Administer > Permissions reference > Patch Management for Solaris Permissions

Patch management for Solaris permissions

This section describes permissions for managing patches on Solaris systems. For patch information on other UNIX systems, see Patch management for other UNIX permissions. For permissions on Solaris patch policies, see Solaris patch policy management permissions.

The Solaris patch management permissions required for user actions table specifies the Patch Management permissions required by users to perform specific actions in the SA Client. For security administrators, the table answers this question: To perform a particular action, what permissions does a user need?

In addition to the permissions listed in the Solaris patch management permissions required for user actions table, every user action also requires the Managed Servers and Groups permission.

In the Solaris patch management permissions required for user actions table, most of the entries in the User Action column correspond to menu items in the SA Client. In addition to action permissions, server permissions are required on the managed servers affected by the patching operation.

If either Allow Install Patch or Allow Uninstall Patch permission is set to Yes, then the Manage Patch and the Manage Windows Patch Policy permissions are automatically set to Read. If you plan to use Solaris patch policies, you should also set Manage Software Policy to Read or Read and Write. For more information, see Solaris patch policy management permissions.

Solaris patch management permissions required for user actions

User Action

Action Permission

Server Permission (Customer, Facility, Device Group)

Patches

Install Patch (Available)

Allow Install Patch: Yes
Manage Patch: Read

Read & Write

Uninstall Patch (Available)

Allow Uninstall Patch: Yes
Manage Patch: Read

Read & Write

Install Patch (Limited Availability)

Allow Install Patch: Yes
Manage Patch: Read & Write

Read & Write

Uninstall Patch (Limited Availability)

Allow Uninstall Patch: Yes
Manage Patch: Read & Write

Read & Write

Open Patch (View Patch)

Manage Patch: Read

N/A

Change Patch Properties

Manage Patch: Read & Write

N/A

Import Patch

Manage Patch: Read & Write

N/A

Export Patch

Manage Patch: Read
Allow Install Patch: Yes (optional)
Allow Uninstall Patch: Yes (optional)
Manage Software Policy: Read (optional)

N/A

Delete Patch

Manage Patch: Read & Write

N/A

The User actions allowed by Solaris patch management permissions table lists the actions that users can perform for each Solaris Patch Management permission. The User actions allowed by Solaris patch management permissions table has the same data as the Solaris patch management permissions required for user actions table, but is sorted by action permission. Although it is not indicated in the User actions allowed by Solaris patch management permissions table, the Managed Servers and Groups permission is required for all Patch Management actions.

For security administrators, the User actions allowed by Solaris patch management permissions table answers this question: If a user is granted a particular action permission, what actions can the user perform?

User actions allowed by Solaris patch management permissions

Action Permission

User Action

Server Permission (Customer, Facility, Device Group)

Allow Install Patch: Yes

Remediate Policy

Read & Write

Allow Install Patch: Yes
Manage Patch: Read

Install Patch (Available)

Read & Write

Uninstall Patch (Available)

Read & Write

Allow Install Patch: Yes
Manage Patch: Read & Write

Install Patch (Limited Availability)

Read & Write

Uninstall Patch (Limited Availability)

Read & Write

Allow Install Patch: Yes
(Also sets Manage Patch: Read)

Export Patch

N/A

Allow Uninstall Patch: Yes
(Also sets Manage Patch: Read)

Export Patch

N/A

Allow Uninstall Patch: Yes
(Also sets Manage Patch: Read)

Uninstall Patch

Read & Write

Manage Patch: Read

Open Patch (View Patch)

N/A

Export Patch

N/A

Manage Patch: Read & Write

Change Patch Properties

N/A

Delete Patch

N/A

Import Patch

N/A