Sign in
Categories
Your Saved List Become a Channel Partner Sell in AWS Marketplace Amazon Web Services Home Help

CIS Hardened Image STIG on Red Hat Enterprise Linux 8

Center for Internet Security | 2.0.0.7

Linux/Unix, Red Hat Enterprise Linux 8 - 64-bit Amazon Machine Image (AMI)

Reviews from AWS customer

56 AWS reviews

External reviews

246 reviews
from and

External reviews are not included in the AWS star rating for the product.


    Yogesh Maloo

Helps with security and patching

  • October 19, 2023
  • Review from a verified AWS customer

What is our primary use case?

Our use case for Red Hat Enterprise Linux is for production applications. 

How has it helped my organization?

We are a Managed Service Provider. Red Hat Enterprise Linux enables us not to be worried about vulnerabilities, security, and patching.

What is most valuable?

The most valuable features are the subscriptions and upgrades. 

What needs improvement?

We need to have more flexibility on the developed versions. Not everybody is ready to subscribe to enterprise versions. They would like to test the tool without subscriptions. 

Which solution did I use previously and why did I switch?

We chose Red Hat Enterprise Linux because of its security. 

What other advice do I have?

We use Red Hat Enterprise Linux with AWS. We started our practice with AWS, and most customers use it instead of GCP or Azure. We use the product in a hybrid environment, mostly when shifting the containers or existing workloads from legacy systems. 

Most of the customers use Red Hat Enterprise Linux because it is the only approved OS. The tool's knowledge base is good but is limited to subscriptions. 

The upgrade migration is straightforward. For the initial projects, we used to execute CLI scripts. We plan to upgrade the system if everything works well in the lower environment. 

I have used the image builder feature. I rate the overall product a nine out of ten. 

Which deployment model are you using for this solution?

Hybrid Cloud


    Edwin Reyes

Comes with an OpenShift feature

  • October 19, 2023
  • Review from a verified AWS customer

What is our primary use case?

We use Red Hat Enterprise Linux for VMs and physical servers. 

How has it helped my organization?

The containerized platform will help us use ROSA. 

What is most valuable?

The tool's most valuable feature is OpenShift. We plan to move all our applications to microservices. The container platform is integrated into one.

How are customer service and support?

I opened a few cases, and the tool's support responded quickly. 

How would you rate customer service and support?

Positive

How was the initial setup?

Deployment is simple if you have been using the solution for a long time. However, it can be complex if you are new to it. 

What other advice do I have?

We use RHEL 7 and RHEL 8 on on-premises. RHEL 8 is on the AWS. There is a security policy like CIS when deploying the solution. You can embed it on the image. I am not sure if there is HIPAA compliance yet. 

Migration from RHEL 8 to RHEL 9 is easy. Upgrade depends on the application that is running on each instance. You need to check if it is compatible with the kernel. We need to plan things before migrating to the latest version. We need to stay current to ensure compliance. We plan to move from RHEL 7 to RHEL 9 and use RHEL 8 and RHEL 9. 

We use Red Hat insights but do not utilize them. It helps with the remediation. I use Image Builder to build AWS and GCP images. I haven't deployed them. 

I rate the product a nine out of ten. 

Which deployment model are you using for this solution?

Hybrid Cloud


    reviewer2297034

Fair price, good support, and regular security updates

  • October 19, 2023
  • Review provided by PeerSpot

What is our primary use case?

We have over a thousand VMs or physical machines running on Red Hat Enterprise Linux. We have various applications, and we also run the OpenShift Container Platform on-prem, so we have a lot of containers. They are migrating a lot of apps from the mainframe over to Spring Boot type of app. It fits well in the container.

How has it helped my organization?

Red Hat Enterprise Linux gave us stability. There is somebody to call when we have issues.

Red Hat Enterprise Linux has affected our system's uptime or security.

Red Hat Enterprise Linux has not yet enabled us to achieve security standards certification because we do not go after any of those. There are some products that we will have to do once we get there, but so far, we have not had to certify anything.

Red Hat Insights gives a lot of insights into known issues that we do not think about unless we call support. It tells us to proactively fix something.

I have used Image Builder and System Roles mainly for Red Hat Enterprise Linux for Edge. It builds out the OS tree build for us, which is very helpful. I do not like to do that myself.

I use the Red Hat console every now and then, but I do not use it heavily. I am old school.

What is most valuable?

The security updates and the support that comes along with it for applications are valuable.

Red Hat Insights was a nice feature to discover. I did not know about Ansible until probably eight years ago. I learned that language, and that was a void or something that was missing for over 25 years.

I like the SCAP Workbench interface that I can use to build some security around. I use Ansible to go out and do configuration management checks as well. Overall, I feel it is very easy to get the data I need.

What needs improvement?

We finally started doing Red Hat Enterprise Linux for Edge. That one definitely is an improvement. One piece that is missing is that we are required to use moby-engine, but currently, Red Hat Enterprise Linux for Edge forces Podman, so we have to work around it.

For how long have I used the solution?

I have been using Red Hat Enterprise Linux for a decade in my current organization, but overall, I have been using Red Hat for over 25 years.

How are customer service and support?

Early on, support was closer to a six, but now, it is a nine out of ten.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

I have used them all back from the early nineties. I have used CentOS and others. The reasons for companies switching from those to Red Hat Enterprise Linux are that most of it is open source, and they get more product features. There is a market. If other companies are doing it, they tend to switch over. Containerization is a major reason as well.

How was the initial setup?

I was involved in the OpenShift deployments. We are also directly involved in every version of Red Hat Enterprise Linux. We are involved in the proof of concept. Its deployment is straightforward.

What about the implementation team?

We used Red Hat with the OpenShift deployments to make sure we were doing it right, and then a lot of other things, such as Red Hat Enterprise Linux 8 or Red Hat Enterprise Linux 9, we just did ourselves.

In terms of our upgrade and/or migration plans to stay current, we are upgrading everything to Red Hat Enterprise Linux 8, and we are going to Red Hat Enterprise Linux 9 already. We are making that a product feature. We are using Red Hat Enterprise Linux for Edge for our remote deployments.

In terms of provisioning and patching, we deploy the base image, and then we use Ansible for the configuration behind it. For Red Hat Enterprise Linux for Edge, we use the OS builders to build out that same image. I use Kickstart to build the base image before the configuration.

What was our ROI?

I do not track that in the company, but I am sure we have seen an ROI.

What's my experience with pricing, setup cost, and licensing?

It seems to be fair. It is not overpriced. I went to the simple model, and that makes it easier for us to deploy.

What other advice do I have?

Overall, I would rate Red Hat Enterprise Linux a nine out of ten.


    RichOwens

A simple and easy-to-use solution for off-the-shelf applications and Oracle databases

  • October 19, 2023
  • Review provided by PeerSpot

What is our primary use case?

We use Red Hat Enterprise Linux for off-the-shelf applications and Oracle databases. 

What is most valuable?

The tool is simple and easy to use. It has good support and doesn't have many outages due to the OS. 

What needs improvement?

The cockpit server doesn't work and is useless. I don't like the images shown in GCP. I prefer the ones in AWS. It seems like the solution is in tune with what we deploy on the private cloud. 

For how long have I used the solution?

I have been using the solution for ten years. 

How are customer service and support?

We open a case whenever we need support. Whenever I need support, I contact the technical guy assigned to us and provide him with the documentation. 

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

I have used different OS like Motorola, Unix Flavors, Solaris, HP-UX, AIX, DG/UX, and Sonos OS. Unix is dying, and everything is moving to Linux. Linux is open-source and easier to use. 

How was the initial setup?

We build our own deployment method. 

What's my experience with pricing, setup cost, and licensing?

Red Hat Enterprise Linux is expensive. We have changed the cloud provider's subscription to a pay-as-you-go model. 

What other advice do I have?

We use the on-premise, cloud, and hybrid versions. We have deployed it on AWS, Microsoft Azure, and Google Cloud. Most of our infrastructure is in the Azure cloud. I work in the server infrastructure team, and other data collectors work on AWS and GCP. We haven't used the tool's features like the image builder. 

The product supports our hybrid cloud strategy. We have been migrating using tools from Microsoft Azure. Its knowledge base is good. Sometimes, finding an article is difficult. However, once I reach them, it contains good information. 

We used Azure's tools for migration to the cloud. It is straightforward. We have no problems deploying the servers. Our main strategy focused on data centers.

We use the Leapp tool to manage the upgrades. It works smoothly on our Oracle databases. Leapp is straightforward to use. 

We use Red Hat Insights quite a bit. I have not explored all the features yet. We use it to look for events our monitoring hasn't picked up. It also helps us with tips and hints for fine-tuning applications like SAP and Oracle. We go by these recommendations and follow them to put the applications in place. I have downloaded the Playbooks for remediation. 

I use system rules for SAP tuning in Oracle. I do not use the image builder since we already have a process to do the server builds. I use the web console once in a while. 

I rate Red Hat Enterprise Linux a nine out of ten. 

Which deployment model are you using for this solution?

Hybrid Cloud


    reviewer2297022

Has comprehensive support,and seamless containerization capabilities

  • October 19, 2023
  • Review from a verified AWS customer

What is our primary use case?

For the past couple of years, our contractor team has been engaged with the Department of Veterans Affairs, focusing on developing and deploying software and containers and we use Red Hat Enterprise Linux for that.

What is most valuable?

One of the most valuable aspects is the ease of installing packages on the server. When we need to run specific software, adding and installing packages on Red Hat Enterprise Linux is quite straightforward.

What needs improvement?

When we initially began working with containers, we encountered some challenges with compatibility. Red Hat provided an older and somewhat outdated version of Docker, which made the early stages of our container journey more challenging than I would have preferred.

For how long have I used the solution?

I have been using Red Hat Enterprise Linux for three years.

How are customer service and support?

The customer support they provide is highly commendable. I would rate it nine out of ten.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

I've mainly used Windows on my computer or laptop. However, it was a different scenario when we were developing in the cloud and were given Red Hat Enterprise Linux servers to work with.

What about the implementation team?

We regularly perform upgrades on our OpenShift clusters, typically on a monthly basis. When it comes to the Red Hat Enterprise Linux servers, we frequently update the images on our virtual machines to ensure that we stay current with the latest versions. We're actively working on implementing automation using Ansible to streamline and facilitate these tasks.

What other advice do I have?

Overall, I would rate it nine out of ten.

Which deployment model are you using for this solution?

Public Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Amazon Web Services (AWS)


    reviewer2295390

Secure, easy maintenance, and good support

  • October 17, 2023
  • Review provided by PeerSpot

What is our primary use case?

We had a lot of IBM AIX servers. We migrated a lot of them to Red Hat Enterprise Linux. We have a lot of VMs, and we have a few physical servers. Currently, we are moving all the Red Hat VMs to the cloud. There are 1,600 to 1,700 Red Hat VMs that we are currently running.

How has it helped my organization?

The main benefit is that it can be easily recovered and easily restored. It is on the VM. We can easily restore every image that we back up on the VM. If something happens, we can easily fix it. Support and maintenance are easy. The most common issues that happen with Red Hat Enterprise Linux are password restore issues. We can go and restore the passwords through the single-user mode. This feature is well-developed and good.

We are using Ansible for the most automations. We can push everything through Ansible. We are moving towards automation to make sure our system can be easily maintained, and we can recover, restore, and do the things that we want. We have 1,600 to 1,700 servers. We have Ansible Tower, and we have a few satellite servers and a lot of capsules to support Red Hat servers.

If anything is supported by Red Hat Enterprise Linux and the feature is available in Red Hat Satellite, we are able to install it on Red Hat Enterprise Linux. We are using Red Hat Satellite to install all the patches and all the packages, so if a feature is available, we can easily install it if it is supported.

Red Hat Enterprise Linux has built-in security features for simplifying risk reduction and maintaining compliance. We are working with most of the security environments. Security is our main concern. We have zero tolerance when it comes to security. We are able to apply security rules and regulations within the Red Hat environment.

What is most valuable?

We are using Red Hat Enterprise Linux 7, and we normally look at how it can easily support the system. With Red Hat Enterprise Linux 7, we have a high-security system. We have a lot of features there. That is the main thing, but currently, we are moving from Red Hat Enterprise Linux 7 to Red Hat Enterprise Linux 8. 

Red Hat Enterprise Linux Leapp and Red Hat Insights have been useful. RHEL Web Console is also helpful.

We have access to the Red Hat knowledge base. We have frequent meetings with Red Hat. Red Hat partners provided us with all the information and any kind of training.

What needs improvement?

We are using the features that are available with Red Hat Enterprise Linux and Ansible. As such, there are no specific features that we are looking for. 

We have frequent meetings with them. We have had some issues on the application side and the OS side for which we opened cases and discussed those concerns and questions in the meetings offered by Red Hat.

For how long have I used the solution?

I have been using Red Hat Enterprise Linux for almost 10 years.

What do I think about the scalability of the solution?

Upgrades and migrations are ongoing processes to stay current. We are a big company. We always have migration going on. We always have the build process. Red Hat's presence keeps increasing in our environment. We are going to have about 2,500 Red Hat Enterprise Linux VMs in the next year.

How are customer service and support?

If there are any concerns, we have a meeting with Red Hat, and they provide the required support. When we have any concerns or questions, they answer them. It is easy. I would rate their support a nine out of ten.

How would you rate customer service and support?

Positive

What was our ROI?

We have probably seen an ROI. Red Hat is getting better every day. 

What other advice do I have?

Overall, I would rate Red Hat Enterprise Linux a ten out of ten.


    reviewer2295381

Hardware-independent, cost-efficient, and saves maintenance time

  • October 17, 2023
  • Review provided by PeerSpot

What is our primary use case?

We host our applications and database servers on Red Hat Enterprise Linux.

We mostly have an on-premises setup. We also have Red Hat Enterprise Linux running on a virtual machine.

How has it helped my organization?

Compared to our previous Unix distro, it is pretty easy and less time-consuming to do patching and maintenance. It saves a lot of time during maintenance.

What is most valuable?

I started with Solaris 10, and then we migrated to Red Hat Enterprise Linux. Apart from local zones and a few other things, its features are similar to Solaris 10. It is getting our job done. It is hardware-independent. We can use Dell, HPE, or any other hardware. It is also more reasonable than the other operating systems.

It integrates closely with other products of Red Hat, such as Ansible, which makes it more efficient.

For how long have I used the solution?

I have been using Red Hat Enterprise Linux since 2010.

How are customer service and support?

We are getting all the support that we need on a timely basis. In the case of any issue, we are getting all the support needed to bring the production back online. I would rate them a nine out of ten.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

We were using Solaris 10. We moved to Red Hat Enterprise Linux because it is cost-efficient and hardware-independent.

How was the initial setup?

I am a part of the team that does the OS deployment. Its initial deployment is straightforward. We use automation for deployment. We have a kickstart to deploy the OS. Once we create that kickstart configuration file, the deployment is straightforward.

In terms of our upgrade and migration plans to stay current, we upgrade it before the OS is end of life. It is pretty straightforward. We are pretty satisfied with Red Hat Enterprise Linux systems when it comes to provisioning and patching.

What about the implementation team?

We deployed it on our own. 

What's my experience with pricing, setup cost, and licensing?

It is cost-effective.

Which other solutions did I evaluate?

There were not many options available.

What other advice do I have?

Overall, I would rate Red Hat Enterprise Linux a nine out of ten.


    reviewer2295378

Offers efficient performance tuning capabilities, enhancing overall system performance

  • October 17, 2023
  • Review provided by PeerSpot

What is our primary use case?

My use cases are mainly limited to databases. I'm also involved in other ETL tools; I worked on migrations from older vendors, like Windows, and transitioning to RedHat Linux.

What is most valuable?

The most valuable features are security, performance tuning, storage management, and OS-level automation. If you wanted to automate while adapting with different vendor scripts or your own development because it's Linux, it's not like an operating system itself. It is always going to perform how you expect it to. IAQt's not like other operating systems. It is based on Linux. 

These are the main features. Storage management is another valuable feature that is very critical in an operating system. It works along hardware and software.

The most valuable features are security, performance tuning, storage management, and OS-level automation. If you wanted to automate while adapting with different vendor scripts or your own development because it's Linux, it's not like an operating system itself. It is always going to perform how you expect it to. IAQt's not like other operating systems. It is based on Linux.

Compared to other OS', Red Hat Enterprise Linux is the best from my 20-plus years of experience. It is well-suited for production environments. In 2003 and 2006 I worked with one of the vendors in another country. We were able to run a database instance on Red Hat Enterprise Linux for two years without restarting it. The database was located in a remote location, and the team could not be on-site to provide support. We installed it ourselves and it worked for two years. We restarted the database instance. We didn't need to touch it internally. It works like a charm.

If it works, it works. You don't need to attach anything at all. You just monitor them remotely. Nobody was there on-site. That's the beauty of it. Red Hat Enterprise Linux is great. I love it.

What needs improvement?

The GUI has room for improvement. It needs to be managed by many administrators. It has basic command lines. They could improve it with better automation. We'd like to be able to create a script, and then have the ability to deploy it where we don't need to write everything manually. That part can be useful for automating. 

We'd like it so that a coder wouldn't need to go through it, read it, go to GUI, and then generate a script. If they want to modify it, they could modify it. If Red Hat Enterprise Linux is going to build something, the REST API can be helpful instead of writing their own, starting from scratch. That would make it easier.

For future releases, there could be more integration. Regarding security, we used a different tool for scanning, but having a tool within Red Hat could enhance it. 

Support is essential for open-source software. If they improve aspects like prevention against hacking, it would be beneficial. 

Before, with a surge in hacking incidents, companies lost data, and once lost, it remains lost forever. You never know when it might be used. Improving security, especially in terms of prevention, is crucial. I would like to see ongoing improvement in this aspect.

For how long have I used the solution?

I've worked with different companies. In my over 20 years of experience, in the last five or six companies I've worked for, all of them have been using Red Hat. They use it mostly for databases. 

I'm in the database sector, primarily working as a senior technical architect. End-to-end, we always find that Red Hat is best suited for Linux, especially for Oracle and other NoSQL databases. It's reliable, first and foremost, and it offers stability and performance. Performance tuning is crucial, and once it's set up, you can rely on it. 

With the cloud, it's moving into containerization, and most of them support the cloud. 

How are customer service and support?

The customer service and support are really good. 

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

I have worked with many different operating systems in the past, including Windows, Linux, and RedHat Linux.

We switched to Red Hat Enterprise Linux because it is a reliable and well-supported enterprise operating system. It is easy to manage, use, and upgrade.

What was our ROI?

We have seen a return on investment. 

What other advice do I have?

As a consultant, I handle sizing, design, and optimization for new infrastructures and I would recommend Red Hat Enterprise Linux to anybody considering it.  

Overall, I would rate the solution a ten out of ten.


    reviewer2295372

Provides in-depth understanding of infrastructure and has strong community support

  • October 17, 2023
  • Review provided by PeerSpot

What is our primary use case?

We predominantly use Red Hat CoreOS we use it to connect to different types of OpenShift clusters.  Whenever I work with RHEL, it's always been with the CLI.

What is most valuable?

Previously, when we were using other distributions, we weren't getting a lot of support for the operating system itself. However, Red Hat has mainly focused on the operating system, so we get more support. 

AWS has its own version of Linux for its instances. All these cloud providers provide more support for the infrastructure and services, but they don't focus on the operating system itself. But Red Hat, with its customer portal, provides better support if something goes down. That's what differentiates RHEL from other products.

One great thing about RHEL is that it has a big community of users. There's a huge community that uses CentOS. If you need some help or have a question online, you get more resources for RHEL compared to other products. 

It's a really good operating system by itself. It's more versatile, integrating with tools like Ansible for automation.

There are amazing resources online, and because we are an enterprise, we have enterprise support. We can always create a support case, and we have some resources to help. The knowledge offered by Red Hat is great.

Another feature I tried was RedHat Insights because they offer it for other RedHat products as well. I've used it for OpenShift. It was helpful. It provides a good, in-depth understanding of what's going on in the actual infrastructure. It gave us good insights into the level at which we can run the containers and if you can scale the infrastructure vertically or horizontally and how to manage it better.

What needs improvement?

There is room for improvement in integration with different cloud platforms. There should be better integration because right now, a lot of cloud platforms have their own versions of Linux, which runs better on them, and they have better integration with the services. RHEL is great, but RHEL is more of a generic form of what Red Hat provides.

For how long have I used the solution?

I've been using RHEL for about four years now.

How are customer service and support?

There were certain times when I encountered issues. There are certain problems with integrations. 

For example, we had an issue once where the operating system had issues accessing the data server on our VMware infrastructure. So we did have a couple of engineers help us out with that, but that's one area where it can improve. But that's nitpicking. 

It's been great so far, but that's one thing I would like to see that would make RHEL a little better product.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

We prominently use RHEL, but we've also used Ubuntu. We also have used PCF. I use Ubuntu Xenial and have worked with Amazon Linux for a while.

One pro is that at the operating system layer, RHEL has better support from Red Hat, and if something goes down, I found many resources for troubleshooting online.

For example, we predominantly use Amazon Linux if I'm using AWS. There aren't a lot of resources if I run into an issue. RHEL has way more documentation on Linux. It has a bigger community, from an operating system perspective.

What about the implementation team?

One of our deployment models is on-premise, and the other is on the cloud. It's a hybrid. We have a big footprint on the cloud.

We use Azure because a lot of resources are already deployed on it. We can use all the features I build on RHEL, but you can scale up the infrastructure, depending on the demand. That's the reason why we use Azure.

For the upgrade process, we mainly use Ansible automation. Whenever we want an upgrade, we just go into the Ansible Tower, change the version, and make sure we are applying that to the right environments so that there's no outage. 

What other advice do I have?

Overall, I would rate the solution an eight out of ten. 

Which deployment model are you using for this solution?

On-premises

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Microsoft Azure


    reviewer1556661

Good security, helpful support, and helps with compliance

  • September 26, 2023
  • Review provided by PeerSpot

What is most valuable?

The solution offers stable distribution and is very focused on security. It's very committed to delivering security fixes. That way, we don't have to keep moving forward with new versions. 

They are very focused on security and their products are well-designed in that regard. Their delivery of fixes for all products is great. It helps us maintain compliance and helps with risk reduction.

They provide satellites as an account management solution to deliver fixes. It helps us figure out where there are security gaps in our system. They offer good compliance out of the box.

We are starting to roll out container approaches for delivering new solutions. It's still early. We are using a very simple setup and we're beginning to test OpenShift. 

The product enables us to achieve security standards certification.

We can build with confidence and ensure availability across physical infrastructures. From the OS perspective, they do have a lot of reliability features. The virtualization is being phased out (their previous solution) and now they are moving to OpenShift. We're just starting to adopt it. 

We can automate security configurations. We're using the Red Hat security ecosystem to manage logical access and security. It delivers a lot of information with regard to security and hardening and how to use its products properly with regard to security, and we try to follow those guidelines. 

What needs improvement?

Overall, they are doing a good job. We're hoping that they continue to onboard open-source products into their operating system.

For how long have I used the solution?

I've been using the solution for about seven years.

How are customer service and support?

Technical support is pretty good. It's one of the main reasons we chose Red Hat over competitors. 

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

We've been working with CentOS. It was used in a very limited scope. We've also used Oracle Enterprise Linux for a limited scope. Red Hat has a more solid community and certifies its products more effectively. 

How was the initial setup?

We're quite experienced with the initial setup at this point. For us, the process is a standard procedure.

The product does require some maintenance. There are about four people dedicated to the technology at this time.  

What's my experience with pricing, setup cost, and licensing?

They are becoming very competitive. There has been more pressure based on competition, which is healthy. They could continue to work on their pricing model. The subscription model for some products needs improvement. The automation shouldn't be combined with managed hosts. Pricing should be based on socket and not endpoints. 

Which other solutions did I evaluate?

We evaluated Oracle Enterprise Linux. 

What other advice do I have?

I'm a customer and end-user. 

We do not use Red Hat Insights just yet due to some restrictions around sending sensitive information off-premises. We're quite limited in terms of using that feature at the moment.

I'd rate the solution nine out of ten. 

Which deployment model are you using for this solution?

On-premises