Update Security
Describes how FreeCORE updates are signed and verified.
FreeCORE operates its own update infrastructure. The update server is
update.freecore.org, and manual downloads are served from
updates.freecore.org. No public downloads are available yet.
Every update is cryptographically signed. The system verifies update signatures against the FreeCORE Update CA before applying them; an update that fails verification is not installed. The CA certificate ships with the system.
Updates install into a new boot environment, so a failed or unwanted update can always be rolled back from System > Boot or from the boot menu.
The update trains retain the TrueNAS lineage naming (TrueNAS-15.0-STABLE,
TrueNAS-15.0-Nightlies); see Updating FreeCORE
for how trains work.