Skip to content

Automatic Security Updates

Timely installation of security updates is a fundamental measure for maintaining server security. dnf-automatic is the official tool for automating updates in the RHEL/CentOS/Rocky Linux/AlmaLinux family, supporting automatic downloading, automatic installation, and email notifications.

Terminal window
sudo dnf install dnf-automatic -y

Verify the installation:

Terminal window
rpm -qi dnf-automatic

The main configuration file for dnf-automatic is located at /etc/dnf/automatic.conf.

Terminal window
sudo vi /etc/dnf/automatic.conf
[commands]
# Update type:
# default - all available updates
# security - security updates only
upgrade_type = security
# Random delay in seconds before execution (0 means no delay)
random_sleep = 0
# Whether to automatically install after downloading
# yes = automatically download and install
# no = download only, do not install
apply_updates = yes
# When apply_updates=no, whether to only download updates
download_updates = yes
# Reboot policy after updates (dnf-automatic 3.0+)
# never - never reboot
# when-changed - reboot when kernel or similar updates require it
# when-needed - reboot after installing updates that require it
reboot = never
# Wait time before reboot (seconds)
reboot_command = "shutdown -r +5 'Rebooting after applying updates'"
[emitters]
# Notification method:
# stdio - output to stdout (logged)
# email - send email
# motd - update /etc/motd
# command_email - use an external command to send email
emit_via = email
[email]
# Sender address
email_from = dnf-automatic@hostname
# Recipient address
# SMTP server
email_host = localhost
[command_email]
# External mail command (when emit_via = command_email)
command_format = "cat"
email_from = dnf-automatic@hostname
stdin_encoding = utf-8
[base]
# Debug level (0-10)
debuglevel = 1
# Excluded packages (not automatically updated)
# exclude = kernel* php*

These two options determine the behavior of dnf-automatic:

CombinationBehaviorUse Case
download_updates=yes + apply_updates=noDownload updates only, do not installManual confirmation required before installation
download_updates=yes + apply_updates=yesAutomatically download and installFully automated security update handling
Section titled “Install Security Updates Only (Recommended)”
[commands]
upgrade_type = security
apply_updates = yes
[commands]
upgrade_type = default
download_updates = yes
apply_updates = no

Add exclusions in the [base] section to prevent automatic updates of critical software that might affect services:

[base]
# Exclude kernel and specific applications
exclude = kernel* mysql* nginx*

dnf-automatic uses systemd timers for periodic execution. Several predefined timers are provided.

TimerDescription
dnf-automatic.timerDownload and install updates
dnf-automatic-download.timerDownload updates only
dnf-automatic-install.timerDownload and install updates
dnf-automatic-notifyonly.timerCheck and notify only, no download or install
Terminal window
sudo systemctl enable --now dnf-automatic-install.timer
Terminal window
sudo systemctl enable --now dnf-automatic-download.timer
Terminal window
sudo systemctl enable --now dnf-automatic-notifyonly.timer
Terminal window
sudo systemctl status dnf-automatic-install.timer
sudo systemctl list-timers --all | grep dnf

The default timer typically runs daily in the early morning with a random delay. To customize the time:

Terminal window
sudo systemctl edit dnf-automatic-install.timer

Add the override configuration:

[Timer]
# Clear default settings
OnCalendar=
RandomizedDelaySec=0
# Set to run daily at 3:00 AM
OnCalendar=*-*-* 03:00:00

Verify the timer configuration:

Terminal window
sudo systemctl daemon-reload
sudo systemctl list-timers | grep dnf

Ensure the system has a mail transfer agent (MTA) installed and configured:

Terminal window
sudo dnf install postfix mailx -y
sudo systemctl enable --now postfix

Configure in automatic.conf:

[emitters]
emit_via = email
[email]
email_from = dnf-automatic@$(hostname)
email_host = localhost

If you need to send email through an external SMTP server:

[emitters]
emit_via = email
[email]
email_from = [email protected]
email_host = smtp.example.com:587

Write update information to /etc/motd so users see it upon login:

[emitters]
emit_via = motd

You can use multiple notification methods simultaneously:

[emitters]
emit_via = email,motd

Check what would be done without actually performing updates:

Terminal window
sudo dnf-automatic --timer
Terminal window
sudo systemctl start dnf-automatic-install.service
Terminal window
sudo journalctl -u dnf-automatic-install.service --no-pager -l
sudo journalctl -u dnf-automatic-install.timer --no-pager -l
Terminal window
# View recent update history
sudo dnf history
# View details of the most recent update
sudo dnf history info last

Hands-On: Deploying Automatic Security Updates

Section titled “Hands-On: Deploying Automatic Security Updates”
  1. Install dnf-automatic:

    Terminal window
    sudo dnf install dnf-automatic -y
  2. Configure the automatic security update policy:

    Terminal window
    sudo cp /etc/dnf/automatic.conf /etc/dnf/automatic.conf.bak
    sudo tee /etc/dnf/automatic.conf <<'EOF'
    [commands]
    upgrade_type = security
    apply_updates = yes
    random_sleep = 300
    reboot = never
    [emitters]
    emit_via = email,motd
    [email]
    email_from = [email protected]
    email_host = localhost
    [command_email]
    command_format = "cat"
    email_from = [email protected]
    stdin_encoding = utf-8
    [base]
    debuglevel = 1
    # Exclude kernel updates for manual handling
    exclude = kernel*
    EOF
  3. Install and start the mail service (if email notifications are needed):

    Terminal window
    sudo dnf install postfix mailx -y
    sudo systemctl enable --now postfix
  4. Enable the auto-install timer:

    Terminal window
    sudo systemctl enable --now dnf-automatic-install.timer
  5. Customize the execution time to 2:00 AM daily:

    Terminal window
    sudo mkdir -p /etc/systemd/system/dnf-automatic-install.timer.d
    sudo tee /etc/systemd/system/dnf-automatic-install.timer.d/override.conf <<'EOF'
    [Timer]
    OnCalendar=
    RandomizedDelaySec=0
    OnCalendar=*-*-* 02:00:00
    EOF
    sudo systemctl daemon-reload
  6. Verify the configuration:

    Terminal window
    # Check timer status
    sudo systemctl status dnf-automatic-install.timer
    sudo systemctl list-timers | grep dnf
    # Manual test run
    sudo systemctl start dnf-automatic-install.service
    sudo journalctl -u dnf-automatic-install.service --no-pager -l
  7. Periodically check update history:

    Terminal window
    sudo dnf history
    sudo dnf history info last

By properly configuring dnf-automatic, you can maintain server security while reducing operational burden. Automatic installation is recommended for security updates, while kernel and critical business software should be excluded for manual handling.