Table of Contents
- Title and Copyright Information
- Preface
- 1 About Oracle Linux 9
-
2
New Features and Changes
- Installation and Boot
- Operating System and Software Management
- Infrastructure Services
-
Security
- Enhanced pcscd Configuration with --disable-polkit
- Enhanced pkcs11-tool Output
- CBC Ciphers in crypto-policies
- nettle Library Updated to Version 3.10.1
- Rsyslog Updated to Version 8.2412.0
- OpenSCAP Updated to Version 1.3.11
- Clevis Updated to Version 21
- New Keylime Policy Management Tool
- SELinux Type Assignment for /dev/hfi1_0
- Enhanced SELinux Confinement for System Services
- SCAP Security Guide Updated to 0.1.76
- Keylime HTTPS Revocation Notifications
-
Networking
- NetworkManager Forward Error Correction
- NetworkManager Can Automatically Add Routes to DNS Servers
- NetworkManager Can Set ipv4.dhcp-send-hostname to Default To false
- NetworkManager Includes ip-ping-addresses And ip-ping-timeout Properties
- NetworkManager DHCP Client IPv6-only Preferred Option for DHCPv4
- Kernel and System Libraries
- File Systems and Storage
- High Availability and Clusters
-
Compilers and Development Tools
- maven Module Stream Updated to 3.9
- Maven OpenJDK Updated to Version 21
- Rust Toolset Updated to Version 1.84
- libva Updated to Version 2.22.0
- LLVM Toolset Updated to Version 19.1.7
- llvm-doc Package Update
- zstd Compression for Clang and LLVM
- PCP Updated to Version 6.3.2
- valgrind Updated to Version 3.24.0
- libabigail Updated to Version 2.6
- elfutils Updated to Version 0.192
- Gnu ld Linker Update
- Boost C++ Libraries Updated to Version 1.75.0.
- Go Toolset Updated to Version1.23
- glibc Updated to Version GB18030-2022
- Containers
- Cockpit Web Console
- Support
- 3 Technology Preview
-
4
Deprecated Features
- Installation
- Software Management
- Shell and Command Line
-
Security
- Unprivileged Access to dmesg Output
- OVAL Data Format
- Using update-ca-trust Without Arguments
- Configuring STunnel Clients to Use the Trusted Root CA Files
- NSS Deprecated Algorithms
- pam_ssh_agent_auth
- scap-workbench
- oscap-anaconda-addon
- /etc/system-fips
- libcrypt.so.1
- SHA-1 Algorithm
- SCP Protocol
- OpenSSL Cryptographic Algorithms
- Digest-MD5
- /etc/system-fips File
- libcrypt.so.1
- fapolicyd.rules File
- OpenSSL RSA Encryption Without Padding
- OpenSSL Engines API
- openssl-pkcs11
- Networking
- Kernel
- File Systems and Storage
- High Availability
- Dynamic Programming Languages, Web and Database Servers
- Compilers and Development
- Identity Management and Authentication
- Virtualization
- Containers
- Deprecated Packages
-
5
Known Issues
- Installation Issues
- Virtualization Issues
- Kernel Issues
- (aarch64) Some GUI Elements Aren't Displayed During Installation and Boot Using VGA Output
- Certain SEV Guest Configurations Might Cause Hypervisor CPU Soft-Lockup Warnings
- Systems With Btrfs Fail to Boot in FIPS Mode
- Leapp Upgrade Messages About Unmounted /proc File System
- Openssl Tool Returns Unable to Print EC Key in FIPS Mode
-
6
Package Changes From the Upstream Release
-
Changes to Binary Packages
- Added Binary Packages for BaseOS by Oracle
- Added Binary Packages for AppStream by Oracle
- Added Binary Packages for CodeReady Linux Builder by Oracle
- Modified BaseOS Binary Packages
- Modified Binary Packages for CodeReady Linux Builder by Oracle
- Modified AppStream Binary Packages
- Removed BaseOS Binary Packages
- Removed AppStream Binary Packages
- Removed CodeReady Linux Builder Binary Packages
- Changes to Source Packages
-
Changes to Binary Packages