News
News
2/15/2006
01:58 PM
Connect Directly
RSS
E-Mail
50%
50%

Linux, Unix Players Beef Up Security

Rivals Sun, Red Hat, and Novell try to one-up one another--and Microsoft--with security enhancements for Solaris and Linux.

As expected, archrivals Sun, Red Hat and Novell unveiled major security improvements for their respective Unix and Linux platforms this week.

At the RSA Conference in San Jose, Calif., Sun revealed plans to release Solaris Trusted Extensions into beta testing in April and simultaneously enter evaluation for Common Criteria Certification at EAL 4+ certification, against Labeled Security Protection Profile (LSPP).

LSPP is one of three levels of advanced security options that are part of EAL 4+, deemed essential for financial, healthcare and government customers that need to protect multiple level of classified data on a single system.

LSPP will add to the existing certification of Solaris 10, now under evaluation, against Controlled Access Protection Profile (CAPP) and Role Based Access Control Protection Profile (RBACPP) at EAL 4+, Sun said.

Sun said the Trusted Extensions will be offered as an add-on to its base Solaris 10 operating system in August.

Meanwhile, archrival Red Hat, whose Linux distribution has stolen many Unix converts, also announced at the RSA conference that its Red Hat Enterprise Linux 4 distribution has achieved CAPP/EAL 4+ certification through a partnership with IBM.

Raleigh, N.C.-based Red Hat also announced at the RSA security conference that an upgrade of its Certificate Server due in mid-2006 will offer integrated smart card support for Linux.

This will allow customers to issue smart cards that support automated log in to a number of leading applications and platforms including Red Hat Linux, Microsoft Windows clients and servers, Internet Explorer and Outlook Express, the company said.

On Tuesday, Microsoft said that its forthcoming Internet Explorer 7 will incorporate its own smart card technology, code named InfoCard, that will also make this possible on the Windows platform.

Redmond, Wash.-based Microsoft also unveiled that it has released into beta testing its own Certificate Lifecycle Management Server that will help customers manage their various digital certificates and authentication tokens. The Microsoft-branded technology came from Alacris, which Microsoft acquired last year.

And Novell, for its part, announced Audit2, a platform that enables customers to monitor and audit user access and other network events in compliance with Sarbanes-Oxley and HIPAA. Novell's SUSE LINUX Enterprise Server 9 on IBM eServers has achieved Controlled Access Protection Profile under the Common Criteria for Information Security Evaluation, known as CAPP/EAL4+.

Partners of Sun, Red Hat, Microsoft and Novell will be able to harness the new capabilities to address compliance issues in each vertical industry and enable more advanced authentication and identity management capabilities for their Unix, Windows and Linux customers.

"Microsoft continues to work toward standards around security and certificate management," said Ken Winell, an executive at Visalign, a Microsoft partner company. "By making their products more standards-oriented, our clients and customers can choose to integrate Microsoft technology or perhaps may use a third party authentication due to heterogeneous environments. "

Comment  | 
Print  | 
More Insights
IT's Reputation: What the Data Says
IT's Reputation: What the Data Says
InformationWeek's IT Perception Survey seeks to quantify how IT thinks it's doing versus how the business really views IT's performance in delivering services - and, more important, powering innovation. Our results suggest IT leaders should worry less about whether they're getting enough resources and more about the relationships they have with business unit peers.
Register for InformationWeek Newsletters
White Papers
Current Issue
InformationWeek Must Reads Oct. 21, 2014
InformationWeek's new Must Reads is a compendium of our best recent coverage of digital strategy. Learn why you should learn to embrace DevOps, how to avoid roadblocks for digital projects, what the five steps to API management are, and more.
Video
Slideshows
Twitter Feed
InformationWeek Radio
Archived InformationWeek Radio
A roundup of the top stories and community news at InformationWeek.com.
Sponsored Live Streaming Video
Everything You've Been Told About Mobility Is Wrong
Attend this video symposium with Sean Wisdom, Global Director of Mobility Solutions, and learn about how you can harness powerful new products to mobilize your business potential.