top of page

Certification Body Decisions

From time to time, issues arise during testing or in response to questions from interested parties. Occasionally, these will lead the NetSecOPEN Certification Body to change the testing requirements.

These decisions will be documented below.

April 2, 2023

NETSECOPEN-CERT-001

Issue: Expand allowable test scenarios for RFC 9411 Appendix A.3.2 https://www.rfc-editor.org/rfc/rfc9411.html#name-test-equipment-configuration-parame-3 for greater flexibility.

Decision: In addition to the RFC 9411 A.3.2 background traffic of 45% HTTP 64K + 45% HTTPS 64K allow the use of the current application mixes (either) at 95%, or HTTP 64K or HTTPS 64K at 95%.

February 2, 2024

NETSECOPEN-CERT-002

Issue: During the vulnerability testing of a DUT it was determined that CVE 2016-3368 was encrypted. All of the CVEs in the test set should be unencrypted.

Decision: In order to avoid needless use of development resources of the test tool vendors, the cert body has directed the labs to not include the detection results for CVE 2016-3368 in future reports. This reduces the size of the public vulnerability set to 1,380 samples.

bottom of page