Installation guide

Motorola WS5100 Wireless Switch and RFS7000 RF Switch Security Target
Page 29 of 85
5.2.1.28 FMT_SMF.1(3) Specification of management functions (cryptographic key data)
FMT_SMF.1.1(3) The TSF shall be capable of performing the following security management
functions: [query, set, modify, and delete the cryptographic keys and key data in support of
FDP_PUD_EXP and enable/disable verification of cryptographic key testing].
Application Note: The intent of this requirement is to provide the ability to configure the TOE’s cryptographic
key(s). Configuring the key data may include: setting key lifetimes, setting key length, etc.
5.2.1.29 FMT_SMR.1(1) Security roles
FMT_SMR.1.1(1) The TSF shall maintain the roles [administrator, wireless user].
FMT_SMR.1.2(1) The TSF shall be able to associate users with roles.
Application Note: The only user allowed direct access to the TOE is the administrator. Wireless users can
pass data through the TOE but do not have direct access. A role of wireless user is included in the TOE, but
the scope of that role should be defined only to the extent necessary to support the activities of wireless users
passing data through the TOE.
This ST also assumes that the TOE will contain a local authentication mechanism and the capability to use a
remote authentication server. Although users are sometimes referred to as local or remote, these references
do not imply a role.
5.2.1.30 FPT_RVM.1(1) Non-bypassability of the TOE Security Policy (TSP)
FPT_RVM.1.1(1) The TSF shall ensure that TSP enforcement functions are invoked and succeed
before each function within the TSC is allowed to proceed.
5.2.1.31 FPT_SEP.1(1) TSF domain separation
FPT_SEP.1.1(1) The TSF shall maintain a security domain for its own execution that protects it
from interference and tampering by untrusted subjects.
FPT_SEP.1.2(1) The TSF shall enforce separation between the security domains of subjects in the
TSC.
5.2.1.32 FPT_STM_EXP.1 Reliable time stamps
FPT_STM_EXP.1.1 The TSF shall be able to provide reliable time stamps, synchronized via an
external time source, for its own use.
Application Note: The TOE must be capable of obtaining a time stamp via an NTP server.
5.2.1.33 FPT_TST_EXP.1 TSF testing
FPT_TST_EXP.1.1 The TSF shall run a suite of self-tests during initial start-up and upon request, to
demonstrate the correct operation of the hardware portions of the TSF.