Re: Patch/Update Management questions

From: Susan Bradley, CPA aka Ebitz - SBS Rocks [MVP] (sbradcpa_at_pacbell.net)
Date: 12/23/04


Date: Wed, 22 Dec 2004 21:29:21 -0800

SUS only does Windows patches and IMHO there's no comparison.

HFnetchPro has the version for 1 server/10 workstations for free.

IMHO Shavlik is worth every penny ...it makes patch day a breeze.

Fixes:
- Fixed a bug in the signature checking routine that prevented some
machines from deploying large patches (such as XP SP2)
- Significantly improved the digital signature checking routine
resulting in improved performance when browsing Patch Information
section of GUI
- Correctly scans for .NET Framework 1.1 SP1
- Fixed a bug where MDAC 2.8 SP1 was recommended on XP Gold, SP1, and
WS03 systems where MDAC 2.8 SP1 is not available
- Deployment engine was updated to address some customer reported issues
- Fixed a bug where DirectX 4.7 patches were being suggested for Windows
2000 Gold and SP1 systems (where SP2 or later is required)
- Fixed a bug where not all patches would appear in the left pane
navigation under Patch Information and in Patch Groups dialog
- Update the scan engine to detect IE6 SP1 on Windows NT vs. Windows
2000 so that proper patches can be recommended for deployment
- Added ability to scan for HFPro hotfixes

Robert wrote:
> See the following thread
>
> http://forum.shavlik.com/viewtopic.php?t=269&highlight=exchange
>
> I was having the same problem, HFNetChkPro told me SP1 was missing, but no
> option to download the SP. Had to do it manually.
>
> How does SUS compare to HFNetChkPro? Since HFNet is pay and SUS is free, if
> SUS is as good or almost as good, I would be better off going with SUS. I
> will probably just install and try it, but knowing what other people think
> will help me decide what to do.
>
> Robert
>
>
> "Susan Bradley, CPA aka Ebitz - SBS Rocks" wrote:
>
>
>>There isn't such a thing....not even WUS will get "All" patches for
>>SBS...only security patches.
>>
>>I deployed Exchange sp1 on it via Shavlik? What's your issue? and the
>>..Net is a misnomer..there's a beta and the next version will fix that.
>>
>>SUS only does Windows patches at this time. WUS is still in beta and
>>only does security patches.
>>
>>Robert wrote:
>>
>>>Can anybody recommend a comprehensive patch management package? I installed
>>>HFNetChkPro4 last night, but wasn't very impressed. It can't deploy Exchange
>>>SP1, couldn't detect the successful installation of .Net SP1 or MDAC 2.8 SP1,
>>>and doesn't detect non-security updates). I would really like one product
>>>that does OS security patches, MS software (i.e. Exchange, Office, IIS,
>>>etc...), as well as non-security updates listed at
>>>microsoft.com/windowsserver2003/sbs/downloads (i.e. recommended update KB
>>>831664 for NTBackup). Will MS SUS do all this for me? Thanks in advance for
>>>your suggestions and opinions.
>>>
>>>Robert
>>

-- 
An open letter to the Security Community::
http://msmvps.com/bradley/archive/2004/12/12/23540.aspx


Relevant Pages

  • RE: Deploying Microsoft patches
    ... If there is a separate patch between xp and 2k, SUS downloads each of them and lets you approve them. ... How can you apply different patches to w2k and win xp ... > Subject: Deploying Microsoft patches ...
    (Security-Basics)
  • Re: MS Software Update Service
    ... I'd use SUS if the client simply checked at boot up to see if it missed a scheduled update and, if so, performed it then. ... synchronized the updates (this pulls all the patches that are available on ... SP3 for windows 2000, it was a simple change to the Group Policy ... update servers, and at 3 am, the workstations log in and grab the ...
    (Focus-Microsoft)
  • Re: Execute Update on multiple network computers
    ... > somplicated as I have to download all patches one by one on the MS website, ... You could consider implementing SUS or something similar (links to some ... Note that the current version will only install critical updates and security ... Here is a third party product that supports Win9x and WinME as well: ...
    (microsoft.public.win2000.active_directory)
  • Re: Execute Update on multiple network computers
    ... > somplicated as I have to download all patches one by one on the MS website, ... You could consider implementing SUS or something similar (links to some ... Note that the current version will only install critical updates and security ... Here is a third party product that supports Win9x and WinME as well: ...
    (microsoft.public.win2000.general)
  • Re: Remote Shutdown Batch Issue
    ... Sorry for being script stupid. ... As for SUS I apoloigize; ... > Dim WshX ... When are patches ...
    (microsoft.public.windows.server.scripting)

Quantcast