Brocade Communications Systems FCX Series User Manual Page 27

  • Download
  • Add to my manuals
  • Print
  • Page
    / 53
  • Table of contents
  • BOOKMARKS
  • Rated. / 5. Based on customer reviews
Page view 26
Version 1.1, 05/19/2014
GSS CCT Evaluation Technical Report Page 27 of 53
© 2014 Gossamer Security Solutions, Inc.
Document: AAR-BrocadeFastIron8010
All rights reserved.
Test 1: The evaluator shall attempt to perform a diffie-hellman-group1-sha1 key exchange, and observe that the
attempt fails. For each allowed key exchange method, The evaluator shall then attempt to perform a key
exchange using that method, and observe that the attempt succeeds.
The evaluator was able to observe from previous tests that diffie-hellman-group14-sha1 key exchange was used in
all negotiations. The evaluator attempted a diffie-hellman-group1-sha1 key exchange and the request was
rejected.
2.2.9 EXPLICIT: TLS (FCS_TLS_EXT.1)
2.2.9.1 FCS_TLS_EXT.1.1
TSS Assurance Activities: The evaluator shall check the description of the implementation of this protocol in the
TSS to ensure that optional characteristics (e.g., extensions supported, client authentication supported) are
specified, and the ciphersuites supported are specified as well. The evaluator shall check the TSS to ensure that the
ciphersuites specified are identical to those listed for this component.
The SFR claims only the required 4 ciphers and those are identified in section 6.2 of the TSS. Section 6.2 also
indicates that TLSv1.0 is supported, matching the SFR claim.
Guidance Assurance Activities: The evaluator shall also check the operational guidance to ensure that it contains
instructions on configuring the TOE so that TLS conforms to the description in the TSS (for instance, the set of
ciphersuites advertised by the TOE may have to be restricted to meet the requirements).
The ST indicates that TLSv1.0 is supported and identifies the following required ciphersuites:
TLS_RSA_WITH_AES_128_CBC_SHA, TLS_RSA_WITH_AES_256_CBC_SHA,
TLS_DHE_RSA_WITH_AES_128_CBC_SHA, and TLS_DHE_RSA_WITH_AES_256_CBC_SHA.
The FIPS Configuration Guide How FIPS Works indicates that the fips enable instruction places the TOE into FIPS
mode. Once in FIPS mode, that section indicates that SSL3.0 is disabled and only TLSv1.0 or greater can be used
with the TOE.
The FIPS Configuration Guide in the “Supported cipher suitessection lists the TLS cipher suites as:
TLS_RSA_WITH_AES_128_CBC_SHA, TLS_RSA_WITH_AES_256_CBC_SHA,
TLS_DHE_RSA_WITH_AES_128_CBC_SHA, and TLS_DHE_RSA_WITH_AES_256_CBC_SHA. This list matches those
provided in the ST.
Testing Assurance Activities: The evaluator shall also perform the following test:
Page view 26
1 2 ... 22 23 24 25 26 27 28 29 30 31 32 ... 52 53

Comments to this Manuals

No comments