RHEL 5 going for Common Criteria EAL 4 rating
RHEL 5 going for Common Criteria EAL 4 rating
Posted Oct 3, 2005 14:22 UTC (Mon) by rmfought (guest, #32833)Parent article: RHEL 5 going for Common Criteria EAL 4 rating
From my understanding, the instant you patch or change the configuration of the evaluated software in any way, the certification is invalid. Thus the Win2k cert was only good for a short while (if at all) until patches were applied (IIRC, the version actually shipped was many revisions past the one certified).
Another important thing to understand (as many other have pointed out) is that EAL level has no relation to how secure an IT product is, only *assurance* of how well it was implemented (i.e. bug and malware-free) based on the security requirements set forth (a la different protection profiles). The protection profile/security target is really where the rubber meets the road as to what actual security features the product provides. The Red Hat PP is stronger security-wise than the one MS used. This is a good overview of the MS cert:
http://eros.cs.jhu.edu/~shap/NT-EAL4.html
Something as complex as an OS is a tough thing to keep certified because changes are so frequent. I guess the real value is in showing that it can be done, and then it is up to the users to trust that the same care will be taken for further revisions.
Posted Oct 4, 2005 20:08 UTC (Tue)
by kweidner (guest, #6483)
[Link]
It's not just a matter of trust. In this case the security target adds the claim to meet the highest CC level of flaw remediation procedures beyond what the protection profiles would require ("augmented with ALC_FLR.3"), this means that the evaluators are examining and confirming that the software developers have effective procedures in place to systematically address security flaws in the product and inform their users about them. Check out page 124 in the standard [PDF link] if you want more details about how this works.
RHEL 5 going for Common Criteria EAL 4 rating
[...]it is up to the users to trust that the same care will be taken for further revisions.