AIX

AIX

Connect with fellow AIX users and experts to gain knowledge, share insights, and solve problems.

 View Only
  • 1.  Security documentation of How ILMT update works?

    Posted Mon July 26, 2021 12:55 PM

    Hello,

    recently we've updated to v9.2.24. The change was approved, however, we're requested to provide documentation to help security understand how this update works. ILMT/BigFix is a monitor app interfacing with the Internet and downloading updates - pretty much what SolarWinds' Orion was doing and we know what happened. So I understand where this request for documentation comes from.

    Is there any detail on how the update through a fixlet happens? I have not managed to find one googling around.



    #AIX
    #Support
    #SupportMigration


  • 2.  RE: Security documentation of How ILMT update works?

    Posted Mon July 26, 2021 01:46 PM

    Hello,

    In case of any security-related doubts, please check the "Security" chapter in ILMT documentation explaining details, e.g. the flow of data chart from:

    https://www.ibm.com/docs/en/license-metric-tool?topic=security-flow-data

    ILMT runs on top of BigFix platform. ILMT talks to BigFix server which orchestrates BigFix clients and obtains updates from BigFix online repository. So when you initiate the upgrade fixlet from BigFix console, then BigFix server downloads ILMT installer files from its repository and passes them to the machine (BigFix client) where ILMT resides. There, BigFix client starts the installer for upgrade. Note the downloads performed by BigFix server are verified based on checksums of files and also communication between BigFix server and BigFix clients is secured - BigFix clients talk only to the BigFix server they know from the masthead file and based on the key you set during BigFix server install.

    If due to any reason you restrict BigFix server from accessing the Internet, then you need to pre-download installer files by means of the Airgap tool of BigFix and place them on the BigFix server:

    https://www.ibm.com/docs/en/license-metric-tool?topic=tool-updating-fixlet-site

    Best regards,

    LMT-MZ



    #AIX
    #Support
    #SupportMigration


  • 3.  RE: Security documentation of How ILMT update works?

    Posted Wed August 04, 2021 02:12 PM

    Hello, thanks for your help. I understand that these are the only available details and description and it will have to suffice to our tech leads. Thanks a lot for that :) Have a great day.



    #AIX
    #Support
    #SupportMigration