Advertisement
Promo

Desktop platforms Toolkit in association with http://ad.doubleclick.net/clk;205413468;14699245;m?http://adfarm.mediaplex.com/ad/ck/2397-58840-22058-14

Red Hat Linux nears security clearance

Matthew Broersma ZDNet.co.uk

Published: 03 Dec 2003 14:10 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Red Hat is nearing completion of a critical certification process that should speed adoption of its Linux operating system distribution by governments and security-conscious businesses.

Oracle, which is sponsoring Red Hat in the project, said the evaluation of Red Hat Enterprise Linux 3 under the Common Criteria scheme was expected to be "substantively complete" by the end of this month. Following this, the UK certification body must carry out a review and issue certification. "Obviously, this phase of the evaluation is not under vendor control, but is expected to take between a month to six weeks," said Tim Payne, Oracle's European head of technology products, on Wednesday.

Red Hat hopes the nearly year-long, $1m (£570,000) process of achieving Common Criteria certification will push Linux into the mainstream, as many government agencies around the world require the certification in order to deploy an operating system. The UK government is among the 19 that recognise the Common Criteria evaluation. A certification from one country is recognised in the others. With countries from Germany to Peru considering using open-source software, having a certified version of Linux could help break down barriers.

Oracle and Red Hat are first pushing Red Hat Linux Advanced Server for a modest level of certification: Evaluation Assurance Level (EAL) 2. In total, there are seven levels of certification attesting to varying grades of security, reliability and developmental process control. The highest level that a commercial software laboratory can certify is EAL 4, which Microsoft received for Windows 2000 last autumn. SuSE Linux Enterprise Server 8 running on IBM's Intel-based xSeries servers achieved EAL 2 in August.

The EAL level needed by a government customer depends largely on the agency and the application in which the software will be used. Earlier this year, the US Department of Defense (DOD) gave Red Hat a Common Operating Environment certification, which attests to a certain level of interoperability with other operating systems.

Oracle 9i has already been certified at EAL 4 on both Windows NT and Solaris, but has to be recertified for each operating system on which it runs. Oracle has said that some government clients have asked Oracle to push for Linux certification.

After Red Hat earns the EAL 2 certification, Oracle plans to work toward getting its Oracle 9i Release 2 database running on the evaluated Red Hat Linux Advanced Server certified at EAL 4. Oracle currently ships Oracle 9i Release 2 on Red Hat Linux Advanced Server as part of its Unbreakable campaign. The final goal for both companies is to have both Red Hat's software and Oracle's software certified under the Common Criteria at EAL 4.

Oracle has tackled the process 15 times on a variety of operating systems.

The Common Criteria, an international standard administered in the UK by a GCHQ division called the Communications-Electronics Security Group (CESG), grades products based not only on their security and reliability, but also on the development and support processes that ensure quick responses to problems.

Other countries that have signed the Arrangement on the Mutual Recognition of Common Criteria Certificates in the Field of IT Security are Australia, New Zealand, the US, Canada, Spain, Germany, Greece, The Netherlands, France, Hungary, Austria, Italy, Turkey, Norway, Finland, Sweden, Israel and Japan.

While the move is important for Linux, the 12-year-old Unix-like operating system still lags competitors in the certification process. Besides Windows 2000, Sun Microsystems' Solaris, IBM's AIX and Hewlett-Packard's HP-UX all have the higher EAL 4 certification.

CNET News.com's Robert Lemos and Stephen Shankland contributed to this report.

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
71 out of 144 people found this useful


Company/Topic Alerts

Create a new alert from the list below:







Video icon

Video

Microsoft Windows 7 Special Report Special Report

How Microsoft can make Windows 7 a success

How Microsoft can make Windows 7 a success

Comment Many businesses have given Vista a wide berth; Microsoft must focus on five areas to make sure Windows 7 doesn't suffer the same fate, argues TechRepublic's Jason Hiner

More Special Reports

Desktop Management Benchmarking

Test Your Desktop Management Systems

How good are your company's desktop management solutions? How do they compare with those of your peers?

Take two minutes to complete our new Desktop Management and Energy Consumption benchmark, and find out what issues your business needs to focus on.


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters