Certification Body Decisions
From time to time, issues arise during testing or in response to questions from interested parties. Occasionally, these will lead the NetSecOPEN Certification Body to change the testing requirements.
These decisions will be documented below.
April 2, 2023
NETSECOPEN-CERT-001
Issue: Expand allowable test scenarios for RFC 9411 Appendix A.3.2 https://www.rfc-editor.org/rfc/rfc9411.html#name-test-equipment-configuration-parame-3 for greater flexibility.
Decision: In addition to the RFC 9411 A.3.2 background traffic of 45% HTTP 64K + 45% HTTPS 64K allow the use of the current application mixes (either) at 95%, or HTTP 64K or HTTPS 64K at 95%.
February 2, 2024
NETSECOPEN-CERT-002
Issue: During the vulnerability testing of a DUT it was determined that CVE 2016-3368 was encrypted. All of the CVEs in the test set should be unencrypted.
Decision: In order to avoid needless use of development resources of the test tool vendors, the cert body has directed the labs to not include the detection results for CVE 2016-3368 in future reports. This reduces the size of the public vulnerability set to 1,380 samples.