In my experience, Debian's security team responds to new CVEs faster than Ubuntu's, but this is purely subjective.
I recently had to move a bunch of Ruby 1.8 applications (where it didn't make financial sense to upgrade them) to new servers. They wouldn't even run on Ubuntu 10.04, where as CentOS 5.5 is still receiving security updates.
You can get supported ruby 1.9.3 on RHEL6 or CentOS6 https://www.softwarecollections.org/en/scls/rhscl/ruby193/ or https://wiki.centos.org/AdditionalResources/Repositories/SCL
Unless they are unwilling to upgrade their rails and using the ruby version as an excuse :) Best of luck to you!
From the ruby193 SCL page you linked to:
"Community Project: Maintained by upstream communities of developers. The software is cared for, but the developers make no commitments to update the repositories in a timely manner."
But if you have a redhat subscription they are fully supported. I should have pointed that out in my first comment though, thanks for bringing it up :)
"All Red Hat Software Collections components are fully supported under Red Hat Enterprise Linux subscription terms of service. Components are functionally complete and intended for production use. " [0]
[0] <https://access.redhat.com/products/Red_Hat_Enterprise_Linux/...
The apps were upgraded where possible but most of them had dependencies that would only run on Ruby 1.8 and have long since been abandoned. We considered rewriting them, but they are only used internally and are most likely going to be shutdown in the next year or so. At least the OS doesn't have any known security issues and is now properly behind a firewall, so that's something.
One of the issues with Ruby 1.8 is that it only compiles against OpenSSL 0.9.x. To compile it from scratch means you need to downgrade that (and a few other deps), which is about as painful as you can imagine. CentOS 5.5 still comes with that and is supported until 2017, where as you would need Ubuntu 8 or lower. I was thinking of creating a LTS version of Ruby 1.8 (a la Rails LTS), but I don't think the need is really there. Businesses who are running Ruby 1.8 have either weighed the risks or simply don't care :/
edit: SCL's aren't supported by RedHat
"All Red Hat Software Collections components are fully supported under Red Hat Enterprise Linux subscription terms of service. Components are functionally complete and intended for production use. " [0]
[0] <https://access.redhat.com/products/Red_Hat_Enterprise_Linux/...
But, we're talking about enterprise here, no young hip startups. Enterprise wants stability over everything else, young hip startups want the new shiny.
There are huge amount of Java 1.3, 1.4, and 1.5 applications still running in Enterprise all around the world with zero issues. Most of the time it doesn't make financial sense to re-build or spend time debugging an upgrade just to have the latest runtime.
"If it ain't broke, don't fix it".
As an aside, J2EE is quite good and very prevalent in enterprise, JBoss, GlassFish, Tomcat, etc...
A paid RHEL subscription will even give you security updates for point releases, in case your needs preclude from upgrading even to backwards compatible versions (e.g. You can use RHEL 6.4 even now, instead of 6.6 or 7.0)
More people know Ubuntu and is why they use it.
When we made our first major Linux deployment this year there's no way I would have picked anything but RHEL/CentOS, we have critical services running on these systems that will be in use for a long time, and playing the upgrade dance in 5 years even (shorter than it sounds) is not an appealing thought.
Given your companies pattern of doing its first deployment of Linux this year, and needing a very long support cycle - I think it's fair to say that you're looking for the equivalent of a traditional UNIX. Slow moving, with lots of stability and strong guarantees on backward compatibility. Red Hat and SUSE focus on that type of "enterprise computing" - they've grown on doing 'UNIX replacement'.
Ubuntu is aimed more at the (as you put it) "hip start-up scene" or at least the area in the technical spectrum that is about new technologies, concepts such as continuous deployment and cloud computing.
The funny thing is most enterprises have a bit of both those types of computing. Some slow-moving "eggs in one basket" services, but also the need for fast-moving innovative areas. So there's room for more than just one sort of distribution.
http://serverfault.com/questions/243343/headless-ubuntu-serv...
The fix is in 12.04-proposed, but was never released, never applied to 14.04 and 15.04 last time I checked. Which is quite ridiculous, IMHO. (Can't find the Launchpad entry right now)
In addition, I think this behavior is not ideal for desktop users either, because (1) spurious errors can also happen in desktop and in that case waiting a few seconds is better than waiting indefinitely, and (2) it is not uncommon to use Wake-on-LAN nowadays.
But I'm not sure this problem is unique to Ubuntu, as Ubuntu shares much of its codebase with Debian. Does anybody know this is also problematic in other distributions?
Ubuntu shares a lot with debian, but grub configuration is one thing that Ubuntu appear to be doing on their own.
https://bugs.launchpad.net/ubuntu/+source/grub2/+bug/1443735
The problem was found (and a fix committed to proposed) in june 2012, but only applied (in -updates) in july 2015. I find that weird, to say the least.
As .service files become normal in the RHEL & Fedora/Debian world, and 14.04 LTS long life cycle runs, upstart is going to look increasingly out of date.
Ubuntu focuses on AppArmor instead.
Exactly. For you. This isn't a con of the actual system.
Seriously though, I've found that most things from the suckless guys are pretty great. st is a perfect terminal; surf would be perfect if it had an ad blocker.
In order to be able to perform URL-level blocking without a proxy; and in order to be able to perform context-sensitive blocking and CSS blocking at all.