Views
12

Your rating
Rate update installation process

Log in to rate this update.
Login

Risk factor
No ratings yet. Be the first to rate this update.

Smooth installs 0%
Minor issues 0%
Major issues 0%

AI enhanced content

Update Summary

Red Hat Enterprise Linux 9.1 introduces new features across installer, security, networking, storage, virtualization, and system roles. It also includes notable bug fixes, technology previews, deprecations, and known issues for RHEL 9.1. Reference IDs: RHSA-2022:8832, CVE-2022-29404.

Update Details

Security

  • Keylime remote attestation is introduced for TPM-based integrity monitoring.
  • OpenSSH adds RequiredRSASize and crypto policies now enforce a 2048-bit minimum RSA key length by default.
  • OpenSSL adds rh-allow-sha1-signatures for backward compatibility with SHA-1 signatures.
  • SELinux user-space packages are updated to 3.4, adding parallel relabeling, SHA-256 module checksums, and new policy utilities.
  • SELinux policy now confines additional services including ksm, nm-priv-helper, rhcd, stalld, systemd-network-generator, targetclid, and wg-quick.
  • NSS no longer supports RSA keys shorter than 1023 bits.
  • SCAP Security Guide is rebased to 0.1.63 with new compliance rules and PAM hardening changes.
  • OpenSSH key generation now uses FIPS-compatible interfaces.
  • OpenSSL in FIPS mode now blocks non-approved cryptography and removes support for arbitrary explicit elliptic curves.
  • CVE-2022-29404 changes Apache HTTP Server LimitRequestBody default to 1 GiB.
  • CVE-2022-29404 is referenced in the httpd security update.
  • crypto-policies add support for sntrup761x25519-sha512@openssh.com post-quantum key exchange.
  • fapolicyd 1.1.3 switches hash computation to OpenSSL and adds the PPID subject attribute.
  • The insights-client SELinux policy permissions are added to prevent AVC denials.
  • The staff_u SELinux users can no longer switch to unconfined_r when secure_mode is enabled.

Bug Fixes

  • Installer now consistently installs the latest package versions from repositories.
  • Anaconda now completes installation when network configuration changes in stage2.
  • ReaR fixes multiple recovery issues, including vi infinite loop, PXE output handling, UUID mismatch reporting, NetBackup 9 support, and false symlink warnings.
  • DNF rollback now works for transactions containing Reason Change Action items.
  • Subscription-manager now shows progress during long operations.
  • NetworkManager fixes IPv6 address ordering and cloud-init-related primary IP handling.
  • OpenSSL fixes FFDHE connection failures, Turkish locale crashes, and PKCS #11 token handling.
  • Kernel fixes include socket tagging in mixed cgroup environments, improved list_lru memory use, and several kdump and driver issues.
  • Stratis fixes assertion failures, encrypted pool handling, and pool/device management behavior.
  • pcs fixes validation and command output for fencing, Booth tickets, and resource recreation.
  • glibc fixes errno handling during NSS enumeration and improves sched_getcpu performance.
  • Samba, SSSD, and IdM include multiple fixes for authentication, trust, and directory operations.
  • Podman fixes image pull, SHA-1 key exchange, and registry trust handling.
  • The web console fixes USB device removal, multiple host device attachment, and update reboot automation.

New Features

  • Image Builder now supports GCP uploads, custom /boot sizing, direct container registry pushes, and blueprint customization during image creation.
  • RHEL for Edge now supports fdo-admin service setup with default configuration.
  • NetworkManager supports migration from ifcfg to keyfile format.
  • New module streams are available for PHP 8.1, Ruby 3.1, Node.js 18, and Maven 3.8.
  • Apache HTTP Server is updated to 2.4.53 and split into httpd and httpd-core packages.
  • Chrony, Unbound, FRR, GCC, GDB, Valgrind, SystemTap, LLVM Toolset, Rust Toolset, and Go Toolset are updated.
  • New packages include xmlstarlet, libnvme, keylime, and catatonit in CRB.
  • RHEL system roles gain support for nmstate, IPoIB, SBD fencing, Corosync settings, thin provisioning, cached volumes, and more.
  • Podman 4.2 and Netavark are fully supported, with sigstore signatures available as a technology preview.
  • Virtualization adds SEV-SNP guest support, IBM Z remote attestation, multi-threaded VM memory preallocation, and improved KVM compliance.

Known Issues

  • Kexec-based installation does not provide a predictable system state.
  • Local media installation may not be detected when booting from a USB created with a third-party tool.
  • RHEL installer may fail to process inst.proxy correctly.
  • RHEL installation on IBM Z can fail with multiple LUNs due to kernel command line length limits.
  • NetworkManager may remove manually configured secondary IP addresses when nm-cloud-setup runs.
  • OpenSSH in RHEL 9.0-9.3 is not compatible with OpenSSL 3.2.2 and later unless OpenSSH is updated.
  • Keylime attestation and measured boot policy generation have several known issues.
  • Some PKINIT and cross-realm Kerberos scenarios remain limited or fail in RHEL 9.1.
  • The mlx5 driver can fail in switchdev mode with DMFS on ConnectX-5 adapters.
  • FADump with Secure Boot can cause GRUB out-of-memory on PowerVM.
  • Device Mapper Multipath is not supported with NVMe/TCP.
  • The delayacct feature is disabled by default, so iotop does not show SWAPIN and IO% columns unless enabled.
  • Several virtualization and cloud scenarios have known issues, including SEV-SNP kdump failures and VMware/Nutanix guest problems.

Hints

  • To keep systems supported after upgrading from RHEL 8, update to the latest RHEL 9.1 or enable RHEL 9.0 EUS repositories.
  • OpenSSH RSA key length can be relaxed with a custom crypto-policy subpolicy, but this reduces security.
  • For openCryptoki, migrate tokens to the new FIPS-compliant data format before enabling FIPS mode.
  • NetworkManager migration to keyfile can be done with nmcli connection migrate.
  • To disable GRUB menu auto-hide, run grub2-editenv - unset menu_auto_hide.
  • The subscription-manager progress messages can be disabled with subscription-manager config --rhsm.progress_messages=0.
  • RHEL 9 installer media should be written with supported tools; third-party USB creation tools may require inst.repo= or regenerated media.
  • The httpd-core package now contains the binary and essential files; httpd no longer provides httpd-mmn.
  • For RHEL system roles, fact gathering can be disabled if fact caching is available.
  • The sshd system role can be managed through /etc/ssh/sshd_config, but custom ports require SELinux policy updates.

Product Information

Vendor: Red Hat

Product: Enterprise Linux Server

Product type: Software

Application category: Utilities

Platform: Linux

Variant: RHEL 9

Version: RHEL 9.1 kernel 5.14.0-162

Vendor release date: Nov 15, 2022

Original release notes: View on vendor site

Published on updatealert.io: Aug 11, 2026