I work for a eu government with extremely high security requirements (in the national identity / IDP / health space).
We actually _CANNOT_ use redhat for compliance reasons.
(We're using ubuntu LTS as it goes)
We actually _CANNOT_ use redhat for compliance reasons.
(We're using ubuntu LTS as it goes)
In the end, we just went with ubuntu for those nodes, and they all passed the certification. Shrug.
Since then, we don't even need the OS to be certified, since we are using confidential computing, and we stuck with ubuntu for our k8s nodes etc -- but we are forbidden from using rhel anywhere by our legal / compliance people now.
The bottom line really is plenty of auditors I've seen don't know how to check for vulnerabilities other than by checking a version... That's it.. Their tools or reporting only know package must have a version greater than x.y.z.