AlmaLinux OS 9.9 Beta 现已发布!  |  AlmaLinux OS 10.3 Beta 现已发布!  |  Find us at ATO Oct 19 & 20, booth #79  |  全新章程与 2026 年董事会选举

AlmaLinux 的安全保障

AlmaLinux OS是透明、可验证和独立认证的。从签名的软件包和公共勘误表到合规工具和正式认证,以下是我们如何帮助您信任工作背后的系统。

安全通告 提交安全漏洞报告 安全聊天

The AlmaLinux Errata portal listing recent security advisories with their severity and publish date

我们的安全方针

我们在安全方面的一切工作都围绕四个核心理念:透明、可验证、提供合规证明工具、以及独立认证保障。

透明

针对我们发布的每项修复,都会公开发布相应的勘误与安全公告。

可验证的供应链

您可以检查已签名的软件包和软件材料清单。

合规性与强化

使用 OpenSCAP、OVAL 和 CIS 工具集来审计和加固您的系统。

独立认证

FIPS 140-3 validated and Common Criteria certified, with more underway.

我们提供的

These are the building blocks AlmaLinux gives you to secure, verify, and audit your systems, from the advisories we publish to the tooling you run yourself. You can also subscribe to the AlmaLinux 安全邮件列表 to get advisories as soon as they are published.

已签名的包

每个软件包都使用 GPG 密钥签名,并且默认会在在安装时进行验证。

合规性与强化

使用 OpenSCAP 和 SCAP Workbench 指南以及 CIS 基准,对您的系统进行审计和加固。

漏洞数据

Public OVAL streams provide machine-readable vulnerability information for AlmaLinux OS 8, 9, and 10.

软件物料清单

我们的构建系统会生成 SBOM,以实现可追溯性和供应链安全保障。

安全启动

AlmaLinux 支持安全启动,并配有由微软签名的 shim 引导加载程序,因此系统仅会启动受信任的软件。

我们如何应对安全问题

The volume of disclosed vulnerabilities keeps rising, and AI-assisted research, proof-of-concept creation, and public disclosure are accelerating it further. No distribution can promise to fix every vulnerability on every timeline. What we can offer is a clear, consistent process for how we handle them.

Patching from upstream

We follow upstream for most patches. AlmaLinux OS is built from the same sources as the rest of the enterprise Linux ecosystem, so as upstream fixes land we build, test, and publish them. Each security fix ships as an advisory (an ALSA), rated Critical, Important, Moderate, or Low, with machine-readable OVAL and OSV data and an announcement to the security mailing list.

Patching ahead of upstream

Sometimes an issue matters enough to the community that we apply a patch ahead of upstream. These are reviewed and approved by ALESCo, the AlmaLinux Engineering Steering Committee, which guides the technical direction of the distribution. When upstream ships its own fix, we re-align with it. Whenever possible or appropriate, we also send patches that we've released upstream: everyone should benefit from the work of open source. Anyone can request that a patch be considered by raising it in the ALESCo 频道 on chat.almalinux.org. A few examples of patches we have shipped or provided for testing:

Direct reports

How we handle an issue reported directly to us depends on what it affects. We aim to acknowledge reports within 2 to 3 days.

  • OS issues that need coordinated disclosure: email security@almalinux.org so we can coordinate a responsible patch and release.
  • OS issues that do not need coordination: file them at bugs.almalinux.org.
  • Anything that is not the operating system itself, such as ELevate or this website: open an issue on that project's repository.

If a direct report is really an upstream issue, we point you to report it upstream so it is fixed at the source for everyone. Critical issues reported to the linux-distros mailing list are patched on the date of disclosure. See our vulnerability disclosure policy for full details.

独立认证

Formal, third-party certification backs our security work with independent validation. AlmaLinux OS is FIPS 140-3 validated and Common Criteria certified, with more underway.

GPG 密钥

AlmaLinux 使用 GPG 密钥对所有软件包进行签名,dnf 和图形更新工具默认验证这些签名。我们建议在安装软件包之前验证其签名。

AlmaLinux OS 10 / AlmaLinux OS Kitten 10

rsa4096/DEE5C11CC2A1E572 (2024-07-11)
AlmaLinux OS 10 <packager@almalinux.org>
位置: /etc/pki/rpm-gpg/RPM-GPG-KEY-AlmaLinux-10

下载: AlmaLinux ,pgp.mit.edu

EE6D B7B9 8F5B F5ED D9DA 0DE5 DEE5 C11C C2A1 E572

AlmaLinux OS 9

rsa4096/D36CB86CB86B3716 (2022-01-18)
AlmaLinux OS 9 <packager@almalinux.org>
位置: /etc/pki/rpm-gpg/RPM-GPG-KEY-AlmaLinux-9

下载: AlmaLinux ,pgp.mit.edu

BF18 AC28 7617 8908 D6E7 1267 D36C B86C B86B 3716

AlmaLinux OS 8 #2

rsa4096/2AE81E8ACED7258B (2023-10-10)
AlmaLinux OS 8 <packager@almalinux.org>
位置: /etc/pki/rpm-gpg/RPM-GPG-KEY-AlmaLinux

下载: AlmaLinux ,pgp.mit.edu

BC5E DDCA DF50 2C07 7F15 8288 2AE8 1E8A CED7 258B

ELevate

rsa4096/429785E181B961A5 (2021-08-20)
ELevate <packager@almalinux.org>
位置: /etc/pki/rpm-gpg/RPM-GPG-KEY-ELevate

下载: AlmaLinux ,pgp.mit.edu

74E7 F249 EE69 8A4D ACFB 48C8 4297 85E1 81B9 61A5

已过期但仍然是可信密钥。

AlmaLinux OS 8 #1

rsa4096/488FCF7C3ABB34F8 (2021-01-12)
AlmaLinux <packager@almalinux.org>
位置: /etc/pki/rpm-gpg/RPM-GPG-KEY-AlmaLinux

下载: AlmaLinux ,pgp.mit.edu

5E9B 8F56 17B5 066C E920 57C3 488F CF7C 3ABB 34F8

Secure Boot certificates

AlmaLinux 从 8.4 版本开始提供安全启动支持。它的 shim 通过了 官方评论 and is signed by Microsoft. The AlmaLinux shim trusts these certificates:

Current

证书签署人:验证人:Validity
almalinux-sb-cert-3.derAlmaLinux Secure Boot CAAlmaLinux Secure Boot CA14.03.2034

上一页

These certificates have expired but remain trusted.

证书签署人:验证人:Validity
almalinux-sb-cert-1.derAlmaLinux OS FoundationSectigo Public Code Signing CA EV R3630.01.2025
almalinux-sb-cert-2.derAlmaLinux OS FoundationSSL.com EV Code Signing Intermediate CA RSA19.01.2025

Stay in the loop

Report a vulnerability, subscribe for advisories, or talk security with us directly.

保持更新!