ZDNET’s key takeaways
- openSUSE Leap is getting an immutable mode.
- openSUSE already contains loads of safety features.
- This addition ought to make Leap one of the safe distros.
I’ve been a fan of SUSE and openSUSE for a very long time. I truly keep in mind SUSE Linux earlier than it was SUSE Enterprise Linux or SUSE Enterprise Linux Desktop. Even again then, the distribution was an influence consumer’s dream come true.
One cause for this was its safety.
openSUSE has been, for a really very long time, one of many safer of the “mainstream” Linux distributions. And in German-speaking nations, openSUSE is quite popular as a consequence of its ties to the German firm SUSE.
Additionally: This Linux distro makes openSUSE accessible to all – even newbies should take a look
Beginning with model 16.1, openSUSE Leap (the secure model of the distro) is including one other layer to its safety that ought to additional elevate it as one of many safer distributions available on the market. That layer is immutable mode.
According to the official openSUSE blog, “Leap 16.1 is the primary Leap launch to supply an Immutable Mode, a transactionally up to date system with a read-only root filesystem. That is primarily what our customers know from Leap Micro, simply built-in immediately into Leap.”
For many who don’t know, Leap Micro is a specialised, light-weight, immutable, and fixed-release working system designed for containerized workloads, edge computing, and virtualized environments. Leap Micro shouldn’t be a desktop OS, however Leap is. And with Leap benefiting from what Micro already has, this may very well be an enormous step ahead.
What’s immutable mode?
First off, the identical weblog mentions that Leap Immutable “is the best way ahead for container and digital machine hosts, edge units and anybody who prefers atomic updates with simple rollback.” It’s the final bit that ought to elevate eyebrows, because the builders intend Leap Immutable not just for specialised deployments however for anybody who prefers atomic updates on the desktop.
Additionally: What is openSUSE and who is it for?
However atomic updates and immutability aren’t precisely the identical factor. Does that imply Leap Immutable will likely be a type of “immutable mild”?
The reply is a convincing “no.” After a little bit of digging, it grew to become clear that Leap Immutable will likely be a totally immutable distribution.
What does that imply?
Additionally: Fedora Kinoite vs. Silverblue: My verdict after testing both immutable Linux distros
First off, immutable mode is a function you may toggle throughout the set up, which suggests you may select which model of openSUSE Leap to make use of: normal or immutable.
Jack Wallen/ZDNETWhen you go along with immutable, what meaning is the basis file system is mounted as read-only. I’ve beforehand mentioned immutability in “Immutable Linux delivers serious security — here are your 5 best options.” Give {that a} learn to seek out out extra.
Primarily, when an OS is immutable, these directories (comparable to /usr and /and so on) are mounted as read-only and can’t be altered. When you had been to by chance run a malicious script on an immutable system, it could be unable to change something in these immutable directories. That’s a critical safety enchancment and can also be the way forward for Linux.
Additionally: 5 reasons to switch to an immutable Linux distro today — and which to try first
However openSUSE Leap doesn’t simply profit from the added safety of immutability, because it already contains loads of security-focused options.
The opposite safety layers
openSUSE was already a extremely safe Linux distribution, due to a number of layers of safety. These layers are as follows.
SELinux
Up till model 15.6, openSUSE used AppArmor as its necessary entry management (MAC) safety function to limit what system sources, recordsdata, and directories applications may entry.
Additionally: I’ve spent years with immutable Linux – RakuOS fixed my biggest annoyance
Beginning with model 16.0, openSUSE made the change to SELinux (Safety-Enhanced Linux), which was created by the NSA (in collaboration with open-source organizations comparable to Crimson Hat) to additional safe Linux programs. SELinux is an extremely highly effective device that labels each file, course of, and port on a system, follows the rule of least privilege to dam actions that aren’t allowed by particular guidelines, and even requires the basis consumer to comply with these guidelines.
Firewall configuration
openSUSE makes use of firewalld as its dynamic firewall administration system, which incorporates zones (predefined belief ranges), runtime vs. everlasting adjustments (adjustments which might be utilized however are eliminated upon reboot vs. adjustments which might be everlasting), and administration instruments (each the command-line device, firewall-cmd, and the GUI app, firewall-config).
Additionally: 5 Linux distros I recommend to help businesses cut costs and boost security
openSUSE’s implementation of firewalld is much like that of most Fedora-based distributions, so it’s well-known for being one of many stronger firewall implementations.
Binary hardening
openSUSE additionally contains binary hardening, which is the gathering of default safety flags and compiler choices which might be used throughout software program compilation to make executable recordsdata and libraries extra resilient to exploits comparable to buffer overflows and reminiscence corruption.
The important thing hardening measures embody:
- Place-independent executables (permit binaries to make use of random reminiscence addresses to make it tougher for hackers to foretell goal areas when utilizing memory-based exploits).
- FORTIFY_SOURCE (retains observe of features that cope with reminiscence strings to stop buffer overflows).
- Stack protector (injects canary values into the stack to detect and halt stack overflow makes an attempt).
- Relocation read-only (marks the International Offset Desk as read-only to stop function-pointer overwriting in stacks).
- Non-executable stack and heap (prevents code execution from particular information areas such because the stack or the heap to stop arbitrary shellcode injection assaults).
Permission profiles
Permission profiles are predefined templates, particularly created to boost safety, that focus on file permissions, possession, and particular execution bits. The aim of those profiles is to centralize management of permissions, implement safety throughout package deal set up and updates, and govern file modes, homeowners, teams, capabilities, and entry management lists (ACLs) for notably delicate directories.
Snapper and Btrfs snapshots
Btrfs snapshots are “moment-in-time” save factors of a file system subvolume, and Snapper is the SUSE device used to mechanically handle these snapshots.
Additionally: One of the most user-friendly Linux distros I’ve ever used is also one of the most secure
With snapshots, it’s attainable to simply roll again a system to a working level, so if one thing had been to go flawed with a system, it may very well be restored from a beforehand working snapshot. With Snapper, it’s attainable to configure when snapshots are taken and what number of snapshots are retained.
In case your system is hacked, you possibly can successfully roll it again to a degree in time previous to the hack after which take motion to stop the hack from taking place once more.
Common supply
Common supply refers back to the repositories utilized by openSUSE, that are the usual Supply RPM Repository and the primary OSS (open-source software program) repository. On top of that, openSUSE is constructed immediately from the supply code from SUSE Enterprise Linux, which ensures enterprise-grade stability and safety.
Put all of it collectively
While you mix immutability with the usual openSUSE safety features, it’s fairly simple to conclude that the distribution will likely be extremely safe. Immutable distributions are already touted as a few of the most safe working programs available on the market, and with openSUSE including an immutable mode to Leap, you may make certain that it should leap forward of the pack with regard to safety.
Additionally: Atomic vs. immutable Linux: Why choose one when these nine distros offer both?
You possibly can obtain an ISO of Leap 16.1, which incorporates immutable mode, from the official openSUSE download server.





