To: Wesley Griffin <wgriffin@Glue.umd.edu>Порився в Інтернеті... Всі BSD десь приблизно мають C2 рейтинг (крім майбутнього TrustedBSD, який намагається отримати B1 http://www.trustedbsd.org/ . Багато компонентів, до речі, запозичено з SЕLinux)
Subject: Re: C2 compliant?
From: Theo de Raadt <deraadt@cvs.openbsd.org>
Date: Tue, 09 Jun 1998 10:36:52 -0600
cc: misc@openbsd.org
Delivery-Date: Tue Jun 9 09:38:05 1998
> my employer is looking at using OpenBSD for a project due to some
> convicing by me <grin>. The problem is, however, we need a C2 compliant OS
> and I would like to know if any work has been done to make OpenBSD C2?
> Thanks for any pointers or information.
C2 is not something you want.
OpenBSD is more secure than the systems that do ship with C2.
Largely, C2 means "if we discover a problem, log it". Nothing else
really substantially security-related happens in those systems which
have been rated C2.
That said, we will never be rated C2 for a number of reasons. First, C2
ratings are determined by US Government organizations, which we never
will get because OpenBSD is a Canadian piece of software (and as soon as
it enters the USA, it becomes encumbered by their stupid crypto laws).
Secondly, getting that C2 stamp requires a huge pile of money.
Don't hold your breath. It's very likely that you don't want C2. You
might want to do some research so that you find out exactly what C2
means -- and what C2 does not mean. On the other hand, if what you
are really searching for is just security, then we've got the best
offering out there.
[td](https://linux.org.ua/proxy.php?request=http%3A%2F%2Fwww.radium.ncsc.mil%2Ftpep%2Ficons%2Flogo.a1.gif&hash=1341a30825581edffba06c29382fcfe5) | Я просто чую, що OpenBSD секюрніша за Linux та інші *BSD Хотілось би знати де всі ОС розташовані з погляду міноборони США, або іншої незалежної організації Європа має здається свою... Коротенький опис... (http://www.dynamoo.com/orange/summary.htm) (позиція офтопіка неправильна "сертифікувалась" NT4.0 SP5-6?, а 2000-2003 навіть не сертифікувались...) тут повний документ: DOD 5200.28-STD (http://www.radium.ncsc.mil/tpep/library/rainbow/5200.28-STD.html) |