RHSA checking

Posted on

We regularly receive security findings that indicate that our RHEL servers are, or could be, affected by specific RHSA alerts.

It seems very unclear to me how to establish the scope of these advisories and whether specific boxes are affected. There seems to be a lack of clarity for working out whether advisories fall into the following categories for each server;
1. RHSA applicable
2. RHSA not applicable
3. RHSA unknown

This cannot be an uncommon issue so I'm wondering what tips do people have for resolving this. It also seems to me that potentially content views may have some bearing on this although I have no idea whether this is actually the case or not.

Any tips for using Satellite/hammer/any other tool to accurately determine applicability of RHSAs appreciated.

Responses