Views
12

Your rating
Rate update installation process

Log in to rate this update.
Login

Risk factor
No ratings yet. Be the first to rate this update.

Smooth installs 0%
Minor issues 0%
Major issues 0%

AI enhanced content

Update Summary

Red Hat Enterprise Linux 8.0 release notes for RHEL 8 describe the initial platform release, including the 4.18.0-80 kernel, new AppStream/BaseOS packaging, system-wide crypto policies, nftables-based networking, and major installer, storage, and virtualization changes.

Update Details

Security

  • System-wide cryptographic policies are enabled by default for TLS, IPsec, SSH, DNSSEC, and Kerberos, with update-crypto-policies to switch modes.
  • OpenSSH 7.8p1 removes SSHv1, weak ciphers, and DSA by default; UsePrivilegeSeparation=sandbox is mandatory.
  • Libreswan defaults to IKEv2 and removes weak/default algorithms such as 3DES, SHA1, and older Diffie-Hellman groups.
  • SELinux adds new policy capabilities and booleans, including support for map permission checks and getrlimit control.
  • Compile-time hardening flags are applied more consistently, including stack protection, FORTIFY, PIE/PIC, and full CFI on x86_64.
  • RPM now validates the entire package payload before installation, improving protection against corrupted or tampered packages.
  • KCM replaces KEYRING as the default Kerberos credential cache backend, improving container suitability.
  • Session recording with tlog is added for auditing security-sensitive systems.
  • securetty is disabled by default, reducing reliance on static TTY allowlists.
  • CVE-2017-5715 Spectre V2 mitigation defaults to Retpolines on supported Intel systems; IBRS can be selected with spectre_v2=ibrs.

Bug Fixes

  • PackageKit can operate on RPM packages.
  • iscsiadm no longer terminates unexpectedly at higher print levels.
  • multipathd no longer disables paths when WWID lookup fails.
  • ltrace prints large structures correctly.
  • GDB exits with a nonzero status when the last batch command fails.
  • __builtin_clz on IBM Z returns correct values in GCC.
  • QEMU fixes incorrect handling of 8-byte GGTT entries.
  • pcs correctly parses cluster XML status and handles renamed fence-agent parameters.
  • dnf and yum can access repositories correctly when subscription-manager proxy settings are used.
  • cloud-init disk reconnection on Azure is more reliable after stop/deallocate cycles.

New Features

  • AppStream and BaseOS repositories introduce modular content delivery.
  • YUM v4 is based on DNF and supports modular content with improved performance.
  • Image Builder can create customized system images for cloud, VM, ISO, and filesystem targets.
  • The web console adds firewall management, IdM integration, mobile browser support, and VM management.
  • Anaconda supports LUKS2, NVDIMM installation, system purpose, modular package installation, and inst.addrepo.
  • nftables replaces iptables as the default packet-filtering framework, and firewalld uses it by default.
  • GNOME Shell 3.28 and Wayland are the defaults for the desktop session.
  • qemu-kvm 2.12 adds Q35, UEFI boot, vCPU hotplug, guest I/O threading, and sandboxing.
  • XFS supports shared copy-on-write extents by default, and LUKS2 becomes the default encrypted-volume format.
  • Pacemaker 2.0.0 and pcs add Corosync 3, knet, node names, and improved fencing history handling.

Known Issues

  • tlog-enabled users cannot log in to the RHEL web console because the shell must be listed in /etc/shells.
  • auth and authconfig Kickstart commands require the AppStream repository via authselect-compat.
  • reboot --kexec and inst.kexec do not provide a predictable system state.
  • Installation can fail if partitions are busy when the partition table is written.
  • podman checkpoint fails because the bundled CRIU version is too old.
  • libssh does not follow system-wide crypto policy settings.
  • virt-install cannot use NFS locations directly as --location.
  • nftables does not support multi-dimensional IP set types.
  • sssd may return incomplete Active Directory group member lists above 1500 members.
  • IdM server does not work in FIPS mode when a certificate server is installed.

Hints

  • RHEL 8.0 is distributed with kernel 4.18.0-80.
  • The default repositories are BaseOS and AppStream; CodeReady Linux Builder is available for unsupported developer packages.
  • yum is now an alias to dnf; legacy YUM v3 Python APIs are no longer available.
  • nfsnobody is merged into nobody with UID 65534.
  • Network scripts are deprecated; use NetworkManager and nmcli.
  • authselect replaces authconfig for authentication setup.
  • update-crypto-policies --set LEGACY re-enables deprecated TLS 1.0/1.1 when required.
  • For XFS with DAX, disable reflink with mkfs.xfs -m reflink=0.
  • nftables debugging uses xtables-monitor -t or nft monitor trace, not dmesg.
  • systemd-resolved is available only as a Technology Preview.

Product Information

Vendor: Red Hat

Product: Enterprise Linux Server

Product type: Software

Application category: Utilities

Platform: Linux

Variant: RHEL 8

Version: 4.18.0-80

Vendor release date: May 7, 2019

Original release notes: View on vendor site

Published on updatealert.io: Aug 8, 2026