Hello, as your sys-vms will connect to the outside world, I would recommend to run those with an OS which gets proper patches/updates. As mentioned in another thread, it is easily possible to switch the sys-vms to fedora-25. I'm running fedora 25 for all my VMs (Qubes 3.2). I suggest that you keep the names of the sys-vms as I've run into a few issues when changing the names. How to migrate: 1) download/install fedora-25 or fedora-25-minimal template in dom0 2) clone this template in a "sys-template" and install some more packages 3) delete your old sys-vms 4) create new sys-vms.
I have written a script which will do all the above steps, so that you can easily start with a fresh copy of sys-vms. One more thing: depending on your hardware it might be, that using a fedora-25-template instead of fedora-25-minimal will be better for sys-net. But as with all VMs, you can easily change the template via dom0 afterwards. I would recommend the fedora-25-minimal templates. If you are interested I can send you the setupscripts to migrate from your existing sys-vms to fedora-25-minimal based sys-vms. [799] > -------- Original Message -------- > Subject: [qubes-users] Re: Update sys-net and sys-firewall to fedora-25? > Local Time: October 19, 2017 5:31 PM > UTC Time: October 19, 2017 3:31 PM > From: yuraei...@gmail.com > To: qubes-users <qubes-users@googlegroups.com> > > On Thursday, October 19, 2017 at 1:18:21 PM UTC, cqui...@gmail.com wrote: > >> Hi, I read around a bit but didn't really find much on this. I just created >> fedora-24 and fedora-25 vms following the docs pages. Since these are newer >> versions of the fedora os, should I switch sys-net and sys-firewall to use >> fedora-25 as a template instead of fedora-23, or should I just leave it as >> is? >> Thanks! >> >> Fedora 23 is not supported by Fedora anymore, hench you don't get the >> important updates. For example, just last monday, a major crisis happened >> with Wi-Fi, leaving essentially all Wi-Fi networks across the planet >> vulnurable, especially those in Linux/Android, but also Windows/iOS/etc, not >> to mention all routors have to be updated too. This update won't come to >> Fedora 23, you will get the update for Fedora 25 however. This is just an >> example, using Fedora 23 is likely to be a big security issue. Dom0 being >> Fedora is less of a concern though, since it has no internet connection, and >> all system commnucation with Dom0 to VM's is updated by the Qubes team/Xen. >> Qubes still send updates to fedora-23 for the qubes toosl, but fedora-23 >> itself isn't being updated anymore. >> >> Essentially the Qubes command to upgrade/install the template should include >> all the Qubes tools, so it shouldn't be a problem to replace them in the >> Qubes Global Settings, as well as the individual VM's. >> >> -- >> You received this message because you are subscribed to the Google Groups >> "qubes-users" group. >> To unsubscribe from this group and stop receiving emails from it, send an >> email to qubes-users+unsubscr...@googlegroups.com. >> To post to this group, send email to qubes-users@googlegroups.com. >> To view this discussion on the web visit >> https://groups.google.com/d/msgid/qubes-users/49518b9c-47ca-44a5-877d-20b4954a3c7e%40googlegroups.com. >> For more options, visit https://groups.google.com/d/optout. -- You received this message because you are subscribed to the Google Groups "qubes-users" group. To unsubscribe from this group and stop receiving emails from it, send an email to qubes-users+unsubscr...@googlegroups.com. To post to this group, send email to qubes-users@googlegroups.com. To view this discussion on the web visit https://groups.google.com/d/msgid/qubes-users/2P7liioHSTxPrv4N-uosFutrgjrE6B8KV4yAYF_gMBCzw5Jae4-4RdVylgKnuPivyWtuUcdrDvSXHnwHWVIafGGx8FPK3pteXWjO_N-LeeI%3D%40protonmail.com. For more options, visit https://groups.google.com/d/optout.