OPNsense Forum

English Forums => General Discussion => Topic started by: dstr on October 27, 2023, 10:25:10 am

Title: please consider German BSI certification
Post by: dstr on October 27, 2023, 10:25:10 am
please consider German BSI certification, otherwise you are very likely  dropped out of the markt for real professional solutions.
Title: Re: please consider German BSI certification
Post by: bimbar on October 27, 2023, 11:10:27 am
Looking at the list of certified networking products: https://www.bsi.bund.de/DE/Themen/Unternehmen-und-Organisationen/Standards-und-Zertifizierung/Zertifizierung-und-Anerkennung/Zertifizierung-von-Produkten/Zertifizierung-nach-CC/Zertifizierte-Produkte-nach-CC/Netzwerkprodukte/produkte.html?nn=456508 , I have to disagree.

Also, CC certification is probably impossible for an open source project.
Title: Re: please consider German BSI certification
Post by: Patrick M. Hausen on October 27, 2023, 11:12:45 am
The list of certified products is pretty short and largely irrelevant:
https://www.bsi.bund.de/DE/Themen/Unternehmen-und-Organisationen/Standards-und-Zertifizierung/Zertifizierung-und-Anerkennung/Zertifizierung-von-Produkten/Zertifizierung-nach-CC/Zertifizierte-Produkte-nach-CC/Netzwerkprodukte/Netzwerkprodukte_node.html

Most prominent BSI certified product is Genugate. Genua have a long history of tailoring their firewall to match public calls for bids and so they are effectively the go-to supplier for everything "government". But then their firewall really cannot do much.

For large enterprises down to SMBs BSI certification is completely irrelevant which is why you see almost no commercial vendor in that list.
Title: Re: please consider German BSI certification
Post by: franco on October 27, 2023, 11:12:54 am
23.10 will be the first business edition to be fully LINCE certified.

See https://www.jtsec.es/lince-evaluation and https://docs.opnsense.org/security.html#framework-type-of-testing-lince


Cheers,
Franco
Title: Re: please consider German BSI certification
Post by: franco on October 27, 2023, 11:13:27 am
Fun fact about Genua is they use OpenBSD :)
Title: Re: please consider German BSI certification
Post by: franco on October 27, 2023, 11:15:55 am
And I agree that Common Criteria is not very suitable to a full software distribution. Maybe a software core, but you need formal verification of your code in the higher levels which is a very difficult endeavour.


Cheers,
Franco
Title: Re: please consider German BSI certification
Post by: dstr on October 27, 2023, 03:47:33 pm
this list is not up to date:

https://www.insys-icom.com/insys-icom-erhaelt-it-sicherheitszertifikat-vom-bundesamt-fuer-sicherheit-in-der-informationstechnik-bsi/
Title: Re: please consider German BSI certification
Post by: dstr on October 27, 2023, 03:53:48 pm
most prominet is insys not genua, its probably to late anyway. we have a project to migrate around 80 sophos utm firewalls, because they are end of life in 2026. right now they will be insys not opnsense, because of this certification.
Title: Re: please consider German BSI certification
Post by: Patrick M. Hausen on October 27, 2023, 03:59:30 pm
Never heard of them.

Prominent manufacturers of enterprise firewalls are among others:

Cisco
Juniper
Checkpoint
Palo-Alto
Fortigate
Forcepoint
Sophos
Sonicwall
...

This is the market OPNsense is competing in. None of the above has got a BSI certification. The one for Sophos is for their OS and completely outdated.
Title: Re: please consider German BSI certification
Post by: dstr on October 27, 2023, 04:02:57 pm
And I agree that Common Criteria is not very suitable to a full software distribution. Maybe a software core, but you need formal verification of your code in the higher levels which is a very difficult endeavour.


Cheers,
Franco

not good... cannot argue then to not move to insys.
Title: Re: please consider German BSI certification
Post by: dstr on October 27, 2023, 04:12:48 pm
Never heard of them.

Prominent manufacturers of enterprise firewalls are among others:

Cisco
Juniper
Checkpoint
Palo-Alto
Fortigate
Forcepoint
Sophos
Sonicwall
...

This is the market OPNsense is competing in. None of the above has got a BSI certification. The one for Sophos is for their OS and completely outdated.

maybe prominent but only in corporate environment and not used in huge numbers. insys is used in industry environment, in huge numbers.
example: we running ~60 opnsense+ counting and ~80 sophos utm firewalls but only 4 corporate firewalls.
Title: Re: please consider German BSI certification
Post by: franco on October 27, 2023, 04:13:57 pm
Err, hold on a second..

https://www.bsi.bund.de/DE/Themen/Unternehmen-und-Organisationen/Standards-und-Zertifizierung/Zertifizierung-und-Anerkennung/Zertifizierung-von-Produkten/Beschleunigte-Sicherheitszertifizierung/Zertifizierte-Produkte-nach-BSZ/zertifizierte-produkte-nach-bsz_node.html

Only lists two things including insys but it says "Aktuelle Zertifikate der Beschleunigten Sicherheitszertifizierung" which suggests this is a lightweight process...

And like bimbar notes this is the REAL page with the known (fully) certified devices:

https://www.bsi.bund.de/DE/Themen/Unternehmen-und-Organisationen/Standards-und-Zertifizierung/Zertifizierung-und-Anerkennung/Zertifizierung-von-Produkten/Zertifizierung-nach-CC/Zertifizierte-Produkte-nach-CC/Netzwerkprodukte/produkte.html?nn=456508

Nothing against your choice, but your conclusion is not based on all of the facts. If your requirement is BSI certification that's fair, but I wouldn't use the BSZ ones if I was on the line here.  ;)


Cheers,
Franco
Title: Re: please consider German BSI certification
Post by: dstr on October 27, 2023, 04:26:39 pm
welcome to the world of "decision makers" if its insys vs opnsense, bsi light vs no bsi, who would you choose rationally? and thats it.
Title: Re: please consider German BSI certification
Post by: franco on October 27, 2023, 04:31:06 pm
No, honestly, here is free corporate advice: stick to the list that bimbar posted and avoid getting burned by BSZ.


Cheers,
Franco
Title: Re: please consider German BSI certification
Post by: Patrick M. Hausen on October 27, 2023, 04:32:12 pm
example: we running ~60 opnsense+ counting and ~80 sophos utm firewalls but only 4 corporate firewalls.
OPNsense and Sophos are corporate firewalls.

But you do you. If this particular vendor fits your criteria, go for it. You won't find many network and security engineers familiar with that product, but if they cater to industrial environments, then maybe things work differently, there. I can e.g. picture their direct support to be way better than any of the large firewall vendors'.
Title: Re: please consider German BSI certification
Post by: franco on October 27, 2023, 04:45:38 pm
And I agree that Common Criteria is not very suitable to a full software distribution. Maybe a software core, but you need formal verification of your code in the higher levels which is a very difficult endeavour.
not good... cannot argue then to not move to insys.

I don't think you understand common criteria certification levels at all. It's near impossible for software to go beyond 4+ because of formal verification requirements. The higher levels are tailored for hardware and mathematics (like radio communication encryption).

You haven't even stated what you would expect from common criteria. If you want level 7 you don't get it in a firewall...ever. If you look for level 4 which is fair I don't think insys has it according to their website. So why are you snubbing not having CC off for anyone else and try to prove your point? ;)


Cheers,
Franco
Title: Re: please consider German BSI certification
Post by: bimbar on November 01, 2023, 10:45:52 am
I would also argue that CC certification says very little about the actual security of the product.

I had a some contact with EAL4 not that long ago and it did not fill me with confidence.

If you want manageable security in a corporate environment with a high number of devices, go for fortinet, is my advice.
Title: Re: please consider German BSI certification
Post by: meyergru on November 01, 2023, 01:24:27 pm
Folks, you misunderstand something here: In corporate environments, more often than not, decisions are made by managers who neither know nor care about the things they have to decide about. However, they have to take the responsibility.

The less informed they are, the more likely is that they will resort to labels which seem to promise good quality. If anything serious happens afterwards, at least they can say: "But I chose the product with certification - what else should I have done? This clearly was not my fault." - which sounds believeable to higher managers who know/care even less than he does.

This is why a few years ago, in financial institutions, IBM was always chosen for anything (database, OS, CRM solution, whatever). The saying was: "If it goes wrong, and it was not an IBM product, I'm fired. If it goes wrong and it was an IBM product, I can always blame it on IBM.". So, they even chose OS/2, which was later abolished by IBM. Bank IT managers would laugh at that decision and not believe it. So, the IBM CEO invited german manager to IBM headquarters and told them he was serious about it. It has been reported that there were fisticuffs and the CEO had to be lead out of the room by his security staff. After that episode, IBM was done in german financial IT.

This is not new, it is called the Peter Princple (https://en.wikipedia.org/wiki/Peter_principle), or more concise: "In a hierarchy every employee tends to rise to his level of incompetence.". @dstr looks to me like the savvy tech guy who wants to keep the better product but has to justify his choice according to what I laid out.

Title: Re: please consider German BSI certification
Post by: dstr on November 03, 2023, 12:39:10 pm
Any update to this topic?

Well if Opnsense is an corp only soluton, how come landitec and thomas krenn offering industrial hardware solutions with opnsense preinstalled? I mean you wasnt even aware of its purpose in industrial solutions before I told you so.
Apart from this, we have 60 business licenses alone coming with our firewall, so we are paying a huge share for the opnsense existense, and there would be another 80 licenses ( it would be 160 license, because we planning clusterd firewall)
I do not understand why you talking like that.

Just want to tell, we turned to an kritis environment which gives opnsense a REAL case and not just some dumb idiot corp or hobby case.

Title: Re: please consider German BSI certification
Post by: franco on November 03, 2023, 12:51:37 pm
To be frank, I am unsure what you are looking for pressuring others and not responding to the questions and concerns we have. I'm out of this one... good luck! ;)
Title: Re: please consider German BSI certification
Post by: dstr on November 03, 2023, 12:56:49 pm
I dont want to pressure anyone, I want opnsense to live (and Insys to die)

If thats too much, then sorry.
Title: Re: please consider German BSI certification
Post by: Patrick M. Hausen on November 03, 2023, 12:59:59 pm
Well if Opnsense is an corp only soluton, how come landitec and thomas krenn offering industrial hardware solutions with opnsense preinstalled?
Because it's a good product? Most customers don't demand a certification that is not worth the paper.

Do you have any idea how many person years it takes to go through a certification process? And you have to recertify for every single new version. Good luck with new releases every 6 months.

I have done corporate and industrial IT as a systems integrator and I have never met a single customer for whom certification was mandatory. Either I could talk them out of it. Or EAL4 like Sidewinder had was enough. Or they bought from someone else. That's life.

Kind regards,
Patrick

P.S. If you want to root for OPNsense in your own corporation, suggest an independent evaluation of both alternatives. Secorvo in Karlsruhe are renowned for their knowledge, professional attitude and the fact that they really are impartial.

I went through exactly this process for the country of Hessen and BSI certification or not Genugate "lost" and Sidewinder "won". Because apart from a certification sometimes you just need certain features. If you support very little like Genugate does, certification is of course way easier.
Title: Re: please consider German BSI certification
Post by: dstr on November 03, 2023, 01:07:33 pm
Mark my words, the BSI train will hit anybody. Its starting with kritis, where we have to deal with it. And there will be enough momentum when this will get to every single corporate firewall.

....and only because its hard, you should fear it so much to not even try it, thats a live quote.
Title: Re: please consider German BSI certification
Post by: dstr on November 03, 2023, 01:33:27 pm

P.S. If you want to root for OPNsense in your own corporation, suggest an independent evaluation of both alternatives. Secorvo in Karlsruhe are renowned for their knowledge, professional attitude and the fact that they really are impartial.

I went through exactly this process for the country of Hessen and BSI certification or not Genugate "lost" and Sidewinder "won". Because apart from a certification sometimes you just need certain features. If you support very little like Genugate does, certification is of course way easier.


problem, thats not all, we need at least a wide temperature. landitec offers 0-50°, i just googled quick and sidewinder does not have a device to meet it.
its really hard to find we searched 6 months to get the perfect combination. thats why I want to stick with opnsense.
Title: Re: please consider German BSI certification
Post by: dstr on November 03, 2023, 01:39:48 pm
To be frank, I am unsure what you are looking for pressuring others and not responding to the questions and concerns we have. I'm out of this one... good luck! ;)

If you dont want to talk to me anymore, than I will reach out via other channels.
I mean we have the business support too, where you need to answer.
Title: Re: please consider German BSI certification
Post by: Patrick M. Hausen on November 03, 2023, 01:43:33 pm
Sidewinder is an EOL product. I just wanted to share an anecdote about the value of certifications from my personal experience.

Industrial environments are not a problem with OPNsense. You can pick any suitable hardware.

I seriously doubt the world of corporate firewalls will revolve around german ideas of certification. Look at the official BSI list - practically no relevant product from one of the major suppliers is on that list. Wanna bet if T-Systems will throw out all of their Cisco gear? Or if Cisco will give a damn about BSI? No and no.
Title: Re: please consider German BSI certification
Post by: dstr on November 03, 2023, 01:48:54 pm
It will get to the point where cisco has to apply, sooner or later. I worked for Daimler for example in the network department, where all of the devices where Cisco. I would bet a thousand euro that if Daimler decides it will only install BSI certified hardware because of security risks, cisco will run. Its just a matter of enough industrial momentun, like I said before.
Title: Re: please consider German BSI certification
Post by: bimbar on November 03, 2023, 03:12:29 pm
most prominet is insys not genua, its probably to late anyway. we have a project to migrate around 80 sophos utm firewalls, because they are end of life in 2026. right now they will be insys not opnsense, because of this certification.

Those are not on the BSI list either, btw.
Title: Re: please consider German BSI certification
Post by: dstr on November 10, 2023, 10:42:40 am
Update, the hardware you are selling in your shop will get the BSI certification, plus opnsense will get it too

Thanks for this :-)
Title: Re: please consider German BSI certification
Post by: mimugmail on November 10, 2023, 02:18:10 pm
And who is sponsoring this? :)