The Russian distribution of Astra Linux Special Edition 1.8 has been released.

The company LLC "RusBITech-Astra" has introduced the special-purpose distribution Astra Linux Special Edition 1.8, which can be used to protect confidential information and state secrets up to the level of "special importance." The distribution is based on the Debian GNU/Linux package base and contains additional security mechanisms, such as its own mandatory access control system, auditing, file integrity and authenticity checks (PARSEC), guaranteed file deletion, and a kernel built with security-enhancing patches. The user environment is built on the proprietary Fly desktop environment with components using the Qt library.

The distribution is distributed under a licensing agreement that imposes several restrictions on users, in particular, commercial use is prohibited without entering into a licensing agreement, as well as decompiling and disassembling the product. The original algorithms and source codes developed specifically for Astra Linux are classified as commercial secrets. The user is allowed to reproduce only one instance of the product on one computer or virtual machine, and is also given the right to create only one backup copy of the medium with the product. Ready installation builds are not publicly provided yet, but container images are available and of virtual machines.

The release successfully passed a comprehensive testing process in the information protection certification system of the FSTEC of Russia at the first, highest, level of trust, i.e., it can be used to process information that constitutes a state secret of "special importance." The certificate confirms compliance with security requirements for operating systems, virtualization and containerization tools, as well as for database management systems.

Key Changes:

  • The package base has been updated to Debian 12.
  • Two Linux kernel packages are offered, based on releases 6.1 and 6.6. The 6.1 kernel comes with modifications and fixes from the RAS Institute for System Programming and will be supported throughout the entire lifecycle of the OS. The 6.6 kernel has been classified as having a short-term support cycle.
  • Two separate repositories are proposed: Main and Extended. The former includes packages that have undergone a complete certification cycle, while the latter contains development tools, packages for building the Main repository, as well as additional application and system packages.
  • A new astra-installer is utilized, which launches after the system boots in Live mode. Remote installation management is supported using the VNC protocol.
  • The update process from the Astra Linux 1.7 branch to the 1.8 release has been automated, and in case of issues during the update, it is possible to roll back to the previous state.
  • A scheme for assigning predictable names to network interfaces has been implemented.
  • The Kea DHCP server is included.
  • The administration interface fly-admin-smc has been replaced with the astra-systemsettings tool, providing access to various settings modules. Among other things, a module for managing local security policy has been integrated, which does not require launching a separate fly-admin-smc program. Modules for user management, mandatory access control, mandatory integrity control, file integrity verification through digital signatures, audit system configuration, connected storage management, memory cleanup settings, enabling kiosk mode, and security feature status assessment are also available.
    The Russian distribution of Astra Linux Special Edition 1.8 has been released.
  • Ready-made recommended security settings profiles for various usage scenarios have been implemented. Previously, configuration instructions were provided to meet different security class requirements, necessitating manual work by administrators. In the new version, the process of modifying settings is automated.
  • For dynamic software integrity control, the ability to use the KSI CryptoPro CSP and certificates for verifying digital signatures issued by the certification authority has been added.
  • A new design style, Astra Proxima, has been proposed, reflecting modern trends in interface design while maintaining familiar layout and minimalism. Four design modes are available: light, dark, simplified (without graphic effects), and service.
    The Russian distribution of Astra Linux Special Edition 1.8 has been released.
  • The applications menu has been modernized and restructured (with the option to revert to the classic menu).
  • A new sound theme "Star Minimalism" has been added, developed with participation from Roscosmos based on sounds from real space objects.
  • The fly-dm-rdp package has been added to facilitate remote connection to the system via the RDP protocol.
  • In the fly-fm file manager, a toolbar editor has been added, and the ability to display mounted network resources in the navigation panel has been introduced. In dual-panel mode, two independent address bars have been implemented.
  • The OpenSSL package has been updated to version 3.2.0.
  • The Tantor DBMS has been upgraded to the PostgreSQL 15 codebase (previously using PostgreSQL 11) with enhancements for information protection and access management. A certificate from the certification authority of the Ministry of Digital Development of the Russian Federation has been embedded into Chromium, Chromium-gost, and Firefox browsers.
  • Support for snapshots of virtual machines with UEFI has been added, along with the export/import of virtual machines with snapshots, backup creation of virtual machines using virtnbdbackup, and grouping virtual machines in virt-manager.
  • The integrity control tools have implemented the ability to utilize a hierarchical integrity level, where the root FS and all file objects after installation have zero linear integrity, while file objects and running processes can be assigned negative linear integrity.
  • The capability to ensure the integrity control of filesystem objects and deb packages based on templates representing file lists for checksum verification has been added.
  • New privileges have been added: cap_perfmon (allows the use of monitoring systems), cap_bpf (allows certain BPF operations), cap_checkpoint_restore (allows the identification of the PID allocated to the next process created within the namespace).

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster