If I was looking for a distro with paid support (a la RHEL/Ubuntu) that's also not incredibly behind bleeding edge (maybe not as bleeding edge as Arch, but also not running patched-to-hell-and-back software like Ubuntu), what are my options? Thankfully I'm not personally looking for this at the moment, I'm more than happy being my own sysadmin and running anything from Arch to Fedora CoreOS to OpenSUSE on my machines…
Ubuntu Security Updates Are a Confusing Mess
11–20 of 40 posts
Re: Ubuntu Security Updates Are a Confusing Mess
#12I don't care they're gating this behind a subscription but the fact that they won't even tell you that you're missing an important security update? That's bad. I wonder how many people think they are fully up to date while being vulnerable to known bugs.
They also publish an oval xml for use with openscap tools to get a list of unpatched CVEs. The issue is not enough people know about those tools. https://security-metadata.canonical.com/oval/
Re: Ubuntu Security Updates Are a Confusing Mess
#13If I was looking for a distro with paid support (a la RHEL/Ubuntu) that's also not incredibly behind bleeding edge (maybe not as bleeding edge as Arch, but also not running patched-to-hell-and-back software like Ubuntu), what are my options? Thankfully I'm not personally looking for this at the moment, I'm more than happy being my own sysadmin and running anything from Arch to Fedora CoreOS to OpenSUSE on my machines…
On desktop/laptop? Only Arch. On servers I'd say RHEL/Rocky (don't disable selinux!) or SuSE; and the deployed services in podman or incus.
Otherwise you're building on an operating system which rebuilds a commercial upstream while explicitly refusing to follow that upstream's rules. IBM has lots of experienced lawyers, as I've heard.
It's also slower at releasing updates, including security updates.
------
Sorry SSLy, I can't reply to you directly because I'm rate limited, it's very late here, and I'm not waiting for the rate limit to expire. So here's my reply:
I think previous decisions made by IBM have shown that they're fine at burning some community goodwill for short-term profit. People were called paranoid for worrying about the future of CentOS when it was taken up by Red Hat for "improved maintenance", and look where we are now.
Maybe you're right, but I personally wouldn't want to build anything serious on top of that "maybe". If something happens, lateral migration should theoretically work, of course..
Re: Ubuntu Security Updates Are a Confusing Mess
#14I don't care they're gating this behind a subscription but the fact that they won't even tell you that you're missing an important security update? That's bad. I wonder how many people think they are fully up to date while being vulnerable to known bugs.
They do tell you that you are missing now. On ubuntu 24.04, apt now reports/nags me about security updates behind esm-apps. They also publish an oval xml for use with openscap tools to get a list of unpatched CVEs. The issue is not enough people know about those tools. https://security-metadata.canonical.com/oval/
Re: Ubuntu Security Updates Are a Confusing Mess
#15Is it not possible to fix the one package from the debian sources vs waiting for ubuntu to allow him to get it from them?
Re: Ubuntu Security Updates Are a Confusing Mess
#16If I was looking for a distro with paid support (a la RHEL/Ubuntu) that's also not incredibly behind bleeding edge (maybe not as bleeding edge as Arch, but also not running patched-to-hell-and-back software like Ubuntu), what are my options? Thankfully I'm not personally looking for this at the moment, I'm more than happy being my own sysadmin and running anything from Arch to Fedora CoreOS to OpenSUSE on my machines…
I've heard good things about AlmaLinux but I haven't used it personally. https://almalinux.org
Re: Ubuntu Security Updates Are a Confusing Mess
#17Earlier quoted context omitted.
On desktop/laptop? Only Arch. On servers I'd say RHEL/Rocky (don't disable selinux!) or SuSE; and the deployed services in podman or incus.
I wish people would stop recommending Rocky. It's a ticking time bomb IMHO caused by their decision to not play nicely with Red Hat and go for questionable tactics like renting temporary RHEL instances to download premade source packages, instead of working together as RH asked them to do. Anybody reading this, do yourself a favor and use Alma, or skip the RHEL ecosystem altogether if you don't absolutely need it. Ot…
Of course they could release the code just for the *GPL packages, but it's an option only slightly less bad socially.
Now, I wonder why there's no one rebuilding Ubuntu Pro like folks are rebuilding RHEL.
Re: Ubuntu Security Updates Are a Confusing Mess
#18If I was looking for a distro with paid support (a la RHEL/Ubuntu) that's also not incredibly behind bleeding edge (maybe not as bleeding edge as Arch, but also not running patched-to-hell-and-back software like Ubuntu), what are my options? Thankfully I'm not personally looking for this at the moment, I'm more than happy being my own sysadmin and running anything from Arch to Fedora CoreOS to OpenSUSE on my machines…
Re: Ubuntu Security Updates Are a Confusing Mess
#19I don't care they're gating this behind a subscription but the fact that they won't even tell you that you're missing an important security update? That's bad. I wonder how many people think they are fully up to date while being vulnerable to known bugs.
I rather not have them push an ad to my face when I open the settings.
I had to install Ubuntu on an embedded board last week and the "Ubuntu Pro" ad is like a greyed out tab in the settings widget if I remember correctly. Worse than the Amazon ad they had some decade ago.
Re: Ubuntu Security Updates Are a Confusing Mess
#20I'd argue we wouldn't have Snap [for the better] if their LTS releases weren't visually bound to years... saving overhead they regularly create for cosmetic reasons. Wouldn't have to create it to consolidate platforms if they stopped making them so often! They have three concurrent LTS releases when they need one. Maybe two. 18.04 is the python2 of distributions. Let it go. Having worked in several places that relied…
> Having worked in several places that relied on it... ESM is being the bad kind of enabler.
The business proposition is 10 years of support with minimal package changes. Are you asking them to just stop selling that product?
Fewer LTS releases wouldn't change that core question, since if they never had a 2018 LTS release those users would be on the 2016 release instead.