Common Criteria Certification
In this section:
- Common Criteria OverviewCommon Criteria certification for a device enforces a set of security standards and feature limitations on a device to be compliant with the Common Criteria standards, similar to placing the device in FIPS mode. These restrictions are in addition to the requirements of FIPS mode. When the device is placed in Common Criteria mode, several security features that are available in FIPS mode are unavailable on the device. Because Common Criteria mode enforces security restrictions additional to FIPS mode, procedures and information are provided in relation to those for the FIPS mode.
- Enabling Common Criteria ModeWhen you enable Common Criteria mode on the device, it enters the Common Criteria Administrative mode. Similar to FIPS, Common Criteria also has administrative and operational modes:
- Encrypted Syslog Servers in Common Criteria ModeFastIron devices in any mode send the generated syslog messages in real time to the local log storage on the device. Local log storage can be configured and holds up to 4,000 messages by default. Old audits are overwritten in local log storage when the configured maximum is reached. FastIron devices in any mode also send generated syslog messages to a syslog server (only if a syslog server is configured and available).
- AAA Servers in Common Criteria ModeCommon Criteria mode requires that devices support NDcPP version 2.2e or above. This standard requires the communication of the device with AAA servers to take place over a TLS-encrypted session.
- Downgrading from Common Criteria Mode to Non-FIPS ModeDowngrading a device from Common Criteria mode either to FIPS mode or to non-FIPS mode uses the same command. You cannot directly downgrade to FIPS mode. You must first downgrade to non-FIPS mode and then enable FIPS mode using the procedures detailed in the previous chapter.
- Commercial Solutions for Classified program
- Configuring NTP
- Configuring PKI
- Network Device Collaborative Protection
ProfileThe Network Collaborative Device Protection Profile (NDcPP) standards provide a set of rules that define the security requirements for network devices. The main purpose of these requirements is to minimize and reduce threats to network devices. NDcPP requires SSH or TLS for syslog and authentication server communications.
- MACsec Configuration