SignaCert Verify Readme Version 1.6.0 Release Date 2/6/2008 1.0 DESCRIPTION This program is used to check and verify binary level compliance with the FDCC standard build for Windows XP desktops (Windows Vista is coming soon). This program scans files in the Windows directory and compares them with files that are part of the Federal Desktop Core Configuration standard build release 1.0.1. The client then creates a report showing the differences between the verified machine and the FDCC standard. 2.0 SECURITY INFORMATION 2.1 Installation The SignaCert Verify client download package can be verified by using the MD5 cryptographic hash provided in the download email. The client is a compressed (.zip) file that needs only to be extracted to run. Files can be extracted into any specified directory. The client does not use an installer and makes no modifications whatsoever to the Windows registry. The client is java based and is completely self- contained. All required Java Runtime Environment files are included in the download package so no additional software is required. 2.2 Execution The client is executed only on user command. Running the 'Start FDCC Verification.cmd' runs a script that launches the client. When running the application communicates with the SignaCert Verify service using SOAP over HTTPS. This takes advantage of port 443 outbound as it is commonly available for communications of this type. The client first makes a request for the appropriate policy to scan the target machine. This policy is delivered as a signed xml document for use by the client. The policy defines what directories and what file types to scan on the target machine. The policy can only be modified by authorized SignaCert Personnel and is not accessible to anyone else. The client scans the disk of the target machine as defined by the policy and computes cryptographic hash values for the files it finds. The policy also specifies the required hash algorithm, SHA1 for this purpose. The path, filename and cryptographic hash values are compiled into a signed xml file to be sent to the SignaCert Verify service for computation. NO USER DATA OR PERSONALLY IDENIFIABLE INFORMATION IS EVER CAPTURED OR TRANSMITTED TO THE SIGNACERT VERIFY SERVICE. The SignaCert Verify service returns a signed verification response to be processed by the client for display. The client uses an xsl transform to create an html report and a csv file for viewing. The client is non-memory resident. Once a scan is complete the client stops running until a user launches it again. 2.3 Removal Delete the "SignaCertVerify_Release1.0.1' folder to remove the client. On extraction the client creates no dependencies on other components and makes no modifications to the system or registry settings. 2.4 Alternate Implementations SignaCert provides a complete suite of verification services and can fulfill many architectures based on your security needs. If you require additional security, please contact us so we may discuss how to best accommodate your needs. 3.0 VERIFYING YOUR DESKTOP The client can be downloaded and extracted to any location on the target machine. Once extracted, open the folder named 'SignaCert Verify_Release1.0.1' and click the 'Start FDCC Verification.cmd' to begin the assessment. The client will then scan the machine and locally capture cryptographic hashes for the files it finds. Scanning is limited by policy to ONLY the c:\windows directories. NO USER DIRECTORIES ARE SCANNED. The following directories within c:\windows will not be scanned due to the dynamic nature of the files stored there: * c:\WINDOWS\Prefetch\ * c:\windows\$* * c:\windows\$hf_mig$ * c:\windows\$ntservicepackuninstall$ * c:\windows\pchealth\helpctr\config * c:\windows\pchealth\helpctr\datacoll * c:\windows\pchealth\helpctr\packagestore * c:\windows\pchealth\helpctr\system\remote assistance\interaction * c:\windows\softwaredistribution\download * c:\windows\system32\config\systemprofile\application data\... ...microsoft\cryptneturlcache * c:\windows\system32\inetsrv\history * c:\windows\system32\wbem\autorecover * c:\windows\system32\wbem\repository\fs * c:\windows\tasks * c:\windows\temp File types are also specified by policy. Only the executable file types listed below are scanned. NO USER FILES ARE SCANNED NOR IS ANY USER SPECIFIC INFORMATION CAPTURED. * .bat * .exe * .cmd * .ocx * .dll * .scr * .drv * .sys SignaCert Verify will NOT examine any other file types to assess FDCC compliance. Once the scan is complete, the client sends a digitally signed xml file to SignaCert Verify to compare these values with the FDCC reference to compute the results. Results are returned to the client which converts them into an html file for viewing locally. This file is named 'FDCCCompliance.html' and is stored in the 'SignaCertVerify_Release1.0.1' folder. You can view these results at any time. 4.0 INTERPRETING RESULTS SignaCert Verify returns the differences between the verified desktop and the appropriate FDCC reference. These deviations take three basic forms; modified files, removed files and added files. For every deviation, SignaCert Verify will attempt to determine what product the file belongs to to provide as much information as possible and help diagnose what caused them. * Modified files--deviations of this type indicate that the file on the verified desktop has the same name and path as specified in the FDCC reference, but has a different cryptographic hash. This means that while the name is the same, the contents of the file have changes. These files should be examined closely to determine if they represent a risk to your computer. * Removed files--deviations of this type indicate that a file that is part of the FDCC reference could not be found on the verified desktop. Removed files may be critical to system operation or security and should be replaced if possible. * Added files--deviations of this types indicate that a file was found on the verified desktop that is not part of the FDCC reference. SignaCert Verify will attempt to identify the product that these files belong to determine if they represent a potential risk. 5.0 MORE INFORMATION More information about SignaCert Verify can be found at: www.signacert.com/products/verify You may request technical support for SignaCert Verify in the following ways: Phone: 1-888-579-4533 E-mail: verifyhelp@signacert.com Hours of operation: * Pacific Daylight Time - 6:00 a.m. to 6:00 p.m. * Eastern Daylight Time - 9:00 a.m. to 9:00 p.m. * Greenwich Mean Time - 1:00 p.m. to 1:00 a.m. * Japan Standard Time - 10:00 p.m. to 10:00 a.m.