ZDNET’s key takeaways
- openSUSE Leap gets an immutable mode.
- openSUSE already includes many security features.
- This addition should make Leap one of the most secure distros.
I have been a fan of SUSE and openSUSE for a long time. I actually remember SUSE Linux before it was SUSE Enterprise Linux or SUSE Enterprise Linux Desktop. Even then, distribution was a power user’s dream come true.
One reason for this was his safety.
openSUSE was, for a very long time, one of the more secure of the “mainstream” Linux distributions. And in German-speaking countries, openSUSE is quite popular because of its connections with the German company SUSE.
As well: This Linux distro makes openSUSE accessible to everyone – even newbies should check it out
Starting with version 16.1, openSUSE Leap (the stable version of the distro) adds another layer to its security, which should further elevate it as one of the more secure distributions on the market. This layer is immutable mode.
According to the official openSUSE blog, “Leap 16.1 is the first Leap release to offer an immutable mode, a transactionally updated system with a read-only root file system.
For those who don’t know, Leap Micro is a specialized, lightweight, immutable and fixed release operating system designed for containerized workloads, edge computing, and virtualized environments. Leap Micro is not a desktop OS, but Leap is. And with Leap taking advantage of what Micro already has, this could be a big step forward.
What is immutable mode?
First, the same blog mentions that Leap Immutable is “the way forward for container and virtual machine hosts, edge devices and anyone who prefers atomic updates with easy rollback.” It’s that last bit that raises eyebrows, because developers want Leap Immutable not just for specialized deployments, but for anyone who prefers atomic updates on the desktop.
As well: What is openSUSE and who is it for?
But atomic updates and immutability are not exactly the same thing. Does this mean that Leap Immutable will be some kind of “immutable light”?
The answer is a clear “No.” After some digging, it became clear that Leap Immutable will be a fully immutable distribution.
What does that mean?
Also: Fedora Kinoite vs Silverblue: My verdict after testing both immutable Linux distros
First, immutable mode is a feature that you can switch during installation, which means you can choose which version of openSUSE Leap to use: standard or unmodified.
If you go with Immutable, what that means is the root filesystem is mounted as read-only. I’ve discussed immutability before in ” Immutable Linux delivers serious security – here are your 5 best options.” Give this a read to find out more.
Essentially, when an OS is unmodified, these directories (such as /usr and /etc) are mounted as read-only and cannot be modified. If you happened to run a malicious script on an immutable system, it wouldn’t be able to change anything in those immutable directories. This is a serious security improvement and is also the future of Linux.
As well: 5 reasons to switch to an immutable Linux distro today – and what to try first
But openSUSE Leap does not only benefit from the added security of immutability, as it already includes many security-focused features.
The other security layers
openSUSE was already a highly secure Linux distribution, thanks to several layers of security. The layers are as follows.
SELinux
Until version 15.6, openSUSE used AppArmor as its mandatory access control (MAC) security feature to restrict which system resources, files, and directories programs can access.
Also: I spent years with unmodified Linux – RakuOS fixed my biggest annoyance
Starting with version 16.0, openSUSE has made the switch to SELinux (Security-Enhanced Linux), which was created by the NSA (in collaboration with open-source organizations such as Red Hat) to further secure Linux systems. SELinux is an incredibly powerful tool that labels every file, process and port on a system, follows the rule of least privilege to block actions not allowed by specific rules, and even requires the root user to follow those rules.
Firewall configuration
openSUSE uses Firewalld as its dynamic firewall management system, which includes zones (predefined trust levels), runtime vs.
As well: 5 Linux distros I recommend to help businesses reduce costs and strengthen security
OpenSUSE’s implementation of Firewalld is similar to that of most Fedora-based distributions, so it is known to be one of the stronger firewall implementations.
Binary hardening
openSUSE also includes binary hardening, which is the collection of standard security flags and compiler options used during software compilation to make executable files and libraries more resilient to exploits such as buffer overflows and memory corruption.
The key hardness measures include:
- Position independent executable (allows binaries to use random memory addresses to make it harder for hackers to predict target locations when using memory-based exploits).
- FORTIFY_SOURCE (keeps track of functions that deal with memory stripes to avoid buffer overflows).
- Stack Protector (injects canary values into the stack to detect and stop stack overflow attempts).
- Relocation read-only (mark the Global Offset Table as read-only to avoid overriding function pointers and stacks).
- Non-executable stack and heap (prevents execution of code from specific data regions such as the stack or heap to prevent arbitrary shellcode injection attacks).
Permission profiles
Permission profiles are predefined templates, specifically created to improve security, targeting file permissions, ownership, and special execution bits. The purpose of these profiles is to centralize control of permissions, enforce security during package installation and updates, and govern file modes, owners, groups, capabilities, and access control lists (ACLs) for particularly sensitive directories.
Snapper and Btrfs snapshots
Btrfs snapshots are “moment-in-time” save points of a file system subvolume, and Snapper is the SUSE tool used to automatically manage these snapshots.
Also: One of the most user-friendly Linux distros I’ve ever used is also one of the most secure
With snapshots, it is possible to easily restore a system to a working point, so if something goes wrong with a system, it could be restored from a previously working snapshot. With Snapper it is possible to configure when snapshots are taken and how many snapshots are retained.
If your system is hacked, you can effectively roll it back to a point in time before the hack and then take action to prevent the hack from happening again.
Regular source
Regular source refers to the repositories used by openSUSE, which are the standard source RPM repository and the main OSS (open-source software) repository. In addition, openSUSE is built directly from the source code of SUSE Enterprise Linux, which ensures the stability and security of the enterprise.
Put everything together
When you combine immutability with the standard openSUSE security features, it is quite easy to conclude that the distribution will be highly secure. Immutable distributions are already considered some of the most secure operating systems on the market, and with openSUSE adding an immutable mode to Leap, you can be sure that it will jump ahead of the pack in terms of security.
As well: Atomic vs.
You can download an ISO of Leap 16.1, which includes the immutable mode, from the official openSUSE download server.
