Maintenance Addendum BlackBerry Enterprise Server Version 4.1.6

Maintenance Report
Issued by:
Communications Security Establishment
Certification Body
Canadian Common Criteria Evaluation and Certification Scheme
© 2008 Government of Canada, Communications Security Establishment Canada
| Document number | 383-7-31-MR |
|---|---|
| Version | 1.0 |
| Date | November 3, 2008 |
1 Introduction
Electronic Warfare Associates-Canada (EWA-Canada) submitted an Impact Analysis Report to the CCS Certification Body on behalf of Research In Motion Limited, the developer of the BlackBerry® Enterprise Server Version 4.1.6 product. The Impact Analysis Report is intended to satisfy requirements outlined in version 1.0 of the Common Criteria document CCIMB-2004-02-009: Assurance Continuity: CCRA Requirements. In accordance with those requirements, the Impact Analysis Report (IAR) describes the changes made to BlackBerry® Enterprise Server Version 4.1.6 (the maintained Target of Evaluation), the evidence updated as a result of the changes and the security impact of the changes.
2 Description of changes
The following characterizes the changes implemented in the BlackBerry® Enterprise Server Version 4.1.6. For each change, it was verified that there were no required changes to the security functional requirements in the ST, and thorough functional and regression testing was conducted by the developer to ensure that the assurance in the Target of Evaluation (TOE) was maintained. The changes in the BlackBerry® Enterprise Server Version 4.1.6 comprise bug fixes. The new releases are as follows:
- BlackBerry Enterprise Server for IBM Lotus Domino Version 4.1.6 (4.1.6 bundle 38) English variant executing on Microsoft Windows Server 2003 Service Pack 2;
- BlackBerry Enterprise Server for Microsoft Exchange Version 4.1.6 (4.1.6 bundle 30) English variant executing on Microsoft Windows Server 2003 Service Pack 2;
- BlackBerry Enterprise Server for Novell Groupwise Version 4.1.6 (4.1.6 bundle 65) English variant executing on Microsoft Windows Server 2003 Service Pack 2;
3 Affected developer evidence
Modifications to the product necessitated changes to a subset of the developer evidence that was previously submitted for the TOE. The set of affected developer evidence was identified in the IAR.
4 Conclusions
Changes to the TOE were bug fixes. Through functional and regression testing of the BlackBerry® Enterprise Server Version 4.1.6 assurance gained in the original TOE certification was maintained. As all of the changes to the TOE have been classified as minor, it is the conclusion of the CB that the maintained TOE is appropriate for assurance continuity and re-evaluation is not required.