Patch Management User Guide for HP-UX 11.x Systems (5900-3011, March 2013)

All information has been logged to /var/adm/cleanup.log.
### Cleanup program completed at 04/13/04 07:17:40
HP-UX patch ratings
HP-UX patches have a corresponding quality rating called the HP rating. HP assigns a patch rating
of 1 (numeral or star) to each HP-UX patch when it is released. Over time, HP might update the
rating value to 2 or 3 (numeral or stars) to convey increased confidence in the patch. The higher
the rating, the lower the risk of side effects and the more suitable the patch is for mission-critical
environments.
You can use the HPSC's Patch Database to find the rating value for a specific patch. The HPSC
graphically represents a patch's rating by displaying one to three stars beside the patch ID in the
results of a patch search. “Obtaining information using the HPSC” (page 39) provides details on
how to do this.
If HP learns of a problem caused by or exposed by an HP-UX patch, HP issues a patch warning
describing the problem and ceases recommending the patch, but does not change the patch rating.
If a patch has a warning associated with it, you will no longer be able to view the rating on the
HPSC's Patch Database. For more information on patch warnings, see “Patch warnings (page 40).
The following rating related information pertains only to patches that have no associated warnings.
HP patch rating of 1
Although these patches have passed rigorous prerelease testing, HP recommends that you use
these patches only if all of the following conditions are true:
If you are in a reactive patching situation.
The highest-rated patch that addresses the problem is rated 1.
You cannot wait for the patch to increase to a higher rating.
Whenever possible, you should wait until the patch gains more exposure and achieves a rating
of 2 or 3. For more information on reactive and proactive patching, see Chapter 4: “Patch
management overview” (page 44).
Rating details
The following list provides more details about patch ratings of 1:
Upon release, patches are assigned a rating of 1.
These patches have successfully completed internal testing by HP.
Because they are new, these patches have an inherent level of risk associated with them that
you might find unacceptable. However, they are made available in case you are willing to
accept the increased risk because the patch resolves a specific issue on a system.
If you choose to use one of these patches, you should evaluate and test it carefully prior to
deployment on a system.
HP patch rating of 2
HP recommends that you use patches rated 2 for both proactive and reactive patching and when
a patch rated 3 is not available.
Patches rated 1 might be upgraded to a rating of 2 on any given day (based on the amount of
customer exposure). Therefore, if you chose to defer patch installation to wait for a patch rating
to be upgraded to a rating of 2, you can check for this upgrade on a daily basis.
36 HP-UX patch overview