Sun UC Client upgrade required, New patch server deployed

Impact: The Sun Update Connection is now transitioning to a new

external patch server which requires a new client protocol.

To insure uninterrupted service to all SunUC users will be

upgraded to the new client software.

We expect this new patch server, which uses Akamai as

the patch distribution source, will be more reliable and offer

improved performance when accessing patches from the

Sun Update Connection.

Affects: All Solaris 10 users of Sun Update Connection System

(Sun Update Manager and smpatch users). Specifically,

systems with patch revisions 121118-06 and earlier(SPARC)

and 121119-06 (x86) and earlier will be affected.

This includes software integrated into Solaris 10 1/06

and Solaris 10 6/06.

Action: Beginning Monday 10/23 Solaris 10 Update Manager and

smpatch will begin offering only the patches required to

upgrade to the new Sun Update Connetion System client.

121118-08 SunOS 5.10: Sun Update Connection Client 1.0.8

121119-08 SunOS 5.10_x86: Sun Update Connection Client 1.0.8

Use the Sun Update Manager or smpatch to apply the patch

appropriate for your system plus any required dependency patches.

After this patch and it's dependencies are installed you will be

offered all current patches applicable to your Solaris 10 system.

Evidence:

The pre-version 1.0.8 client referenced the default patch server on URL

https://getupdates.sun.com/solaris or https://getupdates1.sun.com/solaris

The new server URL is https://getupdates1.sun.com ("/solaris" is dropped).

Running the command 'smpatch get' will reveal the patch server being used

Thank You,

Sun Update Connection Team

[1784 byte] By [ForumModerator] at [2007-11-26 10:56:55]
# 1
On my patch proxy, the command patchsrv setup -l still shows the patch source as the old URL.Is this a problem?
robertcohen at 2007-7-7 3:10:14 > top of Java-index,Administration Tools,Sun Update Connection-System...
# 2
Yes I believe that the patchsvr source will also have to be updated. It's also my understanding that a patch to upgrade the patchsvr portion of SunUC is being worked on to correct the certs issue and update the default source URL
ForumModerator at 2007-7-7 3:10:14 > top of Java-index,Administration Tools,Sun Update Connection-System...
# 3

Well, I tried manually setting the URL in the proxy to the new value.

But I think it broke the update of solaris 9 hosts.

What URL should we be using to access our local proxy.

Currently I use http://server:3816/solaris

I tried dropping the solaris to match the change in the update server url, but that didnt appear to work..

robertcohen at 2007-7-7 3:10:14 > top of Java-index,Administration Tools,Sun Update Connection-System...
# 4
Add a trailing slash to the source url on the clients so that it looks like - http://server:3816/solaris/
ForumModerator at 2007-7-7 3:10:14 > top of Java-index,Administration Tools,Sun Update Connection-System...
# 5
Ok, so what should then be Patch source URL then ?should it be:Patch source URL: https://getupdates1.sun.com/BTW, I still don't see any references to Akami with the new URL...
su_A_ve at 2007-7-7 3:10:14 > top of Java-index,Administration Tools,Sun Update Connection-System...
# 6

Please tell me this isn't re-directed to a random Akamai site ... this will cause great teeth gnashing among our firewall admins ...

Running Solaris10, after applying patch 121118-08 (which did update the remote patch URL), seem to be 2 levels of re-directs, the first to 64.212.198/24 and the second to 81.52.249/24.

After allowing those 2 subnets to be reached on the fw, smpatch returns no patches required ... of which I'm suspicious. How can I verify this is working correctly? Network traffic suggests it is communicating with these remote hosts, but I haven't patches this server in a month and there must be patches available by now.

thanks,

Kris

kryspy at 2007-7-7 3:10:14 > top of Java-index,Administration Tools,Sun Update Connection-System...
# 7
su_A_ve : Your patch source is correctKryspy : It is redirected to a load balancer first.
ForumModerator at 2007-7-7 3:10:14 > top of Java-index,Administration Tools,Sun Update Connection-System...
# 8

>>...(which did update the remote patch URL)...

my mistake - it updates smpatch patchpro.patch.source, but does not update patchsvr Patch source URL, as correctly stated earlier.

>>Kryspy : It is redirected to a load balancer first.

I did guess that from the redirects, thanks for the verification.

Does Sun provide IP information for systems behind the load balancer so we can configure our firewalls for something other than 443 everywhere?

thanks

kryspy at 2007-7-7 3:10:14 > top of Java-index,Administration Tools,Sun Update Connection-System...
# 9

Hi.

Here's the full list of hostnames required for Sun Update (using Akamai):

getupdates1.sun.com

a248.e.akamai.net

cns-services.sun.com

cns-transport.sun.com (if you use the optional web feature)

www.sun.com

The Akamai host's IP has been different every time I have nslookup'ed it, so I don't think I can give a definitive list of IP adresses for the Amamai side.

Mod.

ForumModerator at 2007-7-7 3:10:14 > top of Java-index,Administration Tools,Sun Update Connection-System...
# 10

Was a Sun Alert issued that addressed patch ID 121118-08?

For example, Sun Alert 102639 alerted the Solaris community that a patch was available (patch ID 121118-06): "A New Signing Certificate Will be Used Beginning September 24, 2006."

However, I don't see a Sun Alert that alerts the Solaris Community to the fact that the Sun UC manager client needs to be updated (patch ID 121118-08).

Thanks!

csalemi at 2007-7-7 3:10:14 > top of Java-index,Administration Tools,Sun Update Connection-System...
# 11

There was no alert issued for 121118-08 as it is not required to be installed, and was released to correct problems that affected some users.

The alert was released for 121118-06 because if the patch was not applied, UC would effectively stop working on the expiry of the old certificates.

ForumModerator at 2007-7-7 3:10:14 > top of Java-index,Administration Tools,Sun Update Connection-System...