Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 491
Alerts This Week
Warning Icon 1 491

Stay Ahead With Linux Security News

Filter%20icon Refine news
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security news

We found 6 articles for you...
78

Rocky Linux 8 and 9.2 Confirm FIPS 140-3 Compliance for Enhanced Security

Rocky Linux has taken a major leap forward by achieving FIPS 140-3 compliance for versions 8 and 9.2. This achievement makes the already popular distro an even more attractive option for admins managing environments that require stringent encryption and cryptographic standards, such as in government agencies and regulated industries. . This recent achievement also makes Rocky Linux a trusted open-source alternative for mission-critical workloads in industries that are often hesitant to adopt open-source technology. Beyond raising encryption standards, FIPS 140-3 compliance minimizes vulnerabilities and reduces liability risks—a win-win for organizations prioritizing security. For us admins, the message is clear: adopting and properly configuring Rocky Linux 8 or 9.2 ensures secure, enterprise-grade cryptographic functionality, enabling us to build resilient systems without sacrificing the flexibility of open-source software. In this article, I'll explore what FIPS 140-3 compliance means for Rocky Linux users, how it can improve your overall security posture, and the practical steps you can take to maximize the benefits of this certification. Understanding FIPS 140-3 and its Significance for Rocky Linux Admins Federal Information Processing Standards (FIPS) 140-3 is an evaluation and certification standard established by the U.S. government that validates cryptographic modules used in software, devices, and systems. It's designed to ensure encryption-related functions meet stringent security requirements while being resilient against attacks. FIPS 140-3 certification is essential in industries where privacy and security are of utmost importance. For instance, this certification is particularly vital when protecting sensitive government data, safeguarding patient records in healthcare systems, or securing transactions in the financial sector. Rocky Linux versions 8 and 9.2 now meet FIPS 140-3 requirements, giving organizations confidence that this open-source platform meets federal andindustry security regulations for workloads in regulated environments. FIPS-compliant cryptographic modules provide encrypted communications, data integrity protection , secure access controls, and communication across systems. This gives us admins peace of mind as we deploy Rocky Linux, knowing it meets expectations for secure computing as outlined by government and industry regulators. Rocky Linux achieving FIPS certification marks a significant shift within the open-source ecosystem. While open-source solutions have historically had their credibility questioned in regulated environments, Rocky Linux's FIPS achievement demonstrates that community-driven platforms can deliver enterprise-grade security without relying on proprietary operating systems to meet compliance requirements. As a result, Rocky Linux is an attractive option among organizations looking to reduce their dependency while meeting compliance obligations. Why FIPS Compliance Enhances Security Posture FIPS compliance offers organizations significant value by assuring encryption functions are operating securely under audited standards. Cryptographic modules form the cornerstone of system security, protecting sensitive information while also securing communications and providing strong authentication solutions. Any vulnerabilities within these modules could expose organizations to significant risks, including data breaches, unapproved access, and noncompliance fines. By installing Rocky Linux 8 or 9.2 in environments that require FIPS-certified cryptographic functions, we can substantially reduce these risks. FIPS compliance offers peace of mind because encryption systems within Rocky Linux have passed thorough tests assessing algorithm strength, key management practices, and protection against potential exploits. This validation reduces cryptographic vulnerability risks while ensuring that critical workloads are protected with industry-leading standards. FIPS compliance provides another key advantage during regulatory audits.Many industries, including healthcare and finance, require organizations to demonstrate that they adhere to security standards during routine evaluations. Rocky Linux, equipped with FIPS-compliant cryptographic modules, makes this easier. Administrators simply document their use of certified software without needing complex workarounds or additional justification for operating environments that require FIPS compliance. How Does Rocky Linux's Achievement Benefit Us Admins? Those looking to take full advantage of Rocky Linux's FIPS 140-3 compliance should ensure they are running either Rocky Linux 8 or 9.2 and configure their systems securely. Admins will need to assess whether specific workloads, systems, or applications require further adjustments to fully comply with FIPS compliance standards. They might need to enable specific cryptographic libraries or disable non-compliant algorithms to align systems with FIPS guidelines. Understanding these nuances will help us maximize the benefits of this certification while ensuring consistency across different environments. Rocky Linux adoption can also help organizations strengthen their security posture in other ways. FIPS certification enables admins to replace less secure or non-compliant tools and platforms with standard ones for managing cryptographic security. This reduces complexity for security teams, improves audit readiness, and mitigates liabilities associated with outdated or insecure infrastructure. Bridging the Gap Between Open Source and Enterprise Security Rocky Linux's FIPS certification marks an outstanding victory not just for its users but for open-source technology in general. Open-source solutions have traditionally found it challenging to gain widespread trust across regulated industries due to concerns about consistency, vendor support, and compliance readiness. Rocky Linux is evidence that modern open-source platforms can meet even the most stringent security standards. At a time when organizations are increasinglylooking to diversify their technology stacks while reducing license fees and vendor lock-in, Rocky Linux stands as an attractive drop-in replacement for CentOS, appealing to organizations seeking stability and community-driven support. Thanks to FIPS 140-3 compliance, Rocky Linux has become even more suitable as a secure choice when government standards must be met, making it especially appealing to organizations that want to deploy open-source solutions while maintaining tight security control. FIPS certification extends far beyond technical considerations. Rocky Linux now carries more credibility within industries accustomed to proprietary solutions, potentially speeding adoption rates by businesses seeking cutting-edge open-source tools without jeopardizing compliance in regulated environments . Furthermore, this opens the door for admins to take full advantage of Linux's flexibility without compromising enterprise-grade security—an invaluable feature when managing modern IT infrastructures. Our Final Thoughts on This Notable Achievement Rocky Linux's FIPS 140-3 certification is a significant step forward for those seeking an open-source platform that meets enterprise-grade security standards. Deployed across government agencies, regulated industries, or businesses seeking to adopt modern best practices, Rocky Linux stands out as an impressive candidate for fulfilling mission-critical workloads. Rocky Linux administrators gain an enormous opportunity with Rocky's FIPS certification: an enterprise-grade solution that offers unsurpassed flexibility at a reasonable cost, simplifying compliance while mitigating everyday risks. By adopting Rocky Linux 8 or 9.2, we can realize the full potential of FIPS certification, not only improving our security posture but also paving the way for further open-source adoption in sensitive environments. Looking ahead, Rocky Linux's rising credibility in security-focused industries indicates promising progress - not only for users themselves but for allopen-source ecosystems. Its combination of flexibility, security, and trust makes Rocky Linux an indispensable resource in building resilient systems in an era when reliability and security must always come first. . This recent achievement also makes Rocky Linux a trusted open-source alternative for mission-critica. rocky, linux, taken, major, forward, achieving, 140-3, compliance, versions. . Brittany Day

Calendar%202 Apr 29, 2025 User Avatar Brittany Day Vendors/Products
67

IETF: Removal Of RSA Key Transport From TLS 1.3 Standard Decision

The IETF working group responsible for the TLS 1.3 standard is closing in on a decision to remove RSA key transport cipher suites from the protocol.. Decades-old RSA-based handshakes don The link for this article located at ThreatPost is no longer available. . The IETF task force is approaching agreement to eliminate RSA key exchange methods from the TLS 1.3 specification.. TLS 1.3, RSA Removal, Encryption Standards, Cipher Suites, Security Protocol. . LinuxSecurity.com Team

Calendar%202 May 09, 2014 User Avatar LinuxSecurity.com Team Cryptography
67

Encryption Analysis: NSA Surveillance and Modern Privacy Limits

Recent revelations about the extent of NSA surveillance have put even the standards by which encryption systems are designed into question. Encryption experts Matthew Green, Phillip Zimmermann, and Martin Hellman discuss what makes a code secure and the limits of privacy in the modern age.. The link for this article located at Science Friday is no longer available. . The link for this article located at Science Friday is no longer available.. recent, revelations, about, extent, surveillance, standards, which, encrypt. . LinuxSecurity.com Team

Calendar%202 Oct 21, 2013 User Avatar LinuxSecurity.com Team Cryptography
81

ICO: Data Breach Investigation Of Healthcare Locums Personal Data

The Information Commissioner's Office has found a healthcare recruitment agency in breach of the Data Protection Act after it lost doctors' personal data that ended up being sold online.. Healthcare Locums (HCL) first notified the ICO about the breach when it confirmed that a network storage device containing details about doctors' security clearance and their visa information had been sold on an auction website. Neither the device nor the data were encrypted. HCL's records showed that the hard drive was being transferred from its Skipton branch to its Loughton branch in February 2010 for secure storage prior to decommissioning. The link for this article located at Network World is no longer available. . Medizor Services disclosed that unprotected patient information was traded on the internet, violating privacy regulations. Access the comprehensive findings.. Healthcare Data Breach, Doctors' Personal Data, Unsecured Data Storage. . LinuxSecurity.com Team

Calendar%202 Oct 18, 2010 User Avatar LinuxSecurity.com Team Privacy
67

StrongKey Open-Source Key Management Tool For PCI Compliance

StrongAuth, Inc. has announced the availability of a free and open-source software product - StrongKey - designed to help enterprises manage symmetric encryption keys as a centrally managed resource. This capability, a first for the open-source community, provides implementers with independence from application-specific, operating system-specific or database-specific encryption key-management solutions. . Driven by the requirements of a $1B retailer to comply with PCI-DSS, the software provides the following features: Written in Java as a J2EE application, it runs on any platform that has a Java VM - Windows, UNIX, Linux, Solaris, OS/400 (IBM supplies the RPG modules that works with this software), etc.; Includes a sample utility to perform file, directory and database column-level encryption; Supports 3DES, AES-128, AES-192 and AES-256 bit symmetric keys; Supports upto 4096-bit asymmetric RSA keys to secure the symmetric keys; Supports the use of FIPS 140-2 certified hardware security modules for servers, and smartcards for client platforms; Uses industry standards such as WSS, XMLSignature, XMLEncryption for insulation from proprietary schemes and protocols; Encrypts and digitally signs and verifies every object in the key database for message integrity; Digitally signed requests from clients, encrypted and digitally signed responses from servers to protect the symmetric keys; Encrypted key-cache on clients to continue processing credit-cards and/or other transactions even when the network is unavailable; Fully open-source and free - currently downloadable at . Driven by the requirements of a $1B retailer to comply with PCI-DSS, the software provides the follo. strongauth, announced, availability, open-source, software, product, strongk. . LinuxSecurity.com Team

Calendar%202 Sep 11, 2006 User Avatar LinuxSecurity.com Team Cryptography
67

A Developer's Guide to Implementing AES Encryption Successfully

The following document provides a detailed and easy to understand explanation of the implementation of the AES (RIJNDAEL) encryption algorithm. The purpose of this paper is to give developers with little or no knowledge of cryptography the ability to implement AES. . .. The following document provides a detailed and easy to understand explanation of the implementation of the AES (RIJNDAEL) encryption algorithm. The purpose of this paper is to give developers with little or no knowledge of cryptography the ability to implement AES . The link for this article located at Net-security is no longer available. . Conquer the RSA cryptographic method through this simple manual crafted for optimal application.. AES Implementation, Cryptography Guide, Encryption Standards. . LinuxSecurity.com Team

Calendar%202 Aug 13, 2003 User Avatar LinuxSecurity.com Team Cryptography
67

How FIPS Compliance Bolsters Security Software at InfoGard Labs

These are busy days at InfoGard Labs. The San Luis Obispo (Calif.) outfit is one of only six info-tech laboratories in the U.S. and Canada allowed to issue a government seal of approval known as FIPS compliance. FIPS stands for Federal . . . . These are busy days at InfoGard Labs. The San Luis Obispo (Calif.) outfit is one of only six info-tech laboratories in the U.S. and Canada allowed to issue a government seal of approval known as FIPS compliance. FIPS stands for Federal Information Processing Standard, a rigorous set of criteria established by groups of government and private-sector experts on cryptography standards and implementations. Starting in July, 2002, FIPS 140 level-2 standards became mandatory, replacing the more lenient FIPS 140 level-1 rules. Every company seeking to sell encryption software to the federal government or to do business with Uncle Sam involving computers and encryption has to use equipment that holds a FIPS-2 compliance rating. We're not talking just spookware. Once the strictly the province of military and intelligence communities, encryption is now common in everything from e-mail and instant-messaging software to databases. At the same time, federal laws covering privacy requirements in banking and health care have mandated that more data be encrypted. The steady rise of cyberattacks has likewise made enhanced encryption a priority for business in general. And the rise of the Internet has in many cases forced FIPS compliance on seemingly benign systems, such as automated procurement software, that talk to federal computers. The link for this article located at BusinessWeek is no longer available. . These are busy days at InfoGard Labs. The San Luis Obispo (Calif.) outfit is one of only six info-te. these, infogard, obispo, (calif, outfit, info-te. . LinuxSecurity.com Team

Calendar%202 Oct 02, 2002 User Avatar LinuxSecurity.com Team Cryptography
67

European Advocate Challenges U.S. Encryption Standards in Digital Security

A leading European computer security and privacy advocate is challenging an effort by the American computer industry to create a standard to protect software and digital content, calling the plan a smoke screen by established companies to protect their existing markets. . . . . A leading European computer security and privacy advocate is challenging an effort by the American computer industry to create a standard to protect software and digital content, calling the plan a smoke screen by established companies to protect their existing markets. In a paper to be presented at a technical conference in Toulouse, France, on Thursday, Ross Anderson, a University of Cambridge computer scientist, attacks the Trusted Computing Platform Alliance, an organization formed in October 1999 by Compaq Computer, Hewlett-Packard, I.B.M., Intel and Microsoft. The companies say their intent is to provide a cryptographic system that would ensure privacy and protect intellectual property. The link for this article located at NY Times is no longer available. . A prominent European proponent critiques the encryption protocols of American technology, suggesting they serve merely as a facade for pre-existing markets.. Encryption Standards, Digital Security, Privacy Advocacy, Cryptographic Systems. . LinuxSecurity.com Team

Calendar%202 Jun 20, 2002 User Avatar LinuxSecurity.com Team Cryptography
News Add Esm H340

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200