Red Hat Enterprise Linux 10.1 (RHEL) features some significant updates to RPM and DNF, two technologies designed to help you manage software installs and updates. The RPM package manager (RPM) creates installation files used to install and uninstall an application, and that can be queried for information about what libraries and binaries the application contains. The dnf command is the tool used on RHEL to search for available applications, and then to install, update, or uninstall them. These are important components of a computer system, so we've worked hard to improve them.

RPM signature improvements

As we prepare for the next generation of security threats and adapt to the new and evolving post-quantum computing world, we've made a number of enhancements to RPM's signature capabilities. RPM signatures are a security feature used with RPM packages to verify the package's authenticity and integrity, ensuring it came from a trusted source and hasn't been tampered with since it was signed. These changes include improvements to support differing formats and algorithms, and adding options that give customers greater control over managing signatures. It offers select signature algorithms of your choice like ML-DSA, which can be used for post-quantum signing.

The introduction of RPMv6 signatures enables multiple signatures per package and adds support for the new, stronger OpenPGP v6 standard. OpenPGP v6 is the latest version of the OpenPGP cryptographic standard, finalized as RFC 9580, which updates the standard with modern cryptographic practices. Customers will also have the freedom to select signature algorithms of their choice.

These new features ultimately enable us to ship packages with a set of signatures utilizing different algorithms currently thought to be post-quantum safe. Should an algorithm get compromised at any point, it can be disabled through a system-wide policy while still ensuring the cryptographic integrity of the software with other signatures, thus providing a smooth user experience to a critical and complex area.

Modularity and DNF

Modularity was a packaging system for managing multiple software versions of applications, and it has been deprecated in favour of simpler and versioned RPMs. DNF now issues deprecation warnings so that you may prepare for modularity's eventual sunsetting.

Better software management

To manage a system well, it's vital for you to be able to analyze and understand what's installed, what's running, and what needs updating. RPM and DNF are two foundational technologies used to create a RHEL release, and to keep it current. The better those tools are, the better you can stay informed about your RHEL machines. The latest updates to them ensures that you've got a powerful and user-friendly software management solution for your most important systems.

For more information about these new enhancements, please review the RHEL documentation.

Product trial

Red Hat Enterprise Linux | Product trial

A version of Red Hat Enterprise Linux that orchestrates hardware resources and runs on physical systems, in the cloud, or as a hypervisor guest.

About the author

Samantha Bueno is an Engineering Manager leading the Software Management team, which is responsible for delivering RPM, DNF, and related technologies in Fedora and RHEL. She has been at Red Hat since November 2012 and in that time, has worked on the Anaconda installer and Image Builder in addition to where she is now.

UI_Icon-Red_Hat-Close-A-Black-RGB

Browse by channel

automation icon

Automation

The latest on IT automation for tech, teams, and environments

AI icon

Artificial intelligence

Updates on the platforms that free customers to run AI workloads anywhere

open hybrid cloud icon

Open hybrid cloud

Explore how we build a more flexible future with hybrid cloud

security icon

Security

The latest on how we reduce risks across environments and technologies

edge icon

Edge computing

Updates on the platforms that simplify operations at the edge

Infrastructure icon

Infrastructure

The latest on the world’s leading enterprise Linux platform

application development icon

Applications

Inside our solutions to the toughest application challenges

Virtualization icon

Virtualization

The future of enterprise virtualization for your workloads on-premise or across clouds