Security Patch 02 for ZENworks 11 Appliance

  • 7016312
  • 16-Mar-2015
  • 24-Apr-2015

Environment

Novell ZENworks Configuration Management 11.3
Novell ZENworks Configuration Management 11.2
Novell ZENworks Configuration Management 11.1
Novell ZENworks Configuration Management 11

Situation

Security Patch 02 for ZENworks 11 Appliance is an update that contains the security patches that are applicable to ZENworks 11 Appliances.  These issues are not specifically in ZENworks software, but instead in the underlying base OS used in the appliance (SLES).  It addresses the following vulnerability:

CVE-2015-0204 - OpenSSL RSA Temporary Key Cryptographic Downgrade Vulnerability

Resolution

The patch can be downloaded from the following URL:


This update is applicable to servers running ZENworks Virtual Appliance with version 11.0, 11.1, 11.2, 11.2.0 MU1, 11.2.0 MU2, 11.2.1, 11.2.1 MU1, 11.2.1 MU2, 11.2.2 MU1, 11.2.2 MU2, 11.2.3a , 11.2.3a MU1, 11.2.4, 11.2.4 MU1, 11.3.0 FRU1, 11.3.0, 11.3.1, 11.3.2 and 11.3.2 FRU1. 

Installation Instructions:

Read these instructions carefully, they are different from those for any previous version of ZENworks.

Part 1: Pre-requisites
Ensure that your servers are updated to ZENworks 11.0 or to any later version possible.

Part 2: Preparing for Deployment
1. Download ZCM_11_Security_Patch_2.zip from this patch.
After downloading the zip file, it is recommended that you compare the MD5 checksum for the file with the one shown on the Novell Downloads page, before attempting to deploy.
2. Copy the zip file to one of the ZENworks servers in the zone. (if System Update is configured to use a “Dedicated System Update Server”, use this server for the import). Do not unzip the file. Example:
On Linux, copy the zip file to /tmp
On Windows, copy the zip file to %ZENWORKS_HOME%
3. Using the command prompt on the ZENworks server where you copied the zip file in step 2, run the zman sui [path to zip file]. For details, run the zman sui --help command:
On Windows: zman sui "C:\Program Files\Novell\ZENworks\ZCM_11_Security_Patch_2.zip"
On Linux: zman sui /tmp/ZCM_11_Security_Patch_2.zip
4. The zman sui command should report: "The update(s) contained in ZCM_11_Security_Patch_2.zip will begin importing shortly. You may use ZCC to track the status of your import".
5. In ZENworks Control Center, navigate to Configuration > System Updates and monitor the status of "Security Patch 02 for ZENworks 11 Appliance,'' until it shows "Downloaded”, and track replication by navigating to Security Patch 02 for ZENworks 11 Appliance >Replication Status.

Part 3 Deployment
You can deploy "Security Patch 02 for ZENworks 11 Appliance" to any ZENworks Virtual Appliance running ZENworks 11.0 and later.
See "Deploying Updates" in the ZENworks 11 SP3 documentation for guidelines for deployment.