10 The Patch Assessment Tool

Benefits of the Patch Assessment Tool

You can use the Patch Assessment Tool to create custom patch bundles for individual HP-UX systems and for multiple systems you manage as a group. The Patch Assessment Tool simplifies the bundle creation process by guiding you through system-based patch analysis and selection. HP's web-based Patch Assessment Tool is available on the IT Resource Center (ITRC) website at http://itrc.hp.com.

TIP: HP-UX Software Assistant (SWA) was released in January, 2007 as a software upgrade to

the Patch Assessment Tool. For more information, see Chapter 8: “Using HP-UX Software Assistant for patch management” (page 85).

The Patch Assessment Tool replaces the Custom Patch Manager (CPM) Tool.

In addition to creating custom bundles, you can also use the Patch Assessment Tool to do the following:

Ensure your system meets the HP recommended patch configuration.

Ensure all applicable security patches are installed on the system.

Identify and acquire replacement patches for patches with warnings installed on the system.

If you are implementing a proactive patch management strategy, the Patch Assessment Tool can be useful as your primary method of patch selection. See Chapter 4: “Patch management overview” (page 42) for more information about proactive patching.

The benefits of using the Patch Assessment Tool to select and acquire patches include:

The assessment returns a set of patches customized to your needs based on your input:

Select or deselect patches that provide critical fixes.

Select or deselect patches that fix security vulnerabilities.

Include sets of patches that pertain to specific applications.

Select or deselect replacement (or superseding) patches for patches already on a system that have noncritical or critical warnings.

Require that a specific patch be included in the assessment.

Request the latest Quality Pack (QPK) patch bundle.

The tool automatically checks the selected patches against each other as well as against patches currently installed on the system to detect conflicts and dependencies.

The assessment results include information detailing why each patch was recommended.

You can download recommended patches as a tar, zip, or gzip package.

You can use the program locating commands whereis(1) and which(1) to make sure you have the appropriate software. For example, use whereis gzip to determine if the program is installed and use which gzip to determine if the program is in your path.

Using the Patch Assessment Tool

1.Log in to the ITRC at http://itrc.hp.com.

Please note that you need to log in to the appropriate site (Americas/Asia Pacific or European).

2.Select Patch database.

3.Select run a patch assessment.

The run a patch assessment page is displayed.

88 The Patch Assessment Tool