please consider German BSI certification

Started by dstr, October 27, 2023, 10:25:10 AM

Previous topic - Next topic
Quote from: dstr on October 27, 2023, 04:02:57 PM
Quote from: franco on October 27, 2023, 11:15:55 AM
And I agree that Common Criteria is not very suitable to a full software distribution. Maybe a software core, but you need formal verification of your code in the higher levels which is a very difficult endeavour.
not good... cannot argue then to not move to insys.

I don't think you understand common criteria certification levels at all. It's near impossible for software to go beyond 4+ because of formal verification requirements. The higher levels are tailored for hardware and mathematics (like radio communication encryption).

You haven't even stated what you would expect from common criteria. If you want level 7 you don't get it in a firewall...ever. If you look for level 4 which is fair I don't think insys has it according to their website. So why are you snubbing not having CC off for anyone else and try to prove your point? ;)


Cheers,
Franco

I would also argue that CC certification says very little about the actual security of the product.

I had a some contact with EAL4 not that long ago and it did not fill me with confidence.

If you want manageable security in a corporate environment with a high number of devices, go for fortinet, is my advice.

November 01, 2023, 01:24:27 PM #17 Last Edit: November 01, 2023, 01:39:11 PM by meyergru
Folks, you misunderstand something here: In corporate environments, more often than not, decisions are made by managers who neither know nor care about the things they have to decide about. However, they have to take the responsibility.

The less informed they are, the more likely is that they will resort to labels which seem to promise good quality. If anything serious happens afterwards, at least they can say: "But I chose the product with certification - what else should I have done? This clearly was not my fault." - which sounds believeable to higher managers who know/care even less than he does.

This is why a few years ago, in financial institutions, IBM was always chosen for anything (database, OS, CRM solution, whatever). The saying was: "If it goes wrong, and it was not an IBM product, I'm fired. If it goes wrong and it was an IBM product, I can always blame it on IBM.". So, they even chose OS/2, which was later abolished by IBM. Bank IT managers would laugh at that decision and not believe it. So, the IBM CEO invited german manager to IBM headquarters and told them he was serious about it. It has been reported that there were fisticuffs and the CEO had to be lead out of the room by his security staff. After that episode, IBM was done in german financial IT.

This is not new, it is called the Peter Princple, or more concise: "In a hierarchy every employee tends to rise to his level of incompetence.". @dstr looks to me like the savvy tech guy who wants to keep the better product but has to justify his choice according to what I laid out.

Intel N100, 4 x I226-V, 16 GByte, 256 GByte NVME, ZTE F6005

1100 down / 440 up, Bufferbloat A+

November 03, 2023, 12:39:10 PM #18 Last Edit: November 03, 2023, 12:55:59 PM by dstr
Any update to this topic?

Well if Opnsense is an corp only soluton, how come landitec and thomas krenn offering industrial hardware solutions with opnsense preinstalled? I mean you wasnt even aware of its purpose in industrial solutions before I told you so.
Apart from this, we have 60 business licenses alone coming with our firewall, so we are paying a huge share for the opnsense existense, and there would be another 80 licenses ( it would be 160 license, because we planning clusterd firewall)
I do not understand why you talking like that.

Just want to tell, we turned to an kritis environment which gives opnsense a REAL case and not just some dumb idiot corp or hobby case.


To be frank, I am unsure what you are looking for pressuring others and not responding to the questions and concerns we have. I'm out of this one... good luck! ;)

November 03, 2023, 12:56:49 PM #20 Last Edit: November 03, 2023, 12:58:44 PM by dstr
I dont want to pressure anyone, I want opnsense to live (and Insys to die)

If thats too much, then sorry.

November 03, 2023, 12:59:59 PM #21 Last Edit: November 03, 2023, 01:03:51 PM by Patrick M. Hausen
Quote from: dstr on November 03, 2023, 12:39:10 PM
Well if Opnsense is an corp only soluton, how come landitec and thomas krenn offering industrial hardware solutions with opnsense preinstalled?
Because it's a good product? Most customers don't demand a certification that is not worth the paper.

Do you have any idea how many person years it takes to go through a certification process? And you have to recertify for every single new version. Good luck with new releases every 6 months.

I have done corporate and industrial IT as a systems integrator and I have never met a single customer for whom certification was mandatory. Either I could talk them out of it. Or EAL4 like Sidewinder had was enough. Or they bought from someone else. That's life.

Kind regards,
Patrick

P.S. If you want to root for OPNsense in your own corporation, suggest an independent evaluation of both alternatives. Secorvo in Karlsruhe are renowned for their knowledge, professional attitude and the fact that they really are impartial.

I went through exactly this process for the country of Hessen and BSI certification or not Genugate "lost" and Sidewinder "won". Because apart from a certification sometimes you just need certain features. If you support very little like Genugate does, certification is of course way easier.
Deciso DEC750
People who think they know everything are a great annoyance to those of us who do. (Isaac Asimov)

Mark my words, the BSI train will hit anybody. Its starting with kritis, where we have to deal with it. And there will be enough momentum when this will get to every single corporate firewall.

....and only because its hard, you should fear it so much to not even try it, thats a live quote.

Quote from: Patrick M. Hausen on November 03, 2023, 12:59:59 PM

P.S. If you want to root for OPNsense in your own corporation, suggest an independent evaluation of both alternatives. Secorvo in Karlsruhe are renowned for their knowledge, professional attitude and the fact that they really are impartial.

I went through exactly this process for the country of Hessen and BSI certification or not Genugate "lost" and Sidewinder "won". Because apart from a certification sometimes you just need certain features. If you support very little like Genugate does, certification is of course way easier.


problem, thats not all, we need at least a wide temperature. landitec offers 0-50°, i just googled quick and sidewinder does not have a device to meet it.
its really hard to find we searched 6 months to get the perfect combination. thats why I want to stick with opnsense.

Quote from: franco on November 03, 2023, 12:51:37 PM
To be frank, I am unsure what you are looking for pressuring others and not responding to the questions and concerns we have. I'm out of this one... good luck! ;)

If you dont want to talk to me anymore, than I will reach out via other channels.
I mean we have the business support too, where you need to answer.

Sidewinder is an EOL product. I just wanted to share an anecdote about the value of certifications from my personal experience.

Industrial environments are not a problem with OPNsense. You can pick any suitable hardware.

I seriously doubt the world of corporate firewalls will revolve around german ideas of certification. Look at the official BSI list - practically no relevant product from one of the major suppliers is on that list. Wanna bet if T-Systems will throw out all of their Cisco gear? Or if Cisco will give a damn about BSI? No and no.
Deciso DEC750
People who think they know everything are a great annoyance to those of us who do. (Isaac Asimov)

It will get to the point where cisco has to apply, sooner or later. I worked for Daimler for example in the network department, where all of the devices where Cisco. I would bet a thousand euro that if Daimler decides it will only install BSI certified hardware because of security risks, cisco will run. Its just a matter of enough industrial momentun, like I said before.

Quote from: dstr on October 27, 2023, 03:53:48 PM
most prominet is insys not genua, its probably to late anyway. we have a project to migrate around 80 sophos utm firewalls, because they are end of life in 2026. right now they will be insys not opnsense, because of this certification.

Those are not on the BSI list either, btw.

Update, the hardware you are selling in your shop will get the BSI certification, plus opnsense will get it too

Thanks for this :-)