Canonical’s latest Ubuntu update is highly-focused on security, something that was made abundantly clear during a press conference touting the company’s latest “long term support” (LTS) update to its Linux distribution. That focus includes new work on limiting the damage of inevitable security lapses.

Ubuntu is Canonical’s distribution system for Linux designed to run on computing devices, network servers, and in the cloud. The platform uses a naming scheme based on the year and month of the release, thus this latest update is dubbed 20.04, though it also includes the focal fossa name in keeping with Canonical's animal-focused naming structure. The release also earns an LTS designation, which signifies a larger platform release. The company is using a two-year cycle on these LTS updates, with the last one (18.04) released in April 2018.

The latest LTS release includes what Canonical calls “kernel self-protection measures,” which target control flow integrity and features stack-crash protection. It also has a secure boot feature that protects against low-level attacks and rootkits, and a confinement feature that limits exposure of applications on a desktop or server to limit an attack blast radius.

Canonical CEO Mark Shuttleworth said this stems from a growing focus on failing safely in the kernel environment.

“[The stack-crash protection] is an example of a forward-looking defense and depth security measure,” Shuttleworth said. “It reduces the impact of future vulnerabilities. We know that somewhere in the code that makes up 20.04 today there will be vulnerabilities that will be discovered in the future. When they’re uncovered we take steps now to be able to minimize the blast radius of those mistakes.”

Canonical is also supporting a number of hardware initiatives, including AMD’s Secure Encrypted Virtualization (SEV) and IBM’s z15 mainframe Secure Execution environment and secure container offerings.

Canonical Ubuntu Support Expansion

The latest Ubuntu update also ushers in a new support plan that doubles the length of security maintenance to 10 years for enterprise customers. Shuttleworth said this will include three security updates through 2025 for the base operating system and the desktop application.

However, he added that enterprise customers have increasingly asked for security updates to include more open source platforms.

“Really what's happening is that enterprises want much more open source than just Linux,” Shuttleworth said. “Traditionally, enterprises used to be quite conservative about what they allowed into the building so they would take Linux from a trusted vendor and then applications from trusted vendors, but today we see an incredible acceleration in the widespread use of almost any open source application from the Ubuntu platform, it really is a hockey stick.”

The security coverage expansion provides the 10 years of coverage for those customers and includes all packages in Ubuntu and what Shuttleworth said were the remaining 30,000 packages that were not previously covered by the security updates. “This represents a huge improvement in enterprise security,” he added.

IPO Still On

Oh, and about that long-standing Canonical promise of an initial public offering (IPO)? Shuttleworth said it’s still on the docket, but that due to the ongoing uncertainty around the COVID-19 outbreak “we are taking a cautious posture this year because it's so difficult for us to predict the impact on all of our customers this year and therefore on our growth this year.”

Despite kicking that can further down the road, Shuttleworth did note that the company and the distribution were sound financially. “This has been a very big year for Ubuntu and for Canonical. It is the year where Ubuntu became commercially self-sustaining.”