Re: WU and security?

From: Miha Pihler (mihap-news_at_atlantis.si)
Date: 09/22/04


Date: Wed, 22 Sep 2004 16:11:16 +0200

Hi Scott,

Servers use httpS. This means that client will check if server has Microsoft
certificate and if this certificate is valid (e.g. issued by trusted source,
has not been revoked and has not expired...).

*******************************************************

TCP 10.8.64.79:3190 207.46.157.93:80 ESTABLISHED

TCP 10.8.64.79:3192 207.46.157.93:443 ESTABLISHED

*******************************************************

Next thing, all patches and service packs are digitally signed by Microsoft.
If I was to take a patch and modify one bit in it, digital certificate would
be invalid and patch would fail to install...

http://freeweb.siol.net/mpihler/signok.jpg

I hope this helps,

Mike

"scott" <scott@ehrlichtronics.com> wrote in message
news:490701c4a0ab$04a4d6a0$a301280a@phx.gbl...
> What technology is behind the WU client/server model, and
> what is to prevent a rogue WU server from sending
> malicious updates to client machines or local department
> WU servers?
>
> Thanks.
>
> Scott



Relevant Pages

  • Re: MS02-050 CAVEAT?
    ... The revised patch should be quite sophisticated, ... That's why it's a good idea to require Basic Constraints. ... Constraints by the certificate usage. ...
    (microsoft.public.security)
  • IMAP4 SSL error
    ... When i installed the latest patch 828028 the server seemed to restart ... The server certificate for instance '1' has expired or is not yet valid. ... Of course nothing has changed in the SSL certificate that we have. ...
    (microsoft.public.exchange2000.misc)
  • IMAP4 SSL error
    ... When i installed the latest patch 828028 the server seemed to restart ... The server certificate for instance '1' has expired or is not yet valid. ... Of course nothing has changed in the SSL certificate that we have. ...
    (microsoft.public.exchange2000.connectivity)
  • IMAP4 SSL error
    ... When i installed the latest patch 828028 the server seemed to restart ... The server certificate for instance '1' has expired or is not yet valid. ... Of course nothing has changed in the SSL certificate that we have. ...
    (microsoft.public.exchange2000.admin)
  • IMAP4 SSL error
    ... When i installed the latest patch 828028 the server seemed to restart ... The server certificate for instance '1' has expired or is not yet valid. ... Of course nothing has changed in the SSL certificate that we have. ...
    (microsoft.public.exchange2000.general)