@@ -195,13 +195,13 @@ The product shall implement automatic secure update before or during first use.
This requirement applies to the subset of products within the indicated use cases that have the capability to self-update, i.e. not distributed by an “app store” or package distribution platform that manages all updates.
* UC-1: required
* UC-2: required
* UC-3: required
* UC-4: required
* UC-1: REQ-SU-03 (MI-KEVA) OR REQ-SU-04 (MI-KEVE)
* UC-2: REQ-SU-03 (MI-KEVA) OR REQ-SU-04 (MI-KEVE)
* UC-3: REQ-SU-03 (MI-KEVA) OR REQ-SU-04 (MI-KEVE)
* UC-4: REQ-SU-03 (MI-KEVA) OR REQ-SU-04 (MI-KEVE)
* UC-5: REQ-SU-03 (MI-KEVA) OR REQ-SU-04 (MI-KEVE)
* UC-6: required
* UC-7: required
* UC-6: REQ-SU-03 (MI-KEVA) OR REQ-SU-04 (MI-KEVE)
* UC-7: REQ-SU-03 (MI-KEVA) OR REQ-SU-04 (MI-KEVE)
### 5.5.4 REQ-SU-04 (MI-KEVE) Automatic secure update via operational environment before or during first use
@@ -561,7 +561,7 @@ This requirement applies to the subset of products within the indicated use case
* UC-3: required
* UC-4: required
* UC-5: required
* UC-6: required
* UC-6: not required
* UC-7: required
### 5.6.6 REQ-AAC-06 (MI-AUTH-5) Forced revocation of authorization of endpoints
@@ -582,7 +582,7 @@ This requirement applies to the subset of products within the indicated use case
* UC-3: required
* UC-4: required
* UC-5: required
* UC-6: required
* UC-6: not required
* UC-7: required
### 5.6.7 REQ-AAC-07 (MI-AUTH-6) Brute force protection
@@ -624,7 +624,7 @@ A node shall only allow connections from authorized endpoints.
* UC-3: required
* UC-4: required
* UC-5: required
* UC-6: required
* UC-6: not required
* UC-7: required
### 5.6.9 REQ-AAC-09 (MI-TRAF-5) Fine-grain access control
@@ -757,7 +757,7 @@ The VPN traffic shall be encrypted using session keys generated and held only by
#### 5.7.6.1 Requirement
1.**REQ-CON-06 (MI-DNSL-1)-1** The VPN client shall prominently inform the user of the handling of plaintext DNS queries under the current configuration and the consequences in simple plain language, focusing on the potential risk and impact to the user of such handling and, where applicable, potential steps to resolve this risk, and
1.**REQ-CON-06 (MI-DNSL-1)-1** The VPN client shall prominently inform the user of the visibility of plaintext DNS queries outside the tunnel under the current configuration and the consequences in simple plain language, focusing on the potential risk and impact to the user of such handling and, where applicable, potential steps to resolve this risk, and
2.**REQ-CON-06 (MI-DNSL-1)-2** the product shall require the user to actively confirm having read the information before being able to use the VPN connection.
#### 5.7.6.2 Applicability
@@ -940,22 +940,6 @@ Depending on the data type and operational environment, the product shall protec
* UC-6: required
* UC-7: required
### 5.7.16 REQ-CON-16 Inform user of limits of privacy protection
#### 5.7.16.1 Requirement
The product shall inform the user of the limitations of any privacy protection.
@@ -974,7 +958,6 @@ The product shall inform the user of the limitations of any privacy protection.
| REQ-CON-13 (MI-IPV6-2) | x | x | x | x | x | x | x |
| REQ-CON-14 (MI-CRYPT-1) | x | x | x | x | x | x | x |
| REQ-CON-15 (MI-CDST) | x | x | x | x | x | x | x |
| REQ-CON-16 | | x | x | | | | x |
## 5.8 Integrity protection
@@ -1092,7 +1075,7 @@ The product shall not collect data unnecessary for the operation of the product.
#### 5.9.2.1 Requirement
The product shall not collect Personal Data unless the collection is necessary for an intended purpose of the product, or the user has explicitly authorized it.
The product shall not collect Personal Data unless the collection is necessary for an intended purpose of the product, or the user or administrator has explicitly authorized it.
#### 5.9.2.2 Applicability
@@ -1165,7 +1148,7 @@ The VPN shall not store any Personal Data of the user on the VPN server, gateway
* UC-1: required
* UC-2: required
* UC-3: required
* UC-4: required
* UC-4: not required
* UC-5: not required
* UC-6: not required
* UC-7: required
@@ -1338,23 +1321,6 @@ This clause addresses the requirements in the CRA [\[i.1\]](#_ref_i.1) Annex 1 P
In addition to protecting data transiting the VPN from typical attacks, it is important that the collection of data via RDPS is not also an attack vector. In the event of a successful breach of a VPN manufacturer, attackers cannot exfiltrate data that does not exist.
1.**REQ-EMM-02 (MI-NUTI-1)-1** The VPN client and server shall be configurable to enforce granular packet filtering by application client or server identity, and destination address, and
2.**REQ-EMM-02 (MI-NUTI-1)-2** the VPN client and server shall only permit traffic that is validated and explicitly authorized to transit the VPN connection.
#### 5.13.2.2 Applicability
* UC-1: not required
* UC-2: not required
* UC-3: required
* UC-4: required
* UC-5: required
* UC-6: required
* UC-7: required
### 5.13.3 REQ-EMM-03 (MI-TRAF-2) Route traffic from other sources/destination disabled by default
#### 5.13.3.1 Requirement
@@ -1367,8 +1333,8 @@ The VPN client shall not route traffic through the endpoint from sources/destina
* UC-2: required
* UC-3: required
* UC-4: not required
* UC-5: REQ-EMM-03 (MI-TRAF-2) OR REQ-EMM-02 (MI-NUTI-1)
* UC-6: REQ-EMM-03 (MI-TRAF-2) OR REQ-EMM-02 (MI-NUTI-1)
* UC-5: required
* UC-6: required
* UC-7: not required
### 5.13.4 REQ-EMM-04 (MI-TRAF-3) Notify user if routing traffic from other sources/destination
@@ -1383,8 +1349,8 @@ The VPN client shall alert the user if the endpoint is allowing traffic from sou
* UC-2: required
* UC-3: required
* UC-4: not required
* UC-5: REQ-EMM-04 (MI-TRAF-3) OR REQ-EMM-02 (MI-NUTI-1)
* UC-6: REQ-EMM-04 (MI-TRAF-3) OR REQ-EMM-02 (MI-NUTI-1)
* UC-5: required
* UC-6: required
* UC-7: not required
### 5.13.5 REQ-EMM-05 (MI-TRAF-4) No routing traffic from other sources/destination if not necessary for services
@@ -1399,20 +1365,17 @@ The VPN client shall not require routing of traffic from sources/destinations ot
* UC-2: required
* UC-3: required
* UC-4: not required
* UC-5: REQ-EMM-05 (MI-TRAF-4) OR REQ-EMM-02 (MI-NUTI-1)
* UC-6: REQ-EMM-05 (MI-TRAF-4) OR REQ-EMM-02 (MI-NUTI-1)
* Logs or screenshots demonstrating the failure to read the data without authorization
* Documentation validating the encryption/hashing algorithms used
### 6.7.16 REQ-CON-16 Inform user of limits of privacy protection
#### 6.7.16.1 Objective
Privacy protection
#### 6.7.16.2 Preparation
Perform first install of product.
#### 6.7.16.3 Activities
Launch product.
#### 6.7.16.4 Verdict
PASS if **all** of the following are fulfilled:
* Initial onboarding provides information regarding boundaries of privacy protection.
Otherwise FAIL
#### 6.7.16.5 Evidence
* Screenshots
## 6.8 Integrity protection
### 6.8.1 Overview
@@ -1876,36 +1850,6 @@ Otherwise FAIL
This clause provides assessment for the requirements in [clause 5.13](#exploit-mitigation) relating to CRA [\[i.1\]](#_ref_i.1) Annex I Part 1 (2) (k).
Prevent unauthorized traffic in the VPN connection.
#### 6.13.2.2 Preparation
None
#### 6.13.2.3 Activities
1. Attempt to send traffic that is explicitly blocked by configuration directly to the network port used to route traffic into the VPN connection on the VPN client.
2. Repeat on VPN server.
#### 6.13.2.4 Verdict
PASS if **all** of the following are fulfilled:
* The traffic does not enter the VPN connection, and
* traffic does not exit it.
Otherwise FAIL
#### 6.13.2.5 Evidence
* Configuration file including the deny rule
* Packet capture of both incoming and outgoing interface
* Log message recording the denied traffic
### 6.13.3 REQ-EMM-03 (MI-TRAF-2) Route traffic from other sources/destination disabled by default