SuSE Linux wins security clearance

Daily Newsletters

Sign up to ZDNet UK's daily newsletter.

NEWS
Linux seller SuSE and server maker IBM have obtained a crucial security certification that will make the operating system an option for demanding military and government customers, the companies are expected to announce on Tuesday.

Many governments require certification to the international Common Criteria standard before they're allowed to purchase a specific computing product. SuSE Linux Enterprise Server 8 running on IBM's Intel-based xSeries servers achieved Evaluation Assurance Level 2 (EAL2) of the Common Criteria, the companies are expected to announce at the LinuxWorld Conference and Expo.

"It certainly raises the viability and increases the trust level of Linux in government contracts," IDC analyst Chris Christiansen said. Though commercial buyers don't usually give Common Criteria certification much more than passing notice, "the government market is very large," he said.

Common Criteria certification ensures software meets several security requirements. It also ensures that companies supporting the software meet requirements for documenting security features, handling vulnerabilities and testing products.

However, obtaining the certification is time consuming and expensive. "Unfortunately, only a few very large vendors of hardware and software can afford the certification process," Christiansen said.

While the move is important for Linux, the 12-year-old Unix-like operating system still lags competitors in the certification process. Microsoft's Windows 2000, along with Sun Microsystems' Solaris, IBM's AIX and Hewlett-Packard's HP-UX, have the higher EAL4 certification.

IBM spokesman Clint Roswell said IBM expects to receive EAL3 certification for SuSE Linux by the end of 2003, with EAL4 to come later. Also by the end of the year, IBM's Common Criteria certification for Linux will extend beyond its Intel servers to IBM's other three server lines as well, he said.

Obtaining EAL2 certification typically costs between $400,000 (£248,416) and $500,000, Roswell said.

IBM and SuSE will release "key components of the Common Criteria evaluation" to the Linux development community, the companies said.

Red Hat sells the most widely used version of Linux, a step ahead of No. 2 SuSE. Database giant Oracle is working with Red Hat to obtain Common Criteria EAL2 certification for its product by the end of the year.

One military customer expressed support for the move. "The Common Criteria certification of Linux will be a critical factor as Linux is applied to mission-critical environments," Fritz Schulz of the US Defense Information Systems Agency (DISA), said in a statement.

In a separate announcement on Tuesday, the Free Standards Group is expected to announce that the DISA now requires that Linux meet the FSG's Linux Standard Base specification before it may be used by the US military. The standard will help ensure it's easier to move applications from one version of Linux to another, Schulz said.

IBM said it's working to create a version of SuSE's Linux that complies with another US military requirement, the Common Operating Environment, which is software that shields military computer users from differences between numerous different operating systems.

The security of Linux is "pretty comparable to the security in commercial operating systems," said Neel Mehta a research engineer at Internet Security Systems whose job is to pore through code looking for potential weaknesses. "I think software is becoming more secure, and Linux has followed the same trend. You don't see the simple vulnerabilities or simple coding errors to the same extent you would three or four years ago."

However, Mehta didn't agree with an argument many open-source advocates make, that the open nature of their software's underlying source code means more people can stamp out vulnerabilities.

"I don't think it's necessarily true that it's more secure because the source is out there," Mehta said. "Not everybody looks at it, and not everybody is qualified to evaluate software in an in-depth level."

Post your comment

In order to post a comment you need to be registered and logged in.

You can also log in with Facebook. Log in or create your ZDNet UK account below

  • Login

Will not be displayed with your comment

By signing up for this service, you indicate that you agree to our Terms and Conditions and have read and understood our Privacy Policy. Questions about membership? Find the answers in the Community FAQ

Get ZDNet UK's daily newsletter

Enter your email address to sign up

ZDNet UK Live

kevinmchapman

"the very significant number of users" and "many (most) of us" - you have no evidence for these statements. It is a fact that most users are saying...

2 hours ago by kevinmchapman on A tale of two distros: Ubuntu and Linux Mint
Marg Menzies Harrison

Another grammar faux pas is the improper use of "you". When sitting down down in a restaurant, for example, I get cringe when the waitress...

4 hours ago by Marg Menzies Harrison via Facebook on 10 flagrant grammar mistakes that make you look stupid
zdnetukuser

And NOW, folks, for Canonical's next trick... Kubuntu is late. Here's a pencil. Draw your own conclusions. cf.:...

4 hours ago by zdnetukuser on Linux Minterface
Moley

@kevinmchapman. The discussion here reflects the very significant number of users who really do like the traditional menu system and who wish to...

6 hours ago by Moley on A tale of two distros: Ubuntu and Linux Mint
kevinmchapman

Er, no... It is an efficient means of finding the application/file/setting you need in one place. The icons are a simply a fallback for when you...

8 hours ago by kevinmchapman on A tale of two distros: Ubuntu and Linux Mint
TerryRK

Isn't the provision of a text based search an admission by the developers that the mass of icons approach does not work? I don't need to use a...

9 hours ago by TerryRK on A tale of two distros: Ubuntu and Linux Mint
kevinmchapman

"Unity and GNOME 3 both abandon the old text-based cascading menus in favour of a graphical icon-driven system." Point truly missed. Both use a...

10 hours ago by kevinmchapman on A tale of two distros: Ubuntu and Linux Mint
TerryRK

whs001 - Thank you, I'm glad you liked the article. I absolutely agree with you on your first point. I should perhaps have made it clearer that...

10 hours ago by TerryRK on A tale of two distros: Ubuntu and Linux Mint
Dennis Nilsson

If we allow corporate interest to dictate the way our government circumvents due process against foreign entities then we should accept the same...

11 hours ago by Dennis Nilsson via Facebook on ACTA stumbles in Germany
GHar123

I totally dislike pirating of works, I fear that artists will be deterred from creating works if they think that they are going to get ripped off....

12 hours ago by GHar123 on ACTA stumbles in Germany
JCB33

How dare film makers, artists or anybody that invests in creativity stop us pirating their works for free. I want to be able to walk into my local...

18 hours ago by JCB33 on ACTA stumbles in Germany
Moley

@GrueMaster. I prefer horses for courses rather than one size fits all. I, and I suspect most other computer users, do not really wish to have...

20 hours ago by Moley on A tale of two distros: Ubuntu and Linux Mint
greycynic

The product that scares me every time I have to use it is the Office 2007 version of Excel. The first bug that I found was applying the median...

20 hours ago by greycynic on Ten flawed products that derail productivity
GrueMaster

Nice review and very informative. One thing I'd like to add (in reply to whs001's 1st question), the main reason to have the same interface from...

22 hours ago by GrueMaster on A tale of two distros: Ubuntu and Linux Mint
Frederick Wrigley

I'be been using Mint 12 since the RC came out, and I am far more happy with the Cinnamon, the Mate, and, yes (with extensions), theGnome 3...

23 hours ago by Frederick Wrigley via Facebook on A tale of two distros: Ubuntu and Linux Mint
bdantas

Excellent article. One small correction, though--although a fresh installation of Linux Mint 12 will, indeed, provide the user with a version of...

23 hours ago by bdantas on A tale of two distros: Ubuntu and Linux Mint
Alan Ralph

In related news, the ISPs club together to get the members of the Home Affairs Select Committee (ya goofed on that part, ZDNet UK) copies of "The...

24 hours ago by Alan Ralph via Facebook on MPs urge ISPs to take down terrorist material
Alan Ralph

In related news, the ISPs club together to get the members of the Home Affairs Select Committee (ya goofed on that part, ZDNet UK) copies of "The...

24 hours ago by Alan Ralph via Facebook on MPs urge ISPs to take down terrorist material
Moley

For Gnome 2 die-hards, it is possible to add icons to the bottom panel (or top top panel, if you prefer) which provide the exact Gnome 2...

1 day ago by Moley on A tale of two distros: Ubuntu and Linux Mint
ramwellian

Your comments would seem pretty naive and immature. Your 'solution' appears to be, "gee, let's all just give in to the hackers and give them...

1 day ago by ramwellian on Cloud computing security: no more oxymoron?

Latest in Application Development