RHEL 5 going for Common Criteria EAL 4 rating
Posted Oct 3, 2005 14:22 UTC (Mon) by
rmfought (guest, #32833)
Parent article:
RHEL 5 going for Common Criteria EAL 4 rating
From my understanding, the instant you patch or change the configuration of the evaluated software in any way, the certification is invalid. Thus the Win2k cert was only good for a short while (if at all) until patches were applied (IIRC, the version actually shipped was many revisions past the one certified).
Another important thing to understand (as many other have pointed out) is that EAL level has no relation to how secure an IT product is, only *assurance* of how well it was implemented (i.e. bug and malware-free) based on the security requirements set forth (a la different protection profiles). The protection profile/security target is really where the rubber meets the road as to what actual security features the product provides. The Red Hat PP is stronger security-wise than the one MS used. This is a good overview of the MS cert:
http://eros.cs.jhu.edu/~shap/NT-EAL4.html
Something as complex as an OS is a tough thing to keep certified because changes are so frequent. I guess the real value is in showing that it can be done, and then it is up to the users to trust that the same care will be taken for further revisions.
(
Log in to post comments)