Use > Server patching > Patch management for Unix

Patch management for Unix

In HPE Server Automation (SA), patch management for Unix enables you to identify, install, and remove patches, to maintain a high level of security across managed servers in your organization. Using the SA Client, you can identify and install patches that protect against security vulnerabilities for AIX operating systems.

This section contains information about how to install and uninstall Unix patches using software policies.

SA automates the key aspects of patch management, while offering a fine degree of control over how and under what conditions patches are installed.

Because patches are often released to address grave security threats, an organization needs to be able to roll out patches quickly, before systems are compromised. At the same time, however, patches can cause serious problems, from performance degradation to server failures.

SA allows you to react quickly to newly discovered threats and also provides support for strict testing and standardization of patch installation. If patches cause problems after being tested and approved, SA allows you to uninstall the patches in a safe and standardized way.

SA stores patch information in the SA Library that includes detailed information about every server under management, the patches and software installed on the servers, and the patches and software available for installation. You can use this data to determine the severity of your exposure to a newly discovered threats, and to help assess the benefits of rolling out a patch versus the costs in downtime and testing requirements.

By automating the patching procedure, SA can reduce the amount of downtime required for patching. SA also allows you to schedule patch activity, so that patching occurs during off-peak hours.

HPE Server Automation automates patch management by providing the following features:

  • The SA Library where patches are stored and organized in their formats
  • A database that includes information on every patch that has been applied
  • Customized scripts that can be run before and after a patch is installed
  • Advanced search abilities that identify servers that require patching
  • Auditing abilities that enable security personnel to track the deployment of important patches

These features enable you to browse patches by a certain operating system, schedule patch downloads and installations, set up email notifications, preview a patch installation, use software policies and remediation to install and uninstall patches, and export patch information to a reusable file format.