02/07/03

Fri, 07 Feb 2003 12:36:37 -0800

Casey Schaufler

>In today's world, that is the Common Criteria, there aren't many
>system yet available. Of course, the best ones come from SGI.
>Our Irix system (the basic U2X OS) is CAPP (replaces C2) evaluated
>and our Trusted Irix (Trix to it's friends) system is LSPP (B1)

I wonder why Casey says this :-)

There are numerous CAPP systems out there, either evaluated by the US
other other signatory nations to the MRA. For example, Win 2K,
Solaris, etc. Before you use these systems, you should carefully read
the Security Target and note the assumptions.

>B2 and above still lies in the realm of too expensive to
>seriously consider, which is a shame. I'd personally love
>to attack the issues.

The main reason you are not seeing "B2 and above" is that the
evaluation methodology has not been defined for EAL5 and above. Thus,
there is no mutually accepted way to evaluate these things. However,
even with that, I'm aware of efforts by Getronics (nee Wang Federal
nee HFSI nee Honeywell) to evaluate a high-assurance XTS-400 OS, which
would have a Linux-compatible interface.


