Common criteria is not supported on anything other than Ubuntu 16.04.4
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
Ubuntu Security Certifications |
Fix Released
|
Undecided
|
Unassigned |
Bug Description
As our documentation reports on https:/
"Common criteria evaluated configuration is currently available for Ubuntu 16.04.4 LTS (Server)."
This is particularly an issue for Ubuntu Pro customers who would want to use common criteria, since the latest Ubuntu Pro images already come with Ubuntu 16.04.7 and won't allow customers to enable common criteria even with the manual method described in the link above. As far as I know it's not trivial either to downgrade from Ubuntu 16.04.7 to 16.04.4.
Here is what happens on an Ubuntu Pro 16.04.7 system when trying to manually enable CC-EAL (without using the UA client, which also doesn't work. See bug https:/
=======
ubuntu@xenialpro:~$ sudo apt-key adv --keyserver keyserver.
Executing: /tmp/tmp.
keyserver.
--recv-keys
A166877412DAC26
gpg: requesting key 8D13028C from hkp server keyserver.
gpg: key 8D13028C: "Launchpad PPA for ubuntu-advantage" not changed
gpg: Total number processed: 1
gpg: unchanged: 1
ubuntu@xenialpro:~$ sudo add-apt-repository -u 'deb https://<user>:
ubuntu@xenialpro:~$ sudo apt install ubuntu-
[...]
Unpacking ubuntu-
Setting up ubuntu-
ubuntu@xenialpro:~$ mkdir cc-dir
ubuntu@xenialpro:~$ cd cc-dir
ubuntu@
ubuntu@
ubuntu@
Log file: /var/log/
This script will configure the system to ensure it's compliant
with Common Criteria EAL2.
Do you want to proceed? [N/y] y
Checking system...
This script should be run in a Ubuntu 16.04.4 system
=======
And the script exits with an error code 1.
Concerning Ubuntu Pro: I think we should either allow common criteria to work on 16.04.7 or we should remove it from our Ubuntu Pro documentation/
NOTE: The following method is not tested/ recommended/ supported by Canonical
Just for fun I removed the 16.04.4 check from the common criteria check and ran it on an Ubuntu 16.04 Pro instance (16.04.7) and it ran well enough.
I edited the script Configure- Ubuntu- 16.04-Common- Criteria. sh and commented out the following line:
#if [[ "$DISTRIB_ DESCRIPTION" != 'Ubuntu 16.04.4 LTS' ]]; then
# abort "This script should be run in a Ubuntu 16.04.4 system"
#fi
I then ran the script again:
$ sudo ./Configure- Ubuntu- 16.04-Common- Criteria. sh Ubuntu- 16.04-Common- Criteria. tar.gz
But it ended with this error after just a few seconds:
Some of the required packages are not installed: ebtables libvirt-bin qemu-kvm
So I installed those packages and ran the script again:
$ sudo apt install ebtables libvirt-bin qemu-kvm Ubuntu- 16.04-Common- Criteria. sh Ubuntu- 16.04-Common- Criteria. tar.gz
$ sudo ./Configure-
And this time it went through all the way:
Log file: /var/log/ CC-EAL2- Ubuntu- 16.04.4_ 20210408153319. log
This script will configure the system to ensure it's compliant
with Common Criteria EAL2.
Do you want to proceed? [N/y] y upgrades" ... symptoms" ... bootloader. .. hold-packages. ..
Checking system...
Decompressing tarball...
Checking tarball contents...
Installing PPA key...
Adding temporary APT repository...
Running apt-get update...
Checking for installed packages...
Installing additional packages...
Removing non-compliant packages...
Removing "unattended-
Removing "apport-
Running post installation scripts...
Running post-install script, setumask...
Running post-install script, config-fstab...
Running post-install script, config-auditd...
Running post-install script, config-
Running post-install script, config-sshd...
Running post-install script, config-modprobe...
Running post-install script, config-libvirt...
Running post-install script, config-qemu...
Running post-install script, config-apparmor...
Running post-install script, config-pam...
Running post-install script, screen...
Running post-install script, permissions...
Running post-install script, config-alias...
Running post-install script, config-
Common Criteria EAL2 configuration has successfully completed.
The system must reboot for the configuration to take effect.
Reboot the system now? [N/y] y
Rebooting...
After the reboot I noticed this message when I SSH’d back in:
Starting session in 10 seconds
And there’s a log file with the results:
$ head CC-EAL2- Ubuntu- 16.04.4_ 20210408153319. log cc.Gj8E5U1bjX/ mirror xenial InRelease [24.3 kB] azure.archive. ubuntu. com/ubuntu xenial InRelease
This script will configure the system to ensure it's compliant
with Common Criteria EAL2.
Checking system...
Decompressing tarball...
Checking tarball contents...
Installing PPA key...
Adding temporary APT repository...
Running apt-get update...
Get:1 file:/tmp/
Hit:2 http://
$ tail CC-EAL2- Ubuntu- 16.04.4_ 20210408153319. log Gj8E5U1bjX/ post-inst/ config- hold-packages: zlib1g set on hold. Gj8E5U1bjX/ post-inst/ checkerror: --- Starting execution of /tmp/cc. Gj8E5U1bjX/ post-inst/ checkerror --- Gj8E5U1bjX/ post-inst/ checkerror: Common Criteria Evaluated Configuration
/tmp/cc.
/tmp/cc.
/tmp/cc.
Common Crit...