Skip to main content
Rajan Patel

Rajan Patel

19 posts

Canonical announces live kernel patching for Arm64

Canonical Livepatch now officially supports Arm64, further expanding its security patching automation capabilities. For the first time, Ubuntu on an Arm64 machine can apply critical kernel updates, without service interruption or rebooting. Starting with Ubuntu Core 26 for Arm64, and for Ubuntu Core 20 and onwards for AMD64 machines, a wi

Mythbusting the scope of Livepatch protection

The purpose of this article is to share the technical realities of security patching for the Linux kernel, and the intended scope of the Linux kernel’s livepatch capability. We’ll cover when kernel live patching is most appropriate, and when updating deb and snap packages and then rebooting is the best option.

Live Linux kernel patching with progressive timestamped rollouts

In internet connected environments, where Ubuntu instances can reach livepatch.canonical.com, Livepatch Client supports timestamp-based rollout configurations. Organizations can implement controlled and predictable update pipelines from staging to production environments, without the hassle of deploying a self-hosted Livepatch Server, and

Update Livepatch Client for the newest kernel module signing certificate

The kernel engineering team at Canonical has generated a new module signing certificate on May 16, 2025, and it is embedded in all Ubuntu kernels published after that date. Livepatch Client version 10.11.2 published on June 13, 2025 includes this new certificate. Livepatch Client 10.11.2 or greater is required to successfully Livepatch al

How is Livepatch safeguarded against bad actors?

What safeguards the Livepatch security patching solution against bad actors and malicious code masquerading as an update? Learn about Secure Boot and module signing.

Automated patching for the Linux kernel

To start securely and efficiently, Linux systems follow a carefully orchestrated sequence of steps to initialize firmware and manage services. Applying security patches to the software responsible for some of these early steps of Linux startup often requires a full system reboot. Frequent reboots driven by unplanned critical patching is d

Install FreePBX and Asterisk on Ubuntu 24.04 LTS for security patches until 2036

Deploying FreePBX and Asterisk on a single Ubuntu virtual machine in a public cloud is an ideal solution for personal users and small to medium-sized businesses with voice over IP (VoIP) and fax over IP (FoIP) needs. This setup costs nothing, is scalable and secure, and has daily recovery points with a recovery time measured

How often do you apply security patches on Linux?

Understanding Canonical’s release schedules for software updates and knowing security patching coverage windows are essential pieces of information when defining a security patching strategy.

Deploy fully configured VMs in minutes on Google Cloud, using gcloud CLI and cloud-init

Make reusable deployment templates for Landscape and other applications

Manage FIPS-enabled Linux machines at scale with Landscape 23.03

You or your organisation are tasked with hardening your workstations and servers, where do you begin? Installing Ubuntu and applying all the security patches is a good place to start, but what else is needed? The National Institute of Standards and Technology (NIST), a cybersecurity agency established in 1988, has published a series of se

Create stop motion animation with Dragonframe on Ubuntu

Guillermo del Toro’s Pinocchio was animated using Dragonframe, opening the door for incredible stop motion visual effects. Anyone inspired by the techniques used in Pinocchio can make an animated movie using their iOS or Android device’s camera, connected to Dragonframe running on Ubuntu. Professional animators could go one step further a

3 ways to apply security patches in Linux

There are 3 approaches to applying security patches in Linux: manual patching, via package managers, and automatic updates. If you need security patching that can be automated at scale, and audited on the fly with on-demand reports, Landscape has your bases covered.

Manage Debian, Ubuntu, and derivative Linux distributions with Landscape Scripts

The fastest path towards Linux server management at scale is to leverage technology system administrators know. It is now possible to manage your Debian Bullseye machines with Landscape.

Landscape beta: test the Landscape Server migration to Ubuntu 22.04 LTS

The new Landscape beta makes it easier than ever to administer your entire Ubuntu estate across any architecture, from amd64, riscv, to arm64. Landscape beta’s charms have been rewritten in Juju’s new operator framework, and offer high availability in 3 simple steps.

FIPS certified vs compliant: what’s safer?

Minimise risk by treating the FIPS standard as a baseline, and going above and beyond the baseline to mitigate risk by applying security patches.

An overview of live kernel patching

Learn how Canonical improves security on Linux with live kernel patching. Track Livepatch activity over time in Landscape.

  1. Previous page
  2. 1
  3. 2
  4. Next page