Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.debian.user > #270282 > unrolled thread
| Started by | Jeff Peng <jeff@tls-mail.com> |
|---|---|
| First post | 2024-06-20 05:20 +0200 |
| Last post | 2024-06-20 20:20 +0200 |
| Articles | 8 — 6 participants |
Back to article view | Back to linux.debian.user
suggestion of upgrade to 12 Jeff Peng <jeff@tls-mail.com> - 2024-06-20 05:20 +0200
Re: suggestion of upgrade to 12 Greg Wooledge <greg@wooledge.org> - 2024-06-20 05:20 +0200
Re: suggestion of upgrade to 12 Michael <ml@hemathor.de> - 2024-06-20 09:40 +0200
Re: suggestion of upgrade to 12 Jeff Peng <jeff@tls-mail.com> - 2024-06-20 13:10 +0200
Re: suggestion of upgrade to 12 Richard <rrosner5@gmail.com> - 2024-06-20 12:30 +0200
Re: suggestion of upgrade to 12 Jeffrey Walton <noloader@gmail.com> - 2024-06-20 18:30 +0200
Re: suggestion of upgrade to 12 Richard <rrosner5@gmail.com> - 2024-06-21 10:10 +0200
Re: suggestion of upgrade to 12 "Andrew M.A. Cater" <amacater@einval.com> - 2024-06-20 20:20 +0200
| From | Jeff Peng <jeff@tls-mail.com> |
|---|---|
| Date | 2024-06-20 05:20 +0200 |
| Subject | suggestion of upgrade to 12 |
| Message-ID | <IRgv7-4bZR-1@gated-at.bofh.it> |
Hello, I am running a small mailserver with debian 11 for many years. It's quite solid. Though I have read this article: https://www.cherryservers.com/blog/debian-12-bookworm-release do you think there is any need for me to upgrade from 11 to 12? just for the newer software like postfix, dovecot? Thanks.
[toc] | [next] | [standalone]
| From | Greg Wooledge <greg@wooledge.org> |
|---|---|
| Date | 2024-06-20 05:20 +0200 |
| Message-ID | <IRgv7-4bZR-3@gated-at.bofh.it> |
| In reply to | #270282 |
On Thu, Jun 20, 2024 at 11:09:35 +0800, Jeff Peng wrote: > I am running a small mailserver with debian 11 for many years. It's quite > solid. > Though I have read this article: > https://www.cherryservers.com/blog/debian-12-bookworm-release > do you think there is any need for me to upgrade from 11 to 12? > just for the newer software like postfix, dovecot? If you have to ask this question, then you are obviously not in need of newer versions/features. (If you were, then you would have a specific goal in mind, like "I want to upgrade to postfix version X.Y.Z because it has Feature Q.") This means you get to perform the standard balancing act that most system administrators have to deal with: the desire to *not touch it* because it's not broken, versus the need to upgrade it because that's the only way to continue receiving security support. At this time, Debian 11 is still supported, and you may continue running on that version. But at some point, that will no longer be true, and you'll be forced to upgrade it, or have a potentially insecure system. If you're *able* to upgrade to version 12 without losing any of the features you're using, then you may wish to consider investigating the upgrade process. It's generally easy and smooth, but there are always potential issues, so the more you know going in, the better. If upgrading to version 12 would cause you to lose features, then the sooner you know this, the better. That will give you longer to plan how you will handle the end of support for version 11.
[toc] | [prev] | [next] | [standalone]
| From | Michael <ml@hemathor.de> |
|---|---|
| Date | 2024-06-20 09:40 +0200 |
| Message-ID | <IRkyK-4eui-17@gated-at.bofh.it> |
| In reply to | #270282 |
On Thursday, June 20, 2024 5:09:35 AM CEST, Jeff Peng wrote: > I am running a small mailserver with debian 11 for many years. > It's quite solid. > Though I have read this article: > https://www.cherryservers.com/blog/debian-12-bookworm-release > do you think there is any need for me to upgrade from 11 to 12? > just for the newer software like postfix, dovecot? about dovecot: if you have dovecot installed from the dovecot repository, then be aware that dovecot does not (yet) provide a version for bookworm. if you have dovecot installed from the debian repository, then you should be fine. about debian: read - https://www.debian.org/releases/bookworm/amd64/release-notes/ch-upgrading.en.html - https://www.debian.org/releases/bookworm/amd64/release-notes/ch-information.en.html twice! especially chapter 4.5 and 5. greetings...
[toc] | [prev] | [next] | [standalone]
| From | Jeff Peng <jeff@tls-mail.com> |
|---|---|
| Date | 2024-06-20 13:10 +0200 |
| Message-ID | <IRnPX-4gBx-1@gated-at.bofh.it> |
| In reply to | #270291 |
that's nice to know. thanks for all your help. > about dovecot: > if you have dovecot installed from the dovecot repository, then be > aware that dovecot does not (yet) provide a version for bookworm. > if you have dovecot installed from the debian repository, then you > should be fine. > > about debian: > read > - > https://www.debian.org/releases/bookworm/amd64/release-notes/ch-upgrading.en.html > - > https://www.debian.org/releases/bookworm/amd64/release-notes/ch-information.en.html > twice! especially chapter 4.5 and 5. > > greetings...
[toc] | [prev] | [next] | [standalone]
| From | Richard <rrosner5@gmail.com> |
|---|---|
| Date | 2024-06-20 12:30 +0200 |
| Message-ID | <IRndf-4g9d-3@gated-at.bofh.it> |
| In reply to | #270282 |
[Multipart message — attachments visible in raw view] — view raw
The question with Linux isn't if there's a need to update to the latest version (of the distro) like on Windows, but rather what's keeping you from updating? If there's no urgent reason to stick to 11, update. 11 is now oldstable and will become oldoldstable mid next year. Thus, it currently becomes fewer updates - no idea how the situation is with security updates compared to stable. 10 reaches end of life in about a month or so. So that's the timetable you'll need to keep in mind. Of course, right now there isn't anything forcing you to update, you merely need to update within the next two years to keep getting updates. But chances are very low with more conservative distros like Debian that upgrading will have more drawbacks than benefits. Of course it can always be a smart choice to wait for the first one or two dot releases, as they will fix issues previously unnoticed or where the fix wasn't ready on time. But that's all. Am Do., 20. Juni 2024 um 09:58 Uhr schrieb Jeff Peng <jeff@tls-mail.com>: > Hello, > > I am running a small mailserver with debian 11 for many years. It's > quite solid. > Though I have read this article: > https://www.cherryservers.com/blog/debian-12-bookworm-release > do you think there is any need for me to upgrade from 11 to 12? > just for the newer software like postfix, dovecot? > > Thanks. > >
[toc] | [prev] | [next] | [standalone]
| From | Jeffrey Walton <noloader@gmail.com> |
|---|---|
| Date | 2024-06-20 18:30 +0200 |
| Message-ID | <IRsPD-4jvL-1@gated-at.bofh.it> |
| In reply to | #270295 |
On Thu, Jun 20, 2024 at 10:08 AM Richard <rrosner5@gmail.com> wrote:
>
> The question with Linux isn't if there's a need to update to the latest version (of the distro) like on Windows, but rather what's keeping you from updating? If there's no urgent reason to stick to 11, update. 11 is now oldstable and will become oldoldstable mid next year. Thus, it currently becomes fewer updates - no idea how the situation is with security updates compared to stable. 10 reaches end of life in about a month or so. So that's the timetable you'll need to keep in mind. Of course, right now there isn't anything forcing you to update, you merely need to update within the next two years to keep getting updates. But chances are very low with more conservative distros like Debian that upgrading will have more drawbacks than benefits. Of course it can always be a smart choice to wait for the first one or two dot releases, as they will fix issues previously unnoticed or where the fix wasn't ready on time. But that's all.
One additional data point to consider... there are folks who have
exploits written for vulnerabilities that the community does not know
about.
Generally speaking, the older the software, the more exploits are
available. Developers generally don't work on old versions of their
software. Instead, they fix some things, release a new version and
move on. The only chance to fix the vulnerability is move to a newer
version of the software by building it yourself or using the latest
distro release.
Folks who deal in vulnerabilities and exploits adore the old software
because nothing gets fixed, so their exploits continue to work on old
versions of software. As Greg Kroah-Hartman noted: [1]
We have a very bad history of keeping bugs alive for a long time.
Somebody did a check of it, most known bugs live for five years in
systems. These are things that people know and know how to exploit.
They’re not closed. That’s a problem in our infrastructure...
CVE tracking is not the answer because that assumes every exploitable
bug is tagged with a CVE. There are lots of bugs out there that are
not tracked with a CVE, yet are exploitable. See, for example, the
TTY1 layer bug discussed in [1]. It took over 3 years to figure out it
was exploitable and for the patches to be backported.
(I have first hand knowledge of how one firm operates. The firm sells
their exploits to Northrop Grumman Electronic Warfare Division.)
[1] https://thenewstack.io/design-system-can-update-greg-kroah-hartman-linux-security/
Jeff
> Am Do., 20. Juni 2024 um 09:58 Uhr schrieb Jeff Peng <jeff@tls-mail.com>:
>>
>> I am running a small mailserver with debian 11 for many years. It's
>> quite solid.
>> Though I have read this article:
>> https://www.cherryservers.com/blog/debian-12-bookworm-release
>> do you think there is any need for me to upgrade from 11 to 12?
>> just for the newer software like postfix, dovecot?
>>
>> Thanks.
[toc] | [prev] | [next] | [standalone]
| From | Richard <rrosner5@gmail.com> |
|---|---|
| Date | 2024-06-21 10:10 +0200 |
| Message-ID | <IRHvk-4sV1-1@gated-at.bofh.it> |
| In reply to | #270307 |
[Multipart message — attachments visible in raw view] — view raw
That's the beauty of Debian. If the dev doesn't backport a fix, the maintainer might. It's not uncommon. On Thu, Jun 20, 2024, 22:38 Jeffrey Walton <noloader@gmail.com> wrote: > One additional data point to consider... there are folks who have > exploits written for vulnerabilities that the community does not know > about. > > Generally speaking, the older the software, the more exploits are > available. Developers generally don't work on old versions of their > software. Instead, they fix some things, release a new version and > move on. The only chance to fix the vulnerability is move to a newer > version of the software by building it yourself or using the latest > distro release. > > Folks who deal in vulnerabilities and exploits adore the old software > because nothing gets fixed, so their exploits continue to work on old > versions of software. As Greg Kroah-Hartman noted: [1] > > We have a very bad history of keeping bugs alive for a long time. > Somebody did a check of it, most known bugs live for five years in > systems. These are things that people know and know how to exploit. > They’re not closed. That’s a problem in our infrastructure... > > CVE tracking is not the answer because that assumes every exploitable > bug is tagged with a CVE. There are lots of bugs out there that are > not tracked with a CVE, yet are exploitable. See, for example, the > TTY1 layer bug discussed in [1]. It took over 3 years to figure out it > was exploitable and for the patches to be backported. > > (I have first hand knowledge of how one firm operates. The firm sells > their exploits to Northrop Grumman Electronic Warfare Division.) > > [1] > https://thenewstack.io/design-system-can-update-greg-kroah-hartman-linux-security/ > > Jeff >
[toc] | [prev] | [next] | [standalone]
| From | "Andrew M.A. Cater" <amacater@einval.com> |
|---|---|
| Date | 2024-06-20 20:20 +0200 |
| Message-ID | <IRuy5-4kEe-3@gated-at.bofh.it> |
| In reply to | #270282 |
On Thu, Jun 20, 2024 at 11:09:35AM +0800, Jeff Peng wrote: > Hello, > > I am running a small mailserver with debian 11 for many years. It's quite > solid. > Though I have read this article: > https://www.cherryservers.com/blog/debian-12-bookworm-release > do you think there is any need for me to upgrade from 11 to 12? > just for the newer software like postfix, dovecot? > > Thanks. > The last upload for Debian 11 as a point release is scheduled for the end of June: it then goes to LTS. I _definitely_ suggest reading the reading notes and updating to Bookworm. All the very best, Andy
[toc] | [prev] | [standalone]
Back to top | Article view | linux.debian.user
csiph-web