Red Hat Distribution of Red Hat Enterprise Linux 7.7. Installation images for RHEL 7.7 are available for download only to registered users of the Red Hat Customer Portal and are prepared for x86_64, IBM POWER7+, POWER8 (big endian and little endian), and IBM System z architectures. The source texts of the packages can be downloaded from of the CentOS project.
The RHEL 7.x branch is maintained parallel to the and will be supported until June 2024. The release of RHEL 7.7 is the last one in the full main support phase, which includes the introduction of functional enhancements. RHEL 7.8 to the maintenance phase, where priorities will shift towards bug fixes and security, with minor enhancements related to the support of critical hardware systems.
Key :
- Full support is provided for the application of the Live Patching mechanism () to address vulnerabilities in the Linux kernel without rebooting the system and without stopping the workload. Previously, kpatch was considered an experimental feature;
- Python 3.6 interpreter packages have been added. Previously, Python 3 was supplied only as part of Red Hat Software Collections. By default, Python 2.7 is still offered (transition to Python 3 has been made in RHEL 8);
- Screen presets have been added to the Mutter window manager (\/etc\/xdg\/monitors.xml) for all users in the system (no more need to separately configure screen settings for each user;
- The graphical installer has added definitions for enabling Simultaneous Multithreading (SMT) in the system and displays a corresponding warning;
- Full support for Image Builder, a system image builder for cloud environments, including Amazon Web Services, Microsoft Azure, and Google Cloud Platform, is provided;
- Full support for storing sudo rules in Active Directory has been implemented in SSSD (System Security Services Daemon);
- The default certificate system has added support for additional cipher suites, including TLS_DHE_RSA_WITH_AES_256_GCM_SHA384, TLS_ECDHE_ECDSA_WITH_AES_256_CBC\/GCM_SHA384,
TLS_ECDHE_RSA_WITH_AES_128_CBC\/GCM_SHA256, TLS_ECDHE_RSA_WITH_AES_256_CBC\/GCM_SHA384, and TLS_RSA_WITH_AES_256_GCM_SHA384; - The samba package has been updated to version 4.9.1 (the previous release included version 4.8.3). The 389 directory server has been updated to version 1.3.9.1;
- The maximum number of nodes in a fault-tolerant RHEL-based cluster has been increased from 16 to 32;
- Support for IMA (Integrity Measurement Architecture) is provided for all architectures to verify the integrity of files and related metadata based on a database of pre-stored hashes, along with EVM (extended verification module) to protect file extended attributes (xattrs) from integrity violation attacks (EVM will prevent offline attacks where an attacker could modify metadata, for instance, by booting from their own storage);
- A lightweight toolkit for managing isolated containers has been added, which is used for building containers. , for launching — and for discovering ready-made images — ;
- For new installations, the Retpoline mechanism (‘spectre_v2=retpoline’) is now used by default to protect against Spectre V2 attacks instead of IBRS;
- The source code of the kernel-rt version, which operates in real-time mode, has been synchronized with the main kernel;
- The DNS server bind has been updated to the branch , and ipset to release 7.1. A rpz-drop rule has been added to block attacks that use DNS as a traffic amplifier;
- The NetworkManager has added the ability to set routing rules by source address (policy routing) and support for VLAN filtering on network bridge interfaces;
- A new boltd_t type has been added to SELinux for the boltd daemon, which manages devices with Thunderbolt 3 interfaces. A new bpf rule class has been added for inspecting applications based on the Berkeley Packet Filter (BPF);
- The versions of shadow-utils 4.6, ghostscript 9.25, chrony 3.4, libssh2 1.8.0, tuned 2.11 have been updated;
- Included is the xorriso program for creating and manipulating ISO 9660 images for CD/DVD;
- Support for Data Integrity Extensions has been added, allowing data to be protected from corruption during writing to storage by saving additional error-correcting blocks;
- Support has been added in the virt-v2v utility for conversion to run KVM virtual machines with SUSE Linux Enterprise Server (SLES) and SUSE Linux Enterprise Desktop (SLED), used with hypervisors other than KVM. The performance and reliability of virtual machine conversion from VMWare have been increased. Support for converting virtual machines using UEFI firmware for running in Red Hat Virtualization (RHV) has been added;
- The gcc-libraries package has been updated to version 8.3.1. A compat-sap-c++-8 package with a runtime library variant of libstdc++ compatible with SAP applications has been added.
- The package includes the Geolite2 database, in addition to the outdated Geolite database provided in the GeoIP package;
- The SystemTap tracing toolkit has been updated to branch 4.0, and the Valgrind memory debugging toolkit to version 3.14;
- The vim editor has been updated to version 7.4.629;
- The filter set for the printing system cups-filters has been updated to version 1.0.35. The background process cups-browsed has been updated to version 1.13.4. A new backend implicitclass has been added;
- new network and graphics drivers. Existing drivers have been updated;
Source: opennet.ru
