Validated Product - Wind River Linux Secure 1.0Certificate Date: 05 April 2011 Validation Report Number: CCEVS-VR-VID10430-2011 Product Type: Operating System Conformance Claim: EAL4 Augmented with ALC_FLR.3 PP Identifier: U.S. Government Protection Profile for General-Purpose Operating Systems in a Networked Environment, Version 1.0 CC Testing Lab: atsec information security corporation
PRODUCT DESCRIPTIONWind River Linux Secure is a commercial-grade embedded Linux operating system that provides a flexible and pervasive development and runtime platform. Based on Linux kernel 2.6.27 and GCC 4.3.2, Wind River Linux Secure includes Carrier Grade Linux (CGL) compliant Linux Kernel, supports multi-architecture based hardware platforms and is optimized for embedded architecture based devices. Wind River Linux Secure comes with integrated Eclipse-based Wind River Workbench development suite along with a broad and rich set of command line tools. EVALUATED CONFIGURATIONWind River Linux Secure is certified on well-defined boards based on the Intel Architecture, Power Architecture, and ARM. For details about the certified boards, please see the Security Target. The location of the evaluated configuration guide can be found in the Validation Report for this product.
SECURITY EVALUATION SUMMARYWind River Linux Secure is a commercial-grade embedded Linux development and run-time platform suitable for use where assured security and robustness are key project requirements. Wind River Linux Secure is built on Wind River’s embedded Linux platform and is based on fully traceable sources from kernel.org, which enables companies to develop, test quickly and cost-effectively and enjoy the benefits of open source. The evaluation was performed by Atsec Information Security Corporation. The results of the evaluation can be found in the CCEVS Validation Report for Wind River Linux Secure 1.0. ENVIRONMENTAL STRENGTHSThe functionality of Wind River Linux Secure is consistent with the requirements set forth by the GPOSPP profile it complies with, on the platforms specified in the Security Target. In particular, the TOE implements a number of important security mechanisms:
|