All posts by jzb

10 Years of Let’s Encrypt Certificates

Post Syndicated from jzb original https://lwn.net/Articles/1049965/

Let’s Encrypt has published
a retrospective that covers the decade since it published its first
publicly trusted certificate in September 2015:

In March 2016, we issued our one millionth certificate. Just two years
later, in September 2018, we were issuing a million certificates every
day. In 2020 we reached a billion total certificates issued and as of
late 2025 we’re frequently issuing ten million certificates per
day. We’re now on track to reach a billion active sites, probably
sometime in the coming year.

Kroah-Hartman: Linux CVEs, more than you ever wanted to know

Post Syndicated from jzb original https://lwn.net/Articles/1049963/

Greg Kroah-Hartman is writing
a series of blog posts
about Linux becoming a Certificate
Numbering Authority (CNA):

It’s been almost 2 full years since Linux became a CNA (Certificate
Numbering Authority)
which meant that we (i.e. the kernel.org
community) are now responsible for issuing all CVEs for the Linux
kernel. During this time, we’ve become one of the largest creators of
CVEs by quantity, going from nothing to number 3 in 2024 to number 1
in 2025. Naturally, this has caused some questions about how we are
both doing all of this work, and how people can keep track of it.

So far, Kroah-Hartman has published the introductory post, as well
as a detailed
post about kernel version numbers
that is well worth reading.

[$] Mix and match Linux distributions with Distrobox

Post Syndicated from jzb original https://lwn.net/Articles/1049423/

Linux containers have made it reasonably easy to develop, distribute, and
deploy server applications along with all the distribution dependencies that they
need. For example, anyone can deploy and run a Debian-based PostgreSQL container
on a Fedora Linux host. Distrobox is a project that is designed to
bring the cross-distribution compatibility to the desktop and allow users to
mix-and-match Linux distributions without fussing with dual-booting, virtual
machines, or multiple computers. It is an ideal way to install
additional software on image-based systems, such as Fedora’s Atomic Desktops
or Bazzite, and also
provides a convenient way to move a development environment or
favorite applications to a new system.

Security updates for Wednesday

Post Syndicated from jzb original https://lwn.net/Articles/1049939/

Security updates have been issued by AlmaLinux (abrt and kernel), Debian (libpng1.6, libsoup2.4, pdns-recursor, webkit2gtk, and wordpress), Fedora (imhex, libwebsockets, lunasvg, python3-docs, and python3.14), Mageia (python3 and webkit2), Red Hat (abrt, firefox, mysql8.4, and postgresql:15), Slackware (mozilla), SUSE (gegl, gnutls, go1.24, go1.25, libpng16-16, openssh, postgresql13, python-Jinja2, and sssd), and Ubuntu (fonttools and netty).

[$] Bazzite: a gem for Linux gamers

Post Syndicated from jzb original https://lwn.net/Articles/1046228/

One of the things that has historically stood between Linux and the
fabled “year of the Linux desktop” is its lack of support for video
games. Many users who would have happily abandoned Windows have,
reluctantly, stayed for the video games or had to deal with dual
booting. In the past few years, though, Linux support for
games—including those that only have Windows versions—has
improved dramatically, if one is willing to put the pieces
together. Bazzite, an image-based
Fedora derivative, is a project that aims to let users play games and
use the Linux desktop with almost no assembly required.

Firefox 146 released

Post Syndicated from jzb original https://lwn.net/Articles/1049771/

Version
146.0
of the Firefox web browser has been released. One feature of
particular interest to Linux users is that Firefox now natively
supports fractional scaled displays on Wayland. Firefox Labs has also
been made available to all users even if they opt out of telemetry or
participating in studies. “This means more experimental features
are now available to more people.
“

This release also adds support for Module-Lattice-Based
Key-Encapsulation Mechanism (ML-KEM) for WebRTC. ML-KEM is
“believed to be secure against attackers with large quantum
computers
“. See the release notes for all changes.

Security updates for Tuesday

Post Syndicated from jzb original https://lwn.net/Articles/1049769/

Security updates have been issued by AlmaLinux (kernel, kernel-rt, and webkit2gtk3), Fedora (abrt and mingw-libpng), Mageia (apache and libpng), Oracle (abrt, go-toolset:rhel8, kernel, sssd, and webkit2gtk3), Red Hat (kernel and kernel-rt), SUSE (gimp, gnutls, kubevirt, virt-api-container, virt-controller-container, virt-exportproxy-container, virt-exportserver-container, virt-handler-container, virt-launcher-container, virt-libguestfs-t, and postgresql13), and Ubuntu (gnupg2, python-apt, radare2, and webkit2gtk).

Addressing Linux’s missing PKI infrastructure

Post Syndicated from jzb original https://lwn.net/Articles/1049663/

Jon Seager, VP of engineering for Canonical, has announced
a plan to develop a universal Public Key Infrastructure tool called
upki:

Earlier this year, LWN featured an excellent article titled
“Linux’s missing CRL
infrastructure
“. The article highlighted a number
of key issues surrounding traditional Public Key Infrastructure (PKI),
but critically noted how even the available measures are effectively
ignored by the majority of system-level software on Linux.

One of the motivators for the discussion is that the Online
Certificate Status Protocol (OCSP) will cease to be supported by Let’s
Encrypt. The remaining alternative is to use Certificate Revocation
Lists (CRLs), yet there is little or no support for managing (or even
querying) these lists in most Linux system utilities.

To solve this, I’m happy to share that in partnership with rustls
maintainers Dirkjan Ochtman
and Joe Birr-Pixton, we’re starting the
development of upki: a universal PKI tool. This project initially aims
to close the revocation gap through the combination of a new system
utility and eventual library support for common TLS/SSL libraries such
as OpenSSL, GnuTLS and rustls.

No code is available as of yet, but the announcement indicates that
upki will be available as an opt-in preview for
Ubuntu 26.04 LTS. Thanks to Dirjan Ochtman for the tip.

Security updates for Monday

Post Syndicated from jzb original https://lwn.net/Articles/1049657/

Security updates have been issued by Debian (ffmpeg, krita, lasso, and libpng1.6), Fedora (abrt, cef, chromium, tinygltf, webkitgtk, and xkbcomp), Oracle (buildah, delve and golang, expat, python-kdcproxy, qt6-qtquick3d, qt6-qtsvg, sssd, thunderbird, and valkey), Red Hat (webkit2gtk3), and SUSE (git-bug, go1, and libpng12-0).

Security updates for Friday

Post Syndicated from jzb original https://lwn.net/Articles/1049417/

Security updates have been issued by AlmaLinux (buildah, firefox, gimp:2.8, go-toolset:rhel8, ipa, kea, kernel, kernel-rt, pcs, qt6-qtquick3d, qt6-qtsvg, systemd, and valkey), Debian (chromium and unbound), Fedora (alexvsbus, CuraEngine, fcgi, libcoap, python-kdcproxy, texlive-base, timg, and xpdf), Mageia (digikam, darktable, libraw, gnutls, python-django, unbound, webkit2, and xkbcomp), Oracle (bind, firefox, gimp:2.8, haproxy, ipa, java-25-openjdk, kea, kernel, libsoup3, libssh, libtiff, openssl, podman, qt6-qtsvg, squid, systemd, vim, and xorg-x11-server-Xwayland), Slackware (httpd and libpng), SUSE (chromedriver, kernel, and python-mistralclient), and Ubuntu (cups, linux-azure, linux-gcp, linux-gcp, linux-gke, linux-gkeop, linux-ibm-6.8, linux-iot, and mame).

Alpine Linux 3.23.0 released

Post Syndicated from jzb original https://lwn.net/Articles/1049299/

Version 3.23.0 of Alpine Linux has been released. Notable changes
in this release include an upgrade to version 3.0
of the Alpine
Package Keeper
(apk), and replacing the linux-edge
package with linux-stable:

For years, linux-lts and linux-edge grew apart and developed their
own kernel configs, different architectures, etc.

Now linux-edge gets replaced with linux-stable which has the
identical configuration as linux-lts, but follows the stable releases
instead of the long-term releases (see https://kernel.org/).

The /usr
merge planned for this release has been postponed
; a new timeline
for the change will be published later. See the release
notes
for more information on this release.

cmocka 2.0 released

Post Syndicated from jzb original https://lwn.net/Articles/1049199/

Andreas Schneider has announced
version 2.0
of the cmocka
unit-testing framework for C:

This release represents a major modernization effort, bringing
cmocka firmly into the “modern” C99 era while maintaining the
simplicity and ease of use that users have come to expect.

One of the most significant changes in cmocka 2.0 is the migration
to C99 standard integer types. The LargestIntegralType typedef has
been replaced with intmax_t and uintmax_t from
stdint.h, providing better type safety and portability across
different platforms. Additionally, we’ve adopted the bool type where
appropriate, making the code more expressive and self-documenting.

Using intmax_t and uintmax_t also allows to print
better error messages. So you can now find
e.g. assert_int_equal and assert_uint_equal.

cmocka 2.0 introduces a comprehensive set of type-specific
assertion macros, including `assert_uint_equal()`,
`assert_float_equal()`, and enhanced pointer assertions. The mocking
system has also been significantly improved with type-specific macros
like `will_return_int()` and `will_return_float()`. The same for
parameter checking etc.

LWN covered the
project early in its development in 2013. See the full list of new
features, enhancements, and bug fixes in cmocka 2.0 in the changelog.

Security updates for Thursday

Post Syndicated from jzb original https://lwn.net/Articles/1049251/

Security updates have been issued by AlmaLinux (expat and libxml2), Debian (openvpn and webkit2gtk), Fedora (gi-loadouts, kf6-kcoreaddons, kf6-kguiaddons, kf6-kjobwidgets, kf6-knotifications, kf6-kstatusnotifieritem, kf6-kunitconversion, kf6-kwidgetsaddons, kf6-kxmlgui, nanovna-saver, persepolis, python-ezdxf, python-pyside6, sigil, stb, syncplay, tinyproxy, torbrowser-launcher, ubertooth, and usd), Mageia (cups), SUSE (cups, gegl, icinga2, mozjs128, and Security), and Ubuntu (ghostscript, kernel, linux, linux-aws, linux-aws-5.15, linux-gcp-5.15, linux-hwe-5.15, linux-ibm, linux-ibm-5.15, linux-intel-iotg, linux-intel-iotg-5.15, linux-lowlatency, linux-lowlatency-hwe-5.15, linux-nvidia, linux-nvidia-tegra, linux-nvidia-tegra-5.15, linux-nvidia-tegra-igx, linux-oracle, linux-oracle-5.15, linux-xilinx-zynqmp, linux, linux-aws, linux-aws-hwe, linux-kvm, linux-oracle, linux-aws-fips, linux-fips, linux-aws-fips, linux-fips, linux-gcp-fips, linux-azure-fips, linux-gcp, linux-gcp-4.15, linux-hwe, linux-gcp, linux-gcp-6.8, linux-gke, linux-gkeop, linux-gcp-6.14, linux-raspi, linux-gcp-fips, linux-intel-iot-realtime, linux-realtime, linux-raspi, linux-raspi-realtime, linux-xilinx, and postgresql-14, postgresql-16, postgresql-17).

[$] LWN.net Weekly Edition for December 4, 2025

Post Syndicated from jzb original https://lwn.net/Articles/1047221/

Inside this week’s LWN.net Weekly Edition:

  • Front: Rust in Debian; Python comprehensions; asynchronous Zig; BPF and io_uring; C safety; 6.18 statistics; just.
  • Briefs: Landlock; Let’s Encrypt lifetimes; Last 5.4 kernel; TAB election; AlmaLinux 10.1; FreeBSD 15.0; NixOS 25.11; Django 6.0; Home Assistant 2025.12; PHP 8.5.0; Racket 9.0; Quotes; …
  • Announcements: Newsletters, conferences, security updates, patches, and more.

[$] Just: a command runner

Post Syndicated from jzb original https://lwn.net/Articles/1047715/

Over time, many Linux users wind up with a collection of aliases,
shell scripts, and makefiles to run simple commands (or a series of
commands) that are often used, but challenging to remember and
annoying to type out at length. The just command runner is a
Rust-based utility that just does one thing and does it well: it reads
recipes from a text file (aptly called a “justfile”), and runs the
commands from an invoked recipe. Rather than accumulating a library
of one-off shell scripts over time, just provides a cross-platform tool
with a framework and well-documented syntax for collecting and
documenting tasks that makes it useful for solo users and
collaborative projects.

Security updates for Wednesday

Post Syndicated from jzb original https://lwn.net/Articles/1049103/

Security updates have been issued by Debian (containerd, mako, and xen), Fedora (forgejo, nextcloud, openbao, rclone, restic, and tigervnc), Oracle (firefox, kernel, libtiff, libxml2, and postgresql), SUSE (libecpg6, lightdm-kde-greeter, python-cbor2, python-mistralclient-doc, python315, and python39), and Ubuntu (kdeconnect, linux, linux-aws, linux-realtime, python-django, and unbound).

A final stable kernel update for 5.4

Post Syndicated from jzb original https://lwn.net/Articles/1049059/

Greg Kroah-Hartman has announced the release of the 5.4.302 stable kernel:

This is the LAST 5.4.y release. It is now end-of-life and should not
be used by anyone, anymore. As of this point in time, there are 1539
documented unfixed CVEs for this kernel branch, and that number will
only increase over time as more CVEs get assigned for kernel bugs.

For the curious, Kroah-Hartman has also provided
a list of the unfixed CVEs for 5.4.302.

Let’s Encrypt to reduce certificate lifetimes

Post Syndicated from jzb original https://lwn.net/Articles/1048976/

Let’s Encrypt has announced
that it will be reducing the validity period of its certificates from
90 days to 45 days by 2028:

Most users of Let’s Encrypt who automatically issue certificates
will not have to make any changes. However, you should verify that
your automation is compatible with certificates that have shorter
validity periods.

To ensure your ACME client renews on time, we recommend using ACME
Renewal Information (ARI)
. ARI is a feature we’ve introduced to help
clients know when they need to renew their certificates. Consult your
ACME client’s documentation on how to enable ARI, as it differs from
client to client. If you are a client developer, check out this
integration guide.

If your client doesn’t support ARI yet, ensure it runs on a
schedule that is compatible with 45-day certificates. For example,
renewing at a hardcoded interval of 60 days will no longer be
sufficient. Acceptable behavior includes renewing certificates at
approximately two thirds of the way through the current certificate’s
lifetime.

Manually renewing certificates is not recommended, as it will need
to be done more frequently with shorter certificate lifetimes.

FreeBSD 15.0 released

Post Syndicated from jzb original https://lwn.net/Articles/1048975/

FreeBSD
15.0
has been released. Notable changes in this release include a new
method for installing
the base system using the pkg package manager
, an update
to OpenZFS 2.4.0-rc4,
native support for the inotify(2)
interface, and the addition of Open Container Initiative (OCI) images
to FreeBSD’s release artifacts. See the release
notes
for a full list of changes, hardware
notes
for supported hardware, and check the errata
before installing or upgrading.