Patching minimal install of Solaris 9

Hi!

Background: I'm an experienced Linux admin who's trying to install Solaris on a Sun Fire V100, rather than just manage badly installed systems that other people did in the past. The machine needs Solaris 9 because it is a test for a production machine which is running Solaris 9 too.

What I've done: Installed Solaris 9 (9/05), Core software only. I don't need any web based or desktop stuff, and like to keep my systems as free of as much extra stuff that could be compromised. The "End user" or "Developer" options both wanted to install all sorts of things (GNOME, Java, X, etc) that just aren't wanted on a headless server. At about 300M it's still twice as big as a basic Debian install, but it's better than the nearly 2G full install.

What I'm trying to do: Patch the thing! On Linux I'd do a simple "apt-get update; apt-get upgrade" and it'd all work. I've got some experience of PatchPro and smpatch, but neither of these seem to be available. Can't download PatchPro because that seems to be Solaris 6/7 only now, and can't download Patch Manager because it is only for Solaris 8. Solaris 9 is provided as a patch (!!!), but that won't install because I don't have a stack of packages on the system! Found a local copy of Patch Manager 2.2 for Solaris 9, but that won't install either due to missing packages.

I have managed to get Blastwave on, so can get some decent tools, but still can't patch the basic system.

Is it really impossible to patch Solaris without installing a Desktop environment (It's a server, serial console only) or am I missing something obvious? I can't believe that a minimal install can't be patched without installing lots of unneeded stuff on the system. (I also can't understand why in 2006 it installs a telnet and ftp server, but not an ssh server, but that's another question entirely! ;-) ).

Thanks for any help or advice!

[1955 byte] By [leicmcn] at [2007-11-26 10:34:15]
# 1

Sorry to tell you this but we've tried to get this answer before:

http://forum.sun.com/jive/thread.jspa?threadID=105298&tstart=30

Might want to check out PCA, it seems to be a less bloated patching tool and doesn't require all the authentication steps that provide no value:

http://www.par.univie.ac.at/solaris/pca/

jtej5439 at 2007-7-7 2:43:30 > top of Java-index,Administration Tools,Sun Update Connection-System...
# 2

Hi,

Wow, that looks great. CLI driven, dependency checking, easy to install and use... it makes me wonder why Sun couldn't do something similar. Changing to at least three different patch systems in the last couple of years or so (from my experience, anyway) just seems silly.

I'll have to try it on some of my other installed machines that refuse to patch with Sun's software now... ;-)

Thanks!

Matthew

leicmcn at 2007-7-7 2:43:30 > top of Java-index,Administration Tools,Sun Update Connection-System...