Support Plus User Guide HP-UX 11i Version 1, June 2004

Support Plus User Guide HP-UX 11i v1
Using the Security Patch Check Tool
Chapter 130
Using the Security Patch Check Tool
Whether you plan to install a bundle directly from a depot on the
Support Plus CD or to install from a customized depot you have created,
HP recommends that you run the Security Patch Check tool on the depot.
Use this tool to analyze the patches in the depot and identify two classes
of patches that you should investigate before continuing with patch
installation:
1. Patches that have been the subject of patch warnings.
2. Patches that are recommended to improve system security.
The Security Patch Check tool is available for free download from the
Software Depot web site:
http://software.hp.com
Example
To identify patches, enter:
swlist -l fileset -a supersedes -a revision \
-a software_spec -a state -d @ /path/to/depot | \
security_patch_check - -r -a
Consult the security_patch_check (1m) man page and the FAQ for
additional information:
http://docs.hp.com/hpux/onlinedocs/internet/spc_faq.html
Read the Security Bulletins and patch warnings associated with the
patches identified by the tool to determine what, if any, changes you
want to make to the depot before proceeding with installation.
You may also choose to run Security Patch Check on the systems you are
updating.