Fedora Linux
Fedora is the current SHP platform with a public hardening and certification implementation described on this website.
Fedora certification is governed by the applicable SHP core and Fedora-specific specifications.
Certification is:
- device-bound
- state-bound
- specification-bound
- time-bounded
- derived from verification output
- issued only under SHP-controlled certification authority
No certification should be interpreted beyond the threat model, control scope, exclusions, and specification versions applicable at issuance.
Tier 1
The current public Fedora material focuses on Tier 1.
Tier 1 establishes a defined baseline under an explicit threat model. It is intended to reduce exposure to common and scalable attack classes without claiming resistance to every adversary or attack technique.
The threat model defines what Tier 1 considers, what it assumes, and what lies outside its certification boundary.
Read the Fedora Tier 1 Threat Model
Verification
Fedora controls are evaluated using structured verification rather than informal inspection alone.
Certification decisions must follow the applicable verification and certification rules. Non-Negotiable Controls cannot be bypassed by discretionary judgement.
Certification boundaries
Fedora certification does not mean:
- that compromise is impossible
- that certification remains valid after material state change
- that an expired certification remains active
- that controls from another platform can be assumed equivalent
- that independently running SHP verification tooling constitutes SHP certification
Services
Where an SHP service is publicly offered for a Fedora certification target, the service describes how the applicable standard is delivered.
The service does not redefine the standard.