RE: MS Software Update Service

From: Jared Kelly (JKelly@askjeeves.com)
Date: 02/20/03

  • Next message: Brad Bemis: "RE: MS Software Update Service"
    From: Jared Kelly <JKelly@askjeeves.com>
    To: "Starks, Brad" <BStarks@co.marin.ca.us>
    Date: Thu, 20 Feb 2003 12:14:10 -0800
    
    

    Brad-

    I completed an evaluation of SUS for my company a couple of months ago. The
    main problem I see with it is that it is lacking in several features that
    most enterprises would require for a full rollout of this solution. It lacks
    grouping functions, has no reporting functions, no varying levels of
    administration, and only provides for updates to Microsoft products. Once an
    update is approved it is made available to your entire farm which you may or
    may not want. The logging also is very basic and requires you to sift
    through IIS logs looking for HTTP gets from the target host. You can't tell
    from the server whether a patch has been correctly installed or not and it
    does not offer a centralized way to back out of a patch application. All in
    all it didn't come close to meeting our needs.

    I've been working with Gibraltar's Everguard product now for a couple months
    on an extended evaluation and I'm really impressed with the functionality of
    the product. They still are lacking in a couple features but we've been
    working directly with their engineering team to get them into the release
    schedule. The reporting is fantastic on it and it offers back out
    capabilities, and also supports Linux and Solaris. The system is fully SSL
    based for client security and your vulnerability information is stored
    behind your firewall. It also offers a complete software inventory solution.
    More information on Everguard can be found at http://www.gibraltarsoft.com/.
    Feel free to write me for direct contact information.

    Hope this helps, if even a little.

    Jared

    -----Original Message-----
    From: Starks, Brad [mailto:BStarks@co.marin.ca.us]
    Sent: Wednesday, February 19, 2003 4:43 PM
    To: 'focus-ms@securityfocus.com'
    Subject: MS Software Update Service

    Hi everyone,

    Microsoft's Software Update Service has been out for awhile (they've
    recently released a service pack for it, too) and I was curious as to what
    folks think about it. If you're using this technology, are you happy with
    it? How well does it suit your needs? Is it comparable to other solutions
    like Update Expert, Hfnetchk Pro, Net Octopus, etc.?

    In addition, has anyone used the Feature Pack for SMS that contains the SUS
    (as well as all kinds of additional) components? How does that compare to
    the standard SUS?

    Thanks in advance,

    Brad Starks
    IST Security Team
    County of Marin



    Relevant Pages

    • Re: MS Software Update Service
      ... sus, ... dialed up and the updates are scheduled to download, ... only a dialup connection versus connected through local ethernet connection. ... Subject: MS Software Update Service ...
      (Focus-Microsoft)
    • RE: MS Software Update Service
      ... I've been playing with SUS for a while, but not using it in production. ... -Poor logging ... > Subject: MS Software Update Service ... > Expert, Hfnetchk Pro, Net Octopus, etc.? ...
      (Focus-Microsoft)
    • Re: GPO and SLow Links
      ... SUS (Software Update Service) is quite a good option to patch your machines. ... well on slow links. ... > GPO to remote users such as laptops on 56k links? ...
      (microsoft.public.windows.server.active_directory)
    • Re: How ofthen do you distribute Windows Updates
      ... Most of the patches go to the users the nigh after the patch is out. ... this we are using SUS (Software Update Service). ... Does anyone have plan in place and what ...
      (microsoft.public.windowsxp.security_admin)
    • Re: Push out hotfixes
      ... Is there a programming interface to the MBSA and SUS? ... Windows XP security components are able to detect whether the Virus ... > (Software Update Service) on your network. ...
      (microsoft.public.windows.server.general)