Overview
This is a repackaged open source software product wherein additional charges apply for the development of the included security components, on-going LTS security updates by CIQ to back port security fixes which would otherwise not be available from the community, and for access to CIQ support for basic support engagements via email or ticket.
As the speed, sophistication, and volume of attacks on corporate systems accelerate, CISOs and IT security teams struggle to apply an effective and consistent Linux security policy across all their servers. With Rocky Linux from CIQ Pro - Hardened (RLC-H) with Long-Term Support, you get Enterprise Linux that is delivered securely, configured correctly, locked to a stable minor release, and proactively protecting your apps and services from malicious threats - with backported security patches through November 2029.
RLC-H LTS comes pre-configured against key threat vectors, and delivers hardened kernel and memory integrity checking in runtime. The operating system is pre-hardened and offers further options to apply OpenSCAP policies in compliant environments like DISA-STIG and CIS. FIPS 140-3 validated packages are available and can be enabled as a configuration step. Going beyond reactive security, RLC-H LTS takes a proactive approach to keeping your operating environment safe, and eliminates manual work spent tuning and applying security profiles so you can meet corporate and audit requirements easily and effectively.
Packages with security issues marked as Important or Critical may be eligible for backports. Generally, this applies to packages with a CVSS score of 7.0 or higher. Other security-related backports and bug fixes are at CIQ discretion. Review our CVE Dashboard under Learning Resources for a transparent view of available fixes.
This offer includes Basic Support from CIQ. See the Support Details for information on the available scope of support and how to access our support team, and review the CIQ Support Overview under Learning Resources for more information on the scope of this included support product. CIQ offers SLA-backed Standard and Premium support tiers which are available via Private Offer. View the CIQ Support Overview under Learning Resources to learn more and contact us to request a personalized quote.
Highlights
- Hardened Packages with LTS: Hardened packages including glibc, OpenSSH, and hardened_malloc reduce the attack surface through removal of non-essential libraries and unsafe environment variables, with defense against heap exploitation - all maintained and patched through November 2029.
- LKRG Attack Detection, FIPS, and Compliance: Linux Kernel Runtime Guard detects kernel vulnerability exploits and responds to unauthorized modifications of a running kernel. FIPS 140-3 validated packages are available, and OpenSCAP policies support DISA-STIG and CIS compliance.
- Stronger Security and Extended Stability: passwdqc and yescrypt hashing increase resistance to GPU password cracking. CIQ cryptographically validates all packages, provides an SBOM with each image, and delivers patches for critical CVEs ahead of standard updates - locked to Rocky Linux 9.6 through November 2029.
Details
Introducing multi-product solutions
You can now purchase comprehensive solutions tailored to use cases and industries.
Features and programs
Financing for AWS Marketplace purchases
Pricing
- ...
Dimension | Cost/hour |
|---|---|
t3.xlarge Recommended | $0.06 |
t3.micro | $0.06 |
t2.micro | $0.06 |
m5d.xlarge | $0.06 |
x1e.4xlarge | $0.06 |
r5a.24xlarge | $0.06 |
g5.2xlarge | $0.06 |
c6id.2xlarge | $0.06 |
r6a.12xlarge | $0.06 |
z1d.3xlarge | $0.06 |
Vendor refund policy
No refunds are available, but you may cancel your subscription at any time.
How can we make this page better?
Legal
Vendor terms and conditions
Content disclaimer
Delivery details
64-bit (x86) Amazon Machine Image (AMI)
Amazon Machine Image (AMI)
An AMI is a virtual image that provides the information required to launch an instance. Amazon EC2 (Elastic Compute Cloud) instances are virtual servers on which you can run your applications and workloads, offering varying combinations of CPU, memory, storage, and networking resources. You can launch as many instances from as many different AMIs as you need.
Version release notes
Initial release
Additional details
Usage instructions
Connect to the instance over SSH using the instance public IP, with username "rocky" and the private key generated when you launched the instance.
Example command: $ ssh -i ./ssh-private-key.pem rocky@PublicIPAddress
When you are logged in as "rocky", you can use the sudo command to run administrative tasks. Note that the specific command you use to connect to the instance may vary depending on the operating system and ssh client you are using on your end. By default, the instance is secured by AWS network security configuration; you may optionally install your choice of a local firewall such as firewalld after launch.
Support
Vendor support
This Rocky Linux AMI provided by CIQ includes access to repositories for dnf/rpm updates and is regularly refreshed. This offer includes Basic Support from CIQ, which offers ticket and email-based support covering user accounts, product inquiries, bug reports, onboarding, and basic installation and configuration assistance. More comprehensive SLA-backed Enterprise Support plans at the Standard or Premium level are available from CIQ for additional charges. See the CIQ Support Overview under Learning Resources for full details, or contact us for further information. Contact support@ciq.com for further information. CIQ is committed to providing a working image which meets the highest quality standards. If you have a question or encounter a problem related to deploying the software in this listing into your cloud environment, a question regarding the EULA, or if you are in interested in adding an enterprise support agreement via private offer for help managing your Rocky Linux operating system, contact CIQ Cloud Marketplace Support at cloudmarketplace@ciq.com
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.