Patch compliance

An HP-UX patch compliance scan compares the patches that are installed on a managed server with the patch policies that are attached to the server. If the actual server configuration does not match the patch policies attached to the server, the server is out of compliance with the patch policies. In addition, if a patch in the patch policy has been superseded by a newer patch and the newer patch is installed on a server, that server will be marked as compliant.

In the SA Client, when you perform a patch compliance scan, the scan indicates the server's overall compliance with all HP-UX patch policies that are attached to the server. Even if only one HP-UX patch policy attached to the server is not compliant, the server is considered non-compliant. You can then view the non-compliant server and remediate the server against the applicable patch policy.

The SA Client displays the following compliance information for a patch policy:

Compliance status for a managed server

 

Status

Description

Compliant

All patch policies attached to a server are compliant—all patches specified in all patch policies are installed on the server.

Non-compliant

At least one of the patch policies attached to the server is not compliant—at least one patch in the policy is not installed on the server.

Scan Started

The patch compliance information is currently being collected.

Scan Failed

The patch compliance scan was unable to run.

Scan Needed

The patch compliance information needs to be collected or the compliance information may be inaccurate.

Not Applicable

The patch compliance information does not apply.

See the following figure for an example of patch compliance status for the Standard HP-UX bundle.

Patch compliance status

In this example, Server Automation reports that the compliance status for the Standard HP-UX QPK bundle is “2 of 258 rules out of compliance.” The total number of patches within QPK bundle is 259. SA determined that one patch in this bundle is not applicable to this managed server. Therefore, it reports compliance status only for 258 patches instead of 259 patches.

SA also determined that two patches have superseded patches and that these superseded patches are installed on the server but not uploaded in the repository. Therefore, they are reported as out of compliance.