

Red Hat Enterprise Linux
By Red Hat, Inc
Typical implementation process for Red Hat Enterprise Linux (RHEL), with each step briefly explained in order and estimated timing where possible:
Assess hardware, network, and storage requirements; identify deployment targets (physical, virtual, cloud)
2. Obtain RHEL Subscription and Installation Media
Create a bootable USB drive, DVD, or prepare PXE/network boot as needed.
4. Installation
Boot from installation media, launch the Anaconda graphical installer, and configure localization, storage, software selection, network, and user accounts. Start the installation and wait for completion.
5. Register and Subscribe System
Register the system with Red Hat Subscription Manager and attach the system to a valid subscription to enable updates and support.
6. System Update and Driver Installation
Update the system to ensure all packages and drivers are current, addressing any hardware-specific needs.
7. Post-Installation Configuration
Configure security settings (firewall, SELinux), network, users, and install additional required software or services.
8. Validation and Testing
Verify system functionality, connectivity, security, and application readiness. Run validation scripts or checklists as needed.
9. Documentation and Handover
Red Hat Enterprise Linux (RHEL) can be extensively customized to fit specific business needs. Here are numerous data points and examples illustrating its flexibility:
Custom Image Creation: RHEL offers an Image Builder service that allows IT teams to create tailored OS images for different deployment targets (cloud, virtual, physical, or edge), including only the components and configurations required for each environment.
CoreOS and Ignition: RHEL CoreOS can be customized at first boot using Ignition files, enabling automated, consistent configuration for clusters and edge deployments.
Installer Customization: During installation, administrators can configure storage, partitioning (standard, LVM, thin provisioning), base environments, network, and user accounts, and set up advanced system settings.
Automation and Management: Integration with Red Hat Ansible Automation Platform and Red Hat Satellite allows for automated configuration, patching, and management across large fleets of systems.
Security and Compliance: RHEL includes customizable security profiles, live kernel patching, SELinux, and compliance tools to meet specific regulatory or organizational requirements.
Performance Tuning: Built-in performance monitoring and tuning tools, along with preset tuning profiles, let businesses optimize RHEL for their unique workloads and hardware.
Flexible Deployment: RHEL supports deployment on a wide range of hardware (x86, ARM, IBM Power, IBM Z), virtual machines, containers, clouds (AWS, Azure, GCP, Oracle, IBM), and edge environments.
Application and Workload Optimization: Specialized RHEL variants are available for SAP, SQL Server, high-performance computing (HPC), and graphics-intensive workstations, each with tailored optimizations.
Migration Tools: Utilities are available for migrating from CentOS Linux or other distributions, enabling custom migration paths and configurations.
Custom Software Packaging: Enterprises can package and deploy their own applications using RPM and integrate with Red Hat’s trusted software supply chain.
Networking and Storage Customization: Advanced options for network configuration, firewall, VPN, storage management (LVM, XFS, thin provisioning), and clustering are available.
Integration with Enterprise Tools: RHEL integrates with enterprise authentication (LDAP, Active Directory), monitoring, backup, and other IT management tools.
Edge and Hybrid Cloud Readiness: Create edge-optimized OS images, automate health checks, and manage updates efficiently for distributed or remote environments.
Developer Ecosystem: Access to the Red Hat Developer program, Universal Base Image for containers, and a vast open-source ecosystem for custom development and deployment.
Certified Hardware and Software: RHEL is certified with a wide range of hardware and professional software, ensuring compatibility with business-critical accessories and applications.
Custom Partitioning and Filesystems: During installation, admins can define custom partition layouts and filesystems to match business continuity and performance needs.
Cloud-Native and Container Support: RHEL can be used as a base for OpenShift and other container platforms, supporting cloud-native development and deployment.
Custom Post-Install Scripts: Admins can run custom scripts or configuration management tools post-installation for further system personalization.
Red Hat Enterprise Linux (RHEL) is a commercial Linux distribution with a subscription-based model that includes several potential additional costs beyond the base subscription fee. Here’s a breakdown of typical costs and what they cover:
Base Subscription: Required for every RHEL installation (physical, virtual, or cloud). The subscription grants access to software, updates, security patches, documentation, and support.
Support Levels: Different tiers are available—Self-support, Standard, and Premium—with increasing levels of support, response time, and access to Red Hat resources.
No Separate Setup Fee: There is typically no separate setup fee charged by Red Hat; setup is included as part of the subscription, which covers installation tools and documentation.
Included in Subscription: Ongoing maintenance (updates, bug fixes, security patches) and technical support are included in the subscription fee for the chosen support level.
Optional Add-ons:
Extended Update Support (EUS): For organizations needing to stay on a specific minor release longer, EUS is available as a paid add-on for certain versions and tiers.
Extended Life-cycle Support (ELS): For continued support after the official end of life, ELS is available as an add-on for eligible editions.
Red Hat Satellite: For advanced lifecycle and infrastructure management, available as a separate paid product.
Technical Account Management: Additional premium support services can be purchased on top of standard subscriptions.
Cloud Deployments:
When running RHEL on cloud platforms (e.g., AWS, Azure, IONOS), subscription fees are often charged per vCPU or core, and may scale with the size and duration of the instance.
New Pricing Models: From 2024, some providers use a tiered, per-core pricing model, so costs scale with resources used.
Red Hat Enterprise Linux (RHEL) offers a range of training and support options for new users, combining official courses, certifications, self-paced resources, and robust technical support:
Official Training and Certification: Red Hat provides hands-on training courses for all experience levels, from Linux fundamentals to advanced system administration and automation. Popular entry-level courses include Red Hat System Administration I (RH124) and II (RH134), and the Red Hat Certified System Administrator (RHCSA) exam. There are also specialized courses for automation, security, cloud, and containerization.
Red Hat Learning Subscription: This subscription grants unlimited access to all Red Hat online courses, learning paths, and certification preparation, supporting continuous learning and skill advancement.
Free Introductory Courses: Red Hat offers free online courses such as Red Hat Enterprise Linux Technical Overview (RH024) and technical overviews for OpenStack, Ansible, containers, and more, making it easy for beginners to get started.
Skill Assessments: Users can take skill assessments to identify knowledge gaps and receive personalized training recommendations.
Third-Party Training Providers: Authorized partners like New Horizons and Nexus Human deliver instructor-led courses, exam preparation, and hands-on labs for RHEL certifications.
Self-Paced and Online Learning: Platforms like Coursera offer introductory courses on RHEL basics, command-line usage, and system administration tasks, suitable for those who prefer self-study.
Documentation and Knowledgebase: Extensive official documentation, how-tos, and access to the Red Hat Knowledgebase are available to all users.
Technical Support: RHEL subscriptions include access to Red Hat’s technical support team. Users can open support cases, access troubleshooting resources, and use the Red Hat Support Tool directly from the command line for knowledgebase searches, case management, and file uploads.
Red Hat Enterprise Linux (RHEL) implements a multi-layered security framework to protect data and ensure compliance across hybrid, cloud, and on-premises environments. Here are the key security measures RHEL puts in place:
SELinux (Security-Enhanced Linux): Mandatory access control is enabled by default, isolating processes, users, and containers to prevent unauthorized access and contain breaches.
System-wide Cryptography Policies: Administrators can enforce strong, consistent cryptographic standards (including FIPS and TLS 1.3) across all applications and services, simplifying compliance and improving security for data in transit and at rest.
Firewall and Network Security: Comprehensive firewall management tools restrict network traffic and reduce attack surfaces, while SSH root password login is disabled by default to prevent brute-force attacks.
Application Allow-listing (fapolicyd): Only approved applications can run, preventing execution of unauthorized or malicious code.
Identity and Access Management: Centralized identity controls, integration with external identity providers, smart card authentication, and support for passwordless authentication (including FIDO2 devices) help secure access to systems and data.
Live Kernel Patching: Apply critical security patches to the kernel without rebooting, reducing downtime and exposure to vulnerabilities.
Integrity Measurement Architecture (IMA): Uses digital hashes and signatures to verify and monitor the integrity of the operating system, detecting unauthorized changes or tampering.
Supply Chain Security: Secure build processes, package signing, and vulnerability scanning protect against supply chain threats and ensure only trusted software is installed.
Automated Compliance and Auditing Tools: Built-in tools and system roles automate the enforcement of security baselines (e.g., CIS Benchmarks), perform vulnerability scans, and maintain detailed audit logs for compliance reporting and incident response.
Container and Virtualization Security: Enhanced isolation and attestation technologies (like Keylime) ensure that containerized and virtual workloads meet strict security and integrity requirements.
Regular Security Updates: RHEL provides timely security patches and updates, with extended support options, to address emerging threats and vulnerabilities.
Red Hat Enterprise Linux (RHEL) follows a predictable and stable release and update lifecycle to ensure long-term support and minimize disruption for enterprise users. Here's a breakdown of how updates are released and managed:
Frequency: Approximately every 3–5 years.
Examples: RHEL 7 (2014), RHEL 8 (2019), RHEL 9 (2022).
These are significant upgrades with new features, architectures, and deprecations.
Frequency: Approximately every 6 months.
Examples: RHEL 8.8, 8.9, 9.3, etc.
These include enhancements, new hardware support, and non-disruptive updates.
Backward compatibility is maintained within a major release.
Delivered as soon as they are available and tested.
Often released via Red Hat's Errata system.
Released regularly through minor updates and errata.
Non-critical improvements are rolled into minor releases.
Red Hat Satellite: For managing updates across many systems.
DNF/YUM: For system-level updates (package-based).
RHEL Repositories: Updates are delivered through structured repos (e.g., BaseOS, AppStream).
Red Hat Subscription Management (RHSM): Controls access to updates and entitlements.
RHEL offers up to 10 years of support per major release:
Full Support (first 5 years): All updates, including new hardware enablement.
Maintenance Support (next 5 years): Critical security fixes and high-priority bug fixes.
Red Hat Enterprise Linux (RHEL) has clear policies around data ownership and portability, which align with Red Hat’s broader enterprise-friendly, open-source philosophy. Here's a breakdown of their approach:
You Own Your Data:
Red Hat does not claim ownership over any data you generate, store, or process using RHEL. The operating system is a platform; you retain full rights and control over your data.
Subscription Model:
RHEL is provided under a subscription license, which governs access to updates, support, and tools—not ownership of user data.
Privacy Commitment:
Red Hat collects minimal telemetry (opt-in for most versions) and is transparent about what data is collected, typically only for:
Product improvement
Support
Security insight (e.g., Insights service)
Vendor Lock-In Avoidance:
RHEL adheres to open standards and tools, making it easier to move your data and workloads between:
Other Linux distributions (with some effort for compatibility)
Container and Cloud Native Support:
With Red Hat OpenShift and Podman, RHEL supports containerization, which improves workload portability across platforms.
Red Hat Enterprise Linux (RHEL) is designed to scale flexibly with organizational needs, whether you're increasing or decreasing your infrastructure footprint. Here's a summary of the key terms and practices for scaling up or down under a Red Hat subscription:
Add More Subscriptions:
You can purchase additional subscriptions at any time to cover more systems, CPUs, or cores.
Core-based pricing (for cloud environments)
Cloud & Hybrid Support:
Or use RHEL images from cloud marketplaces, which are billed on a pay-as-you-go basis (no need to manage your own subscription).
Tools like Red Hat Satellite, Ansible, and Red Hat Insights help automate provisioning and configuration as you scale up.
Subscriptions are typically annual, so reductions take effect at the next renewal cycle.
This is useful for rebalancing licenses across departments, data centers, or cloud environments.
Red Hat Enterprise Linux (RHEL) operates on a subscription-based model governed by the Red Hat Enterprise Agreement. Here are the key terms and conditions for contract (subscription) renewal and cancellation, with supporting data points:
Term-Based Subscriptions: RHEL subscriptions are typically sold in one- or three-year terms23. The term begins on the start date specified in the order form and ends at the expiration of the service term unless terminated earlier.
Automatic Renewal: Subscriptions generally automatically renew for successive terms of the same duration as the original, unless either party provides written notice of non-renewal at least 30 days (sometimes 60 days for government contracts) before the end of the current term.
Renewal Process: Red Hat contacts customers via email or a representative before expiration. Customers can renew online (if purchased via the Red Hat Store), through their sales representative, or by contacting their Red Hat partner6. Renewal pricing is available from Red Hat or the original partner.
Importance of Renewal: Renewing ensures continued access to software updates, security patches, upgrades, certified binaries, and technical support. If a subscription expires, these benefits end.
Notice of Non-Renewal: Either party may cancel automatic renewal by providing written notice within the required timeframe (typically 30 days before term end).
Early Termination: The agreement or an order form may be terminated early if either party materially breaches the terms and fails to cure the breach within 30 days of notice.
Effect of Cancellation/Expiration: Upon cancellation or expiration, the right to receive updates, support, and other subscription benefits ceases, but the software may continue to function. Continued use without an active subscription is not compliant with Red Hat’s terms.
Unsubscribing Systems: Administrators can remove subscriptions from systems at any time using the subscription-manager unsubscribe command.
No Refunds: All fees and payments made under the agreement are non-refundable.
Per-Instance Requirement: Each RHEL installation requires its own valid subscription; all active systems must be covered.
Third-Party Support: Customers may purchase third-party support, but as long as any Red Hat subscriptions are active, all instances must remain covered by a valid subscription.
Red Hat Enterprise Linux (RHEL) meets a broad range of internationally recognized compliance standards and certifications, making it suitable for use in highly regulated industries and sensitive computing environments. Here are the key compliance standards and certifications RHEL supports or holds:
Common Criteria (CC): An international standard (ISO/IEC 15408) for computer security certification. RHEL’s minor releases and every Extended Update Support (EUS) release are independently validated against Common Criteria requirements.
FIPS 140-2/140-3 (Federal Information Processing Standards): RHEL’s cryptographic modules are validated to FIPS 140-2/140-3 standards, ensuring proper implementation of cryptographic algorithms for government and regulated sectors.
PCI DSS (Payment Card Industry Data Security Standard): RHEL achieves PCI DSS 4.0 certification and provides guidance and tools to help organizations meet PCI processing payment card data requirements.
SOC 2 Type 2: RHEL and associated Red Hat services have achieved SOC 2 Type 2 attestation, demonstrating strong controls for security, availability, and confidentiality.
ISO 27001, ISO 27017, ISO 27018: RHEL and Red Hat cloud services are certified for ISO 27001 (information security management), ISO 27017 (cloud security), and ISO 27018 (protection of personal data in the cloud).
STIG (Secure Technical Implementation Guidelines): Red Hat provides automation tools and guidance for implementing U.S. Department of Defense STIG requirements on RHEL systems.
FedRAMP: While FedRAMP is specific to cloud services, Red Hat OpenShift Service on AWS (built on RHEL) is approved for FedRAMP High, indicating the platform’s alignment with federal cloud security requirements.
ANSSI BP-028: RHEL follows security configuration guidance from the French National Cybersecurity Agency (ANSSI), supporting compliance with ANSSI BP-028.
UK Cyber Essentials: RHEL supports the UK government’s minimum baseline for cybersecurity, known as Cyber Essentials.