Re: Is OpenBSD + PF accredited or certified in any way ?

Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]
From: T. Ribbrock
Date: Thursday, February 4, 2010 - 2:18 am

On Wed, Feb 03, 2010 at 11:10:59PM +0100, Martin Schr?der wrote:



ITYM http://www.genua.de/produkte/firewall/genugate/zerti/index.en.html

The EAL6 refers to the augmentations they did to the EAL4 package (the
"+" in EAL4+). Nonetheless, neither means *anything* unless you've also
read the claims they've made ("Security Target"). In theory, they could
evaluate the whole firewall under the assumption that no network
connections are present and *still* get a valid EAL4+ certification - so
you really need to know what the claims were.

Genua themselves don't seem to provide easy access on their own site to
the Security Target (though I didn't search very thoroughly), but you
stand a good chance of finding the full public report on
http://www.commoncriteriaportal.org/

Cheerio,

Thomas
-- 
 ****** PLEASE: NO Cc's to me privately, I do read the list - thanks! ******
-----------------------------------------------------------------------------
                    Thomas Ribbrock    http://www.ribbrock.org
   "You have to live on the edge of reality - to make your dreams come true!"
Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]

Messages in current thread:
Re: Is OpenBSD + PF accredited or certified in any way ?, Marco Peereboom, (Mon Feb 1, 4:41 pm)
Re: Is OpenBSD + PF accredited or certified in any way ?, Matthew Szudzik, (Mon Feb 1, 4:59 pm)
Re: Is OpenBSD + PF accredited or certified in any way ?, Martin Schröder, (Tue Feb 2, 12:29 pm)
Re: Is OpenBSD + PF accredited or certified in any way ?, Marco Peereboom, (Tue Feb 2, 12:36 pm)
Re: Is OpenBSD + PF accredited or certified in any way ?, Janne Johansson, (Wed Feb 3, 4:52 am)
Re: Is OpenBSD + PF accredited or certified in any way ?, Martin Schröder, (Wed Feb 3, 3:10 pm)
Re: Is OpenBSD + PF accredited or certified in any way ?, T. Ribbrock, (Thu Feb 4, 2:18 am)
Re: Is OpenBSD + PF accredited or certified in any way ?, Henning Brauer, (Fri Feb 12, 2:55 am)