Occasionally, OS vendor might authorize the update of one or more OS packages to rectify a critical vulnerability that affects a specific version of Unified Access Gateway and for which no viable workaround is available.
You can configure Unified Access Gateway to automatically fetch and apply any available authorized OS package to the Unified Access Gateway version which has been deployed in your environment. These updates are then fetched and applied automatically when the appliance is next booted.
In earlier versions, such critical updates were performed manually using the tdnf command based on the guidance provided by Omnissa Global Support Services.
In the Appliance Updates Settings section, you can select the frequency of applying updates such as on next reboot or every reboot of the Unified Access Gateway appliance.
Note: Updates are applied to the Unified Access Gateway appliance only during the boot cycles after configuring the desired updates scheme on this page.
Procedure
-
Log in to the Admin UI and in the Configure Manually section, click Select.
-
Go to Advanced Settings > Appliance Updates Settings and click the gear box icon.
-
In the Appliance Updates Settings window, enter the following information:
4. Click Save.Configuration Setting Action Apply Updates Scheme Select the frequency at which the OS and Unified Access Gateway updates can be fetched and applied to Unified Access Gateway. By default, the updates scheme is Don’t apply updates.
Important: If you select theApply updates on next bootscheme, then after the updates are applied at the next immediate reboot of Unified Access Gateway, the scheme is automatically set back to the default value.OS Updates URL Enter the location of the repository from which the Unified Access Gateway authorized OS packages list is fetched and applied to the Unified Access Gateway appliance. You can either use the default value or provide a URL to your custom repository by mirroring the default repository. The files in a mirrored repository must not be changed. The value of this text box must be an absolute URL, which can either be an IP address or hostname prefixed with https.
Note: If you provide your custom URL for OS updates, the settings get applied after a maximum of one minute.Appliance Updates URL Enter the location of the OS package repository from which the Unified Access Gateway authorized OS packages list is fetched and applied to the Unified Access Gateway appliance. You can either use the default value or provide a URL to your custom repository by mirroring the default repository. These files in a mirrored repository must not be changed. The value of this text box must be an absolute URL, which can either be an IP address or hostname prefixed with https.
Note: If you provide your custom URL for appliance updates, the settings get applied after a maximum of one minute.Trusted Certificates Note: Normally, it is not necessary to specify the trusted certificates because the default URLs uses a trusted certificate. This setting is only required if you are connecting to a local repository that does not use a certificate issued by a trusted CA. - To select a certificate in PEM format and add to the trust store, click + .
- To provide a different name, edit the alias text box.
By default, the alias name is the filename of the PEM certificate. - To remove a certificate from the trust store, click -.
Results
After the updates are applied, the Unified Access Gateway appliance gets rebooted and a
package-updates.logfile is generated. This log file is available in theUAG-log-archive.zip. You can use thepackage-updates.logfile for checking the status of the update and troubleshooting purpose.For information about accessing
UAG-log-archive.zipfrom the Admin UI, see Collecting Logs from the Unified Access Gateway Appliance.
Was this page helpful?