Outpost Posted July 19, 2007 Posted July 19, 2007 Hi, I would like to know some opinions on updates as I'm unsure of the best route to take. I was wondering on the issue of applying critical/patches updates on servers. Previously I've had a couple of issues where an update has caused a server to crash and not recover without extensive repair work. Currently I have several servers (2003) ticking along nicely but there is a fair amount of updates to put on if I decide to do so. I feel its a kind of 'if it ain't broke don't fix it' policy as everything is working so well. Crazy really that you have to think twice about applying updates in case it causes problems you didn't have in the first place. Regards
ChrisH Posted July 19, 2007 Posted July 19, 2007 I let them download to the server but then have it wait for me to tell it that it can install.
speckytecky Posted July 19, 2007 Posted July 19, 2007 Great sympathy, I'm in the same boat with a vanilla Win 2K server which hugely crashed twice a couple of years ago post applying critical updates. This took some getting back from and it was the considerable help of a colleague that eventually set us sailing again. Since then I have been almost frightened to apply updates to the beast. However, l had to to attempt the Sophos update in the Easter break, all went well with the MS updates but the Sophos EM refused to apply. Life ain't easy is it!
localzuk Posted July 19, 2007 Posted July 19, 2007 I follow the same system as ChrisH - they are downloaded and sit there until I have the time to install them - usually during holidays. The thing with updates is, if they are patching security holes, we are legally obligated to install them on any machine which holds data covered by the data protection act, as failing to do so would be failing to ensure the security of the data.
Geoff Posted July 19, 2007 Posted July 19, 2007 The thing with updates is, if they are patching security holes, we are legally obligated to install them on any machine which holds data covered by the data protection act, as failing to do so would be failing to ensure the security of the data. That's an interesting way to spin it? Are you 100% about it? Because if so, I have a problem..
Outpost Posted July 19, 2007 Author Posted July 19, 2007 Just recently up here in the north CLEO's IIS for dishing out the latest Sophos virus definitions was brought down by applying an update.
localzuk Posted July 19, 2007 Posted July 19, 2007 I am pretty sure - think of it this way, you store the kids information in a filing cabinet, and you know that if you kick the thing in a certain way on that model, the cabinet just unlocks - and this is a known problem that everyone knows. This would be a violation if it weren't fixed in some way as you wouldn't be taking reasonable precautions to prevent access to that information.
plexer Posted July 19, 2007 Posted July 19, 2007 Unless information is stored in a filling cabinet in a specific manner that allows someone looking for information to be able to go directly to the relevant section without rifling through other papers first then it's not covered under the DPA anyway. Ben
plock Posted July 19, 2007 Posted July 19, 2007 We also let them download and then install them when needed. However, I did complete some updates the other day, had issues with RIS and VPN afterwards!!!
localzuk Posted July 19, 2007 Posted July 19, 2007 Unless information is stored in a filling cabinet in a specific manner that allows someone looking for information to be able to go directly to the relevant section without rifling through other papers first then it's not covered under the DPA anyway. It was an example... I know it isn't specifically covered by the DPA but it is covered by the responsibility to keep things safe. Regardless of our legal responsibilities, we have a responsibility to protect the children in school.
tosca925 Posted July 19, 2007 Posted July 19, 2007 let them download to the server but then have it wait for me to tell it that it can install. Same here
mattx Posted July 20, 2007 Posted July 20, 2007 Only install updates during Easter, Xmas or Summer Hols. That way if there is a problem I have some time to try and resolve it !! Workstations get them as and when - easier to fix if there is a problem. I have not had a problem with any MS updates but a few Sophos - [ cough cough ] Sigs have caused BSOD on workstations which I was not very impressed about.... Touch wood, SP2 for Sever 2003 I have just installed have not caused any problems - there is still time though !!
plock Posted July 20, 2007 Posted July 20, 2007 Only install updates during Easter, Xmas or Summer Hols. That way if there is a problem I have some time to try and resolve it !! Workstations get them as and when - easier to fix if there is a problem. I have not had a problem with any MS updates but a few Sophos - [ cough cough ] Sigs have caused BSOD on workstations which I was not very impressed about.... Touch wood, SP2 for Sever 2003 I have just installed have not caused any problems - there is still time though !! I'm certain you're going to discover some SP2 problems! I did!
kearton Posted July 20, 2007 Posted July 20, 2007 I'm certain you're going to discover some SP2 problems! I did! such as?
plock Posted July 20, 2007 Posted July 20, 2007 RIS, VPN and SharePoint issues... everything else seems to be running smoothly! :S
kearton Posted July 20, 2007 Posted July 20, 2007 sweeeet, nothing that I use then. ta. light the blue touchpaper and stand clear.......
plock Posted July 20, 2007 Posted July 20, 2007 hehe, hopefully you will be 'OK' then! I do wish I had left the updates until the holiday though. I do like that idea suggested above. I think it's something I may implement here!
Quackers Posted July 20, 2007 Posted July 20, 2007 Only install updates during Easter, Xmas or Summer Hols. That way if there is a problem I have some time to try and resolve it !! Workstations get them as and when - easier to fix if there is a problem. I have not had a problem with any MS updates but a few Sophos - [ cough cough ] Sigs have caused BSOD on workstations which I was not very impressed about.... Touch wood, SP2 for Sever 2003 I have just installed have not caused any problems - there is still time though !! Thats the way i do it, unless its somthing major like blaster. Sometimes i really hate doing it, as SP1 for XP made XP error when deleting files of network drives, had to get a hotfix of MS for that, SP2 caused the Applying your personal settings to hang for about 20 seconds, took months for MS to do somthing about that, so another hotfix to apply.
Geoff Posted July 20, 2007 Posted July 20, 2007 Patches here are set to download and prompt on servers. I usually leave it until Friday, and keep an eye on various mailing lists and websites during the week to see if there are problems. If there are none, I install them. Servers reboot in a staggered fashion over the weekend automatically.
plock Posted July 20, 2007 Posted July 20, 2007 Patches here are set to download and prompt on servers. I usually leave it until Friday, and keep an eye on various mailing lists and websites during the week to see if there are problems. If there are none, I install them. Servers reboot in a staggered fashion over the weekend automatically. I'd be interested in knowing the mailing lists and websites you use? Would definitely help in tracking any likely issues!
Geoff Posted July 21, 2007 Posted July 21, 2007 http://blogs.technet.com/mu/ http://blogs.msdn.com/ie/ http://blogs.technet.com/wsus/ http://www.wsus.info/forums/ http://msmvps.com/Athif/ http://www.patchmanagement.org/ (mailing lists) http://isc.sans.org/diary.html
ITWombat Posted July 21, 2007 Posted July 21, 2007 There has to be a degree of risk assessment. Do you have to have the latest IE patch if you don't use a server for web browsing. Vulnerabilities affecting services connected to open ports are another matter. @Geoff what do you do in a zero day scenario? Do you just patch an d pray or still wait and see, hoping IDS will see you right? Would be nice to hear from Ric_ & Cybernerd on how they do things on terminal servers. Here you have end-user applications e.g. web browsers and a single point of failure. Do you segregate server access based on whether the user is a staff or student?
Geoff Posted July 21, 2007 Posted July 21, 2007 There has to be a degree of risk assessment. Do you have to have the latest IE patch if you don't use a server for web browsing. Vulnerabilities affecting services connected to open ports are another matter. I usually look at the ISC diary posting for an overview of how critical things are. For example, here's Julys assessment. http://isc.sans.org/diary.html?storyid=3120 what do you do in a zero day scenario? Do you just patch an d pray or still wait and see, hoping IDS will see you right? Given the speed at which MS reacts to 0day exploits. I have no choice. I have to rely on my IDS/Firewall/NAC/AV.
bishopsgarthstockton Posted July 21, 2007 Posted July 21, 2007 Hi, I would like to know some opinions on updates as I'm unsure of the best route to take. I was wondering on the issue of applying critical/patches updates on servers. Previously I've had a couple of issues where an update has caused a server to crash and not recover without extensive repair work. Currently I have several servers (2003) ticking along nicely but there is a fair amount of updates to put on if I decide to do so. I feel its a kind of 'if it ain't broke don't fix it' policy as everything is working so well. Crazy really that you have to think twice about applying updates in case it causes problems you didn't have in the first place. Regards The number one rule is to always have a backup before you make any updates or changes.At least then you can go ahead and make the updates and know that if it nacks up you can revert back to the backup. I always read what the update is for before i go ahead with applying it.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now