{"product_id":11526,"v_id":11526,"product_name":"Red Hat Enterprise Linux 9.4","certification_status":"Certified","certification_date":"2025-02-25T00:00:00Z","tech_type":"Operating System","vendor_id":{"name":"Red Hat, Inc.","website":"http://www.redhat.com"},"vendor_poc":"Chris Zinda","vendor_phone":"+1-717-360-1923","vendor_email":"czinda@redhat.com","assigned_lab":{"cctl_name":"Lightship Security USA, Inc."},"product_description":"<p>Red Hat Enterprise Linux 9.4 is an open-source operating system that supports a general-purpose computing environment for multiple users and applications.</p>","evaluation_configuration":"<p>The TOE operates with the following components in the environment:</p>\r\n<ul>\r\n<li>Update Server. The TOE receives updates from an organization&rsquo;s local repository via TLS.</li>\r\n<li>SSH Server. The TOE is capable of securely communicating with an SSHv2 server.</li>\r\n<li>SSH Client. The TOE is capable of securely communicating with an SSHv2 client.</li>\r\n<li>Compute Platform. The TOE requires a compute platform meeting the following specifications:\r\n<ul>\r\n<li>Intel Xeon Silver x86-64 UEFI platforms (of Cascade Lake microarchitecture)</li>\r\n<li>IBM z16 PR/SM (LPAR) platforms</li>\r\n<li>Power10 PowerVM (LPAR) platforms</li>\r\n</ul>\r\n</li>\r\n</ul>\r\n<p>The following product functions are not included within the scope of the evaluation:</p>\r\n<ul>\r\n<li>SELinux Mandatory Access Control System</li>\r\n<li>OS Virtualization Infrastructure</li>\r\n<li>Containerization Infrastructure</li>\r\n<li>Gnome desktop environment</li>\r\n</ul>","security_evaluation_summary":"<p>The evaluation was carried out in accordance with the Common Criteria Evaluation and Validation Scheme (CCEVS) process and scheme. The criteria against which the Red Hat Enterprise Linux 9.4 was evaluated are described in the Common Criteria for Information Technology Security Evaluation, Version 3.1 Rev. 5. The product, when configured as identified in the Red Hat Enterprise Linux 9.4 Common Criteria Guide, satisfies all of the security functional requirements stated in the Red Hat Enterprise Linux 9.4 Security Target. The project underwent CCEVS Validator review. The evaluation was completed in December 2025. Results of the evaluation can be found in the Common Criteria Evaluation and Validation Scheme Validation Report prepared by CCEVS.</p>","environmental_strengths":"<p>The expected use cases (as defined by PP_OS_V4.3) for the TOE are:</p>\r\n<ul>\r\n<li>Server System. The OS provides a platform for server-side services, either on physical or virtual hardware.&nbsp;</li>\r\n<li>Cloud System. The OS provides a platform for providing cloud services running on physical or virtual hardware.</li>\r\n</ul>\r\n<p>Users interact with the TOE locally (console) via serial connection or remotely (SSH) via a CLI.</p>\r\n<p>This section summarizes the security functionality of the TOE:<br><span style=\"text-decoration: underline;\"><strong>Security Audit</strong></span></p>\r\n<p>The TOE generates and stores security relevant audit events. These logs are stored locally and are protected by restricting access to system administrators only.</p>\r\n<p><span style=\"text-decoration: underline;\"><strong>Cryptographic Support</strong></span></p>\r\n<p>The TOE implements cryptographic operations in support of its security functions.</p>\r\n<p><span style=\"text-decoration: underline;\"><strong>User Data Protection</strong></span></p>\r\n<p>The TOE implements access controls to prevent unauthorized access to files and directories.</p>\r\n<p><span style=\"text-decoration: underline;\"><strong>Identification and Authentication</strong></span></p>\r\n<p>The TOE supports password and public-key authentication. The TOE supports a configurable password and account lockout policy.</p>\r\n<p><span style=\"text-decoration: underline;\"><strong>Security Management</strong></span></p>\r\n<p>The security management facilities provided by the TOE are usable by authorized users and/or authorized administrators to modify the configuration of TSF.</p>\r\n<p><span style=\"text-decoration: underline;\"><strong>Protection of the TSF</strong></span></p>\r\n<p>The TOE implements self-protection mechanisms that protect the security mechanisms of the TOE as well as software executed by the TOE. The following kernel-space isolation and TSF self-protection mechanisms are implemented and enforced (full details are provided in the TSS):</p>\r\n<ul>\r\n<li>Address Space Layout Randomization for user space code.</li>\r\n<li>Kernel and user-space ring-based separation of processes</li>\r\n<li>Stack buffer overflow protection using stack canaries.</li>\r\n<li>Secure Boot ensures that the boot chain up to and including the kernel together with the boot image (initramfs) is not tampered with.</li>\r\n<li>Updates to the operating system are only installed after their signatures have been successfully validated.</li>\r\n<li>Application Allow-lists restrict execution to known/trusted applications.</li>\r\n</ul>\r\n<p><span style=\"text-decoration: underline;\"><strong>TOE Access</strong></span></p>\r\n<p>The TOE displays informative banners before users are allowed to establish a session.</p>\r\n<p><span style=\"text-decoration: underline;\"><strong>Trusted Path/Channels</strong></span></p>\r\n<p>The TOE supports TLSv1.2 and SSHv2 to secure remote communications. &nbsp;Both protocols may be used for communications with remote IT entities. Remote administration is only supported using SSHv2.</p>","features":[{"id":2283,"feature_name":"Asymmetric Key Generation"},{"id":2461,"feature_name":"Auditing"},{"id":2275,"feature_name":"Certificate Authentication"},{"id":2276,"feature_name":"Certificate Validation"},{"id":2279,"feature_name":"Cryptograhic Hashing"},{"id":2280,"feature_name":"Cryptographic Key Establishment”"},{"id":2299,"feature_name":"Cryptographic Signature Generation"},{"id":2278,"feature_name":"DRBG"},{"id":2464,"feature_name":"Key Destruction"},{"id":2277,"feature_name":"Keyed-hash message authentication"},{"id":2287,"feature_name":"Operating System"},{"id":2272,"feature_name":"SSH Client"},{"id":2273,"feature_name":"SSH Server"},{"id":2274,"feature_name":"TLS 1.2"}]}