我们的安全方针
我们在安全方面的一切工作都围绕四个核心理念:透明、可验证、提供合规证明工具、以及独立认证保障。
透明
针对我们发布的每项修复,都会公开发布相应的勘误与安全公告。
可验证的供应链
您可以检查已签名的软件包和软件材料清单。
合规性与强化
使用 OpenSCAP、OVAL 和 CIS 工具集来审计和加固您的系统。
独立认证
FIPS 140-3 validated and Common Criteria certified, with more underway.
我们提供的
These are the building blocks AlmaLinux gives you to secure, verify, and audit your systems, from the advisories we publish to the tooling you run yourself. You can also subscribe to the AlmaLinux 安全邮件列表 to get advisories as soon as they are published.
合规性与强化
使用 OpenSCAP 和 SCAP Workbench 指南以及 CIS 基准,对您的系统进行审计和加固。
漏洞数据
Public OVAL streams provide machine-readable vulnerability information for AlmaLinux OS 8, 9, and 10.
我们如何应对安全问题
The volume of disclosed vulnerabilities keeps rising, and AI-assisted research, proof-of-concept creation, and public disclosure are accelerating it further. No distribution can promise to fix every vulnerability on every timeline. What we can offer is a clear, consistent process for how we handle them.
Patching from upstream
We follow upstream for most patches. AlmaLinux OS is built from the same sources as the rest of the enterprise Linux ecosystem, so as upstream fixes land we build, test, and publish them. Each security fix ships as an advisory (an ALSA), rated Critical, Important, Moderate, or Low, with machine-readable OVAL and OSV data and an announcement to the security mailing list.
Patching ahead of upstream
Sometimes an issue matters enough to the community that we apply a patch ahead of upstream. These are reviewed and approved by ALESCo, the AlmaLinux Engineering Steering Committee, which guides the technical direction of the distribution. When upstream ships its own fix, we re-align with it. Whenever possible or appropriate, we also send patches that we've released upstream: everyone should benefit from the work of open source. Anyone can request that a patch be considered by raising it in the ALESCo 频道 on chat.almalinux.org. A few examples of patches we have shipped or provided for testing:
Direct reports
How we handle an issue reported directly to us depends on what it affects. We aim to acknowledge reports within 2 to 3 days.
- OS issues that need coordinated disclosure: email security@almalinux.org so we can coordinate a responsible patch and release.
- OS issues that do not need coordination: file them at bugs.almalinux.org.
- Anything that is not the operating system itself, such as ELevate or this website: open an issue on that project's repository.
If a direct report is really an upstream issue, we point you to report it upstream so it is fixed at the source for everyone. Critical issues reported to the linux-distros mailing list are patched on the date of disclosure. See our vulnerability disclosure policy for full details.
独立认证
Formal, third-party certification backs our security work with independent validation. AlmaLinux OS is FIPS 140-3 validated and Common Criteria certified, with more underway.
GPG 密钥
AlmaLinux 使用 GPG 密钥对所有软件包进行签名,dnf 和图形更新工具默认验证这些签名。我们建议在安装软件包之前验证其签名。
AlmaLinux OS 10 / AlmaLinux OS Kitten 10
EE6D B7B9 8F5B F5ED D9DA 0DE5 DEE5 C11C C2A1 E572
AlmaLinux OS 9
BF18 AC28 7617 8908 D6E7 1267 D36C B86C B86B 3716
AlmaLinux OS 8 #2
BC5E DDCA DF50 2C07 7F15 8288 2AE8 1E8A CED7 258B
ELevate
74E7 F249 EE69 8A4D ACFB 48C8 4297 85E1 81B9 61A5
已过期但仍然是可信密钥。
AlmaLinux OS 8 #1
5E9B 8F56 17B5 066C E920 57C3 488F CF7C 3ABB 34F8
Secure Boot certificates
AlmaLinux 从 8.4 版本开始提供安全启动支持。它的 shim 通过了 官方评论 and is signed by Microsoft. The AlmaLinux shim trusts these certificates:
Current
| 证书 | 签署人: | 验证人: | Validity |
|---|---|---|---|
| almalinux-sb-cert-3.der | AlmaLinux Secure Boot CA | AlmaLinux Secure Boot CA | 14.03.2034 |
上一页
These certificates have expired but remain trusted.
| 证书 | 签署人: | 验证人: | Validity |
|---|---|---|---|
| almalinux-sb-cert-1.der | AlmaLinux OS Foundation | Sectigo Public Code Signing CA EV R36 | 30.01.2025 |
| almalinux-sb-cert-2.der | AlmaLinux OS Foundation | SSL.com EV Code Signing Intermediate CA RSA | 19.01.2025 |
Stay in the loop
Report a vulnerability, subscribe for advisories, or talk security with us directly.

