Backed by big name partners, SUSE Linux and Red Hat are each putting their security systems through the rigorous paces of Common Criteria Scheme (CCS) testing, with ultimate plans to reach the same security ratings already achieved by Microsoft and Unix players. The Common Criteria stamp of approval "reduces the investment risk and also provides more trust" in Linux, according to Roman Drahtmueller, a member of SUSE's security team.. . .
Backed by big name partners, SUSE Linux and Red Hat are each putting their security systems through the rigorous paces of Common Criteria Scheme (CCS) testing, with ultimate plans to reach the same security ratings already achieved by Microsoft and Unix players. The Common Criteria stamp of approval "reduces the investment risk and also provides more trust" in Linux, according to Roman Drahtmueller, a member of SUSE's security team.

Over a live videoconferencing link from Germany, Drahtmueller told attendees at the recent InfoSecurity conference in New York City that SUSE is "number one" among Linux distributors now being evaluated under the Common Criteria for Information Technology Security Evaluation (CC 2.1).

Drahtmueller added, though, that SUSE is also "grateful that we can contribute together with Red Hat" under the Common Criteria umbrella.

The CCS is aimed at providing IT customers with impartial security assessments of products. Evaluations are conducted by independent labs. In conjunction with Oracle, Red Hat announced plans last February to submit Linux Advanced Server for a Common Criteria ranking at Evaluation Assurance Level (EAL) 2. The initial Red Hat/Oracle evaluation is still under way, Drahtmueller noted. Together with its partner IBM, though, SUSE attained EAL2+ certification in July. The platform already certified under Common Criteria consists of SUSE Linux Enterprise Server (SLES) 8 running on IBM eServer xSeries. Also last July, IBM and SUSE announced that they expected to reach EAL3+ certification by the end of this year for SUSE Linux running "across the eServer product line."

The link for this article located at LinuxPlanet.com is no longer available.