[pca] New Sun policy on security/recommended patch versions

Craig Bell Craig.Bell at standard.com
Sat Jun 19 01:12:10 CEST 2010


Martin Paul wrote:

> Another idea would be to add another suffix "c" to specify the cluster with the minimum revisions, and leave "r" as it is. I'm afraid that this might be even more confusing to new users, though.

  This sounds straightforward to me.  You might emphasize that "c" is still limited to the R flag, as one could assume that "cluster" implies everything found in the new Recommended OS Cluster.  Hmm... that raises a silly question:

  If one cares about the new cluster, then does one ever want only a subset?  It seems like "analyze the whole thing" would be the most common use-case.  This might be desirable (and easily understood) for a new operand suffix.

  Then again, you might consider this out-of-scope.  Further, the xref probably doesn't contain enough information for pca to discern exactly what's in the OS cluster; but, Oracle publishes *_Recommended.README files.  =-)

> That's a rather big difference - 16 patches less to be installed

  That's good to see. You're right, frequent patchers would enjoy a larger advantage.  I was thinking of a much longer patch cycle -- After one year, I think the delta will be much smaller, to the point where I see little benefit.  

> Will support continue to ask "are ALL patches installed?"

  One of my support cases involved a driver bug that was resolved in a patch with no flags set.  All of our careful patch management didn't buy us much, when the (perfectly reasonable) answer is simply "get current".  =-)

  Saving a few extra patch applications is nice, but supportability (what Oracle chooses to flag, and how they "feel" about one's patch levels) trumps convenience.  This has as much to do with our patch strategy as does security.  =-)

  Thanks again...  -cheers, CSB



More information about the pca mailing list