, 63263 Neu-Isenburg, [externer Link] www.geno-tec.de
    0139/2004 Dr. Thomas Holzwarth EXCELSIS Informationssysteme GmbH, 70176 Stuttgart , [externer Link] www.excelsisnet.com

BSI-DSZ-CC-0186-2004

SafeGuard Easy, Version 3.20 SR1 for Microsoft Windows 2000

from

Utimaco Safeware AG

The IT product identified in this certificate has been evaluated at an accredited and licensed/approved evaluation facility using the Common Methodology for IT Security Evaluation, Part 1 Version 0.6, Part 2 Version 1.0 for conformance to the Common Criteria for IT Security Evaluation, Version 2.1 (ISO/IEC 15408:1999) and including final interpretations for compliance with Common Criteria Version 2.2 and Common Methodology Part 2, Version 2.2.

Evaluation Results
Functionality: Product specific Security Target
Common Criteria part 2 conformant
Assurance Package: Common Criteria part 3 conformant
EAL3

This certificate applies only to the specific version and release of the product in its evaluated configuration and in conjunction with the complete Certification Report.

The evaluation has been conducted in accordance with the provisions of the certification scheme of the German Federal Office for Information Security (BSI) and the conclusions of the evaluation facility in the evaluation technical report are consistent with the evidence adduced.

The notes mentioned on the reverse side are part of this certificate.

Bonn, 24. September 2004
The President of the Federal Office for Information Security
Dr. Helmbrecht

BSI-DSZ-CC-0274-2004

Red Hat Enterprise Linux WS
Version 3, Update 3 with eal3-certification package

from

Red Hat Incorporated

sponsored by

Hewlett Packard Company

The IT product identified in this certificate has been evaluated at an accredited and licensed/approved evaluation facility using the Common Methodology for IT Security Evaluation, Part 1 Version 0.6, Part 2 Version 1.0 extended by CEM supplementation "ALC_FLR – Flaw remediation", Version 1.1 February 2002 for conformance to the Common Criteria for IT Security Evaluation, Version 2.1 (ISO/IEC 15408:1999) and including final interpretations for compliance with Common Criteria Version 2.2 and Common Methodology Part 2, Version 2.2.

Evaluation Results
PP Conformance: Controlled Access Protection Profile (CAPP), Issue 1.d, 1999-10-08
Functionality: CAPP conformant plus product specific extensions
Common Criteria Part 2 extended
Assurance Package: Common Criteria part 3 conformant
EAL3 augmented by ALC_FLR.3 (Systematic flaw remediation)

This certificate applies only to the specific version and release of the product in its evaluated configuration and in conjunction with the complete Certification Report.

The evaluation has been conducted in accordance with the provisions of the certification scheme of the German Federal Office for Information Security (BSI) and the conclusions of the evaluation facility in the evaluation technical report are consistent with the evidence adduced.

The notes mentioned on the reverse side are part of this certificate.

Bonn, 23. September 2004
The President of the Federal Office for Information Security
Dr. Helmbrecht

BSI-DSZ-CC-0273-2004

Red Hat Enterprise Linux AS
Version 3, Update 3 with eal3-certification package

from

Red Hat Incorporated

sponsored by

Hewlett Packard Company

The IT product identified in this certificate has been evaluated at an accredited and licensed/approved evaluation facility using the Common Methodology for IT Security Evaluation, Part 1 Version 0.6, Part 2 Version 1.0 extended by CEM supplementation "ALC_FLR – Flaw remediation", Version 1.1 February 2002 for conformance to the Common Criteria for IT Security Evaluation, Version 2.1 (ISO/IEC 15408:1999) and including final interpretations for compliance with Common Criteria Version 2.2 and Common Methodology Part 2, Version 2.2.

Evaluation Results
PP Conformance: Controlled Access Protection Profile (CAPP), Issue 1.d, 1999-10-08
Functionality: CAPP conformant plus product specific extensions
Common Criteria Part 2 extended
Assurance Package: Common Criteria part 3 conformant
EAL3 augmented by ALC_FLR.3 (Systematic flaw remediation)

This certificate applies only to the specific version and release of the product in its evaluated configuration and in conjunction with the complete Certification Report.

The evaluation has been conducted in accordance with the provisions of the certification scheme of the German Federal Office for Information Security (BSI) and the conclusions of the evaluation facility in the evaluation technical report are consistent with the evidence adduced.

The notes mentioned on the reverse side are part of this certificate.

Bonn, 23. September 2004
The President of the Federal Office for Information Security
Dr. Helmbrecht

BSI-DSZ-CC-0270-2004

SuSE Linux Enterprise Server V8
Service Pack 3 with certification-sles-hp-eal3 package

from

SUSE LINUX AG

sponsored by

Hewlett Packard Company

The IT product identified in this certificate has been evaluated at an accredited and licensed/approved evaluation facility using the Common Methodology for IT Security Evaluation, Part 1 Version 0.6, Part 2 Version 1.0 eextended by CEM supplementation "ALC_FLR – Flaw remediation", Version 1.1, February 2002 for conformance to the Common Criteria for IT Security Evaluation, Version 2.1 (ISO/IEC 15408:1999) and including final interpretations for compliance with Common Criteria Version 2.2 and Common Methodology Part 2, Version 2.2.

Evaluation Results
PP Conformance: Controlled Access Protection Profile (CAPP), Issue 1.d, 1999-10-08
Functionality: CAPP conformant plus product specific extensions
Common Criteria Part 2 extended
Assurance Package: Common Criteria part 3 conformant
EAL3 augmented by ALC_FLR.3 (Systematic flaw remediation)

This certificate applies only to the specific version and release of the product in its evaluated configuration and in conjunction with the complete Certification Report.

The evaluation has been conducted in accordance with the provisions of the certification scheme of the German Federal Office for Information Security (BSI) and the conclusions of the evaluation facility in the evaluation technical report are consistent with the evidence adduced.

The notes mentioned on the reverse side are part of this certificate.

Bonn, 23. September 2004
The President of the Federal Office for Information Security
Dr. Helmbrecht

BSI-DSZ-CC-0229-2004

Renesas AE46C1 (HD65246C1) Smartcard Integrated Circuit Version 01

from

Renesas Technology Corp.

The IT product identified in this certificate has been evaluated at an accredited and licensed/approved evaluation facility using the Common Methodology for IT Security Evaluation, Part 1 Version 0.6, Part 2 Version 1.0, extended by advice of the Certification Body for components beyond EAL4 and smart card specific guidance, for conformance to the Common Criteria for IT Security Evaluation, Version 2.1 (ISO/IEC 15408:1999) and including final interpretations for compliance with Common Criteria Version 2.2 and Common Methodology Part 2, Version 2.2.

Evaluation Results
PP Conformance: Protection Profile BSI-PP-0002-2001
Functionality: PP BSI-PP-0002-2001 conformant plus product specific extensions
Common Criteria Part 2 extended
Assurance Package: Common Criteria part 3 conformant
EAL4 augmented by:

ADV_IMP.2 (Development – Implementation of the TSF)
ALC_DVS.2 (Life cycle support – Sufficiency of security measures)
AVA_MSU.3 (Vulnerability assessment – Analysis and testing for insecure states)
AVA_VLA.4 (Vulnerability assessment – Highly resistant)

This certificate applies only to the specific version and release of the product in its evaluated configuration and in conjunction with the complete Certification Report.

The evaluation has been conducted in accordance with the provisions of the certification scheme of the German Federal Office for Information Security (BSI) and the conclusions of the evaluation facility in the evaluation technical report are consistent with the evidence adduced.

The notes mentioned on the reverse side are part of this certificate.

Bonn, 23. September 2004
The President of the Federal Office for Information Security
Dr. Helmbrecht

BSI-DSZ-CC-0227-2004

Philips P5CT072V0M and P5CC072V0M Secure Smart Card Controller

from

Philips Semiconductors GmbH Business Line Identification

The IT product identified in this certificate has been evaluated at an accredited and licensed/approved evaluation facility using the Common Methodology for IT Security Evaluation, Part 1 Version 0.6, Part 2 Version 1.0 extended by advice of the Certification Body for components beyond EAL4 and smart card specific guidance for conformance to the Common Criteria for IT Security Evaluation, Version 2.1 (ISO/IEC 15408:1999) and including final interpretations for compliance with Common Criteria Version 2.2 and Common Methodology Part 2, Version 2.2.

Evaluation Results
PP Conformance: Protection Profile BSI-PP-0002-2001
Functionality: BSI-PP-0002-2001 conformant plus product specific extensions
Common Criteria Part 2 extended
Assurance Package: Common Criteria part 3 conformant
EAL5 augmented by:

ALC_DVS.2 (Life cycle support – Sufficiency of security measures),
AVA_MSU.3 (Vulnerability assessment – Analysis and testing for insecure states),
AVA_VLA.4 (Vulnerability assessment – Highly resistant)

This certificate applies only to the specific version and release of the product in its evaluated configuration and in conjunction with the complete Certification Report.

The evaluation has been conducted in accordance with the provisions of the certification scheme of the German Federal Office for Information Security (BSI) and the conclusions of the evaluation facility in the evaluation technical report are consistent with the evidence adduced.

The notes mentioned on the reverse side are part of this certificate.

Bonn, 16. September 2004
The President of the Federal Office for Information Security
Dr. Helmbrecht

BSI-DSZ-CC-0265-2004

Infineon Smart Card IC (Security Controller) SLE66CX322P with RSA 2048
m1484b14 and m1484f18

from

Infineon Technologies AG

The IT product identified in this certificate has been evaluated at an accredited and licensed/approved evaluation facility using the Common Methodology for IT Security Evaluation, Part 1 Version 0.6, Part 2 Version 1.0 extended by advice of the Certification Body for components beyond EAL4 and smart card specific guidance for conformance to the Common Criteria for IT Security Evaluation, Version 2.1 (ISO/IEC 15408:1999) and including final interpretations for compliance with Common Criteria Version 2.2 and Common Methodology Part 2, Version 2.2.

Evaluation Results
PP Conformance: Protection Profile BSI-PP-0002-2001
Functionality: BSI-PP-0002-2001 conformant plus product specific extensions
Common Criteria Part 2 extended
Assurance Package: Common Criteria part 3 conformant
EAL5 augmented by:

ALC_DVS.2 (Life cycle support – Sufficiency of security measures),
AVA_MSU.3 (Vulnerability assessment – Analysis and testing for insecure states),
AVA_VLA.4 (Vulnerability assessment – Highly resistant)

This certificate applies only to the specific version and release of the product in its evaluated configuration and in conjunction with the complete Certification Report.

The evaluation has been conducted in accordance with the provisions of the certification scheme of the German Federal Office for Information Security (BSI) and the conclusions of the evaluation facility in the evaluation technical report are consistent with the evidence adduced.

The notes mentioned on the reverse side are part of this certificate.

Bonn, 13. September 2004
The Vice President of the Federal Office for Information Security
Hange

BSI-DSZ-CC-0232-2004

BSI-DSZ-CC-0232-2004

from

Philips Semiconductors GmbH Business Line Identification

The IT product identified in this certificate has been evaluated at an accredited and licensed/approved evaluation facility using the Common Methodology for IT Security Evaluation, Part 1 Version 0.6, Part 2 Version 1.0 extended by advice of the Certification Body for components beyond EAL4 and smart card specific guidance for conformance to the Common Criteria for IT Security Evaluation, Version 2.1 (ISO/IEC 15408:1999) and including final interpretations for compliance with Common Criteria Version 2.2 and Common Methodology Part 2, Version 2.2.

Evaluation Results
PP Conformance: Protection Profile BSI-PP-0002-2001
Functionality: BSI-PP-0002-2001 conformant plus product specific extensions
Common Criteria Part 2 extended
Assurance Package: Common Criteria part 3 conformant
EAL5 augmented by:

ALC_DVS.2 (Life cycle support – Sufficiency of security measures),
AVA_MSU.3 (Vulnerability assessment – Analysis and testing for insecure states),
AVA_VLA.4 (Vulnerability assessment – Highly resistant)

This certificate applies only to the specific version and release of the product in its evaluated configuration and in conjunction with the complete Certification Report.

The evaluation has been conducted in accordance with the provisions of the certification scheme of the German Federal Office for Information Security (BSI) and the conclusions of the evaluation facility in the evaluation technical report are consistent with the evidence adduced.

The notes mentioned on the reverse side are part of this certificate.

Bonn, 8. September 2004
The Vice President of the Federal Office for Information Security
Hange

BSI-DSZ-CC-0231-2004

Philips P5CC009V0M Secure Smart Card Controller

from

Philips Semiconductors GmbH Business Line Identification

The IT product identified in this certificate has been evaluated at an accredited and licensed/approved evaluation facility using the Common Methodology for IT Security Evaluation, Part 1 Version 0.6, Part 2 Version 1.0 extended by advice of the Certification Body for components beyond EAL4 and smart card specific guidance for conformance to the Common Criteria for IT Security Evaluation, Version 2.1 (ISO/IEC 15408:1999) and including final interpretations for compliance with Common Criteria Version 2.2 and Common Methodology Part 2, Version 2.2.

Evaluation Results
PP Conformance: Protection Profile BSI-PP-0002-2001
Functionality: BSI-PP-0002-2001 conformant plus product specific extensions
Common Criteria Part 2 extended
Assurance Package: Common Criteria part 3 conformant
EAL5 augmented by:

ALC_DVS.2 (Life cycle support – Sufficiency of security measures),
AVA_MSU.3 (Vulnerability assessment – Analysis and testing for insecure states),
AVA_VLA.4 (Vulnerability assessment – Highly resistant)

This certificate applies only to the specific version and release of the product in its evaluated configuration and in conjunction with the complete Certification Report.

The evaluation has been conducted in accordance with the provisions of the certification scheme of the German Federal Office for Information Security (BSI) and the conclusions of the evaluation facility in the evaluation technical report are consistent with the evidence adduced.

The notes mentioned on the reverse side are part of this certificate.

Bonn, 6. September 2004
The Vice President of the Federal Office for Information Security
Hange