Seitenhistorie
...
Warnung | ||||
---|---|---|---|---|
| ||||
While one could forgo RPM/YUM completely and download/unpack the Tomcat (or Jetty) software outside of any package management and subscribe to Tomcat (or Jetty) announce mailing lists in order to learn about important bugs and security advisories and implement tooling and processes to make updating Tomcat (or Jetty) reliable and painless so you can do it every time an important bug needs patching... it doesn't make much sense to use an "enterprise" GNU/Linux distribution and then run manually installed, unsupported server software on that, for which no security notfications and no automatic updates are available – especially for the only server process on a machine that happens to be a security-relevant service handling passwords and Single Sign-On! |
As such we do not encourage use of RHEL / CentOS / Rocky / Alma Linux as basis for a production Shibboleth IDP service: Either the ACOnet Team or the IDP deployer would have to become responsible for developing developing all system integration, maintenance and security update processes (outside of and in addition to those for the Operating System and the Java Virtual Machine) – which are core features provided by other GNU/Linux distributions such as Debian.
...