Live data from Hacker News

Rocky Linux from CIQ – Hardened

ciq.com

31–40 of 54 posts

Re: Rocky Linux from CIQ – Hardened

#31
post #28

Earlier quoted context omitted.

You are thinking of Alma, and I believe they are still going, though a lot seemed to be up in the air.

No, community is more stable and professional. Frankly given I get less issues than my Rocky counterparts working 1 rack over my look of "I told you so", every time, says it all.

I'm curious -- what issues are your counterparts experiencing?

Re: Rocky Linux from CIQ – Hardened

#32

as seen on the about page[0] "Named in honor of CentOS co-founder Rocky McGaugh" "Gregory Kurtzer, our CEO and founder," the other CentOS guy. [0] https://ciq.com/company/founding-story/

Greg kurtzer is not the founder of CentOS. This is FUD he's been regurgitating ever since tricking one of the past CentOS community managers into doing a blog post. If you read the mailing list archives you'll see the truth.

Well that's certainly _one_ way to tell the story, now isn't it, Jonathan.

Re: Rocky Linux from CIQ – Hardened

#33
post #25

And more drama from the machine that is being the FUD created over every misstep of RHEL/IBM. And I mean misstep not evil attack on the community. CIQ is the worst of FOSS and a blight causing nonsense arguing rather than actually contributing to a better community.

[deleted]

Re: Rocky Linux from CIQ – Hardened

#34
post #25

And more drama from the machine that is being the FUD created over every misstep of RHEL/IBM. And I mean misstep not evil attack on the community. CIQ is the worst of FOSS and a blight causing nonsense arguing rather than actually contributing to a better community.

well that is direct! but from an outsider's point of view.. Isn't the larger picture that nation-states (USA) and federated countries (EU,UK) are requiring secure, signed and authoritative packaging for binaries that are deployed for national critical infrastructure and more. The laws of the EU requiring a public register of origin for software, each binary (?) So despite the direct language there, actually it can get worse, for example hypothetical Irish casino operators make a company that is the title holder to build secure binaries to spec, and it is a massive lawyer-fest and billing machine while things accumulate. Is this possible?

Re: Rocky Linux from CIQ – Hardened

#35
post #32

Earlier quoted context omitted.

Greg kurtzer is not the founder of CentOS. This is FUD he's been regurgitating ever since tricking one of the past CentOS community managers into doing a blog post. If you read the mailing list archives you'll see the truth.

Well that's certainly _one_ way to tell the story, now isn't it, Jonathan.

You can't ban me here for speaking truth like you can on reddit, can you :)

Edit: also, it's literally the true version of the story. Do your own research. It's all public and logged.

Re: Rocky Linux from CIQ – Hardened

#36
post #32

Earlier quoted context omitted.

Well that's certainly _one_ way to tell the story, now isn't it, Jonathan.

You can't ban me here for speaking truth like you can on reddit, can you :) Edit: also, it's literally the true version of the story. Do your own research. It's all public and logged.

[flagged]

Re: Rocky Linux from CIQ – Hardened

#37
post #21

Earlier quoted context omitted.

AlmaLinux is still 100% compatible with RHEL. Any suggestions otherwise is FUD.

This change: https://almalinux.org/blog/future-of-almalinux/ means that Alma is no longer covered by STIGs and other RHEL-specific certifications. Rocky is usually permitted to piggyback on such things. This has directly affected deployments (my team spent time migrating from one o the other as a direct consequence). Compatible, sure, but that is a narrow view of the value CentOS provided.

I cannot speak for AlmaLinux, but it's incorrect to say they're not compatible. They are most definitely still compatible with the upstream distributions. Yes, they have made some changes that make them quite different from the upstreams, but this was their choice and it works for their community and their overall goals. I personally don't see any issues with what they've chosen to do, but that's my extremely narrow view as all clients I work for only use RHEL or Ubuntu.

In regards to STIG, this makes me think of the "scap-security-guide" package that helps the openscap package run tests for compliance like PCI-DSS and HIPPA (among other things). While it is true that we mark ourselves as a "derivative" of RHEL in that package, it doesn't mean we have any certifications or the like and we certainly do not claim to have such certifications. The only thing we actually have officially is a CIS benchmark set at cisecurity.org.

AlmaLinux on the other hand appears to be upstreaming themselves into the content itself, which I think is pretty cool (https://github.com/ComplianceAsCode/content/tree/master/prod...). I've always wanted to see Rocky Linux do the same thing for the past few years, but I don't know what it would take. I've asked our security team some weeks back to look into what has to be done, so maybe something will happen. I just know it will take a long, long time to get things figured out either way. (As much as I'd like to look into it myself and work with the security team, I just don't have the time in between my personal life, day job, and the project.)

Re: Rocky Linux from CIQ – Hardened

#38
post #32

Earlier quoted context omitted.

Well that's certainly _one_ way to tell the story, now isn't it, Jonathan.

You can't ban me here for speaking truth like you can on reddit, can you :) Edit: also, it's literally the true version of the story. Do your own research. It's all public and logged.

[flagged]

Re: Rocky Linux from CIQ – Hardened

#39
post #32

Earlier quoted context omitted.

Well that's certainly _one_ way to tell the story, now isn't it, Jonathan.

You can't ban me here for speaking truth like you can on reddit, can you :) Edit: also, it's literally the true version of the story. Do your own research. It's all public and logged.

[flagged]

Re: Rocky Linux from CIQ – Hardened

#40

as seen on the about page[0] "Named in honor of CentOS co-founder Rocky McGaugh" "Gregory Kurtzer, our CEO and founder," the other CentOS guy. [0] https://ciq.com/company/founding-story/

Greg is not the founder of CentOS and people need to stop believing his lies. He's said this lie so much that even he believes it.
Post reply on HN