Skip to main content

OS Vendor Patches

ServiceOps supports vendor-specific patch management for RedHat and SUSE Enterprise Linux. You can fetch RedHat patches through agent nomination or a satellite server, and manage SUSE patches through subscription registration codes tied to your SUSE Customer Center account.

Subscription Required

A valid subscription is required to perform patch management for RedHat and SUSE Enterprise Linux.

To open the OS Vendor Patches page, navigate to Admin > Patch Management > Patch Administration > OS Vendor Patches.

OS Vendor Patches page showing RedHat Patch Setting and SUSE Enterprise Linux Setting sections

RedHat Patch Setting

The RedHat Patch Setting section lets you choose how ServiceOps fetches RedHat patches, either through nominated agents or a connected RedHat Satellite Server.

RedHat Patch Preference

Choose the preference that best suits your organizational needs for fetching RedHat patches:

  • Agent Nomination: Select this option to nominate specific agents that will handle RedHat patch management.
  • RedHat Satellite Server: Select this option to integrate with a RedHat Satellite Server for patch management.

After selecting your preference, click Update to apply it.

Preference Change Removes Existing Data

Updating the preference removes all existing RedHat patches and agent nomination details from the Patch list.

RedHat Patch Preference options showing Agent Nomination and RedHat Satellite Server choices

Agent Nomination

Agent Nomination lets you designate specific agents (Workstation and Server) to handle RedHat patch management on behalf of your environment.

Agent Nomination section showing nominated agent list for Workstation and Server categories

Prerequisites

Confirm the following before nominating agents:

  • Designated RHEL Host: Identify a specific Red Hat Enterprise Linux machine to act as the Nomination Machine. Avoid using a host that also runs production workloads.
  • Supported OS Version: The Nomination Machine must run RHEL 7 or RHEL 8.
  • ServiceOps Agent Installed: Install the ServiceOps Agent on the Nomination Machine and confirm the host appears in the ServiceOps Endpoints Scope.
  • Registered to Satellite: Register the Nomination Machine with the Satellite Server, attach it to the correct organization, and assign it to a content view or lifecycle environment that exposes the required repositories.
  • Full Repository Access: The Nomination Machine must have access to every repository enabled on the Satellite Server.
  • Capacity and Connectivity: Provision adequate disk space, CPU, memory, and stable network connectivity to the Satellite Server. Repository sync is I/O- and bandwidth-intensive on the first run.
Full Repository Access Required

The Nomination Machine must have access to every repository enabled on the Satellite Server. If even one enabled repository is inaccessible, the repository synchronization step will fail and the entire RHEL patch flow will stop working. Partial coverage is not supported. Before configuration begins, either confirm full repository access or disable any repositories on the Satellite Server that are not required.

Only agents with an active subscription and an internet connection can be nominated. To nominate an agent:

  1. Click the Edit icon next to the desired agent. The following popup appears:

    Edit popup for agent nomination showing Agent ID, Nomination Category, Repo Sync Status, and Last Sync Time fields

  2. Provide the following details in the popup:

    FieldDescription
    Agent IDSelect the Agent ID to nominate. Only agents listed in the Endpoints Scope page are available.
    Nomination CategoryDisplays the category for which the agent is nominated: Workstation or Server.
    Repo Sync StatusShows the status of the repository synchronization: success or failed.
    Last Sync TimeDisplays the date and time of the last synchronization with the RedHat repository.
  3. Click Update to save your changes. If no agents are nominated, the record remains blank.

RedHat Satellite Server Integration

The RedHat Satellite Server integration lets ServiceOps pull patch data directly from your Satellite deployment, covering all RHEL systems managed through it.

RedHat Satellite Server Integration section showing configuration fields and available repositories

Prerequisites

Confirm the following before configuring the satellite server:

  • Operational Satellite Deployment: A supported, production-grade Red Hat Satellite Server is deployed, licensed, and operational.
  • Repositories Enabled: All required RHEL repositories (base OS, AppStream, supplementary, EUS/E4S, and any third-party repositories) are enabled on the Satellite Server.
  • Repositories Fully Synced: Every enabled repository has completed an initial full sync against Red Hat, and a recurring sync schedule is configured for ongoing updates.
  • Valid Satellite Organization and Manifest: A Satellite organization exists with a valid, current Red Hat subscription manifest that covers all in-scope repositories.
  • Admin User Account: An admin user account is available on the Satellite Server with permissions to read organizations, products, and repositories.

Configuration Steps

To configure the satellite server:

  1. Click Edit and provide the following details:

    Edit configuration popup showing Server URL, Username, Password, Enable Schedule, Proxy Server, and Certificate fields

    FieldDescription
    Server URLEnter the satellite server URL or IP address (e.g., https://satellite.serviceops.local).
    UsernameEnter the username for the satellite server.
    PasswordEnter the password for the satellite server.
    Enable ScheduleEnable this option and specify the time to fetch patches daily.
    Proxy ServerSelect the appropriate proxy server if applicable.
    CertificateUpload the .pem certificate obtained from the satellite server (see steps below).

    To obtain the certificate from your RedHat Satellite Server:

    1. Log in to the RedHat Satellite Server web interface.

    2. Navigate to Administer > Organizations.

      RedHat Satellite Server Administer menu showing the Organizations option

    3. Click Edit on the Default Organization.

      Default Organization row with Edit option highlighted

      The organization details page appears:

      Default Organization details page with Generate and Download button

    4. Click Generate and Download to download the certificate in .pem format.

    5. Upload the downloaded .pem file to the ServiceOps portal.

    Once all details are provided, click Save. The saved server configuration appears as shown below:

    Saved RedHat Satellite Server configuration with server URL and status displayed

  2. Click Fetch Repos Now to retrieve repositories.

The repositories appear in the Available Repositories tab:

Available Repositories tab showing list of repositories fetched from the RedHat Satellite Server

SUSE Enterprise Linux Setting

The SUSE Enterprise Linux Setting section lets you register SUSE subscriptions and fetch available patch repositories directly from the SUSE Customer Center.

Configure SUSE Subscription

Connect your SUSE Customer Center account to ServiceOps using subscription registration codes. Once registered, ServiceOps fetches patch repositories for the associated subscription type.

To get your registration codes from SUSE Customer Center:

  1. Sign in to SUSE Customer Center at https://scc.suse.com/subscriptions.
  2. Select your active SUSE subscription (Desktop or Server).
  3. Copy the Registration Code from your subscription details.
  4. Paste the registration code in the Actions column for the Desktop or Server subscription in ServiceOps.

SUSE Enterprise Linux Setting page showing Configure SUSE Subscription steps and the Configuration tab with OS Variant, Name, Expiry At, Last Sync Time, and Actions columns

Configuration

The Configuration tab displays the two default SUSE subscription types and lets you attach registration codes to each.

ColumnDescription
OS VariantThe SUSE subscription type: Server or Desktop.
NameThe subscription name fetched from the SUSE Customer Center API after a valid registration code is saved.
Expiry AtThe subscription expiry date returned from the SUSE API.
Last Sync TimeThe timestamp of the last successful SUSE API call for that subscription.
ActionsClick the key icon to open the Set Registration Code dialog for that subscription type.

Set Registration Code

Click the key icon in the Actions column to open the Set Registration Code dialog for a subscription type.

set registration code

FieldDescription
Registration CodeEnter the registration code copied from your SUSE Customer Center subscription details.

Click Save to apply the code. ServiceOps calls the SUSE Customer Center API and populates the Name, Expiry At, and Last Sync Time columns for that subscription type. Click Cancel to close the dialog without saving.

API Dependency

Name, Expiry At, and Last Sync Time values only populate after a valid registration code is saved and the SUSE API call succeeds.

Sync Required

After saving the registration codes, sync the patch database to fetch SUSE patches. Navigate to Admin > Patch Management > Patch Administration > Patch Repository and trigger a sync.

Available Repositories

The Available Repositories tab lists all SUSE patch repositories fetched from the SUSE Customer Center using the registration codes configured in the Configuration tab.

ColumnDescription
NameThe name of the SUSE patch repository.
URLThe repository URL provided by the SUSE Customer Center API.
DescriptionA short description of the repository content.
Distro TargetThe target distribution for the repository.