AlmaLinux OS 9.9 Beta now available!  |  AlmaLinux OS 10.3 Beta now available!  |  Find us at ATO Oct 19 & 20, booth #79  |  New bylaws & the 2026 board election

Seguridad en AlmaLinux

AlmaLinux OS is built to be transparent, verifiable, and independently certified. From signed packages and public errata to compliance tooling and formal certifications, here is how we help you trust the system underneath your work.

Avisos de seguridad Informar de una vulnerabilidad Chat de seguridad

The AlmaLinux Errata portal listing recent security advisories with their severity and publish date

Cómo abordamos la seguridad

Cuatro ideas dan forma a todo lo que hacemos en torno a la seguridad: transparencia, verificación, brindarle las herramientas para demostrar el cumplimiento y respaldarla con una certificación independiente.

Transparencia

Erratas públicas y avisos para cada solución que enviamos.

Cadena de suministro verificable

Paquetes firmados y una Lista de Materiales de Software que puedes consultar.

Cumplimiento y endurecimiento

Herramientas OpenSCAP, OVAL y CIS para auditar y fortalecer tus sistemas.

Certificación independiente

FIPS 140-3 validated and Common Criteria certified, with more underway.

What we provide

These are the building blocks AlmaLinux gives you to secure, verify, and audit your systems, from the advisories we publish to the tooling you run yourself. You can also subscribe to the lista de correo electrónico de AlmaLinux Security to get advisories as soon as they are published.

Paquetes firmados

Cada paquete está firmado con una clave GPG y verificado de forma predeterminada cuando lo instala.

Cumplimiento y endurecimiento

Audit and harden your systems with the OpenSCAP and SCAP Workbench guides and the CIS Benchmark.

Vulnerability data

Public OVAL streams provide machine-readable vulnerability information for AlmaLinux OS 8, 9, and 10.

Lista de Materiales de Software

Nuestro sistema de compilación produce un SBOM para la trazabilidad y la seguridad de la cadena de suministro.

Arranque Seguro

AlmaLinux supports Secure Boot, with a shim signed by Microsoft, so systems boot only trusted software.

Cómo respondemos a los problemas de seguridad

The volume of disclosed vulnerabilities keeps rising, and AI-assisted research, proof-of-concept creation, and public disclosure are accelerating it further. No distribution can promise to fix every vulnerability on every timeline. What we can offer is a clear, consistent process for how we handle them.

Patching from upstream

We follow upstream for most patches. AlmaLinux OS is built from the same sources as the rest of the enterprise Linux ecosystem, so as upstream fixes land we build, test, and publish them. Each security fix ships as an advisory (an ALSA), rated Critical, Important, Moderate, or Low, with machine-readable OVAL and OSV data and an announcement to the security mailing list.

Patching ahead of upstream

Sometimes an issue matters enough to the community that we apply a patch ahead of upstream. These are reviewed and approved by ALESCo, the AlmaLinux Engineering Steering Committee, which guides the technical direction of the distribution. When upstream ships its own fix, we re-align with it. Whenever possible or appropriate, we also send patches that we've released upstream: everyone should benefit from the work of open source. Anyone can request that a patch be considered by raising it in the ALESCo channel on chat.almalinux.org. A few examples of patches we have shipped or provided for testing:

Direct reports

How we handle an issue reported directly to us depends on what it affects. We aim to acknowledge reports within 2 to 3 days.

  • OS issues that need coordinated disclosure: email security@almalinux.org so we can coordinate a responsible patch and release.
  • OS issues that do not need coordination: file them at bugs.almalinux.org.
  • Anything that is not the operating system itself, such as ELevate or this website: open an issue on that project's repository.

If a direct report is really an upstream issue, we point you to report it upstream so it is fixed at the source for everyone. Critical issues reported to the linux-distros mailing list are patched on the date of disclosure. See our vulnerability disclosure policy for full details.

Certificaciones independientes

Formal, third-party certification backs our security work with independent validation. AlmaLinux OS is FIPS 140-3 validated and Common Criteria certified, with more underway.

Claves GPG

AlmaLinux firma todos los paquetes con una clave GPG, verificada por defecto por dnf y herramientas gráficas de actualización. Recomendamos verificar la firma de un paquete antes de instalarlo.

AlmaLinux OS 10 / AlmaLinux OS Kitten 10

rsa4096/DEE5C11CC2A1E572 (2024-07-11)
AlmaLinux OS 10 <packager@almalinux.org>
Ubicación: /etc/pki/rpm-gpg/RPM-GPG-KEY-AlmaLinux-10

Descarga: AlmaLinux ,pgp.mit.edu

EE6D B7B9 8F5B F5ED D9DA 0DE5 DEE5 C11C C2A1 E572

AlmaLinux OS 9

rsa4096/D36CB86CB86B3716 (2022-01-18)
AlmaLinux OS 9 <packager@almalinux.org>
Ubicación: /etc/pki/rpm-gpg/RPM-GPG-KEY-AlmaLinux-9

Descarga: AlmaLinux ,pgp.mit.edu

BF18 AC28 7617 8908 D6E7 1267 D36C B86C B86B 3716

AlmaLinux OS 8 #2

rsa4096/2AE81E8ACED7258B (2023-10-10)
AlmaLinux OS 8 <packager@almalinux.org>
Ubicación: /etc/pki/rpm-gpg/RPM-GPG-KEY-AlmaLinux

Descarga: AlmaLinux ,pgp.mit.edu

BC5E DDCA DF50 2C07 7F15 8288 2AE8 1E8A CED7 258B

ELevate

rsa4096/429785E181B961A5 (2021-08-20)
ELevate <packager@almalinux.org>
Ubicación: /etc/pki/rpm-gpg/RPM-GPG-KEY-ELevate

Descarga: AlmaLinux ,pgp.mit.edu

74E7 F249 EE69 8A4D ACFB 48C8 4297 85E1 81B9 61A5

Caducó, pero sigue siendo una clave de confianza.

AlmaLinux OS 8 #1

rsa4096/488FCF7C3ABB34F8 (2021-01-12)
AlmaLinux <packager@almalinux.org>
Ubicación: /etc/pki/rpm-gpg/RPM-GPG-KEY-AlmaLinux

Descarga: AlmaLinux ,pgp.mit.edu

5E9B 8F56 17B5 066C E920 57C3 488F CF7C 3ABB 34F8

Certificados de arranque seguro

AlmaLinux provides Secure Boot support starting with the 8.4 release. Its shim passes the revisión oficial and is signed by Microsoft. The AlmaLinux shim trusts these certificates:

Actual

CertificateFirmado por:Comprobado por:Validez
almalinux-sb-cert-3.derAlmaLinux Secure Boot CAAlmaLinux Secure Boot CA14.03.2034

Anterior

These certificates have expired but remain trusted.

CertificateFirmado por:Comprobado por:Validez
almalinux-sb-cert-1.derAlmaLinux OS FoundationSectigo Public Code Signing CA EV R3630.01.2025
almalinux-sb-cert-2.derAlmaLinux OS FoundationSSL.com EV Code Signing Intermediate CA RSA19.01.2025

Manténte informado

Informa de una vulnerabilidad, suscríbete para recibir avisos o habla directamente con nosotros sobre seguridad.

¡Manténgase al día!