Linux Patch Management Settings


Patch Management module helps to scan and assess the patches that are deployed / missing in the Linux systems in the network. This helps to make sure that all the Linux systems on the network are up to date with the critical or recent patches that are released and there are no security vulnerabilities in the network.

The Global Settings for Patch Management 'Enable/Disable Patch management' should be set to 1 to enable Patch Management. You can either do this in the Global Settings screen (Settings->Advanced System Settings->Global Settings)or in the Patch Management Wizard (Settings->Software Management->Patch Management Wizard->Linux Patch Scanning and Deployment Settings).

The configuration involves setting up the profile to include/exclude systems for patch management, setting up schedules for scanning and deployment and marking critical systems for prioritization. These settings can be done from the Patch Management Wizard. Refer to Settings->Software Management->Patch Management Wizard->Linux Patch Scanning and Deployment Settings for more details.

If there is a Proxy Server being used in the organization, create a Proxy Settings Profile (Refer Creating Proxy Settings Profile). If a commercial distribution of Linux is being used (RHEL, SUSE Enterprise), then the Subscription Account credentials need to be configured (Refer Linux Subscription Account).

After creating the profiles, these can be mapped to a set of systems (Refer Map Profile)

SapphireIMS also supports offline patch management for Linux derivatives of Debian including Ubuntu. This is detailed in Linux Offline Patch Management.

 

Creating Proxy Settings Profile

 

proxy_settings_1.gif

 

Linux Subscription Account

The Linux Subscription Account must be configured for commercial Linux distributions like RHEL and SUSE Enterprise

 

linux_subscription_account.gif

 

 

Map Profile

This step is required to map any profiles created to a set of hosts.

Settings-SWMgmt-PatchSettingLinx.jpg

 

 

Notes: Click "Advanced Search" to search for the host names based on Category, Organization Unit and Operating System.

 

Linux Offline Patch Management

SapphireIMS has support for offline patch management for Debian, Ubuntu and other Linux flavors derived from Debian. In the case of offline patch management, the package repository is downloaded and stored on the SapphireIMS server. Further on, the patch scans and deployment are done using the local repository and there is no need for an Internet connection. If the patch repository is not found locally and Internet connectivity is available, then SapphireIMS attempts to access the package from the online sources.

To configure the offline patch scan, a task needs to be configured to automatically download the package. The rest of the patch management configuration is similar to how it is done for online patch management.

 

Settings-ITAuto-PtchUbuntuIcon.jpg

Settings-ITAuto-PtchUbuntu1.jpg

 

Settings-ITAuto-PtchUbuntu2.jpg