Requirements and network access
Supported systems
| System | Versions | Architectures |
|---|---|---|
| Ubuntu | 18.04, 20.04, 22.04, 24.04 | x86-64, ARM64 |
| Debian | 10, 11, 12, 13 | x86-64, ARM64 |
| RHEL, Rocky Linux, AlmaLinux, Oracle Linux | 8 and 9 | x86-64, ARM64 |
| CentOS | 7 | x86-64 |
| SUSE Linux Enterprise, openSUSE Leap | 15 | x86-64, ARM64 |
| Alpine Linux | 3.18 and later | x86-64, ARM64 |
| Windows | Verified on Windows 10 and Windows Server 2022. Other 64-bit Windows versions use the same Windows Update service | x64, ARM64 |
| macOS | 12 Monterey and later; used on 15 Sequoia and 26 | Intel, Apple silicon |
32-bit systems are not supported.
Vulnerability data is available for Ubuntu, Debian, the RHEL family, SUSE and Alpine. CentOS 7 still gets patched, but CentOS publishes no security advisories, so RemediForge cannot tell which CVEs its updates fix. Ubuntu 18.04, Debian 10 and CentOS 7 no longer receive public updates from their vendors.
Debian 10 has moved to Debian's archive. Its usual mirrors no longer
answer, so apt-get update fails until /etc/apt/sources.list points at
http://archive.debian.org/debian and http://archive.debian.org/debian-security.
The scan says so when this is the problem. The agent never changes a host's
package sources itself.
What the host needs
Linux
- Root access (
sudo) to install. curlorwget.sha256sumis used to verify the download.- systemd, or OpenRC on Alpine, for the agent to run as a service. Without either (in a container, for example) the installer starts the agent as a background process instead.
Windows
- An elevated PowerShell (Run as administrator). Windows PowerShell 5.1, included with Windows, is enough.
- The Windows Update service must be allowed to run.
macOS
- An administrator account (
sudo).
Network access
The agent only makes outbound HTTPS connections. Nothing connects in to your hosts; no inbound port has to be opened.
| From the host to | Why |
|---|---|
| Your portal address, port 443 | Enrollment, reporting every minute, receiving jobs, downloading the agent |
| The host's own update sources | Its Linux repositories, Windows Update or your WSUS server, or Apple's updates: whatever the host already uses. |
ipinfo.io, or ifconfig.me if that fails |
Once an hour, to learn the host's public IP address, shown on the device page. Set PATCHPILOT_PUBLIC_IP_LOOKUP=off in the agent's environment to turn this off |
| The program vendors' download sites | To update third-party programs such as Chrome or Zoom. If your firewall allows only listed sites, ask RemediForge support for the list |
If the host cannot reach the portal, the installer stops with "download failed: is … reachable from this host?".
What the agent can do on the host
The agent runs with administrator rights, because installing updates needs them. It only acts on jobs from your portal, and every job is recorded in the Audit log with who started it. A host's credentials cannot be used from another machine, and nothing between the host and the portal can change a job. Updates are installed only when they come genuine from their vendor.