User guideAgents

Requirements and network access

Supported systems

System Versions Architectures
Ubuntu 18.04, 20.04, 22.04, 24.04 x86-64, ARM64
Debian 10, 11, 12, 13 x86-64, ARM64
RHEL, Rocky Linux, AlmaLinux, Oracle Linux 8 and 9 x86-64, ARM64
CentOS 7 x86-64
SUSE Linux Enterprise, openSUSE Leap 15 x86-64, ARM64
Alpine Linux 3.18 and later x86-64, ARM64
Windows Verified on Windows 10 and Windows Server 2022. Other 64-bit Windows versions use the same Windows Update service x64, ARM64
macOS 12 Monterey and later; used on 15 Sequoia and 26 Intel, Apple silicon

32-bit systems are not supported.

Vulnerability data is available for Ubuntu, Debian, the RHEL family, SUSE and Alpine. CentOS 7 still gets patched, but CentOS publishes no security advisories, so RemediForge cannot tell which CVEs its updates fix. Ubuntu 18.04, Debian 10 and CentOS 7 no longer receive public updates from their vendors.

Debian 10 has moved to Debian's archive. Its usual mirrors no longer answer, so apt-get update fails until /etc/apt/sources.list points at http://archive.debian.org/debian and http://archive.debian.org/debian-security. The scan says so when this is the problem. The agent never changes a host's package sources itself.

What the host needs

Linux

  • Root access (sudo) to install.
  • curl or wget. sha256sum is used to verify the download.
  • systemd, or OpenRC on Alpine, for the agent to run as a service. Without either (in a container, for example) the installer starts the agent as a background process instead.

Windows

  • An elevated PowerShell (Run as administrator). Windows PowerShell 5.1, included with Windows, is enough.
  • The Windows Update service must be allowed to run.

macOS

  • An administrator account (sudo).

Network access

The agent only makes outbound HTTPS connections. Nothing connects in to your hosts; no inbound port has to be opened.

From the host to Why
Your portal address, port 443 Enrollment, reporting every minute, receiving jobs, downloading the agent
The host's own update sources Its Linux repositories, Windows Update or your WSUS server, or Apple's updates: whatever the host already uses.
ipinfo.io, or ifconfig.me if that fails Once an hour, to learn the host's public IP address, shown on the device page. Set PATCHPILOT_PUBLIC_IP_LOOKUP=off in the agent's environment to turn this off
The program vendors' download sites To update third-party programs such as Chrome or Zoom. If your firewall allows only listed sites, ask RemediForge support for the list

If the host cannot reach the portal, the installer stops with "download failed: is … reachable from this host?".

What the agent can do on the host

The agent runs with administrator rights, because installing updates needs them. It only acts on jobs from your portal, and every job is recorded in the Audit log with who started it. A host's credentials cannot be used from another machine, and nothing between the host and the portal can change a job. Updates are installed only when they come genuine from their vendor.

Next

Requirements and network access | RemediForge