| By Red Hat News Desk | Article Rating: |
|
| February 18, 2006 11:45 AM EST | Reads: |
6,180 |
atsec information security corporation, an independent, standards-based IT (information technology) security consulting and evaluation services company, has completed the Common Criteria (CC) evaluation of Red Hat Enterprise Linux 4 on a range of IBM server platforms. The evaluation of Red Hat Enterprise Linux 4 at Evaluation Assurance Level (EAL) 4+ is the first successful Linux evaluation at this assurance level performed under the U.S. NIAP (National Information Assurance Partnership) CCEVS (Common Criteria Evaluation and Validation Scheme). This success builds on atsec's long record of more than 20 successful CC evaluations including six Linux evaluations on five different Linux platforms at assurance levels EAL2, EAL3, and EAL4+, performed with several vendors under both the German BSI (Bundesamt für Sicherheit in der Informationstechnik) and U.S. CCEVS schemes.
"atsec and IBM's maturity in evaluating Linux facilitated a smooth and timely evaluation under the U.S. scheme," said Fiona Pattinson, atsec Common Criteria lab manager.
The WS and AS distributions of the Red Hat Enterprise Linux 4 operating system platform were certified by the NIAP CCEVS as conformant to EAL4+ and the Controlled Access Protection Profile (CAPP), which specifies a set of security functional and assurance requirements for IT products.
The scrutiny of Linux continues. Red Hat Enterprise Linux 5 is in evaluation at EAL4 including the security functionality defined in three protection profiles recognized by the Common Criteria: Controlled Access Protection Profile (CAPP), Labeled Security Protection Profile (LSPP) and Role-Based Access Control Protection Profile (RBAC). These profiles support the requirements of Director of Central Intelligence Directive (DCID) 6/3 at Protection Level 4, which specifies security intelligence related information and systems measures, including those necessary for Top Secret and Below Interoperability (TSABI).
One more significant "first" emerged during the Red Hat Enterprise Linux 4 evaluation. In order to address the requirements of the CAPP, the audit subsystem was re-implemented. In accordance with the collaborative, open source nature of Linux development, the audit subsystem solution was offered back to the open source community for discussion and ultimately, acceptance.
"Throughout the history of atsec's Linux evaluation projects, I have been amazed by the level of support provided by commercial enterprises for the open source community," said Stephan Mueller, atsec's lead evaluator for Linux projects since 2004. "IBM demonstrated its real commitment to the Linux open source community -- as well as to security -- by sharing the results of its substantial investment leading to the Red Hat Enterprise Linux 4 evaluation."
The formal announcement of the successful CAPP/EAL4+ evaluation completion of Red Hat Enterprise Linux 4 was made at the RSA Conference 2006 in San Jose, Calif.
Published February 18, 2006 Reads 6,180
Copyright © 2006 SYS-CON Media, Inc. — All Rights Reserved.
Syndicated stories and blog feeds, all rights reserved by the author.
More Stories By Red Hat News Desk
Red Hat News Desk trawls the world's news information sources and brings you timely updates on its flagship Red Hat Enterprise Linux as well as the company's other product lines including database, content, and collaboration management applications; server and embedded operating systems; and software - including its most recent virtualization offerings.
![]() |
linuxworld news desk 02/18/06 12:10:39 AM EST | |||
atsec information security corporation, an independent, standards-based IT security consulting and evaluation services company, has completed the Common Criteria (CC) evaluation of Red Hat Enterprise Linux 4 on a range of IBM server platforms. The evaluation of Red Hat Enterprise Linux 4 at Evaluation Assurance Level (EAL) 4+ is the first successful Linux evaluation at this assurance level performed under the U.S. NIAP CCEVS. |
||||
- Ubuntu-based Open Source Linux Mint Tests KDE Version
- Linux Virtualization and Tired Open Source Myths
- IGEL Supports Red Hat Enterprise Virtualization 3.0
- CloudLinux Announces Support for Atomia
- Amazon Kindle Fire Gets Its Own 'Personal Cloud Desktop' with AlwaysOnPC App Launch
- SPIRIT DSP Receives 2011 INTERNET TELEPHONY Product of the Year Award
- Hadoop Quickstart: Use Whirr to automate standup of your distributed cluster on Rackspace
- Jury Gets Novell Antitrust Case Against Microsoft
- The Utility Infrastructure Security Market 2012-2022: Cybersecurity & Smart Grids
- FORTUNE Magazine Names Rackspace Among “100 Best Companies to Work For”
- EnterpriseDB Announces Availability of Postgres Plus Cloud Database
- iFollowOffice Turns to Virtual Bridges and Savvis for On-Demand Virtual Desktop Services
- i-Technology in 2012: Five Industry Predictions
- Ubuntu-based Open Source Linux Mint Tests KDE Version
- Amazon to Rent Out Supercomputers
- Amazon Émigré Starts Network Monitoring Firm
- HP’s Putting a Back Door in the Itanium Alamo
- Linux Virtualization and Tired Open Source Myths
- CloudLinux Announces Preferred Partner Program
- MapR Pushes the Hadoop Envelope
- Rightware Announces Gaming Performance Benchmark for OpenGL ES 3.0/Halti
- IGEL Supports Red Hat Enterprise Virtualization 3.0
- CloudLinux Announces Support for Atomia
- 3Dconnexion Announces its Newest 3D Mouse - the SpaceMouse Pro
- The i-Technology Right Stuff
- Linux.SYS-CON.com Exclusive: Linus Discloses *Real* Fathers of Linux
- After Ubuntu, Windows Looks Increasingly Bad, Increasingly Archaic, Increasingly Unfriendly
- A Closer Look at Damn Small Linux
- Linus' Top Ten SCO Barbs
- SCO CEO Posts Open Letter to the Open Source Community
- Netscape Co-Founder's 12 Reasons for Growth of Open Source
- Where Are RIA Technologies Headed in 2008?
- *POINT - COUNTERPOINT SPECIAL* What's Wrong with the Open Source Community?
- Introducing "Cooperative Linux" - Linux for Windows, No Less
- Linux.SYS-CON.com Exclusive: What Would UserLinux Look Like?
- Why Recovering a Deleted Ext3 File Is Difficult . . .




















