Following the announcement of the release of RHEL 9, Red Hat has published the release of Red Hat Enterprise Linux 8.6. Installation builds are prepared for x86_64, s390x (IBM System z), ppc64le, and Aarch64 architectures, but are available for download only to registered users of the Red Hat Customer Portal. The source texts for the rpm packages of Red Hat Enterprise Linux 8 are distributed through the CentOS Git repository. The 8.x branch will be supported at least until 2029 and is being developed according to a development cycle that entails releasing updates every six months at predetermined times.
Key changes:
- The fapolicyd framework, which determines which programs can be executed by specific users, has been updated to version 1.1. This version includes placing access rules and lists of trusted resources in the directories /etc/fapolicyd/rules.d/ and /etc/fapolicyd/trust.d instead of the files /etc/fapolicyd/fapolicyd.rules and /etc/fapolicyd/fapolicyd.trust. New options have been added to the fapolicyd-cli utility.
- In fapolicyd, SELinux, and PBD (Policy-Based Decryption for automatic unlocking of LUKS disks), settings have been added to enhance the security of SAP HANA 2.0 databases.
- OpenSSH introduces the ability to use the Include directive in the sshd_config configuration file to substitute settings from other files, which allows for system-specific configurations to be moved to a separate file.
- The semodule command has been enhanced with the "--checksum" option to verify the integrity of installed modules with SELinux rules.
- New versions of compilers and development tools included: Perl 5.32, PHP 8.0, LLVM Toolset 13.0.1, GCC Toolset 11.2.1, Rust Toolset 1.58.1, Go Toolset 1.17.7, java-17-openjdk (while java-11-openjdk and java-1.8.0-openjdk continue to be supplied).
- Server and system packages have been updated: NetworkManager 1.36.0, rpm-ostree 2022.2, bind 9.11.36 and 9.16.23, Libreswan 4.5, audit 3.0.7, samba 4.15.5, 389 Directory Server 1.4.3.
- Image Builder now supports creating images for different intermediate RHEL releases that differ from the current system version, as well as support for configuring and resizing the filesystem on LVM partitions.
- In nftables, memory consumption has been significantly reduced (by up to 40%) when restoring large set lists. The nft utility now supports packet and traffic counters associated with set elements, using the keyword "counter" ("@myset {ip saddr counter}").
- The hostapd package is included, which uses the FreeRADIUS backend and can be used for the operation of the 802.1X authenticator in Ethernet networks. Using hostapd to set up a hotspot or server for Wi-Fi authentication is not supported.
- Support for most eBPF components is provided, such as BCC (BPF Compiler Collection), libbpf, traffic control (tc), bpftracem, xdp-tools, and XDP (eXpress Data Path). Support for AF_XDP sockets for accessing XDP from user space remains in Technology Preview.
- Compatibility with guest system images based on RHEL 9 and the XFS file system is ensured (RHEL 9 uses an updated XFS format with support for bigtime and inobtcount).
- The Samba package includes changes related to option renaming in Samba 4.15. For example, options have been renamed: ‘—kerberos’ (to ‘—use-kerberos=required|desired|off’), ‘—krb5-ccache’ (to ‘—use-krb5-ccache=CCACHE’), ‘—scope’ (to ‘—netbios-scope=SCOPE’), and ‘—use-ccache’ (to ‘—use-winbind-ccache’). Options ‘-e|—encrypt’ and ‘-S|—signing’ have been removed. Duplicate option cleanup has been performed in the utilities ldbadd, ldbdel, ldbedit, ldbmodify, ldbrename, ldbsearch, ndrdump, net, sharesec, smbcquotas, nmbd, smbd, and winbindd.
- An option ‘—list-diagnostics’ has been added to ld.so to output data affecting optimizations in Glibc.
- The web console now supports authentication using smart cards for sudo and SSH, PCI and USB device passthrough in virtual machines and local storage management using Stratis.
- The KVM hypervisor has added support for guest systems with Windows 11 and Windows Server 2022.
- The rig package has been included with a utility for collecting monitoring data and processing events that can help diagnose randomly occurring or very rare issues.
- A set of container-tools 4.0 has been added, including utilities Podman, Buildah, Skopeo, and runc.
- Support for using NFS as storage for isolated containers and their images has been provided.
- The container image with the Podman toolkit has been stabilized. A container with the openssl command-line utility has been added.
- A new batch of packages has been moved to the deprecated category (scheduled for removal in the future), including abrt, alsa-plugins-pulseaudio, aspnetcore, awscli, bpg-*, dbus-c++, dotnet 3.0-5.0, dump, fonts-tweak-tool, gegl, gnu-free-fonts-common, gnuplot, java-1.8.0-ibm, libcgroup-tools, libmemcached-libs, pygtk2, python2-backports, recode, spax, spice-server, star, tpm-tools.
- The experimental (Technology Preview) support for AF_XDP, XDP hardware offloading, Multipath TCP (MPTCP), MPLS (Multi-protocol Label Switching), DSA (Data Streaming Accelerator), KTLS, dracut, kexec fast reboot, nispor, DAX in ext4 and xfs, systemd-resolved, accel-config, igc, OverlayFS, Stratis, Software Guard Extensions (SGX), NVMe/TCP, DNSSEC, and GNOME on ARM64 and IBM Z systems, AMD SEV for KVM, Intel vGPU, Toolbox has been continued.
Source: opennet.ru
