Previous Topic: Software ProceduresNext Topic: View VDI Inventory


Applying Security Patches on Virtual Desktops

To trigger software reinstallation on virtual desktops that do not persist changes after the user logout or reboot, CA ITCM performs the offline RAC process. When the user logs in the virtual desktop next time, offline RAC reinstalls the software and patches that the user had installed before a logout or reboot.

Back to Top

(Optional) Deploy Patches During RAC or on Recomposable Virtual Desktops

By default, patch deployment is excluded during RAC because the patches are redeployed without considering the order of supersedes and rollouts. This behavior can lead to an unexpected outcome. Similarly, blacklisted targets are also excluded during patch deployment.

Recomposable virtual desktops are part of the blacklisted computers by default. The default settings for excluding from RAC and Ignoring blacklisted computers are ideal to handle patch deployment. You can change the settings to modify the default behavior.

Follow these steps:

  1. Log in to CA Patch Manager.
  2. Navigate to Administration, Configuration, System Settings, DSM, Options.

    The configuration options are displayed.

  3. Modify the following parameters as required:
    Exclude From RAC

    Excludes the patch deployment during an RAC process. Clear this option to deploy patches during RAC. The patches are redeployed without considering the order of supersedes and rollouts and hence can lead to an unexpected outcome.

    Ignore Blacklisted computers in Deployment

    Specifies the default option when blacklisted targets are added to the selected targets list during patch deployment. Clear this option to include the selected blacklisted targets for patch deployment. You can also change this option for individual deployments. To ignore blacklisted targets always unless mentioned, keep this option selected.

    Ignore Blacklisted computers in Policies

    Specifies that the blacklisted targets must be ignored during policy evaluation. Selecting this option adds the UPM-Blacklisted query to the UPM policy queries.

    A Black List Query retrieves a list of computers that are excluded from patch deployment. By default, the blacklistQuery parameter is set to UPM–Blacklisted Computers query. This query is linked to a query named Recomposable Computers, which retrieve recomposable desktops that are based on an inventory item. The inventory item IsRecomposable is under Inventory, Operating System, Template Settings. In addition to the recomposable desktops, you can also include computers to the UPM–Blacklisted Computers or create a query to exclude such computers. Verify that the new query includes the query named Recomposable Computers. If you create a query for blacklisted computers, specify the name of the query in the Black List Query parameter.

    Note: To update the existing UPM policies and packages automatically, verify that you have upgraded them. For more information about the upgrade, see Upgrade Patch Manager Packages and Policies.

  4. Save the settings.

    Patch management is configured to handle RAC and blacklisted computers during patch deployment.

Back to Top

Apply the Patch on vDisk or Golden Template

Applying the security patches on vDisk or golden template ensures all the virtual desktops have the necessary security patches installed. To apply the patch on vDisk or golden template, follow the process given in the Updating the Golden Template scenario.

Apply the Patch on Blacklisted Targets or Recomposable Desktops

By default, recomposable desktops are part of the blacklisted targets and all the blacklisted targets are excluded from patch deployment. However, you can apply the patch on blacklisted targets when there is a requirement.

Follow these steps:

  1. Log in to CA Patch Manager and click the patch that you want to apply on the blacklisted targets.
  2. Click Deploy Patch in the Patch Details page.
  3. Select the group that contains blacklisted targets or select individual blacklisted targets and add them to the adjacent Selected Targets pane.

    The list of blacklisted targets in the selected group or targets are displayed in the Blacklisted Targets pane.

  4. Select the targets on which you want to apply the patch from the Blacklisted Targets pane. Add these targets to the adjacent Selected Targets pane. Click Next.
  5. Specify the deployment schedule. Click Next.
  6. Clear the Ignore Blacklisted computers in Deployment option. Click Finish.

    The patch deployment on the selected targets begins at the scheduled time.

Back to Top