Compatibility of PAMSC with Red Hat and SUSE Kernel Live Patching
search cancel

Compatibility of PAMSC with Red Hat and SUSE Kernel Live Patching

book

Article ID: 443688

calendar_today

Updated On:

Products

CA Privileged Access Manager - Server Control (PAMSC)

Issue/Introduction

This article describes the compatibility and recommended procedure for using Privileged Access Manager Server Control (PAMSC) on endpoints where Red Hat Kernel Live Patching (kpatch) or SUSE Live Patching (kGraft/klp) is utilized.

Environment

Product: Privileged Access Manager Server Control (PAMSC)
Operating Systems:
Red Hat Enterprise Linux (RHEL) 7, 8, 9
SUSE Linux Enterprise Server (SLES) 12, 15
Technologies: kpatch, kGraft, klp

Cause

Compatibility inquiry regarding the impact of function-level kernel live patching on PAMSC drivers and interception hooks.

Resolution

PAMSC supports Red Hat Kernel Live Patching and SUSE Live Patching. Because these technologies perform function-level redirection in kernel memory, the PAMSC drivers must be in a dormant state during the patch application to prevent kernel instability or race conditions.

Follow this procedure to apply live patches safely:

Stop PAMSC services on the endpoint to unregister system call hooks.
Apply the live kernel patch using the distribution's standard tools (e.g., kpatch or zypper lp).
Start PAMSC services. Upon startup, the SEOS driver dynamically re-resolves kernel addresses and re-establishes its hooks.


A full unload of the kernel module (rmmod) is not required; stopping the services is sufficient.

Additional Information

For Oracle Linux Ksplice guidance, see KB 422907.
To speak with a customer representative or a Support Engineer see Contact Support. Scroll to the bottom of the page and click on your respective region or refer to KB 206567.