SlideShare una empresa de Scribd logo
1 de 46
Descargar para leer sin conexión
RED HAT TECHNICAL SYMPOSIUM
NSA R&E Symposium Center
Monday November 8th
, 2010
1300-1600
2
AGENDA
1:00-1:20 Software Central Opening Notes
1:20-2:20 Red Hat Enterprise Linux 6 Update
2:20-2:30 Break
2:30-3:30 Red Hat in the Virtualized Environment & Security
3:30-4:00 Q&A Panel w/ Red Hat Technologists
RED HAT ENTERPRISE LINUX 6 UPDATE
Shawn D. Wells
Technical Director, Intelligence Programs
sdw@redhat.com / 443-534-0130
4
RED HAT ENTERPRISE LINUX 6 UPDATE
RHEL6 FOUNDATION FEATURES & THEMES
● Trusted data center platform
Ideally positioned to provide non-disruptive path
forward.
● Application and infrastructure performance,
scalability and security
Support for varied workloads and advanced hardware
capabilities.
● Making IT agile across physical, virtual and Cloud
The right operating system across any environment.
5
RED HAT ENTERPRISE LINUX 6 UPDATE
RHEL6 FOUNDATION FEATURES & THEMES
● Improved manageability
For large scale virtualization deployments, server & desktop. Samba
enhancements for Windows active directory and file sharing
● Power management
Efficiency for lower deployment costs, reduced carbon footprint for
virt, bare metal, desktop. Hardware level as well as dynamic system
service startup and suspend.
● RAS (Reliability, Availability, Serviceability)
Hotplug, memory error reporting, filesystem and data integrity.
Support tools such as automated crash detection and bug reporting.
6
RED HAT ENTERPRISE LINUX 6 UPDATE
RHEL6 FOUNDATION FEATURES & THEMES
● Hardware enablement and scalability
Maximum efficiency, large configurations (cpu, memory, busses, I/O),
NUMA awareness, new BIOS boot loader interface
Supported architectures: x86, x86_64, PPC64, s390x
7
RED HAT ENTERPRISE LINUX 6 UPDATE
SYSTEMS MANAGEMENT INTEGRATION
● Red Hat Network Satellite
● Install & provision new
systems
● Update existing
● Manage configuration files &
maintain over time
● Monitoring system metrics
● Multiple managed Satellites
on ELA
8
RED HAT ENTERPRISE LINUX 6 UPDATE
SYSTEMS MANAGEMENT INTEGRATION
● Red Hat Network Satellite 5.4
● RPMs will be now be encrypted with 256-bit keys,
up from 128-bit.
● Find & remove stale instances that are no longer
being used
● Flex Guest / Floating Entitlements
● Centrally manage SELinux Context on remote
files
●
Expanded APIs for 3rd
party integration
9
RED HAT ENTERPRISE LINUX 6 UPDATE
SYSTEMS MANAGEMENT INTEGRATION
● Satellite Deployment Model
MANAGED SYSTEMS
WEB INTERFACE
●RHN Satellite
• Software Distribution
• Channel Management
• Monitoring
• Provisioning
• RHEL subscription 
management
IT Applications
API LAYER
Custom Content
10
RED HAT ENTERPRISE LINUX 6 UPDATE
SYSTEMS MANAGEMENT INTEGRATION
● Satellite Deployment Model: Single Satellite
11
RED HAT ENTERPRISE LINUX 6 UPDATE
SYSTEMS MANAGEMENT INTEGRATION
● Satellite Deployment Model: Multi Tiered Satellite
12
RED HAT ENTERPRISE LINUX 6 UPDATE
EFFICIENCY, SCALABILITY, RELIABILITY
Red Hat Enterprise Linux 6 evolves in concert with
hardware advances, reducing system power
consumption, taking advantage of hardware with greater
numbers of processing and memory resources, and
withstanding hardware failures better.
13
RED HAT ENTERPRISE LINUX 6 UPDATE
EFFICIENCY, SCALABILITY, RELIABILITY
● New scheduler (Completely Fair Scheduler)
● Dynamic addition of processor and memory
● More robust error reporting for PCIe devices (PCIe
AER)
● Isolation of memory hardware failures with minimal
downtime
14
RED HAT ENTERPRISE LINUX 6 UPDATE
EFFICIENCY, SCALABILITY, RELIABILITY
● Mature file systems to cater to varied usage and
performance characteristics.
● Ext4: Now default, scales to 16TB
● GFS2: Scales to 25TB
● XFS: Scales up to 100TB, tuned for storage arrays
● NFSv4
● Configured to reduce chances of data corruption for
low-end locally attached storage.
15
RED HAT ENTERPRISE LINUX 6 UPDATE
EFFICIENCY, SCALABILITY, RELIABILITY
● Power management
● Tickless kernel
● User-space tools – powertop
● Dynamic throttling of power to devices
● Relatime drive optimization
16
RED HAT ENTERPRISE LINUX 6 UPDATE
EFFICIENCY, SCALABILITY, RELIABILITY
17
RED HAT ENTERPRISE LINUX 6 UPDATE
EFFICIENCY, SCALABILITY, RELIABILITY
18
RED HAT ENTERPRISE LINUX 6 UPDATE
EFFICIENCY, SCALABILITY, RELIABILITY
Objective: Providing scaling
headroom anticipating many years of
upcoming hardware generations.
Tested and supported limits will likely
grow over the course of product
lifespan.
19
RED HAT ENTERPRISE LINUX 6 UPDATE
EFICIENCY, SCALABILITY AND RELIABILITY
● Kernel scalability limits - x86_64
Parameter RHEL5
Supported Limit
RHEL6
Supported Limit
RHEL6
Theoretical Limit
CPUs 64 128 4096
Memory – Physical
addressing
1TB 2TB 64TB
Memory – Process virtual
address space (note –
hardware dependent
2TB 128TB 128TB
IRQs 293 33,024 33,024
# of processes 32,000 32,000
(larger pending
testing)
4 million
KVM guest memory 512GB 8TB 64TB
KVM guest CPU 32 64
(pending testing)
64
(pending testing)
20
RED HAT ENTERPRISE LINUX 6 UPDATE
EFICIENCY, SCALABILITY AND RELIABILITY
● File systems and storage limits - x86_64
Maximum
filesize
Maximum
filesystem size
EXT3 2TB 16TB
EXT4 16TB 16TB
GFS 16TB 16TB
GFS2 25TB 25TB
XFS 100TB 100TB
21
RED HAT ENTERPRISE LINUX 6 UPDATE
DETERMINISM & REALTIME ENHANCEMENTS
● Some capabilities from Red Hat in MRG-realtime kernel
(currently shipping as layered product) mainstreamed in
RHEL6.
● Determinism – Ability to schedule priority tasks
predictably and consistently
● Priority – Ensure highest priority applications are not
blocked by lower priorities
● Timer – Microsecond precision not timer interrupt,
~millisecond precision
22
RED HAT ENTERPRISE LINUX 6 UPDATE
STORAGE MANAGEMENT
● Topology awareness – I/O (alignment and chunk size)
based on info from the storage device. This is in dm, LVM,
md, and utilities such as parted and mkfs. Interfaces
standardized to obtain alignment and optimal I/O stripe
width.
● FcoE (fibre channel over ethernet) on specialized
adapters (Emulex, Qlogic, Cisco), and on standard NICs.
FcoE install & boot support with DCB.
● ISCSI root/boot, including target
● NPIV – n_Port ID Virtualization
23
RED HAT ENTERPRISE LINUX 6 UPDATE
STORAGE MANAGEMENT: LVM/MD
● LVM hot spare; a disk or group of disks used to replace
one failing
● Online resize or mirrored & multipath volumes
● Snapshot scalability enhancements for virtualization
● Multipath enhancements
● Dynamic multipath load balancing. Path selection
based on queue depth, or I/O service time
● Mirroring enhancements
● Mirrored mirror log, avoids need for re-sync after failure
● Selectable hash algorithm for LUKS header, new
cryptsetup commands, new libcryptsetup
24
SOFTWARE RELEASE VERSIONING & SUBSCRIPTIONS
● Red Hat Enterprise Linux Advanced Platform (RHEL AP)
● > 2 CPUs
● Includes Global File System (GFS), Red Hat Cluster Suite
(RHCS)
● Red Hat Enterprise Linux Enterprise Server (RHEL ES)
● Less than 2 CPUs
● Does not include GFS & RHCS
All servers, bare metal or virtual, must have an active Red Hat
subscription.
25
SOFTWARE RELEASE VERSIONING & SUBSCRIPTIONS
● Production 1: Ongoing, active development of features and
hardware enablement for inclusion into RHEL.
● Production 2: New software functionality is not available
during this phase. The focus for minor releases during this
life cycle phase lies on resolving defects with a minimum
priority of high.
● Production 3: No new functionality, new hardware
enablement or updated installation images are planned.
Commonly known as “Maintenance Mode.”
26
SOFTWARE RELEASE VERSIONING & SUBSCRIPTIONS
● General Availability: March 14, 2007
● End of Production 1 phase: Q4 of 2011
● End of Production 2 phase: Q4 of 2012
● End of Production 3 phase: March 31, 2014
● End of Extended Life Cycle phase:March 31, 2017
Latest information available at:
http://www.redhat.com/security/updates/errata/
27
CONSUMING NSA ENTERPRISE SUBSCRIPTIONS
HOW & WHERE TO GET THE SOFTWARE
● Two on-site badged technical consultants at NBP1
● Jeff Weatherford: jweatherford@redhat.com
(u) 240-373-0842
● Joe Glenn jglenn@redhat.com
(u) 410-854-3104
Highside contact information on SearchLight or “go redhat”
RED HAT IN THE VIRTUALIZED
ENVIRONMENT
Chris Runge
Technical Director, U.S
crunge@redhat.com / 703-748-2202
29
RED HAT VIRTUALIZATION
EVOLUTION OF x86 VIRTUALIZATION
30
RED HAT IN THE VIRTUALIZED ENVIRONMENT
KERNEL-BASED VIRTUAL MACHINE (KVM)
Included in Linux kernel since 2006
Added to RHEL 5.4 and included in
RHEL 6
● Xen supported in RHEL 5 through
2014
Available on x86_64 architecture
Requires Intel VT-X or AMD-V CPU
capabilities
31
RED HAT IN THE VIRTUALIZED ENVIRONMENT
KVM GUEST SUPPORT
Runs Linux, Windows and other
operating system guests
RHEL guests supported on third-party
hypervisors:
● Microsoft Hyper-V
● VMWare
Microsoft certified drivers ensure
compliance and support (WHQL and
SVVP)
32
RED HAT IN THE VIRTUALIZED ENVIRONMENT
KVM ADVANTAGES
The OS is the hypervisor
Same platform for bare-metal,
virtualization, and cloud
KVM is a Linux kernel module
VM's run as Linux processes
Simplifies certification
KVM architecture provides high
“feature-velocity”
33
RED HAT IN THE VIRTUALIZED ENVIRONMENT
KVM FEATURE-VELOCITY: SCALABILITY
Host cores
Host memory
Guest vCPUs
Guest memory
Hosts/ cluster
Density
vSphere 4
64 96 4,096
1 TB 64 TB
8 16 64
256 GB 1TB
32 100 200
320 500+ 2,000+
RHEL 5.4/5.5 RHEL 6
After ~7 yrs 1st
6 months 1st
12 months
34
RED HAT IN THE VIRTUALIZED ENVIRONMENT
KVM ADVANCED FEATURES
Kernel Same-Page Merging (KSM)
Memory Page Sharing
Securely shares identical memory pages between virtual machines
35
RED HAT IN THE VIRTUALIZED ENVIRONMENT
KVM ADVANCED FEATURES
Kernel Same-
Page Merging
(KSM)
Enterprise Java
workload
benchmark
Intel Xeon
Processor X5550
with 24GB RAM
Running multiple
3GB Windows
2003 VMs
Scaling up to
200% over-
commit
36
RED HAT IN THE VIRTUALIZED ENVIRONMENT
KVM ADVANCED FEATURES
Thin Provisioning
Allocate storage only when needed
Oversubscribe storage
Transparent to VM
Improve storage utilization
Reduced storage costs
Works with NFS, iSCSI, and FC
37
RED HAT IN THE VIRTUALIZED ENVIRONMENT
VIRTUALIZATION IN RHEL 6
Increased scalability
● Guest/host CPU and memory
● Host: 4096 cores, 64 TB
● Guest: 64 vCPUs, 1 TB
Increased performance
● Improved guest/host memory
management
● Networking improvements
● Storage improvements
Increased Security
● sVirt
Migration Tools Available
● v2v – convert Xen VM's to KVM
38
PHASE 1: CONSOLIDATE
VIRTUALIZE
YOUR
SERVERS
Virtualize your physical
hardware to achieve
higher utilization,
consolidation, and
flexibility.
Virtualization increases the
utilization of physical servers and
provides a foundation for cloud
computing.
Virtualization technology included
in RHEL6.
PHASE 2: AUTOMATE
BUILD A
PRIVATE
CLOUD
As you expand your use
of virtualization, build a
private cloud to manage
the scale and
complexity.
A private cloud abstracts multiple
instances of virtual resources
into elastic pools of computation
with self-provisioning and
scalable services.
PHASE 3: UTILITY
ADD
ADDITIONAL
CLOUDS
As you expand your use
of cloud computing, add
additional clouds
delivered as a utility to
increase capacity and
lower costs.
Red Hat's cloud architecture lets
you manage and integrate
various virtualization systems and
cloud providers together. This
allows you to leverage additional
clouds as a utility.
RED HAT IN THE VIRTUALIZED ENVIRONMENT
FOUNDATION FOR THE CLOUD
39
RED HAT IN THE VIRTUALIZED ENVIRONMENT
FOUNDATION FOR THE CLOUD: MANY COMPONENTS
ALREADY IN NSA INFRASTRUCTURE
RED HAT SECURITY UPDATE
Gunnar Hellekson
CTO, Red Hat Public Sector
gunnar.hellekson@redhat.com / 202-507-9027
41
SECURITY
SELINUX
● Confined users
● Role-based controls to limit system access for users.
● Sandbox
● Untrusted applications can be run confined to prevent
compromising the entire system
● X Access Control Extension (XACE).
● SELinux Kiosk Mode
● Creation of a user session environment that is valid for a
limited time.
42
SECURITY
MLS DESKTOP
43
SECURITY
VIRTUALIZATION
RHEV and KVM inherit the security
features of Linux and RHEL
SELinux security policy infrastructure
Provides protection and isolation for
virtual machines and host
Compromised virtual machine cannot
access other VMs or host
sVirt Project
Sub-project of NSA's SELinux
community. Provides “hardened”
hypervisors
Multilevel security. Isolate guests
Contain any guest breaches
44
SECURITY
SCAP
Access
Requestor
Policy
Enforcement
Point
Policy
Decision
Point
Internets
Remediation
Network
SCAP, TPM
SCAP and TNC
Provides continuous lifecycle
management for virtual machines and
their hosts
Compromised virtual machine can be
quarantined
Allows a provider's security SLA to be
enforced by customers
OpenSCAP
An open source implementation of
SCAP
Included in RHEL 6
45
SECURITY
COMMON CRITERIA UPDATE
RHEL 5.6
● Refreshed to include KVM
● Custom protection profile
RHEL 6
● Will include sVirt, IPSec
● Targeting EAL 4
● Again, custom protection profile
46

www.redhat.com
Q&A PANEL SESSION

Más contenido relacionado

La actualidad más candente

Linux Containers and Docker SHARE.ORG Seattle 2015
Linux Containers and Docker SHARE.ORG Seattle 2015Linux Containers and Docker SHARE.ORG Seattle 2015
Linux Containers and Docker SHARE.ORG Seattle 2015Filipe Miranda
 
NVIDIA GTC 2019: Red Hat and the NVIDIA DGX: Tried, Tested, Trusted
NVIDIA GTC 2019:  Red Hat and the NVIDIA DGX: Tried, Tested, TrustedNVIDIA GTC 2019:  Red Hat and the NVIDIA DGX: Tried, Tested, Trusted
NVIDIA GTC 2019: Red Hat and the NVIDIA DGX: Tried, Tested, TrustedJeremy Eder
 
Whats new in_juno_meetup_barcelona
Whats new in_juno_meetup_barcelonaWhats new in_juno_meetup_barcelona
Whats new in_juno_meetup_barcelonaJaume Devesa Gomez
 
IBM Systems Technical Symposium Melbourne, 2015
IBM Systems Technical Symposium Melbourne, 2015IBM Systems Technical Symposium Melbourne, 2015
IBM Systems Technical Symposium Melbourne, 2015Filipe Miranda
 
2011-03-15 Lockheed Martin Open Source Day
2011-03-15 Lockheed Martin Open Source Day2011-03-15 Lockheed Martin Open Source Day
2011-03-15 Lockheed Martin Open Source DayShawn Wells
 
The Real World with OpenShift - Red Hat DevOps & Microservices Conference 2017
The Real World with OpenShift - Red Hat DevOps & Microservices Conference 2017 The Real World with OpenShift - Red Hat DevOps & Microservices Conference 2017
The Real World with OpenShift - Red Hat DevOps & Microservices Conference 2017 Xpand IT
 
SHARE.ORG Orlando 2015
SHARE.ORG Orlando 2015SHARE.ORG Orlando 2015
SHARE.ORG Orlando 2015Filipe Miranda
 
SPACK: A Package Manager for Supercomputers, Linux, and MacOS
SPACK: A Package Manager for Supercomputers, Linux, and MacOSSPACK: A Package Manager for Supercomputers, Linux, and MacOS
SPACK: A Package Manager for Supercomputers, Linux, and MacOSinside-BigData.com
 
Rhel8 Beta - Halifax RHUG
Rhel8 Beta - Halifax RHUGRhel8 Beta - Halifax RHUG
Rhel8 Beta - Halifax RHUGNicole Maselli
 
Red Hat Summit 2018 5 New High Performance Features in OpenShift
Red Hat Summit 2018 5 New High Performance Features in OpenShiftRed Hat Summit 2018 5 New High Performance Features in OpenShift
Red Hat Summit 2018 5 New High Performance Features in OpenShiftJeremy Eder
 
Andrew J Younge - Vanguard Astra - Petascale Arm Platform for U.S. DOE/ASC Su...
Andrew J Younge - Vanguard Astra - Petascale Arm Platform for U.S. DOE/ASC Su...Andrew J Younge - Vanguard Astra - Petascale Arm Platform for U.S. DOE/ASC Su...
Andrew J Younge - Vanguard Astra - Petascale Arm Platform for U.S. DOE/ASC Su...Linaro
 
Red Hat Linux 5 Hardening Tips - National Security Agency
Red Hat Linux 5 Hardening Tips - National Security AgencyRed Hat Linux 5 Hardening Tips - National Security Agency
Red Hat Linux 5 Hardening Tips - National Security Agencysanchetanparmar
 
Presentation on HP ProLiant value add tools on Linux
Presentation on HP ProLiant value add tools on LinuxPresentation on HP ProLiant value add tools on Linux
Presentation on HP ProLiant value add tools on LinuxBruno Cornec
 
OpenHPC: A Comprehensive System Software Stack
OpenHPC: A Comprehensive System Software StackOpenHPC: A Comprehensive System Software Stack
OpenHPC: A Comprehensive System Software Stackinside-BigData.com
 
It just keeps getting better - SUSE enablement for Arm - Linaro HPC Workshop ...
It just keeps getting better - SUSE enablement for Arm - Linaro HPC Workshop ...It just keeps getting better - SUSE enablement for Arm - Linaro HPC Workshop ...
It just keeps getting better - SUSE enablement for Arm - Linaro HPC Workshop ...Linaro
 
Lenovo HPC: Energy Efficiency and Water-Cool-Technology Innovations
Lenovo HPC: Energy Efficiency and Water-Cool-Technology InnovationsLenovo HPC: Energy Efficiency and Water-Cool-Technology Innovations
Lenovo HPC: Energy Efficiency and Water-Cool-Technology Innovationsinside-BigData.com
 
NVIDIA GTC 2018: Enabling GPU-as-a-Service Providers with Red Hat OpenShift
NVIDIA GTC 2018:  Enabling GPU-as-a-Service Providers with Red Hat OpenShiftNVIDIA GTC 2018:  Enabling GPU-as-a-Service Providers with Red Hat OpenShift
NVIDIA GTC 2018: Enabling GPU-as-a-Service Providers with Red Hat OpenShiftJeremy Eder
 

La actualidad más candente (20)

Linux Containers and Docker SHARE.ORG Seattle 2015
Linux Containers and Docker SHARE.ORG Seattle 2015Linux Containers and Docker SHARE.ORG Seattle 2015
Linux Containers and Docker SHARE.ORG Seattle 2015
 
NVIDIA GTC 2019: Red Hat and the NVIDIA DGX: Tried, Tested, Trusted
NVIDIA GTC 2019:  Red Hat and the NVIDIA DGX: Tried, Tested, TrustedNVIDIA GTC 2019:  Red Hat and the NVIDIA DGX: Tried, Tested, Trusted
NVIDIA GTC 2019: Red Hat and the NVIDIA DGX: Tried, Tested, Trusted
 
Whats new in_juno_meetup_barcelona
Whats new in_juno_meetup_barcelonaWhats new in_juno_meetup_barcelona
Whats new in_juno_meetup_barcelona
 
IBM Systems Technical Symposium Melbourne, 2015
IBM Systems Technical Symposium Melbourne, 2015IBM Systems Technical Symposium Melbourne, 2015
IBM Systems Technical Symposium Melbourne, 2015
 
Rh436 pdf
Rh436 pdfRh436 pdf
Rh436 pdf
 
2011-03-15 Lockheed Martin Open Source Day
2011-03-15 Lockheed Martin Open Source Day2011-03-15 Lockheed Martin Open Source Day
2011-03-15 Lockheed Martin Open Source Day
 
Red Hat Enterprise Linux 7
Red Hat Enterprise Linux 7 Red Hat Enterprise Linux 7
Red Hat Enterprise Linux 7
 
The Real World with OpenShift - Red Hat DevOps & Microservices Conference 2017
The Real World with OpenShift - Red Hat DevOps & Microservices Conference 2017 The Real World with OpenShift - Red Hat DevOps & Microservices Conference 2017
The Real World with OpenShift - Red Hat DevOps & Microservices Conference 2017
 
SHARE.ORG Orlando 2015
SHARE.ORG Orlando 2015SHARE.ORG Orlando 2015
SHARE.ORG Orlando 2015
 
SPACK: A Package Manager for Supercomputers, Linux, and MacOS
SPACK: A Package Manager for Supercomputers, Linux, and MacOSSPACK: A Package Manager for Supercomputers, Linux, and MacOS
SPACK: A Package Manager for Supercomputers, Linux, and MacOS
 
Rhel8 Beta - Halifax RHUG
Rhel8 Beta - Halifax RHUGRhel8 Beta - Halifax RHUG
Rhel8 Beta - Halifax RHUG
 
Red Hat Summit 2018 5 New High Performance Features in OpenShift
Red Hat Summit 2018 5 New High Performance Features in OpenShiftRed Hat Summit 2018 5 New High Performance Features in OpenShift
Red Hat Summit 2018 5 New High Performance Features in OpenShift
 
Andrew J Younge - Vanguard Astra - Petascale Arm Platform for U.S. DOE/ASC Su...
Andrew J Younge - Vanguard Astra - Petascale Arm Platform for U.S. DOE/ASC Su...Andrew J Younge - Vanguard Astra - Petascale Arm Platform for U.S. DOE/ASC Su...
Andrew J Younge - Vanguard Astra - Petascale Arm Platform for U.S. DOE/ASC Su...
 
Red Hat Linux 5 Hardening Tips - National Security Agency
Red Hat Linux 5 Hardening Tips - National Security AgencyRed Hat Linux 5 Hardening Tips - National Security Agency
Red Hat Linux 5 Hardening Tips - National Security Agency
 
Presentation on HP ProLiant value add tools on Linux
Presentation on HP ProLiant value add tools on LinuxPresentation on HP ProLiant value add tools on Linux
Presentation on HP ProLiant value add tools on Linux
 
OpenHPC: A Comprehensive System Software Stack
OpenHPC: A Comprehensive System Software StackOpenHPC: A Comprehensive System Software Stack
OpenHPC: A Comprehensive System Software Stack
 
It just keeps getting better - SUSE enablement for Arm - Linaro HPC Workshop ...
It just keeps getting better - SUSE enablement for Arm - Linaro HPC Workshop ...It just keeps getting better - SUSE enablement for Arm - Linaro HPC Workshop ...
It just keeps getting better - SUSE enablement for Arm - Linaro HPC Workshop ...
 
Lenovo HPC: Energy Efficiency and Water-Cool-Technology Innovations
Lenovo HPC: Energy Efficiency and Water-Cool-Technology InnovationsLenovo HPC: Energy Efficiency and Water-Cool-Technology Innovations
Lenovo HPC: Energy Efficiency and Water-Cool-Technology Innovations
 
Lenovo HPC Strategy Update
Lenovo HPC Strategy UpdateLenovo HPC Strategy Update
Lenovo HPC Strategy Update
 
NVIDIA GTC 2018: Enabling GPU-as-a-Service Providers with Red Hat OpenShift
NVIDIA GTC 2018:  Enabling GPU-as-a-Service Providers with Red Hat OpenShiftNVIDIA GTC 2018:  Enabling GPU-as-a-Service Providers with Red Hat OpenShift
NVIDIA GTC 2018: Enabling GPU-as-a-Service Providers with Red Hat OpenShift
 

Destacado

Kempenfelt Gallery of Garage Doors 2
Kempenfelt Gallery of Garage Doors 2Kempenfelt Gallery of Garage Doors 2
Kempenfelt Gallery of Garage Doors 2Robert Maslen
 
Duvi honig (1)
Duvi honig (1)Duvi honig (1)
Duvi honig (1)Duvi Honig
 
El reinado de Alfonso XIII. 4º ESO
El reinado de Alfonso XIII. 4º ESOEl reinado de Alfonso XIII. 4º ESO
El reinado de Alfonso XIII. 4º ESOMencar Car
 
マイクロフレームワークEnkan(とKotowari)ではじめるREPL駆動開発
マイクロフレームワークEnkan(とKotowari)ではじめるREPL駆動開発マイクロフレームワークEnkan(とKotowari)ではじめるREPL駆動開発
マイクロフレームワークEnkan(とKotowari)ではじめるREPL駆動開発Yoshitaka Kawashima
 
Seasar conference 2015 sa-compojure
Seasar conference 2015 sa-compojureSeasar conference 2015 sa-compojure
Seasar conference 2015 sa-compojureYoshitaka Kawashima
 
โภชนาการสุภาพร
โภชนาการสุภาพรโภชนาการสุภาพร
โภชนาการสุภาพรtassanee chaicharoen
 
Clustering customer data dr sankar rajagopal
Clustering customer data   dr sankar rajagopalClustering customer data   dr sankar rajagopal
Clustering customer data dr sankar rajagopalDr.Sankar Rajagopal
 
IN ESTAMUL
IN ESTAMULIN ESTAMUL
IN ESTAMULcprgraus
 
Mystery at sea
Mystery at seaMystery at sea
Mystery at seacprgraus
 
Оцінка умов праці українців
Оцінка умов праці українцівОцінка умов праці українців
Оцінка умов праці українцівRatinggroup
 

Destacado (17)

English project
English projectEnglish project
English project
 
Lacydes moreno blanco
Lacydes moreno blancoLacydes moreno blanco
Lacydes moreno blanco
 
Kempenfelt Gallery of Garage Doors 2
Kempenfelt Gallery of Garage Doors 2Kempenfelt Gallery of Garage Doors 2
Kempenfelt Gallery of Garage Doors 2
 
Duvi honig (1)
Duvi honig (1)Duvi honig (1)
Duvi honig (1)
 
Ministerio de Salud como autoridad Sanitaria
Ministerio de Salud como autoridad SanitariaMinisterio de Salud como autoridad Sanitaria
Ministerio de Salud como autoridad Sanitaria
 
Intoxicaciones generacion 28 2010
Intoxicaciones generacion 28 2010Intoxicaciones generacion 28 2010
Intoxicaciones generacion 28 2010
 
El reinado de Alfonso XIII. 4º ESO
El reinado de Alfonso XIII. 4º ESOEl reinado de Alfonso XIII. 4º ESO
El reinado de Alfonso XIII. 4º ESO
 
マイクロフレームワークEnkan(とKotowari)ではじめるREPL駆動開発
マイクロフレームワークEnkan(とKotowari)ではじめるREPL駆動開発マイクロフレームワークEnkan(とKotowari)ではじめるREPL駆動開発
マイクロフレームワークEnkan(とKotowari)ではじめるREPL駆動開発
 
Seasar conference 2015 sa-compojure
Seasar conference 2015 sa-compojureSeasar conference 2015 sa-compojure
Seasar conference 2015 sa-compojure
 
Semiologia Geral
Semiologia GeralSemiologia Geral
Semiologia Geral
 
โภชนาการสุภาพร
โภชนาการสุภาพรโภชนาการสุภาพร
โภชนาการสุภาพร
 
Clustering customer data dr sankar rajagopal
Clustering customer data   dr sankar rajagopalClustering customer data   dr sankar rajagopal
Clustering customer data dr sankar rajagopal
 
IN ESTAMUL
IN ESTAMULIN ESTAMUL
IN ESTAMUL
 
Mystery at sea
Mystery at seaMystery at sea
Mystery at sea
 
Media comm essay
Media comm essayMedia comm essay
Media comm essay
 
Оцінка умов праці українців
Оцінка умов праці українцівОцінка умов праці українців
Оцінка умов праці українців
 
Presentación proyecto
Presentación proyectoPresentación proyecto
Presentación proyecto
 

Similar a 2010-11-08 NSA Technical Symposium

OpenStack Benelux Conference 2014 | Plenair | RedHat
OpenStack Benelux Conference 2014 | Plenair | RedHatOpenStack Benelux Conference 2014 | Plenair | RedHat
OpenStack Benelux Conference 2014 | Plenair | RedHatGuston Remie
 
[OpenStack Days Korea 2016] Track1 - Red Hat enterprise Linux OpenStack Platform
[OpenStack Days Korea 2016] Track1 - Red Hat enterprise Linux OpenStack Platform[OpenStack Days Korea 2016] Track1 - Red Hat enterprise Linux OpenStack Platform
[OpenStack Days Korea 2016] Track1 - Red Hat enterprise Linux OpenStack PlatformOpenStack Korea Community
 
2011-11-03 Intelligence Community Cloud Users Group
2011-11-03 Intelligence Community Cloud Users Group2011-11-03 Intelligence Community Cloud Users Group
2011-11-03 Intelligence Community Cloud Users GroupShawn Wells
 
2010-01-28 NSA Open Source User Group Meeting, Current & Future Linux on Syst...
2010-01-28 NSA Open Source User Group Meeting, Current & Future Linux on Syst...2010-01-28 NSA Open Source User Group Meeting, Current & Future Linux on Syst...
2010-01-28 NSA Open Source User Group Meeting, Current & Future Linux on Syst...Shawn Wells
 
Red Hat Enterprise Linux 8
Red Hat Enterprise Linux 8Red Hat Enterprise Linux 8
Red Hat Enterprise Linux 8Kangaroot
 
Red Hat Enterprise Linux 8 Technical overview v1(1).pdf
Red Hat Enterprise Linux 8 Technical overview v1(1).pdfRed Hat Enterprise Linux 8 Technical overview v1(1).pdf
Red Hat Enterprise Linux 8 Technical overview v1(1).pdfSimonCoter2
 
Red_Hat_on_Power-IBM_Systems_Summit_2015-Miguel_Perez
Red_Hat_on_Power-IBM_Systems_Summit_2015-Miguel_PerezRed_Hat_on_Power-IBM_Systems_Summit_2015-Miguel_Perez
Red_Hat_on_Power-IBM_Systems_Summit_2015-Miguel_PerezMiguel Pérez Colino
 
Red Hat Enterprise Linux 8 Workshop
Red Hat Enterprise Linux 8 WorkshopRed Hat Enterprise Linux 8 Workshop
Red Hat Enterprise Linux 8 WorkshopAhmed El-Rayess
 
Red hat on_power-ibm _lop_day_2015
Red hat on_power-ibm _lop_day_2015Red hat on_power-ibm _lop_day_2015
Red hat on_power-ibm _lop_day_2015cmilsted
 
Red Hat for IBM System z Update v5
Red Hat for IBM System z Update v5Red Hat for IBM System z Update v5
Red Hat for IBM System z Update v5Filipe Miranda
 
Ent11+ +Red+Hat+Enterprise+Mrg
Ent11+ +Red+Hat+Enterprise+MrgEnt11+ +Red+Hat+Enterprise+Mrg
Ent11+ +Red+Hat+Enterprise+MrgabcKia
 
Ent11+ +Red+Hat+Enterprise+Mrg
Ent11+ +Red+Hat+Enterprise+MrgEnt11+ +Red+Hat+Enterprise+Mrg
Ent11+ +Red+Hat+Enterprise+MrgabcKia
 
Ent11+ +Red+Hat+Enterprise+Mrg
Ent11+ +Red+Hat+Enterprise+MrgEnt11+ +Red+Hat+Enterprise+Mrg
Ent11+ +Red+Hat+Enterprise+MrgabcKia
 
Red Hat multi-cluster management & what's new in OpenShift
Red Hat multi-cluster management & what's new in OpenShiftRed Hat multi-cluster management & what's new in OpenShift
Red Hat multi-cluster management & what's new in OpenShiftKangaroot
 
The Next Generation Datacenter
The Next Generation DatacenterThe Next Generation Datacenter
The Next Generation DatacenterRed Hat Events
 
Open Hybrid Cloud - Erik Geensen
Open Hybrid Cloud - Erik GeensenOpen Hybrid Cloud - Erik Geensen
Open Hybrid Cloud - Erik GeensenKangaroot
 
Openstack Benelux Conference 2014 Red Hat Keynote
Openstack Benelux Conference 2014  Red Hat KeynoteOpenstack Benelux Conference 2014  Red Hat Keynote
Openstack Benelux Conference 2014 Red Hat KeynoteMicrosoft
 

Similar a 2010-11-08 NSA Technical Symposium (20)

RHEL roadmap
RHEL roadmapRHEL roadmap
RHEL roadmap
 
OpenStack Benelux Conference 2014 | Plenair | RedHat
OpenStack Benelux Conference 2014 | Plenair | RedHatOpenStack Benelux Conference 2014 | Plenair | RedHat
OpenStack Benelux Conference 2014 | Plenair | RedHat
 
[OpenStack Days Korea 2016] Track1 - Red Hat enterprise Linux OpenStack Platform
[OpenStack Days Korea 2016] Track1 - Red Hat enterprise Linux OpenStack Platform[OpenStack Days Korea 2016] Track1 - Red Hat enterprise Linux OpenStack Platform
[OpenStack Days Korea 2016] Track1 - Red Hat enterprise Linux OpenStack Platform
 
2011-11-03 Intelligence Community Cloud Users Group
2011-11-03 Intelligence Community Cloud Users Group2011-11-03 Intelligence Community Cloud Users Group
2011-11-03 Intelligence Community Cloud Users Group
 
tburke_rhel6_summit.pdf
tburke_rhel6_summit.pdftburke_rhel6_summit.pdf
tburke_rhel6_summit.pdf
 
2010-01-28 NSA Open Source User Group Meeting, Current & Future Linux on Syst...
2010-01-28 NSA Open Source User Group Meeting, Current & Future Linux on Syst...2010-01-28 NSA Open Source User Group Meeting, Current & Future Linux on Syst...
2010-01-28 NSA Open Source User Group Meeting, Current & Future Linux on Syst...
 
Red Hat Enterprise Linux 8
Red Hat Enterprise Linux 8Red Hat Enterprise Linux 8
Red Hat Enterprise Linux 8
 
Red Hat Enterprise Linux 8 Technical overview v1(1).pdf
Red Hat Enterprise Linux 8 Technical overview v1(1).pdfRed Hat Enterprise Linux 8 Technical overview v1(1).pdf
Red Hat Enterprise Linux 8 Technical overview v1(1).pdf
 
Red_Hat_on_Power-IBM_Systems_Summit_2015-Miguel_Perez
Red_Hat_on_Power-IBM_Systems_Summit_2015-Miguel_PerezRed_Hat_on_Power-IBM_Systems_Summit_2015-Miguel_Perez
Red_Hat_on_Power-IBM_Systems_Summit_2015-Miguel_Perez
 
Red Hat Enterprise Linux 8 Workshop
Red Hat Enterprise Linux 8 WorkshopRed Hat Enterprise Linux 8 Workshop
Red Hat Enterprise Linux 8 Workshop
 
Red hat on_power-ibm _lop_day_2015
Red hat on_power-ibm _lop_day_2015Red hat on_power-ibm _lop_day_2015
Red hat on_power-ibm _lop_day_2015
 
Red Hat for IBM System z Update v5
Red Hat for IBM System z Update v5Red Hat for IBM System z Update v5
Red Hat for IBM System z Update v5
 
Resume
ResumeResume
Resume
 
Ent11+ +Red+Hat+Enterprise+Mrg
Ent11+ +Red+Hat+Enterprise+MrgEnt11+ +Red+Hat+Enterprise+Mrg
Ent11+ +Red+Hat+Enterprise+Mrg
 
Ent11+ +Red+Hat+Enterprise+Mrg
Ent11+ +Red+Hat+Enterprise+MrgEnt11+ +Red+Hat+Enterprise+Mrg
Ent11+ +Red+Hat+Enterprise+Mrg
 
Ent11+ +Red+Hat+Enterprise+Mrg
Ent11+ +Red+Hat+Enterprise+MrgEnt11+ +Red+Hat+Enterprise+Mrg
Ent11+ +Red+Hat+Enterprise+Mrg
 
Red Hat multi-cluster management & what's new in OpenShift
Red Hat multi-cluster management & what's new in OpenShiftRed Hat multi-cluster management & what's new in OpenShift
Red Hat multi-cluster management & what's new in OpenShift
 
The Next Generation Datacenter
The Next Generation DatacenterThe Next Generation Datacenter
The Next Generation Datacenter
 
Open Hybrid Cloud - Erik Geensen
Open Hybrid Cloud - Erik GeensenOpen Hybrid Cloud - Erik Geensen
Open Hybrid Cloud - Erik Geensen
 
Openstack Benelux Conference 2014 Red Hat Keynote
Openstack Benelux Conference 2014  Red Hat KeynoteOpenstack Benelux Conference 2014  Red Hat Keynote
Openstack Benelux Conference 2014 Red Hat Keynote
 

Más de Shawn Wells

2017-10-10 AUSA 2017: Repeatable DCO Platforms
2017-10-10 AUSA 2017: Repeatable DCO Platforms2017-10-10 AUSA 2017: Repeatable DCO Platforms
2017-10-10 AUSA 2017: Repeatable DCO PlatformsShawn Wells
 
2017-07-12 GovLoop: New Era of Digital Security
2017-07-12 GovLoop: New Era of Digital Security2017-07-12 GovLoop: New Era of Digital Security
2017-07-12 GovLoop: New Era of Digital SecurityShawn Wells
 
2017-07-11 GovLoop: Changing the Open Hybrid Cloud Game (Deploying OpenShift ...
2017-07-11 GovLoop: Changing the Open Hybrid Cloud Game (Deploying OpenShift ...2017-07-11 GovLoop: Changing the Open Hybrid Cloud Game (Deploying OpenShift ...
2017-07-11 GovLoop: Changing the Open Hybrid Cloud Game (Deploying OpenShift ...Shawn Wells
 
2017 02-17 rsac 2017 tech-f02
2017 02-17 rsac 2017 tech-f022017 02-17 rsac 2017 tech-f02
2017 02-17 rsac 2017 tech-f02Shawn Wells
 
2017-02-21 AFCEA West Building Continuous Integration & Deployment (CI/CD) Pi...
2017-02-21 AFCEA West Building Continuous Integration & Deployment (CI/CD) Pi...2017-02-21 AFCEA West Building Continuous Integration & Deployment (CI/CD) Pi...
2017-02-21 AFCEA West Building Continuous Integration & Deployment (CI/CD) Pi...Shawn Wells
 
2016 -11-18 OpenSCAP Workshop Coursebook
2016 -11-18 OpenSCAP Workshop Coursebook2016 -11-18 OpenSCAP Workshop Coursebook
2016 -11-18 OpenSCAP Workshop CoursebookShawn Wells
 
2016-08-29 AFITC Security Automation
2016-08-29 AFITC Security Automation2016-08-29 AFITC Security Automation
2016-08-29 AFITC Security AutomationShawn Wells
 
2016-08-24 FedInsider Webinar with Jennifer Kron - Securing Intelligence in a...
2016-08-24 FedInsider Webinar with Jennifer Kron - Securing Intelligence in a...2016-08-24 FedInsider Webinar with Jennifer Kron - Securing Intelligence in a...
2016-08-24 FedInsider Webinar with Jennifer Kron - Securing Intelligence in a...Shawn Wells
 
2016-08-18 Red Hat Partner Security Update
2016-08-18 Red Hat Partner Security Update2016-08-18 Red Hat Partner Security Update
2016-08-18 Red Hat Partner Security UpdateShawn Wells
 
2015-11-15 - Supercomputing 2015 - Applied Cross Domain
2015-11-15 - Supercomputing 2015 - Applied Cross Domain2015-11-15 - Supercomputing 2015 - Applied Cross Domain
2015-11-15 - Supercomputing 2015 - Applied Cross DomainShawn Wells
 
2015-10-05 Fermilabs DevOps Alone in the Dark
2015-10-05 Fermilabs DevOps Alone in the Dark2015-10-05 Fermilabs DevOps Alone in the Dark
2015-10-05 Fermilabs DevOps Alone in the DarkShawn Wells
 
2015-06-25 Red Hat Summit 2015 - Security Compliance Made Easy
2015-06-25 Red Hat Summit 2015 - Security Compliance Made Easy2015-06-25 Red Hat Summit 2015 - Security Compliance Made Easy
2015-06-25 Red Hat Summit 2015 - Security Compliance Made EasyShawn Wells
 
2015 06-12 DevOpsDC 2015 - Consumer to Collaborator
2015 06-12 DevOpsDC 2015 - Consumer to Collaborator2015 06-12 DevOpsDC 2015 - Consumer to Collaborator
2015 06-12 DevOpsDC 2015 - Consumer to CollaboratorShawn Wells
 
2015-01-27 ssa opening remarks
2015-01-27 ssa opening remarks2015-01-27 ssa opening remarks
2015-01-27 ssa opening remarksShawn Wells
 
2014-12-16 defense news - shutdown the hackers
2014-12-16  defense news - shutdown the hackers2014-12-16  defense news - shutdown the hackers
2014-12-16 defense news - shutdown the hackersShawn Wells
 
2014-07-31 customer convergence applied scap
2014-07-31 customer convergence applied scap2014-07-31 customer convergence applied scap
2014-07-31 customer convergence applied scapShawn Wells
 
2014-07-30 defense in depth scap workbook
2014-07-30 defense in depth scap workbook2014-07-30 defense in depth scap workbook
2014-07-30 defense in depth scap workbookShawn Wells
 
2014-05-08 IT Craftsmanship to IT Manufacturing
2014-05-08 IT Craftsmanship to IT Manufacturing2014-05-08 IT Craftsmanship to IT Manufacturing
2014-05-08 IT Craftsmanship to IT ManufacturingShawn Wells
 
2014-04-28 cloud security frameworks and enforcement
2014-04-28 cloud security frameworks and enforcement2014-04-28 cloud security frameworks and enforcement
2014-04-28 cloud security frameworks and enforcementShawn Wells
 
2014 04-17 Applied SCAP, Red Hat Summit 2014
2014 04-17 Applied SCAP, Red Hat Summit 20142014 04-17 Applied SCAP, Red Hat Summit 2014
2014 04-17 Applied SCAP, Red Hat Summit 2014Shawn Wells
 

Más de Shawn Wells (20)

2017-10-10 AUSA 2017: Repeatable DCO Platforms
2017-10-10 AUSA 2017: Repeatable DCO Platforms2017-10-10 AUSA 2017: Repeatable DCO Platforms
2017-10-10 AUSA 2017: Repeatable DCO Platforms
 
2017-07-12 GovLoop: New Era of Digital Security
2017-07-12 GovLoop: New Era of Digital Security2017-07-12 GovLoop: New Era of Digital Security
2017-07-12 GovLoop: New Era of Digital Security
 
2017-07-11 GovLoop: Changing the Open Hybrid Cloud Game (Deploying OpenShift ...
2017-07-11 GovLoop: Changing the Open Hybrid Cloud Game (Deploying OpenShift ...2017-07-11 GovLoop: Changing the Open Hybrid Cloud Game (Deploying OpenShift ...
2017-07-11 GovLoop: Changing the Open Hybrid Cloud Game (Deploying OpenShift ...
 
2017 02-17 rsac 2017 tech-f02
2017 02-17 rsac 2017 tech-f022017 02-17 rsac 2017 tech-f02
2017 02-17 rsac 2017 tech-f02
 
2017-02-21 AFCEA West Building Continuous Integration & Deployment (CI/CD) Pi...
2017-02-21 AFCEA West Building Continuous Integration & Deployment (CI/CD) Pi...2017-02-21 AFCEA West Building Continuous Integration & Deployment (CI/CD) Pi...
2017-02-21 AFCEA West Building Continuous Integration & Deployment (CI/CD) Pi...
 
2016 -11-18 OpenSCAP Workshop Coursebook
2016 -11-18 OpenSCAP Workshop Coursebook2016 -11-18 OpenSCAP Workshop Coursebook
2016 -11-18 OpenSCAP Workshop Coursebook
 
2016-08-29 AFITC Security Automation
2016-08-29 AFITC Security Automation2016-08-29 AFITC Security Automation
2016-08-29 AFITC Security Automation
 
2016-08-24 FedInsider Webinar with Jennifer Kron - Securing Intelligence in a...
2016-08-24 FedInsider Webinar with Jennifer Kron - Securing Intelligence in a...2016-08-24 FedInsider Webinar with Jennifer Kron - Securing Intelligence in a...
2016-08-24 FedInsider Webinar with Jennifer Kron - Securing Intelligence in a...
 
2016-08-18 Red Hat Partner Security Update
2016-08-18 Red Hat Partner Security Update2016-08-18 Red Hat Partner Security Update
2016-08-18 Red Hat Partner Security Update
 
2015-11-15 - Supercomputing 2015 - Applied Cross Domain
2015-11-15 - Supercomputing 2015 - Applied Cross Domain2015-11-15 - Supercomputing 2015 - Applied Cross Domain
2015-11-15 - Supercomputing 2015 - Applied Cross Domain
 
2015-10-05 Fermilabs DevOps Alone in the Dark
2015-10-05 Fermilabs DevOps Alone in the Dark2015-10-05 Fermilabs DevOps Alone in the Dark
2015-10-05 Fermilabs DevOps Alone in the Dark
 
2015-06-25 Red Hat Summit 2015 - Security Compliance Made Easy
2015-06-25 Red Hat Summit 2015 - Security Compliance Made Easy2015-06-25 Red Hat Summit 2015 - Security Compliance Made Easy
2015-06-25 Red Hat Summit 2015 - Security Compliance Made Easy
 
2015 06-12 DevOpsDC 2015 - Consumer to Collaborator
2015 06-12 DevOpsDC 2015 - Consumer to Collaborator2015 06-12 DevOpsDC 2015 - Consumer to Collaborator
2015 06-12 DevOpsDC 2015 - Consumer to Collaborator
 
2015-01-27 ssa opening remarks
2015-01-27 ssa opening remarks2015-01-27 ssa opening remarks
2015-01-27 ssa opening remarks
 
2014-12-16 defense news - shutdown the hackers
2014-12-16  defense news - shutdown the hackers2014-12-16  defense news - shutdown the hackers
2014-12-16 defense news - shutdown the hackers
 
2014-07-31 customer convergence applied scap
2014-07-31 customer convergence applied scap2014-07-31 customer convergence applied scap
2014-07-31 customer convergence applied scap
 
2014-07-30 defense in depth scap workbook
2014-07-30 defense in depth scap workbook2014-07-30 defense in depth scap workbook
2014-07-30 defense in depth scap workbook
 
2014-05-08 IT Craftsmanship to IT Manufacturing
2014-05-08 IT Craftsmanship to IT Manufacturing2014-05-08 IT Craftsmanship to IT Manufacturing
2014-05-08 IT Craftsmanship to IT Manufacturing
 
2014-04-28 cloud security frameworks and enforcement
2014-04-28 cloud security frameworks and enforcement2014-04-28 cloud security frameworks and enforcement
2014-04-28 cloud security frameworks and enforcement
 
2014 04-17 Applied SCAP, Red Hat Summit 2014
2014 04-17 Applied SCAP, Red Hat Summit 20142014 04-17 Applied SCAP, Red Hat Summit 2014
2014 04-17 Applied SCAP, Red Hat Summit 2014
 

Último

The Real-World Challenges of Medical Device Cybersecurity- Mitigating Vulnera...
The Real-World Challenges of Medical Device Cybersecurity- Mitigating Vulnera...The Real-World Challenges of Medical Device Cybersecurity- Mitigating Vulnera...
The Real-World Challenges of Medical Device Cybersecurity- Mitigating Vulnera...ICS
 
W01_panagenda_Navigating-the-Future-with-The-Hitchhikers-Guide-to-Notes-and-D...
W01_panagenda_Navigating-the-Future-with-The-Hitchhikers-Guide-to-Notes-and-D...W01_panagenda_Navigating-the-Future-with-The-Hitchhikers-Guide-to-Notes-and-D...
W01_panagenda_Navigating-the-Future-with-The-Hitchhikers-Guide-to-Notes-and-D...panagenda
 
Short Story: Unveiling the Reasoning Abilities of Large Language Models by Ke...
Short Story: Unveiling the Reasoning Abilities of Large Language Models by Ke...Short Story: Unveiling the Reasoning Abilities of Large Language Models by Ke...
Short Story: Unveiling the Reasoning Abilities of Large Language Models by Ke...kellynguyen01
 
Tech Tuesday-Harness the Power of Effective Resource Planning with OnePlan’s ...
Tech Tuesday-Harness the Power of Effective Resource Planning with OnePlan’s ...Tech Tuesday-Harness the Power of Effective Resource Planning with OnePlan’s ...
Tech Tuesday-Harness the Power of Effective Resource Planning with OnePlan’s ...OnePlan Solutions
 
Unveiling the Tech Salsa of LAMs with Janus in Real-Time Applications
Unveiling the Tech Salsa of LAMs with Janus in Real-Time ApplicationsUnveiling the Tech Salsa of LAMs with Janus in Real-Time Applications
Unveiling the Tech Salsa of LAMs with Janus in Real-Time ApplicationsAlberto González Trastoy
 
Steps To Getting Up And Running Quickly With MyTimeClock Employee Scheduling ...
Steps To Getting Up And Running Quickly With MyTimeClock Employee Scheduling ...Steps To Getting Up And Running Quickly With MyTimeClock Employee Scheduling ...
Steps To Getting Up And Running Quickly With MyTimeClock Employee Scheduling ...MyIntelliSource, Inc.
 
Diamond Application Development Crafting Solutions with Precision
Diamond Application Development Crafting Solutions with PrecisionDiamond Application Development Crafting Solutions with Precision
Diamond Application Development Crafting Solutions with PrecisionSolGuruz
 
CALL ON ➥8923113531 🔝Call Girls Kakori Lucknow best sexual service Online ☂️
CALL ON ➥8923113531 🔝Call Girls Kakori Lucknow best sexual service Online  ☂️CALL ON ➥8923113531 🔝Call Girls Kakori Lucknow best sexual service Online  ☂️
CALL ON ➥8923113531 🔝Call Girls Kakori Lucknow best sexual service Online ☂️anilsa9823
 
Salesforce Certified Field Service Consultant
Salesforce Certified Field Service ConsultantSalesforce Certified Field Service Consultant
Salesforce Certified Field Service ConsultantAxelRicardoTrocheRiq
 
SyndBuddy AI 2k Review 2024: Revolutionizing Content Syndication with AI
SyndBuddy AI 2k Review 2024: Revolutionizing Content Syndication with AISyndBuddy AI 2k Review 2024: Revolutionizing Content Syndication with AI
SyndBuddy AI 2k Review 2024: Revolutionizing Content Syndication with AIABDERRAOUF MEHENNI
 
why an Opensea Clone Script might be your perfect match.pdf
why an Opensea Clone Script might be your perfect match.pdfwhy an Opensea Clone Script might be your perfect match.pdf
why an Opensea Clone Script might be your perfect match.pdfjoe51371421
 
Advancing Engineering with AI through the Next Generation of Strategic Projec...
Advancing Engineering with AI through the Next Generation of Strategic Projec...Advancing Engineering with AI through the Next Generation of Strategic Projec...
Advancing Engineering with AI through the Next Generation of Strategic Projec...OnePlan Solutions
 
HR Software Buyers Guide in 2024 - HRSoftware.com
HR Software Buyers Guide in 2024 - HRSoftware.comHR Software Buyers Guide in 2024 - HRSoftware.com
HR Software Buyers Guide in 2024 - HRSoftware.comFatema Valibhai
 
Test Automation Strategy for Frontend and Backend
Test Automation Strategy for Frontend and BackendTest Automation Strategy for Frontend and Backend
Test Automation Strategy for Frontend and BackendArshad QA
 
Reassessing the Bedrock of Clinical Function Models: An Examination of Large ...
Reassessing the Bedrock of Clinical Function Models: An Examination of Large ...Reassessing the Bedrock of Clinical Function Models: An Examination of Large ...
Reassessing the Bedrock of Clinical Function Models: An Examination of Large ...harshavardhanraghave
 
(Genuine) Escort Service Lucknow | Starting ₹,5K To @25k with A/C 🧑🏽‍❤️‍🧑🏻 89...
(Genuine) Escort Service Lucknow | Starting ₹,5K To @25k with A/C 🧑🏽‍❤️‍🧑🏻 89...(Genuine) Escort Service Lucknow | Starting ₹,5K To @25k with A/C 🧑🏽‍❤️‍🧑🏻 89...
(Genuine) Escort Service Lucknow | Starting ₹,5K To @25k with A/C 🧑🏽‍❤️‍🧑🏻 89...gurkirankumar98700
 
Learn the Fundamentals of XCUITest Framework_ A Beginner's Guide.pdf
Learn the Fundamentals of XCUITest Framework_ A Beginner's Guide.pdfLearn the Fundamentals of XCUITest Framework_ A Beginner's Guide.pdf
Learn the Fundamentals of XCUITest Framework_ A Beginner's Guide.pdfkalichargn70th171
 

Último (20)

The Real-World Challenges of Medical Device Cybersecurity- Mitigating Vulnera...
The Real-World Challenges of Medical Device Cybersecurity- Mitigating Vulnera...The Real-World Challenges of Medical Device Cybersecurity- Mitigating Vulnera...
The Real-World Challenges of Medical Device Cybersecurity- Mitigating Vulnera...
 
W01_panagenda_Navigating-the-Future-with-The-Hitchhikers-Guide-to-Notes-and-D...
W01_panagenda_Navigating-the-Future-with-The-Hitchhikers-Guide-to-Notes-and-D...W01_panagenda_Navigating-the-Future-with-The-Hitchhikers-Guide-to-Notes-and-D...
W01_panagenda_Navigating-the-Future-with-The-Hitchhikers-Guide-to-Notes-and-D...
 
CHEAP Call Girls in Pushp Vihar (-DELHI )🔝 9953056974🔝(=)/CALL GIRLS SERVICE
CHEAP Call Girls in Pushp Vihar (-DELHI )🔝 9953056974🔝(=)/CALL GIRLS SERVICECHEAP Call Girls in Pushp Vihar (-DELHI )🔝 9953056974🔝(=)/CALL GIRLS SERVICE
CHEAP Call Girls in Pushp Vihar (-DELHI )🔝 9953056974🔝(=)/CALL GIRLS SERVICE
 
Short Story: Unveiling the Reasoning Abilities of Large Language Models by Ke...
Short Story: Unveiling the Reasoning Abilities of Large Language Models by Ke...Short Story: Unveiling the Reasoning Abilities of Large Language Models by Ke...
Short Story: Unveiling the Reasoning Abilities of Large Language Models by Ke...
 
Tech Tuesday-Harness the Power of Effective Resource Planning with OnePlan’s ...
Tech Tuesday-Harness the Power of Effective Resource Planning with OnePlan’s ...Tech Tuesday-Harness the Power of Effective Resource Planning with OnePlan’s ...
Tech Tuesday-Harness the Power of Effective Resource Planning with OnePlan’s ...
 
Unveiling the Tech Salsa of LAMs with Janus in Real-Time Applications
Unveiling the Tech Salsa of LAMs with Janus in Real-Time ApplicationsUnveiling the Tech Salsa of LAMs with Janus in Real-Time Applications
Unveiling the Tech Salsa of LAMs with Janus in Real-Time Applications
 
Steps To Getting Up And Running Quickly With MyTimeClock Employee Scheduling ...
Steps To Getting Up And Running Quickly With MyTimeClock Employee Scheduling ...Steps To Getting Up And Running Quickly With MyTimeClock Employee Scheduling ...
Steps To Getting Up And Running Quickly With MyTimeClock Employee Scheduling ...
 
Diamond Application Development Crafting Solutions with Precision
Diamond Application Development Crafting Solutions with PrecisionDiamond Application Development Crafting Solutions with Precision
Diamond Application Development Crafting Solutions with Precision
 
CALL ON ➥8923113531 🔝Call Girls Kakori Lucknow best sexual service Online ☂️
CALL ON ➥8923113531 🔝Call Girls Kakori Lucknow best sexual service Online  ☂️CALL ON ➥8923113531 🔝Call Girls Kakori Lucknow best sexual service Online  ☂️
CALL ON ➥8923113531 🔝Call Girls Kakori Lucknow best sexual service Online ☂️
 
Salesforce Certified Field Service Consultant
Salesforce Certified Field Service ConsultantSalesforce Certified Field Service Consultant
Salesforce Certified Field Service Consultant
 
Exploring iOS App Development: Simplifying the Process
Exploring iOS App Development: Simplifying the ProcessExploring iOS App Development: Simplifying the Process
Exploring iOS App Development: Simplifying the Process
 
SyndBuddy AI 2k Review 2024: Revolutionizing Content Syndication with AI
SyndBuddy AI 2k Review 2024: Revolutionizing Content Syndication with AISyndBuddy AI 2k Review 2024: Revolutionizing Content Syndication with AI
SyndBuddy AI 2k Review 2024: Revolutionizing Content Syndication with AI
 
why an Opensea Clone Script might be your perfect match.pdf
why an Opensea Clone Script might be your perfect match.pdfwhy an Opensea Clone Script might be your perfect match.pdf
why an Opensea Clone Script might be your perfect match.pdf
 
Advancing Engineering with AI through the Next Generation of Strategic Projec...
Advancing Engineering with AI through the Next Generation of Strategic Projec...Advancing Engineering with AI through the Next Generation of Strategic Projec...
Advancing Engineering with AI through the Next Generation of Strategic Projec...
 
HR Software Buyers Guide in 2024 - HRSoftware.com
HR Software Buyers Guide in 2024 - HRSoftware.comHR Software Buyers Guide in 2024 - HRSoftware.com
HR Software Buyers Guide in 2024 - HRSoftware.com
 
Test Automation Strategy for Frontend and Backend
Test Automation Strategy for Frontend and BackendTest Automation Strategy for Frontend and Backend
Test Automation Strategy for Frontend and Backend
 
Reassessing the Bedrock of Clinical Function Models: An Examination of Large ...
Reassessing the Bedrock of Clinical Function Models: An Examination of Large ...Reassessing the Bedrock of Clinical Function Models: An Examination of Large ...
Reassessing the Bedrock of Clinical Function Models: An Examination of Large ...
 
Call Girls In Mukherjee Nagar 📱 9999965857 🤩 Delhi 🫦 HOT AND SEXY VVIP 🍎 SE...
Call Girls In Mukherjee Nagar 📱  9999965857  🤩 Delhi 🫦 HOT AND SEXY VVIP 🍎 SE...Call Girls In Mukherjee Nagar 📱  9999965857  🤩 Delhi 🫦 HOT AND SEXY VVIP 🍎 SE...
Call Girls In Mukherjee Nagar 📱 9999965857 🤩 Delhi 🫦 HOT AND SEXY VVIP 🍎 SE...
 
(Genuine) Escort Service Lucknow | Starting ₹,5K To @25k with A/C 🧑🏽‍❤️‍🧑🏻 89...
(Genuine) Escort Service Lucknow | Starting ₹,5K To @25k with A/C 🧑🏽‍❤️‍🧑🏻 89...(Genuine) Escort Service Lucknow | Starting ₹,5K To @25k with A/C 🧑🏽‍❤️‍🧑🏻 89...
(Genuine) Escort Service Lucknow | Starting ₹,5K To @25k with A/C 🧑🏽‍❤️‍🧑🏻 89...
 
Learn the Fundamentals of XCUITest Framework_ A Beginner's Guide.pdf
Learn the Fundamentals of XCUITest Framework_ A Beginner's Guide.pdfLearn the Fundamentals of XCUITest Framework_ A Beginner's Guide.pdf
Learn the Fundamentals of XCUITest Framework_ A Beginner's Guide.pdf
 

2010-11-08 NSA Technical Symposium

  • 1. RED HAT TECHNICAL SYMPOSIUM NSA R&E Symposium Center Monday November 8th , 2010 1300-1600
  • 2. 2 AGENDA 1:00-1:20 Software Central Opening Notes 1:20-2:20 Red Hat Enterprise Linux 6 Update 2:20-2:30 Break 2:30-3:30 Red Hat in the Virtualized Environment & Security 3:30-4:00 Q&A Panel w/ Red Hat Technologists
  • 3. RED HAT ENTERPRISE LINUX 6 UPDATE Shawn D. Wells Technical Director, Intelligence Programs sdw@redhat.com / 443-534-0130
  • 4. 4 RED HAT ENTERPRISE LINUX 6 UPDATE RHEL6 FOUNDATION FEATURES & THEMES ● Trusted data center platform Ideally positioned to provide non-disruptive path forward. ● Application and infrastructure performance, scalability and security Support for varied workloads and advanced hardware capabilities. ● Making IT agile across physical, virtual and Cloud The right operating system across any environment.
  • 5. 5 RED HAT ENTERPRISE LINUX 6 UPDATE RHEL6 FOUNDATION FEATURES & THEMES ● Improved manageability For large scale virtualization deployments, server & desktop. Samba enhancements for Windows active directory and file sharing ● Power management Efficiency for lower deployment costs, reduced carbon footprint for virt, bare metal, desktop. Hardware level as well as dynamic system service startup and suspend. ● RAS (Reliability, Availability, Serviceability) Hotplug, memory error reporting, filesystem and data integrity. Support tools such as automated crash detection and bug reporting.
  • 6. 6 RED HAT ENTERPRISE LINUX 6 UPDATE RHEL6 FOUNDATION FEATURES & THEMES ● Hardware enablement and scalability Maximum efficiency, large configurations (cpu, memory, busses, I/O), NUMA awareness, new BIOS boot loader interface Supported architectures: x86, x86_64, PPC64, s390x
  • 7. 7 RED HAT ENTERPRISE LINUX 6 UPDATE SYSTEMS MANAGEMENT INTEGRATION ● Red Hat Network Satellite ● Install & provision new systems ● Update existing ● Manage configuration files & maintain over time ● Monitoring system metrics ● Multiple managed Satellites on ELA
  • 8. 8 RED HAT ENTERPRISE LINUX 6 UPDATE SYSTEMS MANAGEMENT INTEGRATION ● Red Hat Network Satellite 5.4 ● RPMs will be now be encrypted with 256-bit keys, up from 128-bit. ● Find & remove stale instances that are no longer being used ● Flex Guest / Floating Entitlements ● Centrally manage SELinux Context on remote files ● Expanded APIs for 3rd party integration
  • 9. 9 RED HAT ENTERPRISE LINUX 6 UPDATE SYSTEMS MANAGEMENT INTEGRATION ● Satellite Deployment Model MANAGED SYSTEMS WEB INTERFACE ●RHN Satellite • Software Distribution • Channel Management • Monitoring • Provisioning • RHEL subscription  management IT Applications API LAYER Custom Content
  • 10. 10 RED HAT ENTERPRISE LINUX 6 UPDATE SYSTEMS MANAGEMENT INTEGRATION ● Satellite Deployment Model: Single Satellite
  • 11. 11 RED HAT ENTERPRISE LINUX 6 UPDATE SYSTEMS MANAGEMENT INTEGRATION ● Satellite Deployment Model: Multi Tiered Satellite
  • 12. 12 RED HAT ENTERPRISE LINUX 6 UPDATE EFFICIENCY, SCALABILITY, RELIABILITY Red Hat Enterprise Linux 6 evolves in concert with hardware advances, reducing system power consumption, taking advantage of hardware with greater numbers of processing and memory resources, and withstanding hardware failures better.
  • 13. 13 RED HAT ENTERPRISE LINUX 6 UPDATE EFFICIENCY, SCALABILITY, RELIABILITY ● New scheduler (Completely Fair Scheduler) ● Dynamic addition of processor and memory ● More robust error reporting for PCIe devices (PCIe AER) ● Isolation of memory hardware failures with minimal downtime
  • 14. 14 RED HAT ENTERPRISE LINUX 6 UPDATE EFFICIENCY, SCALABILITY, RELIABILITY ● Mature file systems to cater to varied usage and performance characteristics. ● Ext4: Now default, scales to 16TB ● GFS2: Scales to 25TB ● XFS: Scales up to 100TB, tuned for storage arrays ● NFSv4 ● Configured to reduce chances of data corruption for low-end locally attached storage.
  • 15. 15 RED HAT ENTERPRISE LINUX 6 UPDATE EFFICIENCY, SCALABILITY, RELIABILITY ● Power management ● Tickless kernel ● User-space tools – powertop ● Dynamic throttling of power to devices ● Relatime drive optimization
  • 16. 16 RED HAT ENTERPRISE LINUX 6 UPDATE EFFICIENCY, SCALABILITY, RELIABILITY
  • 17. 17 RED HAT ENTERPRISE LINUX 6 UPDATE EFFICIENCY, SCALABILITY, RELIABILITY
  • 18. 18 RED HAT ENTERPRISE LINUX 6 UPDATE EFFICIENCY, SCALABILITY, RELIABILITY Objective: Providing scaling headroom anticipating many years of upcoming hardware generations. Tested and supported limits will likely grow over the course of product lifespan.
  • 19. 19 RED HAT ENTERPRISE LINUX 6 UPDATE EFICIENCY, SCALABILITY AND RELIABILITY ● Kernel scalability limits - x86_64 Parameter RHEL5 Supported Limit RHEL6 Supported Limit RHEL6 Theoretical Limit CPUs 64 128 4096 Memory – Physical addressing 1TB 2TB 64TB Memory – Process virtual address space (note – hardware dependent 2TB 128TB 128TB IRQs 293 33,024 33,024 # of processes 32,000 32,000 (larger pending testing) 4 million KVM guest memory 512GB 8TB 64TB KVM guest CPU 32 64 (pending testing) 64 (pending testing)
  • 20. 20 RED HAT ENTERPRISE LINUX 6 UPDATE EFICIENCY, SCALABILITY AND RELIABILITY ● File systems and storage limits - x86_64 Maximum filesize Maximum filesystem size EXT3 2TB 16TB EXT4 16TB 16TB GFS 16TB 16TB GFS2 25TB 25TB XFS 100TB 100TB
  • 21. 21 RED HAT ENTERPRISE LINUX 6 UPDATE DETERMINISM & REALTIME ENHANCEMENTS ● Some capabilities from Red Hat in MRG-realtime kernel (currently shipping as layered product) mainstreamed in RHEL6. ● Determinism – Ability to schedule priority tasks predictably and consistently ● Priority – Ensure highest priority applications are not blocked by lower priorities ● Timer – Microsecond precision not timer interrupt, ~millisecond precision
  • 22. 22 RED HAT ENTERPRISE LINUX 6 UPDATE STORAGE MANAGEMENT ● Topology awareness – I/O (alignment and chunk size) based on info from the storage device. This is in dm, LVM, md, and utilities such as parted and mkfs. Interfaces standardized to obtain alignment and optimal I/O stripe width. ● FcoE (fibre channel over ethernet) on specialized adapters (Emulex, Qlogic, Cisco), and on standard NICs. FcoE install & boot support with DCB. ● ISCSI root/boot, including target ● NPIV – n_Port ID Virtualization
  • 23. 23 RED HAT ENTERPRISE LINUX 6 UPDATE STORAGE MANAGEMENT: LVM/MD ● LVM hot spare; a disk or group of disks used to replace one failing ● Online resize or mirrored & multipath volumes ● Snapshot scalability enhancements for virtualization ● Multipath enhancements ● Dynamic multipath load balancing. Path selection based on queue depth, or I/O service time ● Mirroring enhancements ● Mirrored mirror log, avoids need for re-sync after failure ● Selectable hash algorithm for LUKS header, new cryptsetup commands, new libcryptsetup
  • 24. 24 SOFTWARE RELEASE VERSIONING & SUBSCRIPTIONS ● Red Hat Enterprise Linux Advanced Platform (RHEL AP) ● > 2 CPUs ● Includes Global File System (GFS), Red Hat Cluster Suite (RHCS) ● Red Hat Enterprise Linux Enterprise Server (RHEL ES) ● Less than 2 CPUs ● Does not include GFS & RHCS All servers, bare metal or virtual, must have an active Red Hat subscription.
  • 25. 25 SOFTWARE RELEASE VERSIONING & SUBSCRIPTIONS ● Production 1: Ongoing, active development of features and hardware enablement for inclusion into RHEL. ● Production 2: New software functionality is not available during this phase. The focus for minor releases during this life cycle phase lies on resolving defects with a minimum priority of high. ● Production 3: No new functionality, new hardware enablement or updated installation images are planned. Commonly known as “Maintenance Mode.”
  • 26. 26 SOFTWARE RELEASE VERSIONING & SUBSCRIPTIONS ● General Availability: March 14, 2007 ● End of Production 1 phase: Q4 of 2011 ● End of Production 2 phase: Q4 of 2012 ● End of Production 3 phase: March 31, 2014 ● End of Extended Life Cycle phase:March 31, 2017 Latest information available at: http://www.redhat.com/security/updates/errata/
  • 27. 27 CONSUMING NSA ENTERPRISE SUBSCRIPTIONS HOW & WHERE TO GET THE SOFTWARE ● Two on-site badged technical consultants at NBP1 ● Jeff Weatherford: jweatherford@redhat.com (u) 240-373-0842 ● Joe Glenn jglenn@redhat.com (u) 410-854-3104 Highside contact information on SearchLight or “go redhat”
  • 28. RED HAT IN THE VIRTUALIZED ENVIRONMENT Chris Runge Technical Director, U.S crunge@redhat.com / 703-748-2202
  • 29. 29 RED HAT VIRTUALIZATION EVOLUTION OF x86 VIRTUALIZATION
  • 30. 30 RED HAT IN THE VIRTUALIZED ENVIRONMENT KERNEL-BASED VIRTUAL MACHINE (KVM) Included in Linux kernel since 2006 Added to RHEL 5.4 and included in RHEL 6 ● Xen supported in RHEL 5 through 2014 Available on x86_64 architecture Requires Intel VT-X or AMD-V CPU capabilities
  • 31. 31 RED HAT IN THE VIRTUALIZED ENVIRONMENT KVM GUEST SUPPORT Runs Linux, Windows and other operating system guests RHEL guests supported on third-party hypervisors: ● Microsoft Hyper-V ● VMWare Microsoft certified drivers ensure compliance and support (WHQL and SVVP)
  • 32. 32 RED HAT IN THE VIRTUALIZED ENVIRONMENT KVM ADVANTAGES The OS is the hypervisor Same platform for bare-metal, virtualization, and cloud KVM is a Linux kernel module VM's run as Linux processes Simplifies certification KVM architecture provides high “feature-velocity”
  • 33. 33 RED HAT IN THE VIRTUALIZED ENVIRONMENT KVM FEATURE-VELOCITY: SCALABILITY Host cores Host memory Guest vCPUs Guest memory Hosts/ cluster Density vSphere 4 64 96 4,096 1 TB 64 TB 8 16 64 256 GB 1TB 32 100 200 320 500+ 2,000+ RHEL 5.4/5.5 RHEL 6 After ~7 yrs 1st 6 months 1st 12 months
  • 34. 34 RED HAT IN THE VIRTUALIZED ENVIRONMENT KVM ADVANCED FEATURES Kernel Same-Page Merging (KSM) Memory Page Sharing Securely shares identical memory pages between virtual machines
  • 35. 35 RED HAT IN THE VIRTUALIZED ENVIRONMENT KVM ADVANCED FEATURES Kernel Same- Page Merging (KSM) Enterprise Java workload benchmark Intel Xeon Processor X5550 with 24GB RAM Running multiple 3GB Windows 2003 VMs Scaling up to 200% over- commit
  • 36. 36 RED HAT IN THE VIRTUALIZED ENVIRONMENT KVM ADVANCED FEATURES Thin Provisioning Allocate storage only when needed Oversubscribe storage Transparent to VM Improve storage utilization Reduced storage costs Works with NFS, iSCSI, and FC
  • 37. 37 RED HAT IN THE VIRTUALIZED ENVIRONMENT VIRTUALIZATION IN RHEL 6 Increased scalability ● Guest/host CPU and memory ● Host: 4096 cores, 64 TB ● Guest: 64 vCPUs, 1 TB Increased performance ● Improved guest/host memory management ● Networking improvements ● Storage improvements Increased Security ● sVirt Migration Tools Available ● v2v – convert Xen VM's to KVM
  • 38. 38 PHASE 1: CONSOLIDATE VIRTUALIZE YOUR SERVERS Virtualize your physical hardware to achieve higher utilization, consolidation, and flexibility. Virtualization increases the utilization of physical servers and provides a foundation for cloud computing. Virtualization technology included in RHEL6. PHASE 2: AUTOMATE BUILD A PRIVATE CLOUD As you expand your use of virtualization, build a private cloud to manage the scale and complexity. A private cloud abstracts multiple instances of virtual resources into elastic pools of computation with self-provisioning and scalable services. PHASE 3: UTILITY ADD ADDITIONAL CLOUDS As you expand your use of cloud computing, add additional clouds delivered as a utility to increase capacity and lower costs. Red Hat's cloud architecture lets you manage and integrate various virtualization systems and cloud providers together. This allows you to leverage additional clouds as a utility. RED HAT IN THE VIRTUALIZED ENVIRONMENT FOUNDATION FOR THE CLOUD
  • 39. 39 RED HAT IN THE VIRTUALIZED ENVIRONMENT FOUNDATION FOR THE CLOUD: MANY COMPONENTS ALREADY IN NSA INFRASTRUCTURE
  • 40. RED HAT SECURITY UPDATE Gunnar Hellekson CTO, Red Hat Public Sector gunnar.hellekson@redhat.com / 202-507-9027
  • 41. 41 SECURITY SELINUX ● Confined users ● Role-based controls to limit system access for users. ● Sandbox ● Untrusted applications can be run confined to prevent compromising the entire system ● X Access Control Extension (XACE). ● SELinux Kiosk Mode ● Creation of a user session environment that is valid for a limited time.
  • 43. 43 SECURITY VIRTUALIZATION RHEV and KVM inherit the security features of Linux and RHEL SELinux security policy infrastructure Provides protection and isolation for virtual machines and host Compromised virtual machine cannot access other VMs or host sVirt Project Sub-project of NSA's SELinux community. Provides “hardened” hypervisors Multilevel security. Isolate guests Contain any guest breaches
  • 44. 44 SECURITY SCAP Access Requestor Policy Enforcement Point Policy Decision Point Internets Remediation Network SCAP, TPM SCAP and TNC Provides continuous lifecycle management for virtual machines and their hosts Compromised virtual machine can be quarantined Allows a provider's security SLA to be enforced by customers OpenSCAP An open source implementation of SCAP Included in RHEL 6
  • 45. 45 SECURITY COMMON CRITERIA UPDATE RHEL 5.6 ● Refreshed to include KVM ● Custom protection profile RHEL 6 ● Will include sVirt, IPSec ● Targeting EAL 4 ● Again, custom protection profile