Press "Enter" to skip to content

CIQ Mixes ‘Open’ Metaphors with RLC Pro Hardened ‘Deployment’

It’s a product announcement framed as a deployment story, with open-source appeal and enterprise pricing.

On Thursday I wondered aloud here on on FOSS Force how Rocky Linux would counter the announcement that AlmaLinux now comes with free use of Codenotary’s security platform. If you don’t know, Rocky and Alma are the biggest players on the RHEL-clone stage.

As it turned out, something of an answer arrived even before that article was actually published, although I’m pretty sure it was an accident of timing and not actually prompted by the AlmaLinux news. On the same Thursday, CIQ made a security announcement centered on Rocky Linux from CIQ Pro Hardened, which is the most secure version of the several distros wearing the RLC label.

The announcement focused on non-free rather than open source solutions, all the while leaning on open source Linux’s reputation. Although Rocky Linux, like AlmaLinux, is open source and released under the GPL license, Rocky Linux from CIQ Pro (and Pro Hardened) contains commercial software that likely includes proprietary elements. It’s a version of Linux with a price tag that isn’t available for free except as a 30-day trial.

CIQ called its announcement the “launch of a deployment.” Actually, it was announcing a workaround — a way to combine RLC Pro Hardened with a couple of other CIQ offerings in a way that could make life easier for IT teams working for US agencies. The other platforms involved are Ascender, CIQ’s open source downstream rebuild of Ansible’s UI, API, and task engine, and Ascender Pro, another non-free proprietary product from CIQ which adds a dashboard along with point-and-click capabilities to Ascender.

** If our coverage matters to you, please consider supporting our work through our FOSS Force Independence 2026 fundraiser. **

Important to this workaround are RLC Pro Hardened’s and Ascender Pro’s real-time kernel exploitation detection, audit-ready compliance, and automated remediation which should be helpful to federal IT teams if an unpatched vulnerability were discovered. That’s because these days federal agencies face a short three-day remediation window to address high-risk vulnerabilities once they become known.

The time limit came about on June 10, when CISA issued Binding Operational Directive 26-04, dictating the start of a three-day clock whenever a security bug enters CISA’s Known Exploited Vulnerabilities catalog, no matter when (or if) a patch ships to fix it. CIQ points out that in cases where black hats release an exploit before a patch is available, the clock will likely already be running when the exploit enters the wild, which would put IT teams in “hurry-up mode.” When the clock runs out, noncompliance penalties can include greater regulatory oversight and temporary loss of the affected system.

CIQ is also touting RLC Pro Hardened’s runtime kernel exploitation detection, a feature that was already in place when BOD 26-04 was released to put federal agencies on the three-day clock. This goes along with RLC Pro Hardened’s Linux Kernel Runtime Guard, which continuously validates kernel integrity, and records kernel-level exploitation as it happens. This means that after the final all clear, it won’t take a room full of forensic engineers weeks to figure out what happened.

All of this just might be exciting if it arrived all wrapped up in an open source package, which would mean government agencies would have a free-to-use solution to an important security issue. As it is, it’s a solution that will cost taxpayers.

Be First to Comment

Leave a Reply

Your email address will not be published. Required fields are marked *