Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.user > #270282 > unrolled thread

suggestion of upgrade to 12

Started byJeff Peng <jeff@tls-mail.com>
First post2024-06-20 05:20 +0200
Last post2024-06-20 20:20 +0200
Articles 8 — 6 participants

Back to article view | Back to linux.debian.user


Contents

  suggestion of upgrade to 12 Jeff Peng <jeff@tls-mail.com> - 2024-06-20 05:20 +0200
    Re: suggestion of upgrade to 12 Greg Wooledge <greg@wooledge.org> - 2024-06-20 05:20 +0200
    Re: suggestion of upgrade to 12 Michael <ml@hemathor.de> - 2024-06-20 09:40 +0200
      Re: suggestion of upgrade to 12 Jeff Peng <jeff@tls-mail.com> - 2024-06-20 13:10 +0200
    Re: suggestion of upgrade to 12 Richard <rrosner5@gmail.com> - 2024-06-20 12:30 +0200
      Re: suggestion of upgrade to 12 Jeffrey Walton <noloader@gmail.com> - 2024-06-20 18:30 +0200
        Re: suggestion of upgrade to 12 Richard <rrosner5@gmail.com> - 2024-06-21 10:10 +0200
    Re: suggestion of upgrade to 12 "Andrew M.A. Cater" <amacater@einval.com> - 2024-06-20 20:20 +0200

#270282 — suggestion of upgrade to 12

FromJeff Peng <jeff@tls-mail.com>
Date2024-06-20 05:20 +0200
Subjectsuggestion of upgrade to 12
Message-ID<IRgv7-4bZR-1@gated-at.bofh.it>
Hello,

I am running a small mailserver with debian 11 for many years. It's 
quite solid.
Though I have read this article:
https://www.cherryservers.com/blog/debian-12-bookworm-release
do you think there is any need for me to upgrade from 11 to 12?
just for the newer software like postfix, dovecot?

Thanks.

[toc] | [next] | [standalone]


#270283

FromGreg Wooledge <greg@wooledge.org>
Date2024-06-20 05:20 +0200
Message-ID<IRgv7-4bZR-3@gated-at.bofh.it>
In reply to#270282
On Thu, Jun 20, 2024 at 11:09:35 +0800, Jeff Peng wrote:
> I am running a small mailserver with debian 11 for many years. It's quite
> solid.
> Though I have read this article:
> https://www.cherryservers.com/blog/debian-12-bookworm-release
> do you think there is any need for me to upgrade from 11 to 12?
> just for the newer software like postfix, dovecot?

If you have to ask this question, then you are obviously not in need
of newer versions/features.  (If you were, then you would have a specific
goal in mind, like "I want to upgrade to postfix version X.Y.Z because
it has Feature Q.")

This means you get to perform the standard balancing act that most
system administrators have to deal with: the desire to *not touch it*
because it's not broken, versus the need to upgrade it because that's
the only way to continue receiving security support.

At this time, Debian 11 is still supported, and you may continue running
on that version.  But at some point, that will no longer be true, and
you'll be forced to upgrade it, or have a potentially insecure system.

If you're *able* to upgrade to version 12 without losing any of the
features you're using, then you may wish to consider investigating the
upgrade process.  It's generally easy and smooth, but there are always
potential issues, so the more you know going in, the better.

If upgrading to version 12 would cause you to lose features, then the
sooner you know this, the better.  That will give you longer to plan
how you will handle the end of support for version 11.

[toc] | [prev] | [next] | [standalone]


#270291

FromMichael <ml@hemathor.de>
Date2024-06-20 09:40 +0200
Message-ID<IRkyK-4eui-17@gated-at.bofh.it>
In reply to#270282
On Thursday, June 20, 2024 5:09:35 AM CEST, Jeff Peng wrote:
> I am running a small mailserver with debian 11 for many years. 
> It's quite solid.
> Though I have read this article:
> https://www.cherryservers.com/blog/debian-12-bookworm-release
> do you think there is any need for me to upgrade from 11 to 12?
> just for the newer software like postfix, dovecot?

about dovecot:
if you have dovecot installed from the dovecot repository, then be aware 
that dovecot does not (yet) provide a version for bookworm.
if you have dovecot installed from the debian repository, then you should 
be fine.

about debian:
read
- 
https://www.debian.org/releases/bookworm/amd64/release-notes/ch-upgrading.en.html
- 
https://www.debian.org/releases/bookworm/amd64/release-notes/ch-information.en.html
twice! especially chapter 4.5 and 5.

greetings...

[toc] | [prev] | [next] | [standalone]


#270296

FromJeff Peng <jeff@tls-mail.com>
Date2024-06-20 13:10 +0200
Message-ID<IRnPX-4gBx-1@gated-at.bofh.it>
In reply to#270291
that's nice to know. thanks for all your help.

> about dovecot:
> if you have dovecot installed from the dovecot repository, then be 
> aware that dovecot does not (yet) provide a version for bookworm.
> if you have dovecot installed from the debian repository, then you 
> should be fine.
> 
> about debian:
> read
> - 
> https://www.debian.org/releases/bookworm/amd64/release-notes/ch-upgrading.en.html
> - 
> https://www.debian.org/releases/bookworm/amd64/release-notes/ch-information.en.html
> twice! especially chapter 4.5 and 5.
> 
> greetings...

[toc] | [prev] | [next] | [standalone]


#270295

FromRichard <rrosner5@gmail.com>
Date2024-06-20 12:30 +0200
Message-ID<IRndf-4g9d-3@gated-at.bofh.it>
In reply to#270282

[Multipart message — attachments visible in raw view] — view raw

The question with Linux isn't if there's a need to update to the
latest version (of the distro) like on Windows, but rather what's keeping
you from updating? If there's no urgent reason to stick to 11, update. 11
is now oldstable and will become oldoldstable mid next year. Thus, it
currently becomes fewer updates - no idea how the situation is with
security updates compared to stable. 10 reaches end of life in about a
month or so. So that's the timetable you'll need to keep in mind.
Of course, right now there isn't anything forcing you to update, you merely
need to update within the next two years to keep getting updates. But
chances are very low with more conservative distros like Debian that
upgrading will have more drawbacks than benefits. Of course it can always
be a smart choice to wait for the first one or two dot releases, as they
will fix issues previously unnoticed or where the fix wasn't ready on time.
But that's all.

Am Do., 20. Juni 2024 um 09:58 Uhr schrieb Jeff Peng <jeff@tls-mail.com>:

> Hello,
>
> I am running a small mailserver with debian 11 for many years. It's
> quite solid.
> Though I have read this article:
> https://www.cherryservers.com/blog/debian-12-bookworm-release
> do you think there is any need for me to upgrade from 11 to 12?
> just for the newer software like postfix, dovecot?
>
> Thanks.
>
>

[toc] | [prev] | [next] | [standalone]


#270307

FromJeffrey Walton <noloader@gmail.com>
Date2024-06-20 18:30 +0200
Message-ID<IRsPD-4jvL-1@gated-at.bofh.it>
In reply to#270295
On Thu, Jun 20, 2024 at 10:08 AM Richard <rrosner5@gmail.com> wrote:
>
> The question with Linux isn't if there's a need to update to the latest version (of the distro) like on Windows, but rather what's keeping you from updating? If there's no urgent reason to stick to 11, update. 11 is now oldstable and will become oldoldstable mid next year. Thus, it currently becomes fewer updates - no idea how the situation is with security updates compared to stable. 10 reaches end of life in about a month or so. So that's the timetable you'll need to keep in mind. Of course, right now there isn't anything forcing you to update, you merely need to update within the next two years to keep getting updates. But chances are very low with more conservative distros like Debian that upgrading will have more drawbacks than benefits. Of course it can always be a smart choice to wait for the first one or two dot releases, as they will fix issues previously unnoticed or where the fix wasn't ready on time. But that's all.

One additional data point to consider... there are folks who have
exploits written for vulnerabilities that the community does not know
about.

Generally speaking, the older the software, the more exploits are
available. Developers generally don't work on old versions of their
software. Instead, they fix some things, release a new version and
move on. The only chance to fix the vulnerability is move to a newer
version of the software by building it yourself or using the latest
distro release.

Folks who deal in vulnerabilities and exploits adore the old software
because nothing gets fixed, so their exploits continue to work on old
versions of software. As Greg Kroah-Hartman noted: [1]

    We have a very bad history of keeping bugs alive for a long time.
    Somebody did a check of it, most known bugs live for five years in
    systems. These are things that people know and know how to exploit.
    They’re not closed. That’s a problem in our infrastructure...

CVE tracking is not the answer because that assumes every exploitable
bug is tagged with a CVE. There are lots of bugs out there that are
not tracked with a CVE, yet are exploitable. See, for example, the
TTY1 layer bug discussed in [1]. It took over 3 years to figure out it
was exploitable and for the patches to be backported.

(I have first hand knowledge of how one firm operates. The firm sells
their exploits to Northrop Grumman Electronic Warfare Division.)

[1] https://thenewstack.io/design-system-can-update-greg-kroah-hartman-linux-security/

Jeff

> Am Do., 20. Juni 2024 um 09:58 Uhr schrieb Jeff Peng <jeff@tls-mail.com>:
>>
>> I am running a small mailserver with debian 11 for many years. It's
>> quite solid.
>> Though I have read this article:
>> https://www.cherryservers.com/blog/debian-12-bookworm-release
>> do you think there is any need for me to upgrade from 11 to 12?
>> just for the newer software like postfix, dovecot?
>>
>> Thanks.

[toc] | [prev] | [next] | [standalone]


#270339

FromRichard <rrosner5@gmail.com>
Date2024-06-21 10:10 +0200
Message-ID<IRHvk-4sV1-1@gated-at.bofh.it>
In reply to#270307

[Multipart message — attachments visible in raw view] — view raw

That's the beauty of Debian. If the dev doesn't backport a fix, the
maintainer might. It's not uncommon.

On Thu, Jun 20, 2024, 22:38 Jeffrey Walton <noloader@gmail.com> wrote:

> One additional data point to consider... there are folks who have
> exploits written for vulnerabilities that the community does not know
> about.
>
> Generally speaking, the older the software, the more exploits are
> available. Developers generally don't work on old versions of their
> software. Instead, they fix some things, release a new version and
> move on. The only chance to fix the vulnerability is move to a newer
> version of the software by building it yourself or using the latest
> distro release.
>
> Folks who deal in vulnerabilities and exploits adore the old software
> because nothing gets fixed, so their exploits continue to work on old
> versions of software. As Greg Kroah-Hartman noted: [1]
>
>     We have a very bad history of keeping bugs alive for a long time.
>     Somebody did a check of it, most known bugs live for five years in
>     systems. These are things that people know and know how to exploit.
>     They’re not closed. That’s a problem in our infrastructure...
>
> CVE tracking is not the answer because that assumes every exploitable
> bug is tagged with a CVE. There are lots of bugs out there that are
> not tracked with a CVE, yet are exploitable. See, for example, the
> TTY1 layer bug discussed in [1]. It took over 3 years to figure out it
> was exploitable and for the patches to be backported.
>
> (I have first hand knowledge of how one firm operates. The firm sells
> their exploits to Northrop Grumman Electronic Warfare Division.)
>
> [1]
> https://thenewstack.io/design-system-can-update-greg-kroah-hartman-linux-security/
>
> Jeff
>

[toc] | [prev] | [next] | [standalone]


#270311

From"Andrew M.A. Cater" <amacater@einval.com>
Date2024-06-20 20:20 +0200
Message-ID<IRuy5-4kEe-3@gated-at.bofh.it>
In reply to#270282
On Thu, Jun 20, 2024 at 11:09:35AM +0800, Jeff Peng wrote:
> Hello,
> 
> I am running a small mailserver with debian 11 for many years. It's quite
> solid.
> Though I have read this article:
> https://www.cherryservers.com/blog/debian-12-bookworm-release
> do you think there is any need for me to upgrade from 11 to 12?
> just for the newer software like postfix, dovecot?
> 
> Thanks.
>

The last upload for Debian 11 as a point release is scheduled for the end of June: it then goes to LTS.

I _definitely_ suggest reading the reading notes and updating to Bookworm.

All the very best,

Andy 

[toc] | [prev] | [standalone]


Back to top | Article view | linux.debian.user


csiph-web