3 ms·
How does RHEL rate in regard to this issue? Isn't that one of Red Hat's selling points?
by raintrees 11y ago
How does RHEL rate in regard to this issue? Isn't that one of Red Hat's selling points?
- danieldk 11y agoRed Hat seems to be very swift when it comes to security updates. They provide reports on this web page: https://www.redhat.com/security/data/metrics/ https://www.redhat.com/security/data/metrics/ Nearly all the vulnerabilities were apparently fixed within one day. This is the report of RHEL 7: https://www.redhat.com/security/data/metrics/summary-rhel7-critical.html https://www.redhat.com/security/data/metrics/summary-rhel7-c... One thing to note is that RHEL comes with far fewer packages than Debian (e.g. Wordpress and phpmyadmin don't seem to be in the main repository), so you may have to rely on slower third-party repositories.
- cpitman 11y agoWhen you actually have a subscription for RHEL, you can also get email notifications whenever security fixes, bug fixes, and/or feature enhancements are released for packages that are installed on your servers. There is some configuration you can do to pick what events you get notified for (like bug fixes only). And if you find yourself managing an enterprise environment, Red Hat Satellite (basically on-premise RHN + promotion/environment/configuration management) tracks what errata are applied to or required by each system and can report on what the gaps are. I work for Red Hat, and making it easy to support Linux is definitely our bread and butter.
- snuxoll 11y agoAnd if you're like me and too cheap to pay for a Red Hat subscription, the CentOS-announce mailing list also announces all the Red Hat errata - you should absolutely be subscribed to this list if you run CentOS in production.