- Community Home
- >
- Servers and Operating Systems
- >
- Operating Systems
- >
- Operating System - HP-UX
- >
- Re: Security Patch Check B.02.00 released
Categories
Company
Local Language
Forums
Discussions
Forums
- Data Protection and Retention
- Entry Storage Systems
- Legacy
- Midrange and Enterprise Storage
- Storage Networking
- HPE Nimble Storage
Discussions
Forums
Discussions
Discussions
Discussions
Forums
Discussions
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
- BladeSystem Infrastructure and Application Solutions
- Appliance Servers
- Alpha Servers
- BackOffice Products
- Internet Products
- HPE 9000 and HPE e3000 Servers
- Networking
- Netservers
- Secure OS Software for Linux
- Server Management (Insight Manager 7)
- Windows Server 2003
- Operating System - Tru64 Unix
- ProLiant Deployment and Provisioning
- Linux-Based Community / Regional
- Microsoft System Center Integration
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Community
Resources
Forums
Blogs
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Printer Friendly Page
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
06-24-2004 11:26 AM
06-24-2004 11:26 AM
Bulletin numbers (w/ revision number) can be placed into $HOME/.spc_ignore to check off those that have been analyzed manually to not apply to your system. hash (#) comments are allowed to document reasons why the patch did not apply.
NOTE: if you download the security_catalog manually, you should start downloading security_catalog2.gz instead, as it has all the information on manual actions and product upgrades.
You can get it here:
http://software.hp.com/portal/swdepot/displayProductInfo.do?productNumber=B6834AA
As before, you'll still need Perl.
http://www.software.hp.com/cgi-bin/swdepot_parser.cgi/cgi/displayProductInfo.pl?productNumber=PERL
This version is also pre-enabled for automated https download of the security catalog, if you have Perl D.5.8.0.C and an upcoming release of openssl installed.
Enjoy! Feedback welcome.
-Keith
Solved! Go to Solution.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
07-06-2004 03:38 PM
07-06-2004 03:38 PM
SolutionI'm having trouble finding the security bulletins that security patch check refers to. Can you tell me where I would find them? The first one on my list is bulletin 16, but I don't even find that listed in the the security_catalog file.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
07-07-2004 04:02 AM
07-07-2004 04:02 AM
Re: Security Patch Check B.02.00 released
http://itrc.hp.com/cki/bin/doc.pl/screen=ckiSecurityBulletin
Unfortunately, the bulletins are ordered by document id instead of date or bulletin number, so it can be confusing at first.
If you go to that page and search in page for "016", it should pop right up. This particular bulletin talks about how to check md5sums of patches.
In the security catalog, you can find the record by searching for "SecBul:
Hope that helps.
-Keith
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
07-07-2004 04:54 AM
07-07-2004 04:54 AM
Re: Security Patch Check B.02.00 released
That is exactly what I needed. I'd tired both the URL and security_catalog yesterday, but you provided the keys to find them in both.
Thank you very much,
Tom
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
10-01-2004 08:19 PM
10-01-2004 08:19 PM
Re: Security Patch Check B.02.00 released
is there a way to manually download the security_catalog file. I cannot access ftp directly from my server due to company restrictions.
Thanks
Patrick
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
10-03-2004 06:34 AM
10-03-2004 06:34 AM
Re: Security Patch Check B.02.00 released
The man page points to several download locations:
https://itrc.hp.com/service/patch/securityPatchCatalog.do?item=security_catalog2.gz
http://itrc.hp.com/service/patch/securityPatchCatalog.do?item=security_catalog2.gz
ftp://ftp.itrc.hp.com/export/patches/security_catalog2.gz
Hope This helps
Tyler
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
10-04-2004 05:24 AM
10-04-2004 05:24 AM
Re: Security Patch Check B.02.00 released
Tyler gave the locations to download from. Then you just need to find a way to copy the catalog to your server (ssh, tape/floppy/usb?) and you can use the -c option to point at the catalog.
Hope that helps.
-Keith
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
10-04-2004 05:38 AM
10-04-2004 05:38 AM
Re: Security Patch Check B.02.00 released
I already have 6 homebrewn versions of perl (amongst which are 5.8.5 and 5.9.2 both in 32 and 64bit), and the most recent versions of openssl/openssh from the porting center and all SSL modules that connect the two
How could I test that?
Enjoy, Have FUN! H.Merijn
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
10-04-2004 05:55 AM
10-04-2004 05:55 AM
Re: Security Patch Check B.02.00 released
We have only tested it with the HP versions of Perl and openssl, and therefore only support it that way. If you decide to go ahead and hack something together using your own Perl and openssl, be aware:
1. You'll need the LWP modules, along with a combination of working SSLeay parts and shared libraries. There are a few different ways to get this to work depending on which parts and pieces you have...
2. The official HP OpenSSL ships verisign certificates so that certificate validation can be done properly out-of-the-box. You'll need to import those into your trust store, then use the OPENSSLDIR setting in /etc/opt/sec_mgmt/spc/spc_config to point to your openssl binaries, including c_rehash.
3. For just base functionality (no https), you'll still need a reasonably recent version of Perl (sounds like this is the least of your worries) and the SD dependencies at install-time will enforce this based on HP's version of Perl.
4. Any vulnerabilities in your versions of Perl/openssl or their interactions with Security Patch Check will not be announced by HP and therefore would not be covered by Security Patch Check. SPC relies heavily on SD's installed-product database to determine if you are affected by something.
Back to your question of "will it work"...probably, but it's not for the faint-of-heart, so proceed with caution.
Hope that helps.
-Keith
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
10-04-2004 07:53 PM
10-04-2004 07:53 PM
Re: Security Patch Check B.02.00 released
I've downloaded the depot, but the depot name clearly states 11.22, indicating Itanium. I didn't see that in your announcement post.
Will/should this also work on 11.00 and 11.11?
Enjoy, Have FUN! H.Merijn
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
10-05-2004 02:54 AM
10-05-2004 02:54 AM
Re: Security Patch Check B.02.00 released
Thanks for letting us know.
John
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
10-05-2004 04:58 AM
10-05-2004 04:58 AM
Re: Security Patch Check B.02.00 released
I didn't suspect you were faint-of-heart, just wanted to make sure you and anyone else who tried to follow in your footsteps had fair warning :)
The depot name contains the architecture string, which is
HP-UX_B.11.22_32/64
By convention, that means that it works on 32 and 64 bit systems (PA), and the minimum itanium OS it runs on is 11.22 (supports 11.23 but not 11.20). From a technical standpoint, this field is completely ignored by SD.
Instead, you should look at the os_release field, which is "B.11.*". You can find this field by doing
swlist -l fileset -a os_release
A runtime check on 11.20 would tell you that it's not supported.
Hope that helps.
By the way, I'm planning to use these questions to feed into the FAQ, so thanks to all for asking!
-Keith