Re: Auto-Updates for production servers



Hi Brian,
I hope you won't mind advice that contradicts your presumed views.
When Microsoft or any software vendor discovers a flaw that can be
exploited, they need to fix it.
If you don't apply the fix, you are vulnerable from that time on because
everyone knows what the flaw is.
You can test the fix to see if it breaks anything, but you still need to
apply it even if it does.
So really it could be a responsibility of the developers to be aware of
fixes, maintain a testing environment and identify what to do if a fix
breaks their software. They would then need to deploy their own patch within
a week or two. If they object to having to test, it demonstrates that it is
really an argument about who should do the work rather than whether it
should be done.
The only way to avoid patching, or to postpone it till the developers are
ready, is to maintain a sealed environment. You can do this as follows:
- run the application on terminal services
- allow no other applications to run: no IE, no Word, no iTunes etc, just
the application.
- run a firewall between the LAN and the terminal servers and allow no other
connections to the terminal servers.
Apart from that, you just have to live with patching. What problems exactly
does it cause? Rebooting should be addressed either by patching
out-of-hours, or by a resilient service (e.g more than one application
server). What are the miscellaneous problems? You should probably identify
what they are and try to resolve them rather than prevent patching.
Hope that helps,
Anthony, http://www.airdesk.co.uk



"Brian Kitt" <BrianKitt@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:FB252A39-79A5-4522-9113-71C1A1303DBB@xxxxxxxxxxxxxxxx
Hello.
I am a developer, and have been having an ongoing battle with our Network
Admins, and would like advice here.

They have Microsoft Windows Auto-Updates turned on for all production
servers. This has caused numerous problems, because patches get applied,
then cause servers to reboot, or other miscellaneous problems.

I keep trying to tell them it is not a 'best practice' to have
auto-updates
on for production servers, but rather they should push them out with admin
tools on a regular scheduled basis. They assure me they 'know what they
are
doing', and auto updates 'are required to prevent viruses and hackers'.
They
have assured me that Microsoft strongly recommends auto updates for all
production servers.

The amount of problems alone this has causes ought to be proof enough this
is a bad idea, but can anyone point me to 'official' statements from
Microsoft as to 'auto-updates' for production servers? I am having
trouble
finding an official statement from Microsoft either way.


.



Relevant Pages

  • RE: New DC 2003 R2 with SBS2003 replication problem. Need Help !
    ... SBS domain and you get some KCC errors on SBS. ... Step-by-Step Guide to Adding and Managing Additional Servers in a Windows ... Microsoft CSS Online Newsgroup Support ... newsgroups so that they can be resolved in an efficient and timely manner. ...
    (microsoft.public.windows.server.sbs)
  • Re: Multiple copies of the Language Bar
    ... Microsoft CSS Online Newsgroup Support ... This newsgroup only focuses on SBS technical issues. ... Hi, thanks for the response. ... Both the Windows 2003 Standard servers and the SBS2003 are all at ...
    (microsoft.public.windows.server.sbs)
  • Re: 4.4.7 NDRs on sent email - messages remain in STMP queue until expiry
    ... the free email servers seems very hit and miss. ... This issue occurs may because the Symantec Antivirus Corporate Edition ... Microsoft Exchange Server servers or on Microsoft Windows SMTP servers. ... Please collect the MPS Report for Exchange: ...
    (microsoft.public.windows.server.sbs)
  • Re: Security and the User experience
    ... User installs an application that needs to communicate to SQL servers and/or FTP servers and/or web services. ... whenever the user installs any applications they are either presented with a message saying "block/unblock" message and sometimes even messages suggesting the application could be a virus. ... Microsoft do seem to be aware of this user experience problem after my initial look at Beta 2 of Vista and how it grays out everything except the program needing communication. ... I would venture to say though that even the *nix OS' distributors and probably even Apple will still say that it's the users job to make sure their computer is secure. ...
    (microsoft.public.security)
  • RE: Boot device error 0x0000007B+0xf789e63c
    ... says that main problem with booting servers from SANs is ... > Blue Screen Preparation Before Contacting Microsoft ... > Windows NT ... > the Selective Startup button. ...
    (microsoft.public.windows.server.migration)