<Past |
Future> |
4.x |
Unapproved |
Unapproved |
Unapproved |
Unapproved |
Unapproved |
Unapproved |
Unapproved |
Unapproved |
Prohibited |
Prohibited |
Prohibited |
Prohibited |
5.x |
Approved w/Constraints [2] |
Approved w/Constraints [2] |
Approved w/Constraints [2] |
Approved w/Constraints [2] |
Divest [2, 3, 4] |
Divest [2, 3, 4] |
Divest [2, 3, 4] |
Divest [2, 3, 4] |
Unapproved |
Unapproved |
Prohibited |
Prohibited |
6.x |
Approved w/Constraints [2] |
Approved w/Constraints [2] |
Approved w/Constraints [2] |
Approved w/Constraints [2] |
Approved w/Constraints [2, 3, 4] |
Approved w/Constraints [2, 3, 4] |
Approved w/Constraints [2, 3, 4] |
Approved w/Constraints [2, 3, 4] |
Approved w/Constraints [3, 4, 5, 6] |
Approved w/Constraints [3, 4, 5, 6] |
Approved w/Constraints [3, 4, 5, 6] |
Approved w/Constraints [3, 4, 5, 7] |
7.x |
Approved w/Constraints [2] |
Approved w/Constraints [2] |
Approved w/Constraints [2] |
Approved w/Constraints [2] |
Approved w/Constraints [2, 3, 4] |
Approved w/Constraints [2, 3, 4] |
Approved w/Constraints [2, 3, 4] |
Approved w/Constraints [2, 3, 4] |
Approved w/Constraints [3, 4, 5, 6] |
Approved w/Constraints [3, 4, 5, 6] |
Approved w/Constraints [3, 4, 5, 6] |
Approved w/Constraints [3, 4, 5, 7] |
8.x |
Unapproved |
Unapproved |
Unapproved |
Unapproved |
Unapproved |
Unapproved |
Unapproved |
Unapproved |
Unapproved |
Unapproved |
Unapproved |
Unapproved |
| | [1] | Product use is restricted to laboratory and development test systems only. Product may not be used for VistA site mirror test systems or other pre-production verification systems. Applications and strategies developed on systems running this product must be tested properly on enterprise level Red Hat platforms prior to production release. Product must remain properly patched in order to mitigate known and future security vulnerabilities. Organization security baseline configuration standards for Linux systems must be employed and properly maintained. Only versions 5.x and higher are permitted. | | [2] | Product use is restricted to laboratory and development test systems only. Product may not be used for VistA site mirror test systems or other pre-production verification systems. Applications and strategies developed on systems running this product must be tested properly on enterprise level Red Hat platforms prior to production release. Product must remain properly patched in order to mitigate known and future security vulnerabilities. Organization security baseline configuration standards for Linux systems must be employed and properly maintained. | | [3] | Users should check with their supervisor, Information Security Office (ISO) or local OIT representative for permission to download and use this software. Downloaded software must always be scanned for viruses prior to installation to prevent adware or malware. Freeware may only be downloaded directly from the primary site that the creator of the software has advertised for public download and user or development community engagement. Users should note, any attempt by the installation process to install any additional, unrelated software is not approved and the user should take the proper steps to decline those installations. | | [4] | Due to National Institute of Standards and Technology (NIST) identified security vulnerabilities, extra vigilance should be applied to ensure the versions remain properly patched to mitigate known and future vulnerabilities. The local ISO can provide assistance in reviewing the NIST vulnerabilities. | | [5] | Users must abide by the constraints and limitations of the Red Hat Enterprise Linux TRM entry.
Use of this product is restricted to laboratory and development test systems only. This product may not be used for Veterans Information Systems and Technology Architecture (VistA) site mirror test systems or other pre-production verification systems. Applications and strategies developed on systems running this product must be tested properly on enterprise level Red Hat platforms prior to production release. This product must remain properly patched in order to mitigate known and future security vulnerabilities. Organization security baseline configuration standards for Linux systems must be employed and properly maintained. | | [6] | Due to potential information security risks, cloud based technologies may not be used without an Enterprise Security Change Control Board (ESCCB) approval. This body is in part responsible for ensuring organizational information, Personally Identifiable Information (PII), Protected Health Information (PHI), and VA sensitive data are not compromised. (Ref: VA Directive 6004, VA Directive 6517, VA Directive 6513 and VA Directive 6102). | | [7] | Due to potential information security risks, cloud based technologies may not be used without the approval of the VA Enterprise Cloud Services (ECS) Group. This body is in part responsible for ensuring organizational information, Personally Identifiable Information (PII), Protected Health Information (PHI), and VA sensitive data are not compromised. (Ref: VA Directive 6004, VA Directive 6517, VA Directive 6513 and VA Directive 6102). |
|
Note: |
At the time of writing, version 8 (2105) is end-of-life as of 12/31/2021. At the time of writing, 2009 is the most current update for version 7 and released 11/11/2020. |