Release of Red Hat Enterprise Linux 8.8 distribution

Following the release of Red Hat Enterprise Linux 9.2, an update for the previous branch Red Hat Enterprise Linux 8.8 has been announced, which will be maintained alongside the RHEL 9.x branch at least until 2029. Installation builds are prepared for x86_64, s390x (IBM System z), ppc64le, and Aarch64 architectures, but they are available for download only to registered users of the Red Hat Customer Portal (CentOS Stream 9 ISO images and free RHEL developer builds can also be used). The source code for the rpm packages of Red Hat Enterprise Linux 8 is distributed through the CentOS Git repository.

New releases are prepared according to a development cycle that implies forming releases every six months at a predetermined time. Until 2024, the 8.x branch will be in full support, which includes functional enhancements, after which it will transition to a maintenance phase, where priorities will shift towards bug fixes and security, with minor improvements related to important hardware system support.

Key changes:

  • Server and system packages have been updated: nginx 1.22, Libreswan 4.9, OpenSCAP 1.3.7, Grafana 7.5.15, powertop rebased 2.15, tuned 2.20.0, NetworkManager 1.40.16, mod_security 2.9.6, samba 4.17.5.
  • Included are new versions of compilers and developer tools: GCC Toolset 12, LLVM Toolset 15.0.7, Rust Toolset 1.66, Go Toolset 1.19.4, Python 3.11, Node.js 18.14, PostgreSQL 15, Git 2.39.1, Valgrind 3.19, SystemTap 4.8, Apache Tomcat 9.
  • FIPS mode settings have been modified to comply with FIPS 140-3 standards. 3DES, ECDH, and FFDH have been disabled; the minimum size for HMAC keys is limited to 112 bits, and for RSA keys to 2048 bits. Hashes SHA-224, SHA-384, SHA512-224, SHA512-256, SHA3-224, and SHA3-384 have been disabled in the DRBG pseudorandom number generator.
  • SELinux policies have been updated to ensure the operation of systemd-socket-proxyd.
  • The yum package manager has implemented the offline-upgrade command for applying updates to the system in offline mode. The essence of offline updating is that new packages are first downloaded using the command "yum offline-upgrade download", after which the "yum offline-upgrade reboot" command is executed to restart the system into a minimal environment and install the available updates without disrupting ongoing processes. After the updates are installed, the system reboots into the normal working environment. When loading packages for offline updates, filters can be applied, such as "—advisory", "—security", "—bugfix".
  • A new package synce4l has been added to use SyncE (Synchronous Ethernet) frequency synchronization technology, supported by some network cards and switches, which allows for improved data exchange efficiency in RAN (Radio Access Network) applications through more precise time synchronization.
  • A new configuration file /etc/fapolicyd/rpm-filter.conf has been added to the fapolicyd (File Access Policy Daemon) framework, which determines which programs a certain user can run and which they cannot. This new configuration file can be used to exclude certain applications installed via the RPM package manager from access policies.
  • In the kernel, when logging information about detected SYN floods, details about the accepting connection's IP address have been provided to simplify identifying the flood target on systems with handlers bound to different. IP addresses.
  • A system role for the podman toolkit has been added, allowing for the management of Podman configurations, containers, and systemd services that run Podman containers. Podman now supports audit event generation, connection of handlers before execution (/usr/libexec/podman/pre-exec-hooks and /etc/containers/pre-exec-hooks), and using the Sigstore format for storing digital signatures alongside container images.
  • The toolkit for managing isolated containers, container-tools, has been updated, including packages such as Podman, Buildah, Skopeo, crun, and runc.
  • A toolbox utility has been added, allowing the launch of an additional isolated environment that can be configured arbitrarily using the standard package manager DNF. The developer just needs to run the command "toolbox create", after which they can enter the created environment at any time using the command "toolbox enter" and install any packages using the yum utility.
  • Support has been added for creating images in the vhd format used in Microsoft Azure for the ARM64 architecture.
  • SSSD (System Security Services Daemon) now includes support for converting home directory names to lowercase (through the use of the substitution "%h" in the override_homedir attribute specified in /etc/sssd/sssd.conf). Additionally, users are allowed to change passwords stored in LDAP (enabled by setting the shadow value for the ldap_pwd_policy attribute in /etc/sssd/sssd.conf).
  • A new sorting algorithm has been implemented in glibc for dynamic linking of DSO, using a depth-first search (DFS) method to address performance issues when handling cyclic dependencies. A parameter glibc.rtld.dynamic_sort=2 has been provided to select the DSO sorting algorithm, allowing a value of "1" to revert to the old algorithm.
  • The rteval utility now provides a summary of program loads, threads, and CPUs involved in executing these threads.
  • Additional options for measuring latency have been added to the oslat utility.
  • New drivers have been added for Intel Elkhart Lake SoC, Solarflare Siena, NVIDIA sn2201, AMD SEV, AMD TDX, ACPI Video, Intel GVT-g for KVM, HP iLO/iLO2.
  • Experimental support has been added for Intel Arc discrete graphics cards (DG2/Alchemist). To enable hardware acceleration on such graphics cards, the PCI identifier of the card should be specified at boot time using the kernel parameter "i915.force_probe=pci-id".
  • The inkscape inkscape1 package has been replaced with inkscape1, which uses Python 3. The Inkscape version has been updated from 0.92 to 1.0.
  • The kiosk mode now provides the option to use the GNOME on-screen keyboard.
  • Support for authentication in Microsoft Exchange Server using the NTLMv2 protocol has been added to the libsoup library and the Evolution email client.
  • In GNOME, it is now possible to customize the context menu displayed when right-clicking on the desktop. Users can now add items to the menu to launch custom commands.
  • In GNOME, switching can be disabled virtual desktops by swiping up or down with three fingers on the touchpad.
  • The experimental (Technology Preview) support for AF_XDP, XDP hardware offloading, Multipath TCP (MPTCP), MPLS (Multi-protocol Label Switching), DSA (Data Streaming Accelerator), KTLS, dracut, kexec fast reboot, nispor, DAX in ext4 and xfs, systemd-resolved, accel-config, igc, OverlayFS, Stratis, Software Guard Extensions (SGX), NVMe/TCP, DNSSEC, and GNOME on ARM64 and IBM Z systems, AMD SEV for KVM, Intel vGPU, Toolbox has been continued.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster