Red Hat Reinforces Red Hat Enterprise Linux as a Foundation for Sensitive Computing with Common Criteria Certification, Commercial Solutions for Classified Status

Raleigh, N.C. (Sept. 14, 2020) — Red Hat, Inc., the world's leading provider of open source solutions, today announced that Red Hat Enterprise Linux has further solidified itself as a platform of choice for users requiring more secure computing, with Red Hat Enterprise Linux 7.6 achieving Common Criteria Certification as well as Commercial Solutions for Classified (CSfC) Status. These validations show Red Hat's commitment to supporting customers that use the world's leading enterprise Linux platform for critical workloads in classified and sensitive deployment scenarios.


For Common Criteria, Red Hat Enterprise Linux 7.6 was certified by the National Information Assurance Partnership (NIAP), with testing and validation completed by Acumen Security, a U.S. government-accredited laboratory. The platform was tested and validated against the Common Criteria Standard for Information Security Evaluation (ISO/IEC 15408) against version 4.2.1 of the NIAP General Purpose Operating System Protection Profile and is the latest Red Hat Enterprise Linux version to appear on the NIAP Product Compliant List.


Additionally, Red Hat Enterprise Linux 7.6 is now an approved TLS Protected Server component for Commercial Solutions for Classified (CSfC) solutions and is included in the CSfC TLS Protected Servers Components List. This program, established by the National Security Agency (NSA), enables commercial products to be used in layered solutions protecting National Security System (NSS) data. Red Hat Enterprise Linux and Evaluation Assurance Levels (EAL)


Previously, Red Hat Enterprise Linux operating systems were certified at EAL4+. The treaty that enables countries to recognize certifications across borders now includes a new Common Criteria Recognition Arrangement that only recognizes up to EAL2. This treaty also rewrote Protection Profiles across products to be very specific about individual product requirements, documentation and testing procedures. It is now expected that a solution either meets the Protection Profile exactly or does not.


In the previous EAL system, the number (EAL2, EAL4, etc.) distinguished the degree of rigor applied to meeting open-ended requirements. This revised certification is designed to be more predictable and better suited to an operating system with frequent minor releases like Red Hat Enterprise Linux, with future platform certifications intended to be aligned with this certification method. Red Hat Enterprise Linux 8 and Common Criteria


Red Hat seeks to make the latest platform innovations meet the most stringent requirements for critical IT infrastructure. Red Hat Enterprise Linux 8.1 is now officially "In Evaluation" for Common Criteria certification as well.


About Red Hat

Red Hat is the world's leading provider of enterprise open source software solutions, using a community-powered approach to deliver reliable and high-performing Linux, hybrid cloud, container, and Kubernetes technologies. Red Hat helps customers integrate new and existing IT applications, develop cloud-native applications, standardize on our industry-leading operating system, and automate, secure, and manage complex environments. Award-winning support, training, and consulting services make Red Hat a trusted adviser to the Fortune 500. As a strategic partner to cloud providers, system integrators, application vendors, customers, and open source communities, Red Hat can help organizations prepare for the digital future.