<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: RH AS 3.0  Patching Best-Practices in Operating System - Linux</title>
    <link>https://community.hpe.com/t5/operating-system-linux/rh-as-3-0-patching-best-practices/m-p/3893258#M25869</link>
    <description>Here you got good information about up2date.&lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://www.redhat.com/advice/tips/up2date.html" target="_blank"&gt;http://www.redhat.com/advice/tips/up2date.html&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://kb.swsoft.com/article_17_234_en.html" target="_blank"&gt;http://kb.swsoft.com/article_17_234_en.html&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;</description>
    <pubDate>Mon, 06 Nov 2006 15:21:18 GMT</pubDate>
    <dc:creator>Ivan Ferreira</dc:creator>
    <dc:date>2006-11-06T15:21:18Z</dc:date>
    <item>
      <title>RH AS 3.0  Patching Best-Practices</title>
      <link>https://community.hpe.com/t5/operating-system-linux/rh-as-3-0-patching-best-practices/m-p/3893257#M25868</link>
      <description>&lt;!--!*#--&gt;Hi All,&lt;BR /&gt;&lt;BR /&gt;I have seven DL380 with RH AS 3.0, never been patched, I need to install any critical dsec patches. what is the Best-Practice to patced all my servers from the Command-Line(CLI).  I have no GUI.  Do you have any doc you can share with me?  Again I am looking for the Command.  &lt;BR /&gt;&lt;BR /&gt;When I ran up2date --download; it is asking for the patchage names ???? is there any otherways to download all RPMS and save them all without providing the package names?&lt;BR /&gt;&lt;BR /&gt;Thanks for you help.&lt;BR /&gt;</description>
      <pubDate>Mon, 06 Nov 2006 14:49:34 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-linux/rh-as-3-0-patching-best-practices/m-p/3893257#M25868</guid>
      <dc:creator>Dary</dc:creator>
      <dc:date>2006-11-06T14:49:34Z</dc:date>
    </item>
    <item>
      <title>Re: RH AS 3.0  Patching Best-Practices</title>
      <link>https://community.hpe.com/t5/operating-system-linux/rh-as-3-0-patching-best-practices/m-p/3893258#M25869</link>
      <description>Here you got good information about up2date.&lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://www.redhat.com/advice/tips/up2date.html" target="_blank"&gt;http://www.redhat.com/advice/tips/up2date.html&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://kb.swsoft.com/article_17_234_en.html" target="_blank"&gt;http://kb.swsoft.com/article_17_234_en.html&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Mon, 06 Nov 2006 15:21:18 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-linux/rh-as-3-0-patching-best-practices/m-p/3893258#M25869</guid>
      <dc:creator>Ivan Ferreira</dc:creator>
      <dc:date>2006-11-06T15:21:18Z</dc:date>
    </item>
    <item>
      <title>Re: RH AS 3.0  Patching Best-Practices</title>
      <link>https://community.hpe.com/t5/operating-system-linux/rh-as-3-0-patching-best-practices/m-p/3893259#M25870</link>
      <description>Thanks for your e-mail,  but When I ran up2date --download; it is asking for the patchage names ???? &lt;BR /&gt;Is there any otherways to download all RPMS and save them all without providing the package names?&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Mon, 06 Nov 2006 16:03:52 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-linux/rh-as-3-0-patching-best-practices/m-p/3893259#M25870</guid>
      <dc:creator>Dary</dc:creator>
      <dc:date>2006-11-06T16:03:52Z</dc:date>
    </item>
    <item>
      <title>Re: RH AS 3.0  Patching Best-Practices</title>
      <link>https://community.hpe.com/t5/operating-system-linux/rh-as-3-0-patching-best-practices/m-p/3893260#M25871</link>
      <description>Shalom,&lt;BR /&gt;&lt;BR /&gt;You should just be able to click a radio button for all patches.&lt;BR /&gt;&lt;BR /&gt;Just run up2date without options.&lt;BR /&gt;&lt;BR /&gt;Best practice is to have all servers licensed and patch them individually. That being a pain I maintain a server with all packages installed and retain patches off that and use them with rpm -Fvh to patch other systems so nothing new gets added.&lt;BR /&gt;&lt;BR /&gt;There is also a product called Satellite server that lets you have a single install point.&lt;BR /&gt;&lt;BR /&gt;SEP</description>
      <pubDate>Mon, 06 Nov 2006 17:14:40 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-linux/rh-as-3-0-patching-best-practices/m-p/3893260#M25871</guid>
      <dc:creator>Steven E. Protter</dc:creator>
      <dc:date>2006-11-06T17:14:40Z</dc:date>
    </item>
    <item>
      <title>Re: RH AS 3.0  Patching Best-Practices</title>
      <link>https://community.hpe.com/t5/operating-system-linux/rh-as-3-0-patching-best-practices/m-p/3893261#M25872</link>
      <description>Steven,&lt;BR /&gt;&lt;BR /&gt;I have No GUI interface, so I am running up2date from Command Line, in that case you don't have an option to select/choose radio. &lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Mon, 06 Nov 2006 17:49:45 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-linux/rh-as-3-0-patching-best-practices/m-p/3893261#M25872</guid>
      <dc:creator>Dary</dc:creator>
      <dc:date>2006-11-06T17:49:45Z</dc:date>
    </item>
    <item>
      <title>Re: RH AS 3.0  Patching Best-Practices</title>
      <link>https://community.hpe.com/t5/operating-system-linux/rh-as-3-0-patching-best-practices/m-p/3893262#M25873</link>
      <description>Gday Dary,&lt;BR /&gt;&lt;BR /&gt;Modify /etc/sysconfig/rhn/up2date (make a copy of the original first) with the following:&lt;BR /&gt;&lt;BR /&gt;useNoSSLForPackages[comment]=Use the noSSLServerURL for package, package list, and header fetching&lt;BR /&gt;useNoSSLForPackages=1&lt;BR /&gt;storageDir[comment]=Where to store packages and other data when they are retrieved&lt;BR /&gt;storageDir=/var/spool/up2date&lt;BR /&gt;pkgSkipList[comment]=A list of package names, optionally including wildcards, to skip&lt;BR /&gt;pkgSkipList=;&lt;BR /&gt;retrieveOnly[comment]=Retrieve packages only&lt;BR /&gt;retrieveOnly=1&lt;BR /&gt;noSSLServerURL[comment]=Remote server URL without SSL&lt;BR /&gt;noSSLServerURL=&lt;A href="http://xmlrpc.rhn.redhat.com/XMLRPC" target="_blank"&gt;http://xmlrpc.rhn.redhat.com/XMLRPC&lt;/A&gt;&lt;BR /&gt;networkSetup[comment]=None&lt;BR /&gt;networkSetup=1&lt;BR /&gt;networkRetries[comment]=Number of attempts to make at network connections before giving up&lt;BR /&gt;networkRetries=5&lt;BR /&gt;pkgsToInstallNotUpdate[comment]=A list of provides names or package names of packages to install not update&lt;BR /&gt;pkgsToInstallNotUpdate=kernel;kernel-modules;&lt;BR /&gt;noBootLoader[comment]=To disable modification of the boot loader (lilo, silo, etc)&lt;BR /&gt;noBootLoader=0&lt;BR /&gt;updateUp2date[comment]=Allow up2date to update itself when possible&lt;BR /&gt;updateUp2date=1&lt;BR /&gt;keepAfterInstall[comment]=Keep packages on disk after installation&lt;BR /&gt;keepAfterInstall=1&lt;BR /&gt;useGPG[comment]=Use GPG to verify package integrity&lt;BR /&gt;useGPG=1&lt;BR /&gt;showAvailablePackages[comment]=None&lt;BR /&gt;showAvailablePackages=1&lt;BR /&gt;headerCacheSize[comment]=The maximum number of rpm headers to cache in ram&lt;BR /&gt;headerCacheSize=40&lt;BR /&gt;forceInstall[comment]=Force package installation, ignoring package, file and config file skip list&lt;BR /&gt;forceInstall=0&lt;BR /&gt;systemIdPath[comment]=Location of system id&lt;BR /&gt;systemIdPath=/etc/sysconfig/rhn/systemid&lt;BR /&gt;retrieveSource[comment]=Retrieve source RPM along with binary package&lt;BR /&gt;retrieveSource=0&lt;BR /&gt;enableRollbacks[comment]=Determine if up2date should create rollback rpms&lt;BR /&gt;enableRollbacks=1&lt;BR /&gt;gpgKeyRing[comment]=The location of the gpg keyring to use for package checking&lt;BR /&gt;gpgKeyRing=/etc/sysconfig/rhn/up2date-keyring.gpg&lt;BR /&gt;adminAddress[comment]=List of e-mail addresses for update agent to communicate with when run in batch mode&lt;BR /&gt;adminAddress=rootlocalhost;&lt;BR /&gt;serverURL[comment]=Remote server URL&lt;BR /&gt;serverURL=&lt;A href="http://xmlrpc.rhn.redhat.com/XMLRPC" target="_blank"&gt;http://xmlrpc.rhn.redhat.com/XMLRPC&lt;/A&gt;&lt;BR /&gt;fileSkipList[comment]=A list of file names, optionally including wildcards, to skip&lt;BR /&gt;fileSkipList=;&lt;BR /&gt;versionOverride[comment]=Override the automatically determined system version&lt;BR /&gt;versionOverride=&lt;BR /&gt;sslCACert[comment]=The CA cert used to verify the ssl server&lt;BR /&gt;sslCACert=/usr/share/rhn/RHNS-CA-CERT&lt;BR /&gt;noReplaceConfig[comment]=When selected, no packages that would change configuration data are automatically installed&lt;BR /&gt;noReplaceConfig=0&lt;BR /&gt;enableProxyAuth[comment]=To use an authenticated proxy or not&lt;BR /&gt;enableProxyAuth=1&lt;BR /&gt;disallowConfChanges[comment]=Config options that can not be overwritten by a config update actionx&lt;BR /&gt;disallowConfChanges=noReboot;sslCACert;useNoSSLForPackages;noSSLServerURL;serverURL;disallowConfChanges;&lt;BR /&gt;headerFetchCount[comment]=The maximimum number of rpm headers to fetch at once&lt;BR /&gt;headerFetchCount=10&lt;BR /&gt;removeSkipList[comment]=A list of package names, optionally including wildcards that up2date will not remove&lt;BR /&gt;removeSkipList=kernel*;&lt;BR /&gt;debug[comment]=Whether or not debugging is enabled&lt;BR /&gt;debug=0&lt;BR /&gt;noReboot[comment]=Disable the reboot actions&lt;BR /&gt;noReboot=1&lt;BR /&gt;#&lt;BR /&gt;proxyUser[comment]=The username for an authenticated proxy&lt;BR /&gt;proxyUser=&lt;BR /&gt;enableProxy[comment]=Use a HTTP Proxy&lt;BR /&gt;enableProxy=1&lt;BR /&gt;proxyPassword[comment]=The password to use for an authenticated proxy&lt;BR /&gt;proxyPassword=&lt;BR /&gt;httpProxy[comment]=HTTP proxy in host:port format, e.g. squid.redhat.com:3128&lt;BR /&gt;httpProxy=proxy.server.com:8080&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;If your site has a proxy server you will likely need to setup it a username/password may be required. We switched off the SSL version and download via RHN.&lt;BR /&gt;&lt;BR /&gt;With this in place you should just do an up2date --config to update entries via a menu or just edit the text file.&lt;BR /&gt;&lt;BR /&gt;You will then need to register to rhn. Ensure before all this that you have a RHN account and subscriptions are loaded into the system for that account.&lt;BR /&gt;&lt;BR /&gt;You will also need to import your rpm-gpg-key this is done via rpm --import /usr/share/rhn/RPM-GPG-KEY&lt;BR /&gt;&lt;BR /&gt;And then you can register to RHN via up2date -u --nox&lt;BR /&gt;&lt;BR /&gt;This will put up a text screen menu system where you enter your RHN account name, email address, and profile name etc, you can also amend you packages however we work with what the server has installed and go with the defaults. It then saves your profile onto the Redhat Network.&lt;BR /&gt;&lt;BR /&gt;One thing though ensure auto errata update is set to yes (on rhn.network.com) as this ensures all servers download packages automatically to /var/spool/up2date - you can if your game get the up2date config to auto install however we disable this and do it manually.&lt;BR /&gt;&lt;BR /&gt;A hint we often test systems by using evaluation licenses, especially if we are awaiting on license keys from Redhat. So we have to rhn accounts a prod and eval one to not confuse us with all the profiles etc.&lt;BR /&gt;&lt;BR /&gt;One can reregister the server again if you remove the existing profile id from RHN and the other way is to delete /etc/sysconfig/rhn/systemid as this is the link to the profile not the profile/server name if you happen to rename servers etc. If you duplicate servers you will also need to recreate up2date-uid as well as the checksum is used too (uuidgen can be used for this purpose it creates a new number which one copies/pastes into the up2date-uid file).&lt;BR /&gt;&lt;BR /&gt;Hope some of this helps.&lt;BR /&gt;&lt;BR /&gt;Robert.&lt;BR /&gt;&lt;BR /&gt;PS: as for keeping track, at the moment I just run a find /var/spool/up2date/*.rpm -perm 644 -ls via cron on a weekly basis. When I update servers I chmod 770 the rpm package for the time being until its time to clean out the /var/spool/up2date directory.&lt;BR /&gt;&lt;BR /&gt;PPS: One can set up a fools proxy server by using up2date -u --nodownload --nox - this only downloads the headers not the rpms and then using a nfs server copy the individual rpms over - this way you could save internet bandwidth if all your servers are the same. One does the downloads the others use the rpms from it while the nodownload option tracks whch patches are needed by the Redhat Network.&lt;BR /&gt;</description>
      <pubDate>Mon, 06 Nov 2006 21:01:20 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-linux/rh-as-3-0-patching-best-practices/m-p/3893262#M25873</guid>
      <dc:creator>Robert Walker_8</dc:creator>
      <dc:date>2006-11-06T21:01:20Z</dc:date>
    </item>
    <item>
      <title>Re: RH AS 3.0  Patching Best-Practices</title>
      <link>https://community.hpe.com/t5/operating-system-linux/rh-as-3-0-patching-best-practices/m-p/3893263#M25874</link>
      <description>Dary,&lt;BR /&gt;&lt;BR /&gt;Other usefull stuff to include is the rpm macros:&lt;BR /&gt;&lt;BR /&gt;/etc/rpm/macros&lt;BR /&gt;%_transaction_color   3&lt;BR /&gt;%_query_all_fmt %%{name}-%%{version}-%%{release}.%%{arch}&lt;BR /&gt;%_repackage_all_erasures 1&lt;BR /&gt;%_unsafe_rollbacks 1180792800&lt;BR /&gt;&lt;BR /&gt;The usefull one is repackage_all_erasures this allows rollbacks see rpm and query_all_fmt as this provides the architecture stuff in the rpm qa command. Note however some systems dont expect the architecture stuff and could bomb (Oracle might be such a beast) however it saves having to remember the syntax. I found these by googling hope they help.&lt;BR /&gt;&lt;BR /&gt;Robert.</description>
      <pubDate>Mon, 06 Nov 2006 21:06:10 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-linux/rh-as-3-0-patching-best-practices/m-p/3893263#M25874</guid>
      <dc:creator>Robert Walker_8</dc:creator>
      <dc:date>2006-11-06T21:06:10Z</dc:date>
    </item>
  </channel>
</rss>

