AIX Patch management challenges with security and HIPER efixes.
This blog is created to address some security challenges with installing and checking efixes.
One of the good things is that most of efixes now have a signature file. This guarantees that the download was ok and the emgr efix package were not tampered.
That is a good thing.
There is now also a “new” AIX command emgr_sec that automatically verifies the package signature before installation.
That is also good improvement!
However there are some still some challenges, read work to be done: