RLC+ videos

Release notes: Rocky Linux 8.8 and 9.2

This release overview walks through the notable changes in Rocky Linux 9.2 and 8.8. It starts with the Universal Base Image, which has been aligned more closely with the upstream UBI by swapping libcurl for curl-minimal, adding gdb, gdbserver, and gzip, removing packages absent upstream, and cleaning up dangling network configuration. The LVM cloud variants now drop the system.devices file so images boot on any hypervisor, and Azure images are published in the shared image gallery as well as the marketplace.

On the security side, 9.2 rebases the Keylime remote attestation tool to 6.5.2, updates Clevis to accept external tokens, and extends the fapolicyd framework with RPM database filtering so administrators can track what changed in real time. OpenSSL moves to 3.0.7. For Rocky Linux 8.8, the kernel FIPS mode settings now conform to FIPS 140-3, which can break connections to legacy systems using DSA signatures or RSA keys shorter than 2048 bits.

Administrators planning an update learn where Rocky Linux runs, including Oracle Cloud, AWS, Google Cloud, Azure, OpenStack, and QEMU/KVM, along with Vagrant boxes and container images on Docker Hub, quay.io, and git.resf.org. The video closes with the simple upgrade path, dnf upgrade as root, and a reminder to read the release notes for 9.2 gotchas.

Key takeaways

  • The Rocky Linux UBI now mirrors upstream more closely, replacing libcurl with curl-minimal and adding gdb, gdbserver, and gzip.
  • LVM cloud variants remove the system.devices file so images boot on any hypervisor rather than the build hardware.
  • Azure images are now published in the shared image gallery in addition to the marketplace, enabling faster future updates.
  • Rocky Linux 9.2 rebases Keylime to 6.5.2, lets Clevis accept external tokens, and adds RPM database filtering to fapolicyd.
  • Rocky Linux 8.8 updates kernel FIPS mode to FIPS 140-3, which can block DSA signatures and RSA keys under 2048 bits.
  • Upgrading from any prior version to the latest release is done with dnf upgrade as root; check the release notes first.

Questions this video answers

What changed for FIPS mode in Rocky Linux 8.8?

The kernel FIPS mode settings in Rocky Linux 8.8 were updated to conform to FIPS 140-3, which imposes stricter restrictions on cryptographic algorithms, functions, and cipher suites. With FIPS mode enabled, connections to non-conformant systems may fail, for example SSH keys using DSA signatures or RSA keys shorter than 2048 bits, including some legacy CentOS 7 systems.

How do I upgrade to Rocky Linux 9.2 or 8.8?

Run dnf upgrade, or dnf -y upgrade, as the root user to move from 9.1 to 9.2, 8.7 to 8.8, or any earlier version to the latest release. Desktop users can also update through GNOME Software or KDE Discover. Review the release notes beforehand, as 9.2 has a few upgrade-related gotchas.

About this video

We are pleased to announce the general availability of Rocky Linux 9.2. This release is currently available for the x86-64, aarch64, and s390x architectures. Please review the release notes in the Rocky Linux Documentation These notes contain important information including known bugs and more comprehensive details about changes in this version.

Current users of Rocky Linux 9 can upgrade to 9.2 from the terminal via dnf update, or from the desktop with GNOME Software, KDE Discover, etc.

This video is part of the RLC+ playlist. Browse every CIQ video by product and topic.

Transcript

thank you the universal base image for Rocky Linux has been updated to make it more similar to the Upstream Universal base image images uh in particular will be replaced lip curl with curl minimum just a smaller version of curl it has basically all the features that you need in addition we added GDB GDB server as well as gzip and removed video Till's broccoli and DMI to code which aren't present in the Upstream images We additionally added some Network config cleanup to make sure that there aren't any dangling configurations when you could run this image on your system in our lvm Cloud variants we

now remove the Etsy lvm devices system.devices file in order to make the image bootable on any hypervisor that you booted on without being tied to specific Hardware that was used during the build there's also an upstream bug related to this that will be fixed by Upstream in incoming release of ldm our image is more compatible that's the uh that's the takeaway also our Microsoft Azure images are now published in the shared image gallery as well as in the Azure Marketplace which is a the shared image gallery is more similar to aws's just sharing an image or an Ami publicly so you can now go and

search for those from the rocky enterprise software foundation on Azure to subscribe and use those images without going through the marketplace supporting itself and this will enable us in the future to publish images more frequently and get updates to users faster without having to go through the processes that want to consume the latest confidence images and you can always check out rockylinics.org for all the latest details on where to find the cloud images and get the links right from us 90.2 also had some dates and changes related to um foreign for secure boot environments essentially and using TPM in your Hardware so keyline which is

a remote station tool that was added in 9.1 I believe was three base two version 6.5.2 along with that there's a change for clevis which is part of a program that allows for p-lab to do what it does with a testing to the signature of your devices that now accepts external tokens which enables some functionality in Key Lime to facilitate the attestation that it does to make sure that you're really booting what you intend to do so there's there's some really great Innovation actually going on in Rocky and rail 9.2 around making sure that you're you're really not booting a virus and interviewing the the

View full transcriptHide full transcript

binaries that um are actually wanted to do uh I think the only the other thing for security on 9.2 is that the FAA policy D framework which is a framework for um essentially like automation for security alerting and analyzing systems to detect patterns and such it now provides filtering for the RPM database allowing an administrator to utilize the fa policy D framework in order to query the RPM database and get information about what changed when it changed all that sort of stuff in real time to be able to send it to like a steam or some sort of similar security Appliance just uh you know

minor updates remaining compatible we're up to openssl 3.0.7 and Rocky 9.2 which is um that's a bit of a bump but it's uh it's still the open ssl3 library and um yeah should be said compatible and hopefully uh updated and secure for years to come on the rocky 8 side the fips mode settings in the kernel were updated to conform to fips 140-3 which is the current uh most recent federal information processing standard it does introduce some stricter changes to restrictor settings on many cryptographic algorithms functions and Cipher Suites so this means that when you upgrade to Rocky 8.8 you may if you have tips

mode enabled experience trouble connecting to other systems which are not conformant to fit 140-3 the thing that pops out of my head right now is SSH keys with DSA signatures or RSA Keys less than 2048 bits would no longer be available so Legacy systems and abs into S7 system you might have trouble connecting to and from after this change and that's also something you'll have trouble with my industry will get it because those are decisions that were introduced directly into 9.0 when it came out Rocky Linux is available on Oracle Cloud platform uh Amazon AWS Google Cloud platform and event at Microsoft Azure it's also

available for other cloud service providers that maintain their own images um Rocky Linux provides generic cloud images which can work in openstack environments and in qemu kbm environments as well in addition to those we provide vagrant and container images for use and development kubernetes pods Etc those are all available on basically wherever we would like to find Container images they're on Docker Hub quay.io and also available on git.resf.org to upgrade from Rocky Linux 8.7 to 8.8 or from 9.1 to 9.2 or really from any version to the latest version all you have to do is run dnf-y upgrade or dnf upgrade as as the root

user and you'll be on your way to getting the latest version I would recommend that you consult the release notes there are a few gotchas specifically in 9.2 related to upgrades so check out the release notes and they'll end the link below for um some information on what to look at work or what to look for in that we pride ourselves at Rocky Linux um being an Enterprise operating system um is boring right that's the whole point of it and so yeah simple dnf upgrade will get you where you need to go it's just like any other upgrade really anytime you're updating your packages which

you should be frequently right highly recommended and um you know ideally for the vast majority of users you should not notice anything just newer packages newer stuff foreign

Built for scale. Chosen by the world’s best.

2.75M+

Rocky Linux instances

Being used world wide

90%

Of fortune 100 companies

Use CIQ supported technologies

250k

Avg. monthly downloads

Rocky Linux

9

Enterprise products

Spanning the kernel to the orchestrator

Have questions about your infrastructure?

Talk to a CIQ engineer about Rocky Linux, HPC, and AI infrastructure.

Talk to an Expert