Hi
Apple's Software Update Service will struggle (if it works at all) if access to the Apple's downloads servers (akugami.net) is via a Proxy Server. Of all the schools, colleges and other educational establishments I've been to up and down the country I've yet to implement this service because of this limiting factor.
SUS tends to work best in an Open Directory environment and when mac clients are joined to the LDAP node and have the Software Update as a managed preference. This can be done at either User, Computer or Groups level. I'm not sure if the service can be made to work in an AD-OD environment? However see above as to why.
It does not make any difference if the OD Master is 10.4 or 10.5.
As ever it always comes down to how well the DNS Service is configured. Especially the Reverse Pointer. I have been to schools where there is an existing Active Directory (supposedly working) only to find no Reverse Zone had been configured.
Apple's Open Directory tends to struggle if the network environment consists of HP ProCurve Switches with VLANs applied. Even if VLANs are not applied yet the tags remain it will still struggle. It also struggles with some Class C subnets - 255.255.192.0 for example but only if the information is provided by DHCP. It does work if the addresses are manually set.
By the way Netboot does not work with class A or B subnets unless the server and clients are within the same range/subnet or if there is a Netboot server for each range/subnet.
If your mac clients are a mix of 10.4 and 10.5 (previous OS are not supported) machines and you want to 'push' out SUS as a Managed Preference then your SUS Service must be on 10.5 Server. If your server is 10.4 and if your clients include 10.5 Client OS then these macs will only receive updates common to both OS. For example, iTunes, Safari etc updates. 10.4 Server cannot 'serve' 10.5 specific updates to 10.5 clients.
Bear in mind the updates I am talking about here are for Apple specific applications and Apple specific OS. If you have the suite of Adobe applications installed these are updated via Adobe's updates servers, not Apple's. SUS does not recognize other updates specific to the mac platform.
You can use the command line to point clients to your SUS server. Consult the relevant manual page (man defaults). The XML file (or property list - .plist - that is changed is the one found in /Library/Preferences, not the one in /User/Home/Library/Preferences. This can be hit and miss.
The other method of pushing out mac specific updates is as already mentioned here. However you would have to manually download these first. Makes sure they are all available on a mac used for administrative purposes that has ARD installed. You could install ARD on another mac (or multiple macs depending on your license) and use that/those as a Task Server or Task Servers. That way if you have lots of updates to 'push' out the load can be spread over two or more macs.
Clearly for the above method to work updates and/or applications must be in .pkg or .mpkg form.
Finally you can't provide updates to Apple specific software for the Windows platform. Yes I know Apple's own documentation says its possible however it is wrong. If some of you have consulted Apple's Server specific Administration software before you will have probably realized that quite a bit of the documentation is at best generalized and at worst inaccurate.
I hope this helps a little in clearing up what confusion there is regarding the Service, Apple Updates and other related matters in general?
Antonio Rocco (ACSA)