Re: WSUS/Reboot

From: Susan Bradley (sbradcpa_at_pacbell.net)
Date: 06/27/05

  • Next message: Depp, Dennis M.: "RE: WSUS/Reboot"
    Date: Mon, 27 Jun 2005 10:41:51 -0700
    To: David LeBlanc <dleblanc@mindspring.com>
    
    

    Yes but... if you have an issue with the server and don't reboot.. a
    year goes by and you have an issue and you'll not associate it with the
    earlier patch.

    Guess you haven't heard of "hotpatching" eh? Microsoft is supporting
    this 'no reboot' as a technque that is starting to be fully supported in
    Windows patches.

    Someone told them ...but you need to be running newer Windows.

    Many of the server patches these days on 2k3 are hot patch-d.

    BTW there's a WSUS listserve set up on www.patchmanagement.org for
    another WSUS community and feedback.

    David LeBlanc wrote:

    >>Did someone ever tell Microsoft that they should have a look
    >>on unixoid systems. The only scenario a unixoid box _must_ be
    >>rebooted is, when the kernel has been patched or the main
    >>glibc must be changed for some reasons. But even the latter
    >>does not mean to always you need to reboot the system.
    >>
    >>
    >
    >Reducing reboots is something that I know is a priority for Microsoft, and
    >you're right - having systems rebooting all the time is a problem, even if
    >they're just desktops. I think you'll see improvement on this over time, and
    >one of the new features of WSUS I notice is immediate application of patches
    >that don't need reboots.
    >
    >However, they way that you get this system uptime on most *nix systems is to
    >drop the service in question, apply patches and restart the service. IMHO,
    >if the system's job is to provide that service, there is only a little
    >difference between bouncing the service and bouncing the box. If you take
    >the same approach on a Windows server, you will often find that you get
    >similar gains. For example, back when there were enough IIS patches to worry
    >about, you could stop the web service and if the patch were applied when
    >then server wasn't up, it didn't need a reboot. You'd then restart the
    >service once the patch was applied. Many of the patches only trigger a
    >reboot if a file that needed to be replaced will only get replaced on
    >reboot.
    >
    >IMHO, it would be a good thing if the patch were to do this on it's own, but
    >in the meantime you can certainly do it yourself.
    >
    >
    >---------------------------------------------------------------------------
    >---------------------------------------------------------------------------
    >
    >
    >
    >

    ---------------------------------------------------------------------------
    ---------------------------------------------------------------------------


  • Next message: Depp, Dennis M.: "RE: WSUS/Reboot"

    Relevant Pages

    • The patch killed my system!
      ... prompts for a reboot, I say "Yes"...boom! ... that reason more often than any other on a server. ... when a patch appears to cause a problem with your server its more likely ... Now I'm not saying this to discourage reports of problems with patches, ...
      (NT-Bugtraq)
    • Re: [Total OT] Trying to improve some numbers ...
      ... But patch frequency means what exactly? ... Thus making only, say, a driver or some kernel component reboot, ... Actually it means advertising an unpatched machine running unpatched services not available to the outside. ... a lot of work-arounds for security patches amount to "lock the front door." ...
      (freebsd-questions)
    • Re: MS Critical Patches - Reboot - Did not reboot.
      ... Generally the 7036 event pops up after a reboot, ... the install of critical patches. ... down and it comes up using PING SERVER -t. ... I tried connecting through RDP and could not connect. ...
      (microsoft.public.windows.server.general)
    • Re: [Total OT] Trying to improve some numbers ...
      ... But patch frequency means what exactly? ... Thus making only, say, a driver or some kernel component reboot, ... Actually it means advertising an unpatched machine ... a lot of work-arounds for security patches amount to "lock the ...
      (freebsd-questions)
    • MS Patches last Mon - Recap
      ... complained that the time between the server and client is different. ... I did reboot server and client meanwhile) A ... I hadn't before since at first glance the patches did ... I tried uninstalling the patches from ...
      (Bugtraq)