The Ubuntu LTS default repository problem
Sunday, November 8th, 2009I’ve often seen Ubuntu being chosen instead of Debian because the LTS version offers support and security-fixes for five years. This kind of SLA is often a critical argument. But while Ubuntu is happily claiming to be enterprise-ready they yet enable the universe and multiverse software repositories per default even in the LTS server edition. Since these two repositories are not included in the SLA you might end up with software that is not provided with patches and therefore the whole security guarantee get’s thrown out of the window. While I’m not saying community backed security is bad it basically sets Ubuntu into the same mode of operation as Debian and this even without a specific warning or even notice. To be on the safe side you should disable the universe and multiverse repositories after installation or at least be aware of this fact.

