> Poate si pe voi va dispera orice conferinta cu un 
> microsoftist care se lauda cu CERTIFICAREA COMMON CRITERIA PE 
> CARE O ARE WINDOWS 2000. Ei bine o are si Suse, iar fanii M$ 
> pot fi usor redusi la tacere (si
> nonesenta) cu argumentul final: o are si Linuxul. De remarcat 
> ca la 2000 e valabila cu anumite proceduri de instalare data de ei.

De adaugat faptul ca SuSE are Evaluation Assurance Level (EAL3), si se spera
obtinerea EAL4. Ce inseamna asta?
<quote>
EAL3 is applicable in those circumstances where developers or users require
a moderate level of independently assured security, and require a thorough
investigation of the TOE and its development without substantial
re-engineering.
EAL3 provides assurance by an analysis of the security functions, using a
functional and interface specification, guidance documentation, and the
high-level design of the TOE, to understand the security behaviour.
This EAL represents a meaningful increase in assurance from EAL2 by
requiring more complete testing coverage of the security functions and
mechanisms and/or procedures that provide some confidence that the TOE will
not be tampered with during development.

EAL4 is applicable in those circumstances where developers or users require
a moderate to high level of independently assured security in conventional
commodity TOEs and are prepared to incur additional security specific
engineering costs.
EAL4 provides assurance by an analysis of the security functions, using a
functional and complete interface specification, guidance documentation, the
high-level and low-level design of the TOE, and a subset of the
implementation, to understand the security behaviour. Assurance is
additionally gained through an informal model of the TOE security policy.
This EAL represents a meaningful increase from EAL3 by requiring more design
description, a subset of the implementation, and improved mechanisms and/or
procedures that provide confidence that the TOE will not be tampered with
during development or delivery.
</quote>

--
Ionut  


--- 
Detalii despre listele noastre de mail: http://www.lug.ro/


Raspunde prin e-mail lui