Skip to navigation

PCPro-Computing in the Real World Printed from www.pcpro.co.uk

Register to receive our regular email newsletter at http://www.pcpro.co.uk/registration.

The newsletter contains links to our latest PC news, product reviews, features and how-to guides, plus special offers and competitions.

// Home / Blogs

Posted on October 16th, 2009 by Jon Honeyball

The perils of auto-patching

Easy wayI have a rackmounted server in a data center some 50 miles away from me in Huntingdon. It’s a lights-out operation, and I can’t remember the last time I visited the server in person. Everything just works through Terminal Services.

The server has been humming along quite happily for a number of years, which is why it’s running Server 2003 and Exchange 2003 – if it ain’t broke, don’t fix it, sez I.

With such a remote server, you have a hard choice to make – do you set it to auto-update when Microsoft issues new patches, or do you bring them down to a local machine, check them out and then apply them yourself, preferably waiting a few days to see if others have problems?

Well, I would always advocate a managed patch implementation for a local network – it can dramatically reduce the download of updates to multiple identical machines, and gives you, the sysadmin, control over when updates are applied. This can be critically important to the business workflow, of course.
But for a remote server, sat out there in internet-land? Frankly it’s to easy to forget that it’s there, and that you need to keep it patched up, especially if the server isn’t connected to the local LAN via a VPN tunnel. So for such servers, the risk assessment says that its better to go with auto-patching than to forget to patch.

Which is just fine when it goes well. But this morning, I woke up to find my Exchange Server 2003 had no SMTP, no IMAP and no POP3 services running. It had patched itself at 3am as usual, rebooted and come up cleanly except for these services. Hence my inbox was empty. In the approximate words of Pooh, the more I looked, the more my email wasn’t there.

Chatting to mates on Twitter this morning suggests that others have had exactly the same problem, so it is not a localised problem with my box. It might be worth checking that those services are running. Just kick them into action manually, or reboot the server.

Tags: ,

Posted in: Just in, Real World Computing

Permalink

Follow any responses to this entry through the RSS 2.0 feed.

Social Bookmark this article: What is this?

You can skip to the end and leave a response. Pinging is currently not allowed.

2 Responses to “ The perils of auto-patching ”

  1. Dave Laljee Says:
    October 16th, 2009 at 4:54 pm

    There have been other reports of problems with this glut of patches – Justin James at TechRepublic reports problems wrt KB974571 with OCS & LCS in this blag post comment:
    http://techrepublic.com.com/5208-12843-0.html?forumID=102&threadID=319036&messageID=3181113&tag=leftCol;post-1666

    Dave

     
  2. David Wright Says:
    October 21st, 2009 at 8:05 pm

    Got caught out by an anti-virus upgrade on the DC this week… My first weeks holiday in the new job!

    The software autoupdate, but needed to restart. The conflict between the version of the software on disk and the one in memory slowed the machine to a crawl!

    So much for taking a week off!

     

Leave a Reply

* required fields

* Will not be published

Categories

Authors

Archives

advertisement

SEARCH
SIGN UP

Your email:

Your password:

remember me

advertisement


Hitwise Top 10 Website 2008