SUSE Linux Enterprise 12 Security Certifications



Similar documents
SUSE Linux Enterprise 12 Security Certifications Common Criteria, EAL, FIPS, PCI DSS,... What's All This About?

Advanced Systems Management with Machinery

Running SAP HANA One on SoftLayer Bare Metal with SUSE Linux Enterprise Server CAS19256

We are watching SUSE

Implementing Linux Authentication and Authorisation Using SSSD

Relax-and-Recover. Johannes Meixner. on SUSE Linux Enterprise 12.

Using SUSE Linux Enterprise to "Focus In" on Retail Optical Sales

Build Platform as a Service (PaaS) with SUSE Studio, WSO2 Middleware, and EC2 Chris Haddad

Operating System Security Hardening for SAP HANA

Challenges Implementing a Generic Backup-Restore API for Linux

Installing, Tuning, and Deploying Oracle Database on SUSE Linux Enterprise Server 12 Technical Introduction

SUSE Linux uutuudet - kuulumiset SUSECon:sta

Configuration Management in SUSE Manager 3

SUSE Storage. FUT7537 Software Defined Storage Introduction and Roadmap: Getting your tentacles around data growth. Larry Morris

TUT5605: Deploying an elastic Hadoop cluster Alejandro Bonilla

SUSE Customer Center Roadmap

Data Center Automation with SUSE Manager Federal Deployment Agency Bundesagentur für Arbeit Data Center Automation Project

HO15982 Deploy OpenStack. The SUSE OpenStack Cloud Experience. Alejandro Bonilla. Michael Echavarria. Cameron Seader. Sales Engineer

kgraft Live patching of the Linux kernel

How To Make A Cloud Work For You

Big Data, SAP HANA. SUSE Linux Enterprise Server for SAP Applications. Kim Aaltonen

Software Defined Everything

Workflow und Identity Management - Genehmigungsprozesse, Role Mining, Role Design und Compliance Management

Using btrfs Snapshots for Full System Rollback

Public Cloud. Build, Use, Manage. Robert Schweikert. Public Cloud Architect

DevOps and SUSE From check-in to deployment

How an Open Source Cloud Will Help Keep Your Cloud Strategy Options Open

High Availability and Disaster Recovery for SAP HANA with SUSE Linux Enterprise Server for SAP Applications

Securing Your System: Security Hardening Techniques for SUSE Linux Enterprise Server

Using SUSE Cloud to Orchestrate Multiple Hypervisors and Storage at ADP

Oracle Products on SUSE Linux Enterprise Server 11

Ceph Distributed Storage for the Cloud An update of enterprise use-cases at BMW

Wicked A Network Manager Olaf Kirch

Common Criteria Evaluation Challenges for SELinux. Doc Shankar IBM Linux Technology Center

SUSE OpenStack Cloud 4 Private Cloud Platform based on OpenStack. Gábor Nyers Sales gnyers@suse.com

Linux w chmurze publicznej SUSE na platformie Microsoft Azure

SUSE Enterprise Storage Highly Scalable Software Defined Storage. Gábor Nyers Sales

How SUSE Is Helping You Rock The Public Cloud

Certification Report

Btrfs and Rollback How It Works and How to Avoid Pitfalls

Deploying Hadoop with Manager

Securing Your System: Security Hardening Techniques for SUSE Linux Enterprise Server 12

Of Pets and Cattle and Hearts

Wicked Trip into Wicked Network Management

SUSE Cloud 5 Private Cloud based on OpenStack

Certification Report

HO5604 Deploying MongoDB. A Scalable, Distributed Database with SUSE Cloud. Alejandro Bonilla. Sales Engineer abonilla@suse.com

Certification Report

How To Evaluate Watchguard And Fireware V11.5.1

Certification Report

Certification Report

NIST ITL July 2012 CA Compromise

Leveraging Wikis to Manage SCP Documentation TWiki Novell Technical Services

Kangaroot SUSE TechUpdate Interoperability SUSE Linux Enterprise and Windows

FIPS Security Policy

Certification Report

SUSE Virtualization Technologies Roadmap

Certification Report

High Availability Storage

Certification Report

KVM, OpenStack and the Open Cloud SUSECon November 2015

RED HAT ENTERPRISE LINUX 6 SECURITY TECHNICAL IMPLEMENTATION GUIDE (STIG) OVERVIEW. Version 1, Release July 2015

Certification Report

SUSE Virtualization Technologies Roadmap

Certification Report

U.S. Federal Information Processing Standard (FIPS) and Secure File Transfer

File Management Suite. Novell. Intelligently Manage File Storage for Maximum Business Benefit. Sophia Germanides

UNCLASSIFIED. Trademark Information

Certification Report

AN OVERVIEW OF INFORMATION SECURITY STANDARDS

CAS18543 Migration from a Windows Environment to a SUSE Linux Enterprise based Infrastructure Liberty Christian School

Certification Report

Cryptographic and Security Testing Laboratory. Deputy Laboratory Director, CST Laboratory Manager

kamai Technologies Inc. Commonly Accepted Security Practices and Recommendations (CASPR)

Novell Collaboration Vibe OnPrem

DoD ANNEX FOR MOBILE DEVICE MANAGEMENT (MDM) PROTECTION PROFILE Version 1, Release February 2014

How SUSE Manager Can Help You Achieve Regulatory Compliance

Certification Report

Product comparison. GFI LanGuard 2014 vs. Microsoft Windows Server Update Services 3.0 SP2

Introducing Director 11

Certification Report

Certification Report

Certification Report

Information Security Standards by Dr. David Brewer Gamma Secure Systems Limited Diamond House, 149 Frimley Road Camberley, Surrey, GU15 2PS

UNITED STATES PATENT AND TRADEMARK OFFICE. AGENCY ADMINISTRATIVE ORDER Agency Administrative Order Series. Secure Baseline Attachment

Based on Geo Clustering for SUSE Linux Enterprise Server High Availability Extension

Secure Content Automation Protocol (SCAP): How it is increasingly used to automate enterprise security management activities

REDUCE RISK WITH ORACLE SOLARIS 11

CASPR Commonly Accepted Security Practices and Recommendations

Certification Report

Transcription:

SUSE Linux Enterprise 12 Security Certifications Common Criteria, FIPS, PCI DSS, DISA STIG,... What's All This About? Thomas Biege Team Lead Maintenance/Security thomas@suse.com

2

Evaluation Validation Certification Validation Compare behavior of the software / module against an existing standard or expected behavior. Evaluation Examine claims made about a target. Claims do not need to be based on standards. Certification 3

Security Certifications that matter

Common Criteria How can I be sure to get the security functions I need? ISO/IEC 15408 (ITSEC, CTCPEC, TCSEC) Accepted by 26 countries Tested and verified by independent 3 rd party (the evaluator), at different Evaluation Assurance Levels Certificate created by government agency Includes development processes, IT infrastructure, physical security, and HR procedures 5

FIPS 140-2 How can I be sure my ciphers are correct and up-to-date? Federal Information Processing Standard (FIPS) FISMA, NIST SP 800, FedGov, financial industry Certificate is issued by NIST (US) and CSE (Canada) FIPS 140-2 ensures that Crypto algorithms/modes follow the newest standard No obvious crypto weakness exists No outdated algorithms or too short keys are used Self tests and integrity checks with each invocation of CM 6

DISA STIG How can I lockdown my system to make it less vulnerable? DISA = Defense Information Systems Agency STIG = Security Technical Implementation Guides Secure configuration guides for military field users Mandatory requirement US DoD customers through DISA 7

PCI DSS (Payment Card Industry) Conformance Certification for a customers environment Covers more than the Operating System an Operating System cannot be PCI DSS certified SUSE Linux Enterprise Server can be configured and deployed to fulfill PCI DSS requirements 8

BSI IT Grundschutz (IT baseline protection) ISO/IEC 27001 Information Security Management System (ISMS) Business Continuity Management (BCM) Certification of customers' environment Covers more than the Operating System an Operating System cannot be ITGS certified Requires Common Criteria for higher security levels SLES can be configured to comply with required measurements 9

SUSE Linux Enterprise 12 Security Certifications Summary

Common Criteria Certification Certification Body: Evaluation Lab: Target of Evaluation (TOE): SLES12 Protection Profile: OSPP 2.0 (including advanced management, advanced audit, and virtualization) With augmentation for Flaw Remediation (FLR) EAL4, with mutual recognition! 11

Common Criteria Certification Architectures x86-64 (Intel and AMD) s390x Virtualization with KVM First time SELinux is used to separate VMs With btrfs and full system rollback... or with full disk encryption Audit, IPSec, SSH,... Installation via a special ISO (also contains FIPS modules) 12

FIPS 140-2 Architectures x86-64 other architectures might follow Modules 1. Kernel 2. OpenSSL 3. libgcrypt 4. OpenSSH Client 5. OpenSSH Server 6. NSS (Level 2, depends on CC) 7. StrongSWAN (IPSec) 8. (Disk encryption) 13

FIPS 140-2 Status according to NIST Module Name Vendor Name IUT Review In Review Coordination Finalization Pending SUSE Mozilla-NSS SUSE LLC SUSE Linux Enterprise Server 12 - StrongSwan Cryptographic Module SUSE Linux Enterprise Server 12 libgcrypt Cryptographic Module SUSE Linux Enterprise Server 12 - OpenSSH Server Module SUSE Linux Enterprise Server 12 - OpenSSH Client Module SUSE Linux Enterprise Server 12 - Kernel Crypto API Cryptographic Module version 1.0 SUSE Linux Enterprise Server 12 OpenSSL Module SUSE LLC SUSE LLC Certificate received (#2464) SUSE LLC SUSE LLC SUSE LLC SUSE LLC Certificate received (#2435) http://csrc.nist.gov/groups/stm/cmvp/documents/140-1/140inprocess.pdf (2015-10-30) 14

Dependencies of FIPS CSMs in SUSE Linux Enterprise 12 openssh server openssh client strongswan IKE v1/v2 EDC FIPS 140-2 Level 2 requires an OS with CC EAL2, at least CC EAL4+ libgcrypt openssl initialize IPSec NSS crypto algos PBKDF dm_crypt cryptsetup PBKDF kernel Crypto API initialize block ciphers 15

DISA STIG SUSE is currently developing STIGs based on: General Purpose Operating System SRG Web Server SRG Project officially started with US Gov in June 2015 Further development may cover: matching SCAP / OVAL content for automation cooperation with technology partners and community further roles / SRGs based on demand 16

PCI DSS (Payment Card Industry) Covers more than the Operating System an Operating System cannot be PCI DSS certified SUSE Linux Enterprise Server can be configured and deployed to fulfill PCI DSS requirements We provide consulting NEW: How-to guide for SLES12 is in preparation 17

Dependencies of Certifications STIG DISA US-Mil PCI DSS Finance BSI IT Grundschutz DE-Gov FIPS 140-2 (Crypto) ARCH¹ RNG² Common Criteria (Security) ¹ ARCH = Security Architecture Document ² RNG = Random Number Generator 18

When will certifications be available? FIPS 140-2 openssl Cert#2435 received this August libgcrypt Cert#2464 received this October waiting on CMVP only now Common Criteria Q1 2016 (est.) DISA STIG Q1 CY 2016 (est.) PCI DSS Guide H1 CY 2016 (est.) 19

20

21

Your Questions! Thank you. 22

Corporate Headquarters Maxfeldstrasse 5 90409 Nuremberg Germany +49 911 740 53 0 (Worldwide) www.suse.com Join us on: www.opensuse.org 23

Unpublished Work of SUSE LLC. All Rights Reserved. This work is an unpublished work and contains confidential, proprietary and trade secret information of SUSE LLC. Access to this work is restricted to SUSE employees who have a need to know to perform tasks within the scope of their assignments. No part of this work may be practiced, performed, copied, distributed, revised, modified, translated, abridged, condensed, expanded, collected, or adapted without the prior written consent of SUSE. Any use or exploitation of this work without authorization could subject the perpetrator to criminal and civil liability. General Disclaimer This document is not to be construed as a promise by any participating company to develop, deliver, or market a product. It is not a commitment to deliver any material, code, or functionality, and should not be relied upon in making purchasing decisions. SUSE makes no representations or warranties with respect to the contents of this document, and specifically disclaims any express or implied warranties of merchantability or fitness for any particular purpose. The development, release, and timing of features or functionality described for SUSE products remains at the sole discretion of SUSE. Further, SUSE reserves the right to revise this document and to make changes to its content, at any time, without obligation to notify any person or entity of such revisions or changes. All SUSE marks referenced in this presentation are trademarks or registered trademarks of Novell, Inc. in the United States and other countries. All third-party trademarks are the property of their respective owners.