-

Red Hat Adds Common Criteria Certification for Red Hat Enterprise Linux 8

Red Hat Enterprise Linux 8.1 extends the world’s leading enterprise Linux platform as a foundation for more secure computing across the open hybrid cloud and from traditional to cloud-native workloads

RALEIGH, N.C.--(BUSINESS WIRE)--Red Hat, Inc., the world's leading provider of open source solutions, today announced further strengthening of Red Hat Enterprise Linux as a platform of choice for users requiring more secure computing, with Red Hat Enterprise Linux 8.1 achieving Common Criteria Certification. The first major security certification for Red Hat Enterprise Linux 8, this validation emphasizes Red Hat’s commitment to supporting customers that use the world’s leading enterprise Linux platform for critical workloads in classified and sensitive deployments.

For Common Criteria, Red Hat Enterprise Linux 8.1 was certified by the National Information Assurance Partnership (NIAP), with testing and validation completed by Acumen Security, a U.S. government-accredited laboratory. The platform was tested and validated against the Common Criteria Standard for Information Security Evaluation (ISO/IEC 15408) against version 4.2.1 of the NIAP General Purpose Operating System Protection Profile including Extended Package for Secure Shell (SSH), version 1.0 and is the latest Red Hat Enterprise Linux version to appear on the NIAP Product Compliant List.

Red Hat Enterprise Linux and Evaluation Assurance Levels (EAL)

Previously, Red Hat Enterprise Linux operating systems were certified at EAL4+. The treaty that enables countries to recognize certifications across borders now includes a new Common Criteria Recognition Arrangement that only recognizes up to EAL2. This treaty also rewrote Protection Profiles across products to be very specific about individual product requirements, documentation and testing procedures. It is now expected that a solution either meets the Protection Profile exactly or does not.

In the previous EAL system, the number (EAL2, EAL4, etc.) distinguished the degree of rigor applied to meeting open-ended requirements. This revised certification is designed to be more predictable and better suited to an operating system with frequent, predictable minor releases like Red Hat Enterprise Linux, with future platform certifications intended to be aligned with this certification method.

DISA STIG for Red Hat Enterprise Linux 8

Red Hat’s long history of working with government and defense agencies extends beyond Common Criteria validation. Part of this collaboration includes the creation and validation of more secure configurations of the world’s leading enterprise Linux platform for sensitive computing environments. The Defense Information Systems Agency (DISA) recently published a Secure Technical Implementation Guide (STIG) for Red Hat Enterprise Linux 8, which offers a configuration roadmap to deploy Red Hat Enterprise Linux 8 with an approved security baseline while still helping to drive innovation across an organization.

Red Hat Consulting has years of experience and specialized expertise in deploying more secure configuration of Red Hat Enterprise Linux in sensitive computing environments. Red Hat Training helps teams master their Linux skills.

Supporting Quotes

Paul Smith, senior vice president and general manager, Public Sector, North America, Red Hat
“From bare metal servers to expansive hybrid cloud deployments, the operating system is the foundation for modern IT, making platform security even more important when it comes to sensitive environments. This first Common Criteria certification for Red Hat Enterprise Linux 8 shows that Red Hat continues to maintain crucial IT security certificates for its next-generation operating system as well as the fact that the world’s leading enterprise Linux platform can now provide a more secure and more intelligent platform for critical and classified deployments while retaining the flexibility, scalability and innovation of Linux. ”

Ashit Vora, vice president, Acumen Security
“Acumen Security congratulates Red Hat on the successful NIAP Common Criteria certification of Red Hat Enterprise Linux 8.1, the first for the Red Hat Enterprise Linux 8 platform. This rigorous security evaluation against stringent requirements identified by the National Security Agency under the global Common Criteria Certification Standard demonstrates and confirms Red Hat’s commitment to make CC certified versions of Red Hat Enterprise Linux available to security conscious customers such as the national security-related agencies, finance and healthcare verticals. We are honored that Red Hat has once again selected Acumen Security as their security certification partner to achieve this significant milestone that few other operating system vendors in the industry have accomplished. ”

Additional Resources

Connect with Red Hat

About Red Hat, Inc.

Red Hat is the world’s leading provider of enterprise open source software solutions, using a community-powered approach to deliver reliable and high-performing Linux, hybrid cloud, container, and Kubernetes technologies. Red Hat helps customers integrate new and existing IT applications, develop cloud-native applications, standardize on our industry-leading operating system, and automate, secure, and manage complex environments. Award-winning support, training, and consulting services make Red Hat a trusted adviser to the Fortune 500. As a strategic partner to cloud providers, system integrators, application vendors, customers, and open source communities, Red Hat can help organizations prepare for the digital future.

Forward-Looking Statements

Certain statements contained in this press release may constitute "forward-looking statements" within the meaning of the Private Securities Litigation Reform Act of 1995. Forward-looking statements provide current expectations of future events based on certain assumptions and include any statement that does not directly relate to any historical or current fact. Actual results may differ materially from those indicated by such forward-looking statements. The forward-looking statements included in this press release represent the Company's views as of the date of this press release and these views could change. However, while the Company or its parent International Business Machines Corporation (NYSE:IBM) may elect to update these forward-looking statements at some point in the future, the Company specifically disclaims any obligation to do so. These forward-looking statements should not be relied upon as representing the Company's views as of any date subsequent to the date of this press release.

###

Red Hat, Red Hat Enterprise Linux and the Red Hat logo are trademarks or registered trademarks of Red Hat, Inc. or its subsidiaries in the U.S. and other countries. Linux® is the registered trademark of Linus Torvalds in the U.S. and other countries.

Contacts

Media:
John Terrill
Red Hat, Inc.
+1-571-421-8132
jterrill@redhat.com

Red Hat, Inc.

Details
Headquarters: Raleigh, North Carolina
CEO: Matt Hicks
Employees: 22,000
Organization: OTH

Release Summary
Red Hat Enterprise Linux 8 adds Common Criteria certification
Release Versions

Contacts

Media:
John Terrill
Red Hat, Inc.
+1-571-421-8132
jterrill@redhat.com

More News From Red Hat, Inc.

Red Hat Recognized as a Leader in the 2026 Gartner® Magic Quadrant™ for Server Virtualization Platforms

RALEIGH, N.C.--(BUSINESS WIRE)--Red Hat, the world's leading provider of open source solutions, today announced that it has been recognized as a Leader in the 2026 Gartner® Magic Quadrant™ for Server Virtualization Platforms with Red Hat OpenShift Virtualization. This recognition is based on Red Hat’s Completeness of Vision and Ability to Execute. As enterprise IT organizations re-evaluate traditional virtualization strategies to mitigate rising hypervisor costs and avoid operational lock-in, R...

Red Hat Puts Safety and Observability at the Core of Enterprise AI with Red Hat AI 3.5

RALEIGH, N.C.--(BUSINESS WIRE)--Red Hat, the world’s leading provider of open source solutions, today announced significant updates across the Red Hat AI portfolio with the release of Red Hat AI 3.5. As enterprise teams move past early experimentation and pilot successes, IT and platform engineering leaders face the challenge of running AI with the same operational rigor as mission-critical infrastructure. By providing the scalable foundation required to control, secure and observe these worklo...

Red Hat Positioned as a Leader in the 2026 Gartner® Magic Quadrant™ for Container Management

RALEIGH, N.C.--(BUSINESS WIRE)--Red Hat, the world's leading provider of open source solutions, today announced that it has been named a Leader in the 2026 Gartner® Magic Quadrant™ for Container Management for its hybrid cloud platform, Red Hat OpenShift. This recognition marks the fourth consecutive year that Red Hat has been positioned in the Leaders quadrant, based on the company’s Completeness of Vision and Ability to Execute. As enterprise IT organizations scale modern container infrastruc...
Back to Newsroom