Re: Automatic Updates security concern



If you run WSUS then you can use group policy to configure
your machines' autoupdate client to use only your WSUS
servers. If those servers are not configured to support SSL
on tcp 443 then the update clients will be forced to use tcp
80 (in policy you would point them to http://yourWsus not
to https://yourWsus)

"rusga" <only@newsgroup> wrote in message
news:ODi76aqMIHA.6060@xxxxxxxxxxxxxxxxxxxxxxx
Hi,

Is there any way of setting the AU repository so it never uses https (tcp
443) and only uses http (tcp 80)?
Or, it uses only admin allowed update servers?

This might be a bit strange, but on a highly security strict LAN with
content filtering proxy (as in this case), this imposes a security risk
since https doesn't permit content parsing. Meaning that tcp 443 rules
*must* be set at the routers/firewalls and so, default configured http
clients (browsers on out-of-the box installs for instance) end up
rendering
content that they weren't suposed to.

Thank you,
rusga




.



Relevant Pages

  • Re: Automatic Updates security concern
    ... Had to find time to read about what a WSUS server is;-) ... If those servers are not configured to support SSL ... on tcp 443 then the update clients will be forced to use tcp ... Is there any way of setting the AU repository so it never uses https ...
    (microsoft.public.security)
  • Re: RPC over HTTPS Performance issue
    ... All clients are running outlook 2007 sp1, ... have been configured for rpc over https. ... exchange servers. ...
    (microsoft.public.exchange.admin)
  • Re: Help with setting up Sites.
    ... Site A - respresenting physical site B ... servers is increasing by the day. ... Do you have any DCs at SiteB? ... clients servers in the relevant sites to authenticate against them. ...
    (microsoft.public.windows.server.active_directory)
  • Re: adding machine to domain with NATed IPs
    ... sounds that the DCs are not reaching the>> clients ... can the servers pint the clients by IP and Name? ... we specified these IPs as DNS server within ...
    (microsoft.public.windows.server.active_directory)
  • Re: Computer Browsing Service - anyone want to contribute for a good conversation?
    ... Do you have all client machines and servers ... Browse lists are built and exchanged by the computer browser service. ... It doesn't matter which subnet your clients are in. ... The most common cause of master browser failures is multihomed ...
    (microsoft.public.windows.server.networking)

Loading