April 29, 2004 10:57 AM PDT

Red Hat gains security certification

Red Hat's newest version of Linux has been granted a significant security certification, bringing the company a step closer to competitors.


Get Up to Speed on...
Enterprise security
Get the latest headlines and
company-specific news in our
expanded GUTS section.


Version 3 of Red Hat Enterprise Linux has been certified to meet Evaluation Assurance Level 2 (EAL2) of the Common Criteria certification, Red Hat said Thursday. The internationally recognized Common Criteria certification is a typical requirement for government customers.

However, Red Hat still lags behind its main rival, Novell, whose SuSE Linux has been certified to meet the more stringent EAL3. It also trails versions of Unix and Windows that have EAL4 certification.

Common Criteria certification is expensive. Oracle helped Red Hat achieve its certification, while IBM helped with SuSE Linux.

Red Hat also said it will add support for Security-Enhanced Linux, a project begun by the National Security Agency. SELinux uses "mandatory access controls" to reduce security threats by giving minimum privileges to computer users and processes.

The SELinux support will arrive in RHEL 4, due in early 2005, but also will be in a hobbyist version called Fedora Core 2, due May 17. However, merging SELinux has been difficult, and in the newest Fedora test version, released Tuesday, Red Hat disabled SELinux by default.

2 comments

Join the conversation!
Add your comment (Log in or register)
Windows has a "4" on security...
rating. This shows that this "yardstick" must be a foot shy. What a joke. The number one cause of network intrusions is rated a "4". Microsoft must own the rating institution!
Posted by bjbrock (98 comments )
Reply Link Flag
There are 7 levels
A 2 or 3 is not very impressive and should not be relied on for security if what you have to protect is important.

You can see a list of OS products that have been evaluated at <a class="jive-link-external" href="http://niap.nist.gov/cc-scheme/" target="_newWindow">http://niap.nist.gov/cc-scheme/</a>
and follow the links labeled VPL (Product type)
and choosing Operating Systems. <a class="jive-link-external" href="http://www.digitalnet.com/solutions/info_sec_sol/xts400_trusted_sys.htm" target="_newWindow">http://www.digitalnet.com/solutions/info_sec_sol/xts400_trusted_sys.htm</a>

DigitalNet has a secure OS called STOP that is currently rated EAL4+ and is in evaluation against a 5+ standard.
Posted by (1 comment )
Reply Link Flag
 

Join the conversation

Add your comment

The posting of advertisements, profanity, or personal attacks is prohibited. Click here to review our Terms of Use.

Inside CNET News

1-2 of 12

Scroll Left Scroll Right

What's Hot

Discussions

Shared

RSS Feeds

Add headlines from CNET News to your homepage or feedreader.

Markets

Market news, charts, SEC filings, and more

Related quotes

Oracle (-1.37%) -0.40 28.50
Microsoft (-0.89%) -0.28 30.50
IBM (-0.37%) -0.71 192.42
Novell (0.00%) 0.00 6.10
Dow Jones Industrials (-0.69%) -89.23 12,801.23
S&P 500 (-0.69%) -9.31 1,342.64
NASDAQ (-0.80%) -23.35 2,903.88
CNET TECH (-0.58%) -11.91 2,032.01
  Symbol Lookup