Rocky Linux or RLC Pro Hardened: what CISA's OSS guidance means for your kernel

Rocky Linux or RLC Pro Hardened: what CISA's OSS guidance means for your kernel

Contributors

The CIQ Team

CISA's new Open Source Software: Security Principles and Practices guide gives federal agencies a clear set of expectations for open source software: assess it before adoption, understand who maintains it, track dependencies, patch quickly, and know when to move to a supported alternative. Rocky Linux, as a community distribution, is built around exactly that kind of transparency. RLC Pro Hardened takes that same foundation and adds a layer CISA's guidance gestures toward but leaves to each organization to build: active defense against kernel exploitation while a patch is still in progress.

Both are legitimate ways to run Enterprise Linux. The right one depends on what an organization is equipped to own.

What community Rocky Linux gives you

Rocky Linux is exactly what CISA's guidance describes as good practice made real. The source is fully open and independently reviewable. It's actively maintained by a global community, with no single vendor standing between an organization and the code. Patches move through the same transparent process CISA recommends agencies look for when they assess a project before adoption, and there's no licensing cost standing in the way of adoption at any scale.

The case for running community Rocky Linux:

  • Complete source transparency, reviewable by your own team on your own timeline.
  • No procurement cycle and no per-system licensing cost.
  • Full control over configuration, patch timing, and every layer of the stack.
  • A large, active community and upstream project with a strong track record of security response.

What it asks of the team running it:

  • Runtime kernel exploit detection isn't part of the base distribution. If an agency wants that capability, it has to be evaluated, integrated, and maintained separately.
  • Hardening to a framework like DISA STIG, CIS, or FIPS 140-3 is work the team scopes and executes itself, image by image.
  • Support runs through the community. Agencies with the in-house Linux and security expertise to resolve issues independently do well here. Agencies that need a vendor to call do not have that option on the community path.

For a team with strong kernel and security engineering depth and the bandwidth to own that work, community Rocky Linux is a complete, sound foundation, and it's the same foundation everything else CIQ builds sits on top of. NASA's Flight Sciences Lab runs its most demanding missions, including support for Artemis II, on Rocky Linux and RLC Pro, and its team's experience is a good illustration of what that support relationship looks like in practice.

What RLC Pro Hardened adds

RLC Pro Hardened starts from Rocky Linux and adds the layer of active, runtime defense that a base distribution doesn't carry. It ships with Linux Kernel Runtime Guard (LKRG) enabled and configured by default, the only Enterprise Linux distribution to do so. LKRG continuously validates kernel integrity and process credentials and flags the behavior patterns real kernel exploits rely on, rather than waiting for a signature or a patch. It was built by Adam "pi3" Zabrocki and is co-maintained by Alexander Peslyak (Solar Designer), founder of Openwall, whose exploit research LKRG's detection is built to counter. Independent academic testing, including a University of Oulu thesis benchmarking five Linux rootkit detection tools, rated it the most effective of the group, and it has caught the real exploitation techniques behind public proof-of-concept exploits for CVEs including CVE-2024-1086 and CVE-2021-3490.

RLC Pro Hardened pairs that with a broader hardening baseline: glibc hardening that strips unsafe environment variables across privilege boundaries, OpenSSH hardening that trims non-essential libraries, a hardened memory allocator, and cryptographically signed packages with an SBOM per image. It ships 95%+ DISA STIG and 99% CIS compliant at first boot, with FIPS 140-3 validated cryptography, and LKRG is signed into the UEFI Secure Boot chain with keys pre-installed on supported hardware.

The case for RLC Pro Hardened:

  • Active kernel exploit detection out of the box, covering the window between disclosure and patch that a base distribution leaves open.
  • A hardened, compliance-mapped baseline (DISA STIG, CIS, FIPS 140-3) at first boot instead of a manual build-out.
  • Vendor support behind every layer, including help interpreting what LKRG flags rather than triaging it alone.
  • Secure Boot signing handled as part of the image, not a separate integration project.

What it asks in return:

  • It's a commercial product, so it carries a licensing cost the community path doesn't.
  • Some configuration decisions are made as part of the pre-hardened baseline, trading a degree of granular control for a consistent, audited starting point.

Same foundation, different starting line

RLC Pro Hardened doesn't replace what the Rocky Linux community builds. It's built on it, and CIQ's engineering on LKRG and the broader hardening work is contributed back upstream where it can benefit the wider ecosystem. Choosing between the two isn't choosing between open source and something else. It's deciding whether an organization builds its own runtime defense and compliance baseline in-house, or gets one engineered, supported, and audit-ready from first boot.

CISA's guidance is right to ask agencies to assess software honestly before adopting it and to understand what support actually looks like once it's in production. That's the same question that decides which Rocky Linux is the right fit: does your team have the depth to build and own active kernel defense, or does that capacity belong somewhere else while your team focuses elsewhere?

Further reading

Subscribe to our newsletter

Related posts

2023 Holiday Gift Guide for Rocky Linux Users

2023 Holiday Gift Guide for Rocky Linux Users

6 Signs That It's Time to Move to Rocky Linux

6 Signs That It's Time to Move to Rocky Linux

A Deep Dive into Linux Kernel Runtime Guard (LKRG)

A Deep Dive into Linux Kernel Runtime Guard (LKRG)

AI infrastructure labor: What GPU setup really costs

AI infrastructure labor: What GPU setup really costs

Built for scale. Chosen by the world’s best.

2.75M+

Rocky Linux instances

Being used world wide

90%

Of fortune 100 companies

Use CIQ supported technologies

250k

Avg. monthly downloads

Rocky Linux

Have questions about your infrastructure?

Talk to a CIQ engineer about Rocky Linux, HPC, and AI infrastructure.

Talk to an Expert