Administer > Permissions reference > Patch Management for Other UNIX Permissions

Patch management for other UNIX permissions

This section describes permissions for managing patches on UNIX systems other than Solaris. For Solaris information, see Patch management for Solaris permissions. You can use software policies with UNIX patches. For more information, see Software management permissions.

The UNIX Patch Management Permissions Required for User Actions table specifies the Patch Management permissions required by users to perform specific actions in the SA Client. For security administrators, the table answers this question: To perform a particular action, what permissions does a user need?

In addition to the permissions listed in the UNIX Patch Management Permissions Required for User Actions table, every user action also requires the Managed Servers and Groups permission.

In the UNIX Patch Management Permissions Required for User Actions table, most of the entries in the User Action column correspond to menu items in the SA Client. In addition to action permissions, server permissions are required on the managed servers affected by the patching operation.

If either Allow Install Patch or Allow Uninstall Patch permission is set to Yes, then the Manage Patch and the Manage Windows Patch Policy permissions are automatically set to Read. If you plan to use policies, you should also set Manage Software Policy to Read or Read and Write.

UNIX Patch Management Permissions Required for User Actions

User Action

Action Permission

Server Permission (Customer, Facility, Device Group)

Patches

Install Patch (Available)

Allow Install Patch: Yes
Manage Patch: Read

Read & Write

Uninstall Patch (Available)

Allow Uninstall Patch: Yes
and Manage Patch: Read

Read & Write

Install Patch (Limited Availability)

Allow Install Patch: Yes
Manage Patch: Read & Write

Read & Write

Uninstall Patch (Limited Availability)

Allow Uninstall Patch: Yes
and Manage Patch: Read & Write

Read & Write

Open Patch (View Patch)

Manage Patch: Read

N/A

Change Patch Properties

Manage Patch: Read & Write

N/A

Export Patch

Manage Patch: Read
and Package

N/A

Export Patch

or Allow Install Patch: Yes
and Package: Yes

N/A

Export Patch

or Allow Uninstall Patch: Yes
and Package

N/A

Export Patch

or Manage Policy: Read
and Package

N/A

Delete Patch

Manage Patch: Read & Write

N/A

The User Actions Allowed by UNIX Patch Management Permissions table lists the actions that users can perform for each Patch Management permission. The User Actions Allowed by UNIX Patch Management Permissions table has the same data as the UNIX Patch Management Permissions Required for User Actions table, but is sorted by action permission. Although it is not indicated in the User Actions Allowed by UNIX Patch Management Permissions table, the Managed Servers and Groups permission is required for all Patch Management actions.

For security administrators, the User Actions Allowed by UNIX Patch Management Permissions table answers this question: If a user is granted a particular action permission, what actions can the user perform?

User Actions Allowed by UNIX Patch Management Permissions

Action Permission

User Action

Server Permission (Customer, Facility, Device Group)

Allow Install Patch: Yes

Copy Exception

Read & Write

Remediate Policy

Read & Write

Set Exception

Read & Write

Allow Install Patch: Yes
and Manage Patch: Read

Install Patch (Available)

Read & Write

Uninstall Patch (Available)

Read & Write

Allow Install Patch: Yes
and Manage Patch: Read & Write

Install Patch (Limited Availability)

Read & Write

Uninstall Patch (Limited Availability)

Read & Write

Allow Install Patch: Yes
and Package: Yes

Export Patch

N/A

Allow Uninstall Patch: Yes

Copy Exception

Read & Write

Set Exception

Read & Write

Allow Uninstall Patch: Yes
and Package

Export Patch

N/A

Manage Patch: Read

Open Patch (View Patch)

N/A

Manage Patch: Read & Write

Change Patch Properties

N/A

Delete Patch

N/A

Import Patch Database

N/A

Manage Patch: Read & Write
and Package

Import Patch

N/A

Manage Patch: Read
and Manage Policy: Read & Write

Add Patch to Policy

N/A

Manage Patch: Read
and Package

Export Patch

N/A

Manage Policy: Read
and Package

Export Patch

N/A