Trusted ExtensionsはSolaris10の11/06で登場


TrustedExtensions(略してTX)は越後湯沢で実物を見てきました。
そういえば先月にSunからの正式アナウンスあったんだ


Sun Announces Solaris 10 in Evaluation for Highest Global Security Certification
http://www.sun.com/smi/Press/sunflash/2006-09/sunflash.20060913.3.xml

Most Secure OS on the Planet to Receive Common Criteria Certification LSPP; At EAL 4+ with 3 Protection Profiles on SPARC(R) and x86/x64 Systems


Solaris10の11/06でやっと登場です。

NEW YORK, NY September 13, 2006 Sun Microsystems, Inc., (NASDAQ: SUNW) today announced that the Solaris 10 Operating System (OS) with Solaris Trusted Extensions is in evaluation for the highest globally recognized level of certification for any commercial OS
the Common Criteria Certification Labeled Security Protection Profile (LSPP) at Evaluation Assurance Level 4+ (EAL 4+), including 3 Protection Profiles.
Solaris Trusted Extensions – a new feature in Solaris 10 11/06 OS, available later this year – will allow Solaris 10 OS customers, who have specific regulatory or information protection requirements, to take advantage of labeling features previously only available in highly specialized operating systems or appliances.


PPはいつものCAPP、RBACPP、LSPPの3つ

The Solaris 10 OS is currently being evaluated for Common Criteria LSPP at EAL 4+ for the Controlled Access Protection Profile (CAPP) and Role-Based Access Control Protection Profile (RBACPP) at EAL 4+. In addition, Solaris 10 11/06 OS with Solaris Trusted Extensions is being evaluated for the LSPP Protection Profile, a requirement for financial, healthcare and government customers that need to protect the use of data with different classifications (top secret, secret, public) on the same systems.


導入実績の多さと長い歴史による信頼度は突出です。

"Sun and Solaris software have an 18-year history of independent security certification, exceeding the most comprehensive, government-mandated security requirements," said Tom Goguen, Vice President for Solaris marketing, Sun Microsystems. "The Solaris 10 OS with Solaris Trusted Extensions is the most secure foundation on the planet for the deployment of identity and compliance solutions for government and industry."


MLSは完全なBLPのはず

The Solaris Trusted Extensions feature, currently in beta release, allows a strong Mandatory Access Control (MAC) security policy―an essential part of any highly secure solution―to be implemented using the Solaris 10 OS. Solaris Trusted Extensions helps ensure that access to communications between objects is strictly controlled and all objects in the OS have a well-defined, easily audited relationship to each other.
For example, the feature allows information labeled "Top Secret" or "Classified" to be hosted and processed on the same system as information labeled "Public" or "Unclassified."


ネットワーク、印刷、JDS、CDEも全部ラベル対応

Solaris Trusted Extensions also supports labels with any file system, labeled networking for secure networks, labeled printing, a full multi-level desktop using the GNOME-based Java Desktop System and CDE, and support for both SPARC(R) processor-based and x86/x64 systems.


OpenSolarisでのTXのプロジェクトのサイト
http://www.opensolaris.org/os/community/security/projects/tx/


WhitePaperもあります。
http://www.opensolaris.org/os/community/security/projects/tx/TrustedExtensionsArch.pdf


他のニュース記事もありました
Solaris 10 with Trusted Extensions Readied for 11/06 Update
http://www.itjungle.com/tug/tug092106-story02.html


Trusted Extensionsのドキュメントについてはdocs.sun.comにまるごとあります。
7月に書いたやつ