Rocky Linux from CIQ – Hardened
ciq.com
ciq.com
* CentOS used to be a free rebranding of RHEL.
* IBM effectively cut off CentOS.
* Rocky Linux is the replacement free RHEL-compatible distro, but is higher effort to maintain than CentOS was.
* "Rocky Linux from CIQ" is a commercial product that is attempting to compete with RHEL, by being lower-cost essentially-RHEL while still satisfying some is-there-a-company-behind-it "compliance" checkboxes that companies require?
* "Rocky Linux from CIQ - Hardened" offers some supposed security improvements that vanilla RHEL doesn't?
CentOS was a binary/functionally compatible build of RHEL without the RHEL branding.
>IBM effectively cut off CentOS.
Red Hat (not IBM) made the decision to end CentOS Linux and move their focus toward CentOS Stream.
>Rocky Linux is the replacement free RHEL-compatible distro...
Rocky Linux is one of many choices for a RHEL-compatible distribution. I would also say CentOS Stream is also a viable choice. It works well from my own personal experience.
>but is higher effort to maintain than CentOS was.
Speaking as the lead of Release Engineering, it does require quite a bit of effort to maintain Rocky Linux. It can be especially time consuming during May and November when releases are scheduled, given that it's volunteer time.
As for CIQ, who knows what they offer or what it is they are actually doing with our distribution. Is it to check a box? Probably, given the way I've seen some companies act around these sorts of things. Does it offer security improvements? Who really even knows.
The fact is that Red Hat killed centos a little after it was acquired by IBM. Who decided this is not something that we'll learn (or even care anyway).
One of the main value propositions of RHEL (and RHL before it) is that each distro version has a fixed ABI throughout (kernel included), making it a valid compilation target for binary-only software. Neither Stream nor even Alma are that.
If Rocky is claiming they're better their either breaking rules or lying. And if the community believes them I'm just going to walk away and talk to the business small medium and large putting their money where it matters, not in more CIQ FUD.
Maybe for current point releases of RHEL and derivatives, building against CentOS Stream may not be that great of an idea. For example, EPEL has different build targets that build against RHEL or CentOS Stream to account for the differences between point releases such as libraries (especially qt libraries!) and also to make the transition easier for their users between point releases when running a dnf update on the next RHEL point release.
As a side tangent: In my opinion, I think vendors should be compiling software against CentOS Stream to ensure compatibility and validation for the next RHEL point release, which should work for the next point release of RHEL, Rocky Linux, AlmaLinux, and even Oracle Linux. I've not seen many vendors do this, though.
With that said, the differences that AlmaLinux have should not cause incompatibilities (and if there are, I can't see them being anything more than minor issues). This means that builds on an AlmaLinux build root should allow the software to still work on the others. Any of the distributions in the family should be fine as build targets.
I don't understand what you mean here? Wasn't Red Hat already owned by IBM when this decision was made?
Looking forward to Rocky 10!
Wasn't (isn't) there another CentOS replacement that was created around the same time? Are they still around? Are there alternatives or is Rocky pretty much it?
AlmaLinux was originally launched by CloudLinux. It was then transferred into a new purpose specific foundation.
I think you're reading into the changes completely wrong. AlmaLinux has power to actually do things, fix issues, contribute real and meaningful changes, all while maintaining 100% compatibility. A lot has been done already, with plenty more to come, with 0 compatibility issues.
In regards to STIG, this makes me think of the "scap-security-guide" package that helps the openscap package run tests for compliance like PCI-DSS and HIPPA (among other things). While it is true that we mark ourselves as a "derivative" of RHEL in that package, it doesn't mean we have any certifications or the like and we certainly do not claim to have such certifications. The only thing we actually have officially is a CIS benchmark set at cisecurity.org.
AlmaLinux on the other hand appears to be upstreaming themselves into the content itself, which I think is pretty cool (https://github.com/ComplianceAsCode/content/tree/master/prod...). I've always wanted to see Rocky Linux do the same thing for the past few years, but I don't know what it would take. I've asked our security team some weeks back to look into what has to be done, so maybe something will happen. I just know it will take a long, long time to get things figured out either way. (As much as I'd like to look into it myself and work with the security team, I just don't have the time in between my personal life, day job, and the project.)
Frankly given I get less issues than my Rocky counterparts working 1 rack over my look of "I told you so", every time, says it all.
- Greg Kurtzer, CIQ's founder and CEO, is the creator of Rocky Linux and the president & owner of the Rocky Enterprise Software Foundation.
- Many of the Rocky Linux maintainers are CIQ employees.
- The EULA for CIQ's commercial version of Rocky Linux is just as restrictive as the terms that Red Hat used to cut off RHEL source code availability. Notably, there's a section saying that customers may not "provide, license, sublicense, sell, resell, rent, lease, share, lend, or otherwise transfer or make available the Software to any third parties, except as expressly permitted by Ctrl IQ in writing".
" .... The license granted in this Section 4 is conditioned upon Customer’s and its Authorized Users ’compliance with this Agreement. To the extent that the Software provided to you is not under an open source license, ...."
missed that part?
Now check the RHEL EULA wrt distributing the SOURCES of the FOSS based binaries.
RHEL's EULA has a similar sentence, "This Agreement establishes the rights and obligations associated with Subscription Services and is not intended to limit your rights to software code under the terms of an open source license." That's what I meant by "just as restrictive". Both services are subscriptions where continued access to the software provided by the subscription is conditional on the subscriber not giving third parties access to the service. CIQ's EULA also says that subscribers may not "access the Software in order to build a competitive product or services", which seems ironic considering their business model.
How deep does this go.
Are they inspecting every line of code in every source repo ?
What happens when I need a package they haven't validated yet ?
"Gregory Kurtzer, our CEO and founder," the other CentOS guy.
If you read the mailing list archives you'll see the truth.
Edit: also, it's literally the true version of the story. Do your own research. It's all public and logged.
I'd be happy to discuss and debate this with you, but you weren't actually there. I tell you what, go find someone else who was actually there at that time, and I'd be happy to discuss it with them publicly.