Enabling Live Patch for Ubuntu

in #linux6 years ago

image.png

While you may already be using unattended-upgrades package to keep your Ubuntu machine up to date, you will find yourself frequently doing reboots to fully patch your system.

Unattended-upgrades will upgrade most packages on your system but when you log in you will frequently see:

*** System restart required ***

Starting with Ubuntu 16.04 a new feature has been offered called Canonical Livepatch Service. This service will allow you to auto-upgrade security updates without requiring a reboot.

"The Livepatch Service intends to address high and critical severity Linux kernel security vulnerabilities, as identified by Ubuntu Security Notices and the CVE tracker. Since there are limitations to the kernel livepatch technology, some Linux kernel code paths cannot be safely patched while running. There may be occasions when the traditional kernel upgrade and reboot might still be necessary."
- Canonical Livepatch F.A.Q.

Canonical Livepatch will patch most security updates while the kernel is running and will not require a reboot. You will still get the "reboot required" messages for some packages but the requirement to reboot will be a lot less frequent and not as critical.

Livepatch is a paid service offered by Canonical but you can enable it for up to three machines for free.

How to install Livepatch

You will first need to create a Canonical account here.

I recommend selecting Ubuntu User unless you have a paid service contract.

You will receive a token that you can use for your installation.

Then you need to install the livepatch module.

sudo snap install canonical-livepatch

Finally, enable livepatch using the token you received in the first step.

sudo canonical-livepatch enable [YOUR NEW TOKEN]

If you want to verify everything is good, use the following command:

canonical-livepatch status --verbose

Sort:  

Quit flagging my post. Flagged!

Thanks for visiting.

Yeah it is useful info, i would have upvoted but... you know!

Posted using Partiko iOS

I expect nothing less from you.

You don't have to expect anything from me, I can do whatever I want!

You can't fly to the moon, can you? I always wanted to do that.

I have flown to the moon before as a matter if fact, it was so cool. An when I arrived i floated down into a monster truck and attended a monster truck crushing event where I bounced and drove over other trucks and crushed them on the moon! Funny you asked, I had the best view of the round earth from up there! lol

I'm more of a CentOS/Redhat/Amazon Linux user and haven't experienced a message like this (probably because I don't update unless I REALLY need to—I ain't got time to fix it, if it breaks haha!). Windows still wins hands down for the least amount of uptime on a server.

Windows have scheduled updates once a month.

Same day as Taco Tuesday.

!giphy tacos



// You can support giphy by using one of your witness votes on untersatz! //

Hmmm, turns out it isn't supported on 19.04:

error executing enable: Livepatchd error: The platform Ubuntu 19.04 is not supported. exiting.

I just set up a 19.04 machine and have not seen that notice, so perhaps it's not an issue? Or perhaps it is only for LTS versions...

Sorry, it is only for LTS versions. When you sign up for an account it says LTS only.

Didn't even know about that function! I guess I need to create a canonical account now... I'll do it when I reinstall Ubuntu on my laptop, made the mistake of installing Ubuntu with UEFI secure boot on now I need to sign kernel modules everytime I update the OS, I've seen some scripts around that do the whole signing thing automatically but I'm not sure how to use them yet...

Do you know if there is any reason to keep UEFI on? Do I lose performance by having it on? Do I lose security by having it off?

Newsteem at work.

High-quality post.

For 0.0001% of steemians.

But, hey. It's on trending page and I'm sure it'll bring many new people on steem.

Sorry for saying this.

Maybe I just have a bad day.

I try to write about a lot of things I am interested in that I think will help others. Not everything will be interesting to everyone. I do think the % is a lot higher than 0.0001%. In fact I think more than that many active Steemian actually responded as sad as that sounds.

What would you like to see on trending (no idea it was there until you said it, I didn’t buy votes)? A lot have been complaining trending has turned into Steem only related posts. I could easily do many of them but everyone else already is.

You're probably right.
Like I said. I have a bad day.
After reading @exyle's post I already feel better, hehe.

No worries, I think a lot of us are.

I’ll check out his post.

Downvoting all u faquas! U can either get along or not, up 2 u i d k! STeEm down again today since that’s what you deserve for those flags u flag flamer u! lol

Did u even cite the source of that rainbow? I went looking for the link to no avail! Did u even take that pic, looks awfully generic?? I didn’t know you were a photographer???? wow!!!!

Generic? Looks pretty unique to me.

I just meant it almost felt like I saw that one before? Just a flat sea and some patchy clouds with a rainbow, not much color, overcast sky. Something about that rainbow though, or double rainbow might I add, might just be an app? I don't know it was just a quick opinion I made yesterday after glancing at the image. My subconscious says there's something up with it!! I think it might be a very unique computer generated image that is for sure!! It looks totally fake to me and I think you just took a random ocean scene and popped a rainbow on there with rainbow love or something like that! lol

I didn’t cite the source of that picture.
I didn’t take that picture.
I am a photographer, not professionally but I own a Canon 5D Mark III with 3 L series lenses and a few others and know how to use it.

Sounds like a mystery. I love mysteries.

Wait a sec if u didn’t take the picture you need to cite that!

As I said, it isn't my picture.

You know full well why you are flagged and will continue to be flagged.

That's the point. If it isn't your picture then whose is it? Why didn't you source it and tell us? I'm confused here? Why did you keep dodging around the question?

I do? I'm pretty sure I don't.
It's one of life's greater mysteries.

I love mysteries.

I'm a proud Ubuntu user. Will try it out once I'm home.

Ubuntu is great, I love using it! 😎