LinuxQuestions.org
Share your knowledge at the LQ Wiki.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Server
User Name
Password
Linux - Server This forum is for the discussion of Linux Software used in a server related context.

Notices


Reply
  Search this Thread
Old 05-19-2016, 05:53 AM   #1
dlol
LQ Newbie
 
Registered: May 2016
Posts: 3

Rep: Reputation: Disabled
Centos server patching strategy


Hi everybody,

I have a question about patching Centos (7) servers. How do you decide which patches to apply to the machine? Is there some tool which can help you determine which updates are relevant? Also, there are servers which are e.g connected to the internet vs those which are behind a firewall and are not exposed to any untrusted networks. Is it ok not to patch, or to patch such "internal" servers just with security updates?
I have seen several threads with similar topics, but they all deal more with "how to perform an update" rather than "how to select which updates to apply"?
Of course, the strategy would be to test the updates on test servers first - but I doubt even there you should "update all"... We are using a "minimal" install of Centos and would like it to stay as "minimal" as possible...

What do you think?
 
Old 05-19-2016, 06:08 AM   #2
TenTenths
Senior Member
 
Registered: Aug 2011
Location: Dublin
Distribution: Centos 5 / 6 / 7
Posts: 3,474

Rep: Reputation: 1553Reputation: 1553Reputation: 1553Reputation: 1553Reputation: 1553Reputation: 1553Reputation: 1553Reputation: 1553Reputation: 1553Reputation: 1553Reputation: 1553
Quote:
Originally Posted by dlol View Post
How do you decide which patches to apply to the machine?
By applying knowledge of the system requirements and looking at the nature of the patch.
Quote:
Originally Posted by dlol View Post
Is there some tool which can help you determine which updates are relevant?
You could consider filtering yum to only list updates that are marked as security updates and then Google the rest. Somewhere in my server build document I've notes on how to configure yum to get a daily e-mail of security updates.
Quote:
Originally Posted by dlol View Post
Also, there are servers which are e.g connected to the internet vs those which are behind a firewall and are not exposed to any untrusted networks. Is it ok not to patch, or to patch such "internal" servers just with security updates?
Depending on your IT security and patching policies yes or no.
Quote:
Originally Posted by dlol View Post
[..]I doubt even there you should "update all"... We are using a "minimal" install of Centos and would like it to stay as "minimal" as possible.
"update all" will only update packages that are already on your server (plus their dependencies), so it won't necessarily "grow" your minimal install.
 
Old 06-05-2016, 04:20 PM   #3
dlol
LQ Newbie
 
Registered: May 2016
Posts: 3

Original Poster
Rep: Reputation: Disabled
TenTenths, thank you for your answer, it was helpful
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
[SOLVED] Patching Centos yohey03 Linux - Server 4 10-08-2012 10:38 AM
CENTOS patching crackerB Linux - Kernel 2 09-06-2012 02:51 AM
centos vs rhel patching drManhattan Linux - Server 1 10-20-2011 02:26 PM
strategy for resolving rpm dependence hell (centos) anadem Linux - Software 5 12-14-2010 06:20 PM
RHEL Patching Strategy. jasoneh Red Hat 3 11-24-2008 03:19 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Server

All times are GMT -5. The time now is 03:08 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration