Let us Patch Up with Patching - weblogic/soa suite
Patching is a confusing topic for beginners. In this post, I will try to explain different terminologies.
CPU – Short for Critical Patch Update. It comprises of security patches.
PSU – Short for Patch Set Updates. It includes security and priority fixes.
Both patches are released quarterly on the Tuesday closest to the 17th day of the months of January, April, July and October. Both the patches are cumulative that means every patch includes fixes of the early patches. So, there is no need to apply earlier patches. Once a PSU has been applied on the system, the recommended method to apply all future CPU program security content is to apply future PSUs. In other words, once a PSU has been applied, it is not recommended to switch back to traditional N-apply patches. Reverting to CPU from PSU is complex and time consuming task and so it is not recommended.
One-Off: If Oracle finds critical vulnerability that can’t wait till next patch release, it releases One-Off Patch.
Error Correction Period: This is the period beyond which Oracle doesn’t release any fixes either PSU or CPU. There is different criteria for different product versions. Please refer to Oracle documentation for more details.
How to get current patch set level:
12c:
In WebLogic Server 12.1.2 and higher (that is, the versions which use OPatch rather than Smart Update), you need to use OPatch to query what patches (including what PSU) are installed. To do this, use the OPatch lsinventory command.
For example: opatch lsinventory
11g:
In WebLogic Server versions prior to 12.1.2, you can determine what PSU and other one-off patches are applied to your environment by using the weblogic.version command. To do this, follow these steps:
i) Set the environment for your WLS installation by running the WL_HOME/server/bin/setWLSEnv (cmd or sh) script.ii) Run the weblogic.version command.
or
i) cd $MW_HOME/utils/bsu/ii) ./bsu.sh -view -status=applied -prod_dir=/app_base/PRDBTB/Middleware/wlserver_10.3/ -verbose -view
Note: In WLS 11g (10.3.4+) and 12.1.1, each PSU will conflict with any prior PSU in the series. To install a subsequent PSU, any existing PSU must first be uninstalled. This restriction is no longer applicable in WLS 12.1.2 and higher. In those versions, OPatch automatically rolls back the previous PSUs and there should be no requirement that customers manually roll back prior to installing the PSU.
References:
Oracle Doc id: 1306505.1
Comments
Post a Comment