Account Links: Cart | Register | Log In

Skip to content

Certifications and Accreditations

Source Code for Red Hat Certificate System Released

Red Hat Certificate System was acquired from AOL three years ago as part of the Netscape technology acquisition. Read more.

Red Hat is committed to providing secure and stable software that can be easily used in security-sensitive environments. Red Hat's enterprise software includes extensive security tools and features.

Red Hat Enterprise Linux is the most certified operating system available today. Through its history, Red Hat Enterprise Linux has passed the Common Criteria process 12 times on four different hardware platforms. Red Hat Enterprise Linux 5 has even received Common Criteria certification at Enterprise Assurance Level 4 (EAL 4+) under the Controlled Access Protection Profile (CAPP), Label Security Protection Profile (LSPP) and the Role-Based Access Control Protection Profile (RBACPP), providing a level of security and a feature set that was previously unheard-of from a mainstream operating system.

Red Hat's JBoss Enterprise Middleware solutions include support for common middleware security standards. Additionally, JBoss Enterprise Application Platform is the only open source application server to seek Common Criteria certification (EAL 2+) and certification for MetaMatrix Data Services Platform is currently underway.

For US Department of Defense customers, Red Hat Government can provide simple tools to meet the DISA STIG requirements. Red Hat can also provide simple DCID 6/3 compliance tools for intelligence customers.

Red Hat Mailing Lists

US government and contractors may be interested in the Red Hat Government Security mailing list, a moderated forum for Red Hat users in the information assurance and certification/accreditation community: https://www.redhat.com/mailman/listinfo/gov-sec

Red Hat Security Training and Certifications

Red Hat provides a number of security-specific courses, and also provides a formal certification program for systems engineers working in the security field. For more information about the Red Hat Certified Security Specialist (RHCSS) certification, visit https://www.redhat.com/training/security/courses/.

Red Hat Cleared Engineers

Red Hat has cleared representatives and engineers available for both pre-sales help and consulting engagements.

Security and Hardening Guides

NIAP Common Criteria

Directorate of Central Intelligence Directive (DCID) 6/3

Red Hat Enteprise Linux has been used in systems from Protection Level 3 (PL3) up to PL5. For more information, please speak with your Red Hat account representative.

DISA Security Technical Implementation Guides (STIGs)

Red Hat Enterprise Linux can easily meet the requirements of the DISA STIGs. The Red Hat Government group has implementation tools that can help. Please contact your local Red Hat representative.

NISPOM Chapter 8

Red Hat Enterprise Linux provides out-of-the-box compliance with the NISPOM Chapter 8 audit requirements. A sample implementation can be found in /usr/doc/audit-1.5.2/nispom.rules in Red Hat Enterprise Linux versions 4 and 5.

FIPS 140-2

Red Hat provides FIPS 140-2 certified cryptography through the Network Security Services (NSS) libraries. These libraries are now certified to Level 1 and Level 2: http://csrc.nist.gov/groups/STM/cmvp/documents/140-1/140crt/140crt815.pdf. The certified NSS libraries are provided with Red Hat Enterprise Linux version 4 and 5.

OVAL

Red Hat has been a leader in adopting standards like CVE and OVAL which help customers identify and assess security vulberabilities. For example, each Red Hat Errata includes both CVE references and OVAL data. You can find the OVAL documents for Red Hat Enterprise Linux 3, 4, and 5 at the Red Hat OVAL site.


More information about the Common Criteria Scheme can be found at:

List of Certifications