Catch up on stories from the past week (and beyond) at the Slashdot story archive

 



Forgot your password?
typodupeerror
×
Encryption Security

C2 for Linux? 4

Signal 11 asks: "I've been doing some research on government security certifications for Linux, specifically the C2 classification put out by the NSA. The results are that there is only one project underway - SGI Linux is apparently a low profile project underway at SGI (sorry for breaking it wide open guys) to get C2 for Linux. They won't begin testing though until 2001. Given that there is virtually no information about this project, however, I rather wonder whether SGI is still pursuing it. My question is: what's being done for C2 or higher classification of Linux right now?"
This discussion has been archived. No new comments can be posted.

C2 for Linux?

Comments Filter:
  • NT4 got it's C2 at the end of 1999 - two or three months before Win2K shipped.

    Don't expect the C2 for kernel 2.2 before the release of kernel 2.8 .
    And even then, it will be a special kernel with a special distro - and
    til these modifications go into mainstream we will have kernel 3.0 or 3.2.
    Expect 3.2 to arrive at 2008 (assuming they don't any version-jumping).
  • by Anonymous Coward
    If you want a 'secure linux', the best bet for now is to wait for the release of the Flask port to Linux: http://www.cs.utah.edu/flux/fluke/html/linux.html
    Almost jumped out of my skin when I saw http://oss.sgi.com/projects/ob1/, the components that make Trusted IRIX/B "trusted". That may be what SGI is adapting to Linux.
  • http://www.intersectalliance.com/news/index.html

    The InterSect Alliance Development Target beginning 2nd Quarter 2000 has been identified as investigating the integration of a government strength C2 security audit module for the Linux operating system.

    One of the factors that has been identified as hindering the migration of open-source operating systems into the government market is the lack of core integrated security services.

    InterSect Alliance intends to provide resources towards the investigation into introducing kernel and module level extensions to the Linux operating system in order to facilitate C2 level auditing capabilities.
  • NT has only recieved a C2 rating based on a non-networked version. No OS to my knowledge has recieved a C2 rating for networking. Their is an orange book standard and a black book standard at work, I forgot which is which.

What this country needs is a good five dollar plasma weapon.

Working...