Overview
Hardened Oracle Linux 10 - secure by default
Oracle Linux 10 hardened to CIS Level 1 and OpenSCAP-verified: SELinux enforcing, SSH lockdown, automatic security updates, zero baked-in credentials, security-maintained by Verified Images.
This is a repackaged open source software product wherein additional charges apply for the hardened, security-maintained image (rebuilt and re-verified as new CVEs are disclosed).
Verified Images publishes a hardened, production-ready build of Oracle Linux 10, a free, enterprise-grade, RHEL-compatible Linux distribution. The image ships secure by default and stays current automatically, so you can launch trusted Linux infrastructure in minutes.
What's included:
- A security-hardened baseline aligned with the CIS Oracle Linux 10 Benchmark, Level 1 (Server profile), independently verified with OpenSCAP against the closest published SCAP Security Guide CIS Level 1 profile (the RHEL-10-compatible AlmaLinux 10 content; no native Oracle Linux CIS profile is published in the SCAP Security Guide, so the substitution is disclosed here; 100.0% of applicable Level 1 controls pass, with 71 documented cloud-compatibility exceptions; verification report available on request): SSH password authentication and root login are disabled, SELinux runs enforcing (targeted policy), a kernel/network sysctl hardening profile is applied, password-aging and umask defaults are set, and no default passwords or SSH keys are baked in. This hardening also maps to system-hardening requirements in PCI DSS, NIST 800-53, and HIPAA technical safeguards. Verified Images is not affiliated with or certified by the Center for Internet Security; CIS Benchmarks is a trademark of CIS.
- SELinux enforcing out of the box (targeted policy), not just installed: a mandatory access control layer on top of standard Linux permissions.
- Automatic security updates enabled out of the box (dnf-automatic), using Oracle Linux's free public repositories, keeping the OS patched against CVEs without manual intervention.
- Time synchronized against the EC2 link-local NTP source (chrony) and an audit trail via the file-integrity tool AIDE (database initialized on first boot, so it reflects your instance, not the build pipeline).
- AWS Systems Manager (SSM) agent preinstalled for keyless, auditable instance management.
- Ongoing security maintenance: the hardened image is rebuilt and re-verified against the CIS benchmark as new CVEs are disclosed, so new launches stay current.
Oracle and Oracle Linux are registered trademarks of Oracle and/or its affiliates. Verified Images is an independent repackager and is not affiliated with, sponsored by, or endorsed by Oracle. "Oracle Linux" is used here solely to identify the operating system this image is built from. This image is built from Oracle Linux's freely redistributable packages (GPLv2 and other open source licenses). Complete corresponding source code for all GPL-licensed components is published by Oracle at yum.oracle.com and oss.oracle.com/sources; in addition, Verified Images will provide the complete corresponding source for any GPL-licensed package in this image, for at least three years from the date of distribution, for no more than the cost of physically performing source distribution (contact support@verified-images.com ). This product does not include Oracle Linux Support, Ksplice, or Unbreakable Linux Network (ULN) access.
Highlights
- Secure by default, verified - hardened toward the CIS Oracle Linux 10 Benchmark Level 1 and independently OpenSCAP-verified against the closest published CIS Level 1 profile (RHEL-10-compatible AlmaLinux 10 content; substitution disclosed, as no native Oracle Linux CIS profile is published; 100.0% of applicable Level 1 controls pass, with 71 documented cloud-compatibility exceptions); SSH password/root login disabled, SELinux enforcing, sysctl and login hardening, zero baked-in credentials.
- Stays patched, automatically - dnf-automatic security updates from Oracle Linux's free public repositories, chrony time sync, AIDE file-integrity monitoring (first-boot baseline), and the SSM agent preinstalled.
- Security-maintained, independent - the hardened image is rebuilt and re-verified against the CIS benchmark as new CVEs are disclosed. Verified Images is an independent repackager, not affiliated with Oracle; no Oracle Support/Ksplice/ULN is included.
Details
Introducing multi-product solutions
You can now purchase comprehensive solutions tailored to use cases and industries.
Features and programs
Financing for AWS Marketplace purchases
Pricing
Dimension | Cost/hour |
|---|---|
t3.small Recommended | $0.06 |
t3.micro | $0.05 |
t3.medium | $0.10 |
t3.2xlarge | $0.40 |
m5.xlarge | $0.25 |
t3.large | $0.16 |
m5.2xlarge | $0.40 |
m5.4xlarge | $0.70 |
t3.xlarge | $0.25 |
m5.large | $0.16 |
Vendor refund policy
Refunds are handled through AWS Marketplace in accordance with AWS Marketplace's standard refund policy. To request a refund, buyers should submit a request via AWS Marketplace. For product-related questions, contact support@verified-images.com .
How can we make this page better?
Legal
Vendor terms and conditions
Content disclaimer
Delivery details
64-bit (x86) Amazon Machine Image (AMI)
Amazon Machine Image (AMI)
An AMI is a virtual image that provides the information required to launch an instance. Amazon EC2 (Elastic Compute Cloud) instances are virtual servers on which you can run your applications and workloads, offering varying combinations of CPU, memory, storage, and networking resources. You can launch as many instances from as many different AMIs as you need.
Version release notes
Initial release: hardened Oracle Linux 10 image with SELinux enforcing, dnf-automatic security updates (free public repos), SSH lockdown, chrony time sync, AIDE file-integrity monitoring, and SSM agent preinstalled. CIS Level 1 verification via OpenSCAP against the closest published CIS profile (AlmaLinux 10, RHEL-10-compatible; substitution disclosed, no native Oracle Linux CIS profile is published); 100.0% of applicable Level 1 controls pass, with 71 documented cloud-compatibility exceptions.
Additional details
Usage instructions
-
Launch this AMI from AWS Marketplace. Choose an instance type (t3.small recommended) and assign your own EC2 key pair for SSH access.
-
Security group: open TCP 22 (SSH) from your IP. No other ports are required by the base image.
-
Connect via SSH as the "cloud-user" user with your key pair: ssh -i /path/to/your-key.pem cloud-user@<public-ip> Password authentication and root login are disabled by design. Use "sudo" for privileged commands.
-
SELinux runs enforcing (targeted policy) by default. Check status any time with: getenforce Automatic security updates are enabled (dnf-automatic) from Oracle Linux's free public repositories; no action needed for routine patching.
-
(Optional) Manage the instance without SSH keys using AWS Systems Manager: attach an IAM role with the AmazonSSMManagedInstanceCore policy, and the instance will appear in Systems Manager.
-
Questions: support@verified-images.com . Include your instance ID and a description of the issue.
-
Documentation: full setup, configuration, hardening details, and the CIS verification report are available at https://verified-images.com (contact support@verified-images.com for the per-instance report).
Trademark notice: Oracle and Oracle Linux are trademarks of Oracle and/or its affiliates. Verified Images is an independent repackager and is not affiliated with, sponsored by, or endorsed by Oracle; "Oracle Linux" is used solely to identify the operating system this image is built from.
Support
Vendor support
support@verified-images.com (Verified Images, a DBA of CarmelTech LLC).
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
Similar products
