Please wait while the page is being loaded Skip this advertisement >
ARN

HP gets Common Criteria certification for Red Hat Linux

Integrity, ProLiant, and BladeSystem platforms receive the Evaluation Assurance Level 4 for RHL 5
Ellen Messmer (Network World)  18 July, 2007 08:32:47

HP says a broad range of its computer hardware running Red Hat Enterprise Linux 5 has been examined and certified as compliant under the international Common Criteria product-evaluation program backed by the U.S. government and sometimes required for government technology acquisitions.

HP's Integrity, ProLiant, and BladeSystem platforms, as well as workstations and desktops, have received the Evaluation Assurance Level 4 (EAL4+) Common Criteria security certification for Red Hat Enterprise Linux 5, the version of the operating system released last March. EAL4+ is the highest level of security that unmodified commercial software can achieve. Higher rankings to level 7 typically involve highly customized systems designed for maximum-security government purposes.

However, Erik Lillestolen, program manager for open source and Linux at HP, noted that the Zen-based technology for virtualization that's part of Red Hat Linux 5, was not tested under the Common Criteria program.

"Nobody has included the virtualization technology yet," he added about the Common Criteria security evaluation program, which is backed by several countries as a multinational testing regimen.

HP submitted its computer gear for evaluation at Atsec, a certified lab under the U.S. government program known as the National Information Assurance Partnership (NIAP), a collaborative effort among the National Institute of Standards and technology (NIST) and the National Security Agency (NSA) which administers the Common Criteria program in the United States.

The EAL4+ certification level for unmodified commercial products assures that they work with security "profile" requirements, such as the Controlled Access Protection Profile, the Role-based Access Control protection Profile and the labeled Security protection profile. Lillestolen noted that the lab review entailed an inspection of source code and evaluation of how software performed on hardware platforms.

Comments

Post new comment

Users posting comments agree to the ARN comments policy.
Login or register to link comments to your user profile, or you may also post a comment without being logged in.
The content of this field is kept private and will not be shown publicly.
Enter the fully qualified URL, eg. http://www.example.com/
  • Web page addresses and e-mail addresses turn into links automatically.
  • Allowed HTML tags: <a> <em> <strong> <cite> <code> <ul> <ol> <li> <dl> <dt> <dd>
  • Lines and paragraphs break automatically.

More information about formatting options

Syndicate content
 
ARN Vendor Directory
ARN Community Comments
ARN Library

Storage Security Best Practices

SNIA’s vendor-neutral guidance for organisations wishing to secure their storage systems and infrastructure.

Subscribe to ARN

ARN has been the premier provider of information to the Australian IT channel for more than 12 years. As the only weekly publication dedicated to the channel, ARN produces timely, accurate news and analysis about IT business issues, products and services, new technology and market opportunities.
Sponsored Links