Installation guide

Table Of Contents
Patching Managed Machines
9
Patching Managed Machines
VCM patch assessment, deployment, and verification ensures continuous security in your environment
through proactive compliance of your IT infrastructure. VCM ensures that your managed machines have
the latest security patches and other software installed. You can evaluate each physical and virtual
managed machine in your environment to ensure that they have the latest supported vendor patches or
security bulletins installed, and deploy the recommended patches to those managed machines.
VCM assesses the patch status of Linux and UNIX managed machines, and deploys patches to those
machines to ensure compliance in your environment. You can have VCM deploy Linux and UNIX patches
without your intervention or you can deploy them manually.
This chapter includes the following topics:
Patch Assessment and Deployment 137
Prerequisite Tasks and Requirements 138
Manually Patching Managed Machines 141
Getting Started with VCM Manual Patching 143
Configuring An Automated Patch Deployment Environment 156
Deploying Patches with Automated Patch Assessment and Deployment 169
How the Linux and UNIX Patch Staging Works 177
How the Linux and UNIX Patching Job Chain Works 178
How the Deploy Action Works 178
Patch Deployment Wizards 179
Running Patching Reports 180
Patch Assessment and Deployment
VCM can deploy patches to 32-bit and 64-bit Linux, UNIX, and Windows managed machines. When you
deploy patches on Linux and UNIX machines, follow the best practices defined by the OS vendor.
Supported managed machine types include Red Hat Linux, SUSELinux, UNIX-based operating systems
such as Mac OSX, Solaris, AIX, and HP-UX machines, and Windows machines.
To ensure that Linux, UNIX, and Windows managed machines always include the latest patches, you can
have VCM deploy patches to the managed machines when certain events occur in your environment.
After you perform the initial configuration for the automatic deployment, no intervention is required to
deploy patches to managed machines.
VMware, Inc.
137