Skip to content

ESC as source for TOE updates (App PP base) #3

Description

@jfisherbah

This PP-Module requires the TOE to obtain updates to itself from a call control server or file server managed by the organization deploying the TOE. The NDcPP does not specify a manner of obtaining updates so there is no issue here when the TOE is a network device. However, when the TOE is a software application, FPT_TUD_EXT.2 in the App PP requires application updates to be delivered either in the form of the "platform-provided package manager" or a container image.

Since this particular case has the TOE obtaining an update from the ESC as opposed to an intermediary package manager/app store/etc., it could be any executable format. For example, a Linux application running on Red Hat would not use rpm to obtain the update and so the update may not necessarily be packaged as a .rpm file.

Is this distinction something we should be concerned about and if so, what should be the appropriate way to handle it in section 5.2? It is probably reasonable to say that the update must still be packaged in the format used by the platform's package manager even if that package manager isn't used to distribute the TOE.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions