Views
19

Your rating
Rate update installation process

Log in to rate this update.
Login

Risk factor
No ratings yet. Be the first to rate this update.

Smooth installs 0%
Minor issues 0%
Major issues 0%

AI enhanced content

Update Summary

Red Hat Enterprise Linux 10.0 introduces major installer, security, kernel, storage, networking, and container changes. It also documents removed features, technology previews, and known issues for RHEL 10.0.

Update Details

Security

  • System-wide crypto policies, OpenSSL, GnuTLS, NSS, and OpenSSH add post-quantum algorithm support as a Technology Preview.
  • OpenSSH 9.9 adds key-agent forwarding restrictions, FIDO improvements, stronger hardening, and removes DSA keys and pam-ssh-agent.
  • OpenSSL replaces the deprecated ENGINE API with pkcs11-provider for hardware token access.
  • GnuTLS 3.8.9 and NSS 3.112 add TLS 1.3, PBMAC1, and other cryptographic updates; RSA PKCS #1 v1.5 encryption is disallowed by default.
  • SELinux policy and userspace were updated, including new confinement for additional services and audit2allow CIL output support.
  • Keylime 7.12 adds IDevID/IAK support, TLS 1.3 by default, and the new keylime-policy tool.
  • Landlock is introduced as a new Linux Security Module to restrict filesystem access for processes and containers.
  • The default crypto policy rejects TLS RSA key exchange and SHA-1 signatures in TLS contexts.
  • OpenSC 0.26.1 includes fixes for multiple CVEs: CVE-2024-45615, CVE-2024-45616, CVE-2024-45617, CVE-2024-45618, CVE-2024-45619, and CVE-2024-45620.
  • NSS adds ML-DSA and hybrid post-quantum support; a later fix resolves ML-DSA seed corruption after database password changes.

Bug Fixes

  • Installer and image creation fixes include improved virtual network device handling, RDP-based remote access, and better Kickstart support for encrypted DNS and CA certificates.
  • DNF and RPM management improvements include reduced metadata downloads by default, dnf --transient support, and consistent PGP processing via rpm-sequoia.
  • Storage and filesystem fixes include XFS, multipath, NVMe, LUKS, and RAID improvements, plus snapshot and atomic write support.
  • Identity Management fixes include certificate renewal, LDAP timeout handling, replication behavior, and Directory Server reindexing and health-check improvements.
  • Networking fixes include nftables, iptables, firewalld, wpa_supplicant, and NetworkManager improvements, plus VPN TunnelVision mitigation.
  • Virtualization fixes include SEV-SNP, live migration, virtiofs, Windows guest, and cloud platform stability improvements.
  • System roles received many fixes for podman, storage, network, sshd, bootloader, logging, and HA cluster automation.
  • Supportability tools such as sos and crash received fixes for cleanup, obfuscation, and reporting behavior.

New Features

  • RDP replaces VNC for graphical remote access during installation.
  • RHEL image builder and bootc-image-builder gain advanced partitioning, Kickstart injection, and improved image customization.
  • Kea DHCP replaces ISC DHCP, and dnsconfd is added for local DNS caching and DNS-over-TLS setup.
  • The web console gains the cockpit-files file manager.
  • RHEL system roles add new roles and capabilities, including aide, sudo, enhanced podman, systemd, ha_cluster, and storage features.
  • RHEL 10 introduces Python 3.12, Ruby 3.3, Node.js 22, Perl 5.40, PHP 8.3, PostgreSQL 16, MySQL 8.4, MariaDB 10.11, GCC 14.2, glibc 2.39, and systemd 257.
  • The kernel adds Landlock, atomic write, dynamic EFIVARS pstore switching, a Deadline server for CFS starvation protection, and container-oriented networking improvements.
  • Container tooling adds Podman v5 features such as Quadlets for pods, multi-architecture farm builds, OCI artifact support, and persistent podman update changes.
  • RHEL Lightspeed command-line assistant is introduced.
  • Unified Kernel Image (UKI) support is fully available for RHEL cloud and virtualized environments.

Known Issues

  • IdM integrated DNS is unavailable or only partially functional in RHEL 10.0.
  • NSS database password updates previously corrupted ML-DSA seeds; a later advisory fixes this.
  • Encrypted DNS with custom CA can fail during installation when inst.repo or inst.stage2 is used on the kernel command line.
  • Some installer workflows can become unresponsive during final RPM installation or in rescue mode.
  • RHEL 10 cloud and virtualization have several known issues, including NVMe device name changes after reboot and some VM boot or migration limitations.
  • uname -i and uname -p return unknown output; use uname -m instead.
  • The pkcs11-provider does not work correctly in FIPS mode without additional configuration.
  • RHEL 10 WSL images are self-supported and have limitations such as no FIPS mode and no SELinux enforcing mode.

Hints

  • In-place upgrade is supported from RHEL 9.6 to RHEL 10.0 on x86-64-v3, ARMv8.0-A, POWER10, and IBM Z z14; direct upgrade from RHEL 8 to RHEL 10 is not supported.
  • RHEL 10 disk images use predictable network interface names by default, and net.ifnames=0 has been removed from image arguments.
  • The RPM database moved from /var/lib/rpm to /usr/lib/sysimage/rpm.
  • RHEL 10 uses cgroup v2 by default; cgroup v1 and the runc runtime are removed.
  • Postfix now uses LMDB by default; Berkeley DB is no longer available and existing databases may need conversion after upgrade.
  • Custom SELinux modules that reference /var/run should be updated to /run.
  • System V init scripts, authconfig, fips-mode-setup, and several legacy installer and networking options are removed.
  • For RHEL 10 containers, podman system migrate --new-runtime=crun may be needed after upgrade from older releases.
  • The storage.conf file moved to /usr/share/containers.
  • The cockpit-composer package is deprecated in favor of cockpit-image-builder.

Product Information

Vendor: Red Hat

Product: Enterprise Linux Server

Product type: Software

Application category: Utilities

Platform: Linux

Variant: RHEL 10

Version: Red Hat Enterprise Linux 10.0

Vendor release date: May 20, 2025

Original release notes: View on vendor site

Published on updatealert.io: Jul 31, 2026