<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Security Patch Check output in Operating System - HP-UX</title>
    <link>https://community.hpe.com/t5/operating-system-hp-ux/security-patch-check-output/m-p/3499215#M216293</link>
    <description>I recently went through the Security Patch Check stuff and found the following worked well for me:&lt;BR /&gt;&lt;BR /&gt;1) Use Mozilla Firefox as your browser.&lt;BR /&gt;&lt;BR /&gt;2) Open a tab for the HP Security Bulletin Archive at:&lt;BR /&gt;&lt;A href="http://www1.itrc.hp.com/service/cki/secBullArchive.do?admit=-682735245+1110292197471+28353475" target="_blank"&gt;http://www1.itrc.hp.com/service/cki/secBullArchive.do?admit=-682735245+1110292197471+28353475&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;This tab will contain the bulletin numbers you are seeing in the "Bull" column of your output but does not show them in the same format.  Instead you'll see a column which has the rev# which is equivalent to the r# you see in output.  Also the first part of the number you have in your output is the end of a longer number in the next column of this tab.  You should do a search for the number adding a space to the end of it. &lt;BR /&gt;&lt;BR /&gt;The bulleting will be followed either by a description or an SSRT number.  In Firefox you can open the link in a new tab (thereby preserving this tab as you'll need it many times and it sometimes is slow to load).  Items not followed by an SSRT are usually informational and don't specify patches but rather actions to be taken.&lt;BR /&gt;&lt;BR /&gt;3) Open a second tab for the HP Security Patch matrix at:&lt;BR /&gt;&lt;A href="http://www1.itrc.hp.com/service/cki/docDisplay.do?admit=-682735245+1110292229244+28353475&amp;amp;docId=hpuxSecurityMatrix" target="_blank"&gt;http://www1.itrc.hp.com/service/cki/docDisplay.do?admit=-682735245+1110292229244+28353475&amp;amp;docId=hpuxSecurityMatrix&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;You can look up the SSRT numbers found from the first tab in this second tab.  (Here again preserve this tab as you'll need it multiple times.)&lt;BR /&gt;&lt;BR /&gt;Example:&lt;BR /&gt;Security Patch Check output line:&lt;BR /&gt;#   Recommended     Bull   Cnt  Spec Reboot PDep Description&lt;BR /&gt;--------------------------------------------------------------------------------&lt;BR /&gt;1   Ignite-UX       111r2  1st  man  ?      ?    check /etc/passwd on trusted sy&lt;BR /&gt;stems ignited from old images&lt;BR /&gt;&lt;BR /&gt;We need to find 111r2 as it is in the "Bull" column.&lt;BR /&gt;&lt;BR /&gt;In first tab search for "111 " and you'll see:&lt;BR /&gt;  2005 Jan 26 rev.0 HPSBUX01111 SSRT5900 rev.0 HP-UX TGA daemon remote Denial of Service (DoS)&lt;BR /&gt;Since it is rev 0 it is NOT the one we want. &lt;BR /&gt;&lt;BR /&gt;Search next and we find:&lt;BR /&gt;2004 Dec 01  rev.2 HPSBUX0002-111 SSRT4878 rev.2 Ignite-UX failed to save /etc/passwd for trusted systems&lt;BR /&gt;Sice it is rev 2 it IS the one we want (111r2).&lt;BR /&gt;&lt;BR /&gt;In the second tab do a search for SSRT4878.  &lt;BR /&gt;&lt;BR /&gt;The above is fairly cumbersome but was the best approach I found.   &lt;BR /&gt;&lt;BR /&gt;By the way items without an r number in your output are equivalent to rev.0.</description>
    <pubDate>Tue, 08 Mar 2005 10:00:12 GMT</pubDate>
    <dc:creator>Jeff Lightner_1</dc:creator>
    <dc:date>2005-03-08T10:00:12Z</dc:date>
    <item>
      <title>Security Patch Check output</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/security-patch-check-output/m-p/3499210#M216288</link>
      <description>Howdy, &lt;BR /&gt;&lt;BR /&gt;I see that SPC has changed the output.  Can someone help me in finding out more info on what it now reports?&lt;BR /&gt;&lt;BR /&gt;EX:&lt;BR /&gt;&lt;BR /&gt;#   Recommended     Bull   Cnt  Spec Reboot PDep Description          &lt;BR /&gt;--------------------------------------------------------------------------------&lt;BR /&gt;1   Ignite-UX       111r2  1st  man  ?      ?    check /etc/passwd on trusted systems ignited from old images&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;For this I went to the security bulletin page listed at the bottom of the patch check.  I then searched for 111r2 and got no results.  What's the easiest way to find out more information on what SPC now reports?</description>
      <pubDate>Mon, 07 Mar 2005 10:27:33 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/security-patch-check-output/m-p/3499210#M216288</guid>
      <dc:creator>Sean OB_1</dc:creator>
      <dc:date>2005-03-07T10:27:33Z</dc:date>
    </item>
    <item>
      <title>Re: Security Patch Check output</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/security-patch-check-output/m-p/3499211#M216289</link>
      <description>The product would appear to be reporting a possible security problem if you ignite a trusted system from older images.&lt;BR /&gt;&lt;BR /&gt;I can't figure out whether this means prior tot he conversion to trusted or in any event.&lt;BR /&gt;&lt;BR /&gt;I would check such systems with pwck and grpck at the very least and make sure passwords for a few users you know work right and are not nulled out.&lt;BR /&gt;&lt;BR /&gt;I an find nothing on this in HP's web sites.&lt;BR /&gt;&lt;BR /&gt;SEP</description>
      <pubDate>Mon, 07 Mar 2005 11:39:55 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/security-patch-check-output/m-p/3499211#M216289</guid>
      <dc:creator>Steven E. Protter</dc:creator>
      <dc:date>2005-03-07T11:39:55Z</dc:date>
    </item>
    <item>
      <title>Re: Security Patch Check output</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/security-patch-check-output/m-p/3499212#M216290</link>
      <description>I think this is the bulletin SPC is referring to. I agree that the output isn't very clear and takes a bit of perseverance and guesswork to find the relevant bulletin.&lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://www5.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX0002-111" target="_blank"&gt;http://www5.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX0002-111&lt;/A&gt;</description>
      <pubDate>Mon, 07 Mar 2005 11:59:16 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/security-patch-check-output/m-p/3499212#M216290</guid>
      <dc:creator>Gordon  Morrison</dc:creator>
      <dc:date>2005-03-07T11:59:16Z</dc:date>
    </item>
    <item>
      <title>Re: Security Patch Check output</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/security-patch-check-output/m-p/3499213#M216291</link>
      <description>I guess my question was more in general, on how do you find the right bulletin for what is listed in the SPC results.&lt;BR /&gt;&lt;BR /&gt;Searching for the bulletin as listed in SPC brings back no results for anything I've tried.&lt;BR /&gt;&lt;BR /&gt;I really don't have time to read through 200 bulletins looking for the right one.&lt;BR /&gt;&lt;BR /&gt;HP, if you are reading this, please make it easier to find the info you list in SPC.&lt;BR /&gt;&lt;BR /&gt;Thanks!</description>
      <pubDate>Mon, 07 Mar 2005 14:19:16 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/security-patch-check-output/m-p/3499213#M216291</guid>
      <dc:creator>Sean OB_1</dc:creator>
      <dc:date>2005-03-07T14:19:16Z</dc:date>
    </item>
    <item>
      <title>Re: Security Patch Check output</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/security-patch-check-output/m-p/3499214#M216292</link>
      <description>As I said, it's not very clear. This is the way I find bulletins (it's a bit of a performance):&lt;BR /&gt;SPC specifies bulletin 111. This is not the complete bulletin reference number, but the complete number will end in 111. Go to the Security Bulletin website, and in Internet Explorer, click "Edit" --&amp;gt; "Find (on this page)" then enter 111 in the "find what" box, then click "Find next".&lt;BR /&gt;Keep clicking "Find next" until you come to something that looks vaguely like the description from SPC. If it says anything like "rev. 2" in there, it's a bonus, but don't count on it.&lt;BR /&gt;&lt;BR /&gt;HP, I would like to second Sean's request for increased clarity and ease of use.</description>
      <pubDate>Tue, 08 Mar 2005 04:03:05 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/security-patch-check-output/m-p/3499214#M216292</guid>
      <dc:creator>Gordon  Morrison</dc:creator>
      <dc:date>2005-03-08T04:03:05Z</dc:date>
    </item>
    <item>
      <title>Re: Security Patch Check output</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/security-patch-check-output/m-p/3499215#M216293</link>
      <description>I recently went through the Security Patch Check stuff and found the following worked well for me:&lt;BR /&gt;&lt;BR /&gt;1) Use Mozilla Firefox as your browser.&lt;BR /&gt;&lt;BR /&gt;2) Open a tab for the HP Security Bulletin Archive at:&lt;BR /&gt;&lt;A href="http://www1.itrc.hp.com/service/cki/secBullArchive.do?admit=-682735245+1110292197471+28353475" target="_blank"&gt;http://www1.itrc.hp.com/service/cki/secBullArchive.do?admit=-682735245+1110292197471+28353475&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;This tab will contain the bulletin numbers you are seeing in the "Bull" column of your output but does not show them in the same format.  Instead you'll see a column which has the rev# which is equivalent to the r# you see in output.  Also the first part of the number you have in your output is the end of a longer number in the next column of this tab.  You should do a search for the number adding a space to the end of it. &lt;BR /&gt;&lt;BR /&gt;The bulleting will be followed either by a description or an SSRT number.  In Firefox you can open the link in a new tab (thereby preserving this tab as you'll need it many times and it sometimes is slow to load).  Items not followed by an SSRT are usually informational and don't specify patches but rather actions to be taken.&lt;BR /&gt;&lt;BR /&gt;3) Open a second tab for the HP Security Patch matrix at:&lt;BR /&gt;&lt;A href="http://www1.itrc.hp.com/service/cki/docDisplay.do?admit=-682735245+1110292229244+28353475&amp;amp;docId=hpuxSecurityMatrix" target="_blank"&gt;http://www1.itrc.hp.com/service/cki/docDisplay.do?admit=-682735245+1110292229244+28353475&amp;amp;docId=hpuxSecurityMatrix&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;You can look up the SSRT numbers found from the first tab in this second tab.  (Here again preserve this tab as you'll need it multiple times.)&lt;BR /&gt;&lt;BR /&gt;Example:&lt;BR /&gt;Security Patch Check output line:&lt;BR /&gt;#   Recommended     Bull   Cnt  Spec Reboot PDep Description&lt;BR /&gt;--------------------------------------------------------------------------------&lt;BR /&gt;1   Ignite-UX       111r2  1st  man  ?      ?    check /etc/passwd on trusted sy&lt;BR /&gt;stems ignited from old images&lt;BR /&gt;&lt;BR /&gt;We need to find 111r2 as it is in the "Bull" column.&lt;BR /&gt;&lt;BR /&gt;In first tab search for "111 " and you'll see:&lt;BR /&gt;  2005 Jan 26 rev.0 HPSBUX01111 SSRT5900 rev.0 HP-UX TGA daemon remote Denial of Service (DoS)&lt;BR /&gt;Since it is rev 0 it is NOT the one we want. &lt;BR /&gt;&lt;BR /&gt;Search next and we find:&lt;BR /&gt;2004 Dec 01  rev.2 HPSBUX0002-111 SSRT4878 rev.2 Ignite-UX failed to save /etc/passwd for trusted systems&lt;BR /&gt;Sice it is rev 2 it IS the one we want (111r2).&lt;BR /&gt;&lt;BR /&gt;In the second tab do a search for SSRT4878.  &lt;BR /&gt;&lt;BR /&gt;The above is fairly cumbersome but was the best approach I found.   &lt;BR /&gt;&lt;BR /&gt;By the way items without an r number in your output are equivalent to rev.0.</description>
      <pubDate>Tue, 08 Mar 2005 10:00:12 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/security-patch-check-output/m-p/3499215#M216293</guid>
      <dc:creator>Jeff Lightner_1</dc:creator>
      <dc:date>2005-03-08T10:00:12Z</dc:date>
    </item>
    <item>
      <title>Re: Security Patch Check output</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/security-patch-check-output/m-p/3499216#M216294</link>
      <description>See this thread:&lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://forums1.itrc.hp.com/service/forums/questionanswer.do?threadId=854460" target="_blank"&gt;http://forums1.itrc.hp.com/service/forums/questionanswer.do?threadId=854460&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;I have posted a sed script which will give you direct links to the bulletins.  We are also taking this feedback and incorporating improved reporting mechanisms into the next release.&lt;BR /&gt;&lt;BR /&gt;Thanks&lt;BR /&gt;&lt;BR /&gt;-Keith</description>
      <pubDate>Tue, 25 Oct 2005 15:59:33 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/security-patch-check-output/m-p/3499216#M216294</guid>
      <dc:creator>Keith Buck</dc:creator>
      <dc:date>2005-10-25T15:59:33Z</dc:date>
    </item>
  </channel>
</rss>

