home.social

#rhel — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #rhel, aggregated by home.social.

  1. Das #Cern spart fast 6 Millionen Euro durch Umstieg von #RHEL auf #Debian, um veraltete Hardware weiterzuverwenden. RHEL 9 und 10 erfordern neue Hardware, die das Cern vermeiden will. Die Umstellung auf Debian 15 ist bis 2030 geplant, aktuell läuft Debian 12. golem.de/news/statt-rhel-cern-

  2. Das #Cern spart fast 6 Millionen Euro durch Umstieg von #RHEL auf #Debian, um veraltete Hardware weiterzuverwenden. RHEL 9 und 10 erfordern neue Hardware, die das Cern vermeiden will. Die Umstellung auf Debian 15 ist bis 2030 geplant, aktuell läuft Debian 12. golem.de/news/statt-rhel-cern-

  3. Das #Cern spart fast 6 Millionen Euro durch Umstieg von #RHEL auf #Debian, um veraltete Hardware weiterzuverwenden. RHEL 9 und 10 erfordern neue Hardware, die das Cern vermeiden will. Die Umstellung auf Debian 15 ist bis 2030 geplant, aktuell läuft Debian 12. golem.de/news/statt-rhel-cern-

  4. Das #Cern spart fast 6 Millionen Euro durch Umstieg von #RHEL auf #Debian, um veraltete Hardware weiterzuverwenden. RHEL 9 und 10 erfordern neue Hardware, die das Cern vermeiden will. Die Umstellung auf Debian 15 ist bis 2030 geplant, aktuell läuft Debian 12. golem.de/news/statt-rhel-cern-

  5. Das #Cern spart fast 6 Millionen Euro durch Umstieg von #RHEL auf #Debian, um veraltete Hardware weiterzuverwenden. RHEL 9 und 10 erfordern neue Hardware, die das Cern vermeiden will. Die Umstellung auf Debian 15 ist bis 2030 geplant, aktuell läuft Debian 12. golem.de/news/statt-rhel-cern-

  6. New info and links on sketchesfromahomelab.com/artic

    - A patched kernel for RHEL systems is now available!
    - Added links to the original 2017 commit introducing the #CopyFail bug and to the patch fixing it. Also included a list of the Linux kernel versions containing the patch. Hopefully this will help those that compile their own kernels!
    - Added a link to GrapheneOS's analysis that Android is NOT vulnerable to Copy Fail due to its extensive use of SELinux and its prohibition on setuid/setgid binaries. I know a lot of people were concerned about Android devices, especially older ones, so this is welcome news.

    People needing more information about the patched RHEL kernel can go to:

    access.redhat.com/errata/RHSA-

    #copyfail #cve_2026_31431 #linux #security #rhel

  7. Fresh gist: mitigating CVE-2026-31431 ("Copy Fail") on RHEL 8/9/10 with a tiny Ansible playbook.

    It blacklists algif_aead via a kernel boot arg (initcall_blacklist=algif_aead_init), reboots only when needed, and asserts the mitigation actually stuck after reboot. Idempotent & safe to re-run.

    codeberg.org/Larvitz/gists/src

    #Ansible #RHEL #Linux #InfoSec #SysAdmin #DevOps #CVE #CVE_2026_31431 #copyfail

  8. Friday evening + homelab VM + bad ideas = RHEL 9.7 on ZFS root.

    I patched convert2rhel until it stopped saying no.

    New blog post: blog.hofstede.it/rhel-on-zfs-r

    #Linux #RHEL #ZFS #homelab #unsupported

  9. I need RHEL+Podman for something. But I also really really like ZFS, that I use on my #FreeBSD systems ...

    RHEL 9.7 on a ZFS root 😀

    Note: This is ENTIRELY unsupported and shouldn't be done in a production environment (seriously!) 🤡 😆

    #linux #rhel #redhat #zfs #openzfs #unsupported #sysadmin

  10. So. one of the things that I am busy with, is part of a lab that will be used at conferences and events around RHEL Image mode (bootc), on building compliance and hardening into the base image. Pretty neat stuff.

    You can use OpenSCAP in the Containerfile, and harden the OS before it ever hits hardware. On the other side of it, you get an immutable OS, thats configured to your compliance profile. Pretty cool.

    But its due tomorrow, which is what makes it stressful. :P

    #redhat #rhel #bootc #linux #openscap #compliance

  11. I found out that hardening #AlpineLinux with use of industry standard tools (to make high-level #production #security) is quite different like #OpenSCAP doesn't work as expected and I'm figuring it out. I know #RHEL-based #Linux would be better for this purpose, but I'm taking the challenge. :blobcatwitch:

  12. If you look for a hardening guide for your linux system, I can recommend "The practical linux hardening Guide" by trimstray.

    trimstray.github.io/the-practi

    Why?

    1. It's based on SCAP policies.
    2. It uses standards
    3. It provides you with references and rationals, not just actions

    This will allow you to consider whenever or not you should apply this configuration to your setup.

    #linux #security #infosec #OpenSCAP #hardening #centos #Fedora #RHEL