As we have detailed on previous posts, VMware is committed to using Photon OS in just about all the appliances that are being deployed with various products now. The new vCenter Server appliance is a case in point to that. Since Photon OS is a custom built OS from VMware, they can achieve a much more aggressive patch/support schedule. This is a great change from a security perspective as historically, VCSA patches when running on SuSE were not released that often. VMware has documented in their security response policy that patch releases will be based on the vulnerability severity. Let’s take a look at how to install VMware VCSA vCenter appliance Photon OS security patches.
Install VMware VCSA Security Patches GUI
The method that most will be familiar with in patching a VCSA appliance is from the GUI interface. We can get to the Update functionality by browsing out to the VAMI interface https://<your vcenter IP>:5480. Choose the Update menu option.
Select the Update option.
Under the Check Updates menu, click the Check Repository option. This will pull updates from the online VCSA update repository.
As shown below, the 6.5.0.10100 Build Number 6671409 update is available. We can choose to Install All Updates.
We will be presented with the EULA for the update. Click the Accept button.
You can choose whether or not you want to join the CEIP program by checking or unchecking the box. Then click the Install button.
The patches are staged for installation.
The update process runs a few pre-install scripts. You can select the Show Details button to reveal the specifics of the process.
The packages will begin updating after the pre-install scripts run.
After the update is finished, you will see the message that a reboot is required to complete installation.
If we go back to the Update menu, we will see the current build number is showing now, however, we still see the reboot directive.
We can easily reboot from the VAMI interface, by going to the Summary tab and selecting the Rebootoption.
Select Yes on the reboot the system directive.
Install VMware VCSA Security Patches Command Line
A very easy and powerful way to install patches to VMware VCSA appliance is by using the command line. We can pull the updates directly from the VMware online repository as well. We can find the URL for patching from the online repository by logging into the VCSA VAMI interface https://<your vcenter IP>:5480 and choosing Update >> Settings. Under the Repository Settings you will see the URL for the online repository. We can copy that and use it from the command line.
Login via SSH to your VCSA appliance. Make sure your shell is set to the default appliance shell. We will use the software-packages install –url command to stage and install the patches. We use the URL we copied from the VAMI interface Update settings.
We will see the EULA presented from the command line. You can also use the following command to accept the EULAs automatically:
After the EULA, we type out yes to the “Do you accept the terms and conditions?” question.
After the reboot of the VCSA 6.5 appliance, we will have the latest patches/security patches installed.
Great Article
ReplyDeleteCyber Security Projects for CSE Students
JavaScript Training in Chennai
Project Centers in Chennai
JavaScript Training in Chennai
This is such a great resource that you are providing and you give it away for free. I love seeing blog that understand the value. Im glad to have found this post as its such an interesting one! I am always on the lookout for quality posts and articles so i suppose im lucky to have found this! I hope you will be adding more in the future... visit here
ReplyDeleteVery informative post! There is a lot of information here that can help any business get started with a successful social networking campaign. visit this site
ReplyDeleteI discovered your blog post site online and check a few of your early posts. Always keep within the really good operate. I additional up your RSS feed to my MSN News Reader. Looking for forward to reading more from you later on!
ReplyDeletevisa de canadá
I discovered your blog post site online and check a few of your early posts. Always keep within the really good operate. I additional up your RSS feed to my MSN News Reader. Looking for forward to reading more from you later on!
ReplyDeleteBlanket Boxes
Thank you for some other informative blog. Where else could I get that type of information written in such an ideal means? I have a mission that I’m just now working on, and I have been at the look out for such information. visit this site
ReplyDeleteNice post ✅. I was checking constantly this blog and I am impressed! Extremely helpful information specially the last part
ReplyDeleteCAM Accounting