LWN.net Logo

Advertisement

E-Commerce & credit card processing - the Open Source way!

Advertise here

RHEL 5 going for Common Criteria EAL 4 rating

Posted Oct 12, 2005 5:07 UTC (Wed) by etbe (subscriber, #17516)
In reply to: RHEL 5 going for Common Criteria EAL 4 rating by Vladimir
Parent article: RHEL 5 going for Common Criteria EAL 4 rating

The administrator has to perform tasks such as fixing file system
corruption, backing up data, and installing new applications (including
custom applications). These tasks are not compatible with preventing the
administrator from accessing secret data.

We have a secadm_r role for security administration which can be separate
from the sysadm_r for general system administration. This is currently
an experimental feature and is designed to be discretionary in nature.
We can't entirely prevent the sysadm from doing the wrong thing in regard
to security administration, but if they do so then they can't claim it to
be an accident, mistake, or an issue where their duties were unclear.


(Log in to post comments)

Copyright © 2008, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds
Powered by Rackspace Managed Hosting.