Views
13

Your rating
Rate update installation process

Log in to rate this update.
Login

Risk factor
No ratings yet. Be the first to rate this update.

Smooth installs 0%
Minor issues 0%
Major issues 0%

AI enhanced content

Update Summary

Red Hat Enterprise Linux 9.0 introduces major security hardening, updated core components such as OpenSSL 3.0.1 and OpenSSH 8.7p1, and broad platform changes across networking, storage, virtualization, and desktop. It also documents notable bug fixes, deprecations, technology previews, and known issues for RHEL 9.0.

Update Details

Security

  • SHA-1 is deprecated for cryptographic use; RHEL 9 disables SHA-1 signatures by default in most crypto policies, with limited exceptions such as HMAC and interoperability cases.
  • System-wide crypto policies were tightened by disabling older protocols and algorithms including TLS 1.0/1.1, DTLS 1.0, RC4, Camellia, DSA, 3DES, and FFDHE-1024.
  • OpenSSL 3.0.1 adds provider-based crypto, FIPS-aware behavior, and support for newer algorithms and protocols.
  • OpenSSH 8.7p1 adds SFTP-by-default for file transfer, FIDO/U2F support, private key protection in RAM, and a minimal RSA key size option.
  • SELinux policy and defaults were hardened, including improved policy coverage, removal of SELINUX=disabled kernel support via config file alone, and selinuxuser_execmod disabled by default.
  • NSS removes legacy DBM support and raises the minimum RSA key size to 1023 bits.
  • OpenSCAP and SCAP Security Guide were updated, including new profiles and compressed CVE OVAL feeds for compliance scanning.
  • FIPS-related behavior changed across components, including OpenSSL provider handling, openCryptoki token migration requirements, and crypto-policy interactions.

Bug Fixes

  • Anaconda and installer behavior were improved, including automatic network activation, static hostname handling, and fixes for boot order and kickstart workflows.
  • DNF/RPM and package management received updates such as zstd compression, sqlite-based RPM database, weak dependency controls, and modular metadata preservation in createrepo_c.
  • Networking fixes include improved firewalld zone behavior, NetworkManager enhancements, and corrected handling of hostnames and interface naming.
  • Kernel and kdump fixes address crashkernel handling, vmcore capture, module loading, and several architecture-specific issues.
  • Storage and filesystem fixes include multipath improvements, GFS2 format changes, NVMe/TCP support, and LVM device selection behavior.
  • Identity Management and SSSD fixes improve Kerberos, keytab discovery, sudo behavior, and Directory Server authentication handling.
  • Virtualization fixes include QEMU/libvirt updates, virtiofs support, VM snapshot limitations, and guest/device handling improvements.
  • Desktop and web console fixes include GNOME 40 updates, PipeWire audio handling, and Cockpit usability improvements.

New Features

  • GNOME 40 is the default desktop environment, with PipeWire as the default audio service.
  • NetworkManager now stores new connection profiles in keyfile format by default.
  • cgroup v2 is enabled by default in RHEL 9.
  • The GRUB configuration layout is unified across CPU architectures.
  • RHEL for Edge gains Greenboot health checks, rpm-ostree enhancements, and improved image-building capabilities.
  • Image Builder adds filesystem customization and bootable installer image creation.
  • New or updated application streams include Python 3.9, Node.js 16, Ruby 3.0, PHP 8.0, Git 2.31, PostgreSQL 13, MySQL 8.0, MariaDB 10.5, Redis 6.2, and .NET 6.0.
  • Virtualization adds vTPM support, virtiofs, modular libvirt daemons, and QEMU built with Clang.
  • RHEL system roles expand significantly, including firewall, VPN, HA cluster, metrics, and Microsoft SQL Server management roles.

Known Issues

  • Kexec-based installation or reboot does not provide a predictable system state.
  • Some USB-created installation media may not be detected as local media during installation.
  • Kdump may fail without explicit crashkernel reservation or on encrypted targets with insufficient memory.
  • OpenSSL FIPS and PKCS#11 interactions can fail in some TLS scenarios.
  • RHEL 9.0 has several virtualization limitations, including some VM snapshot, NVIDIA/Wayland, and failover NIC issues.
  • Some Identity Management PKINIT scenarios require enabling DEFAULT:SHA1 for compatibility with older or non-RHEL KDCs.
  • Device Mapper Multipath is not supported with NVMe/TCP.
  • Several installer, networking, and desktop issues are documented as known issues for RHEL 9.0.

Hints

  • In-place upgrade is supported from RHEL 8.6 to RHEL 9.0 on selected architectures; direct in-place upgrade from RHEL 7 to RHEL 9 is not supported.
  • To re-enable SHA-1 for compatibility, use update-crypto-policies --set DEFAULT:SHA1 or the LEGACY policy, but this reduces security.
  • To disable SELinux, add selinux=0 to the kernel command line; changing /etc/selinux/config alone is no longer sufficient.
  • NetworkManager now prefers keyfile profiles; ifcfg format remains supported but is deprecated.
  • OpenSSH uses SFTP by default for SCP-style transfers; use -O to force the legacy SCP/RCP protocol if needed.
  • OpenSSL provider selection can affect remote access; enabling a non-default provider may break services such as OpenSSH.
  • For FIPS compliance with openCryptoki, migrate tokens to the new data format before enabling FIPS mode.
  • RHEL 9 installation media is ISO-based; the installation ISO is large and USB media is recommended.
  • The crashkernel=auto boot option is no longer supported in RHEL 9.

Product Information

Vendor: Red Hat

Product: Enterprise Linux Server

Product type: Software

Application category: Utilities

Platform: Linux

Variant: RHEL 9

Version: RHEL 9.0 kernel 5.14.0-70

Vendor release date: May 18, 2022

Original release notes: View on vendor site

Published on updatealert.io: Aug 11, 2026