Posted on October 16th, 2009 by Jon Honeyball
The perils of auto-patching
I have a rackmounted server in a data center some 50 miles away from me in Huntingdon. It’s a lights-out operation, and I can’t remember the last time I visited the server in person. Everything just works through Terminal Services.
The server has been humming along quite happily for a number of years, which is why it’s running Server 2003 and Exchange 2003 – if it ain’t broke, don’t fix it, sez I.
With such a remote server, you have a hard choice to make – do you set it to auto-update when Microsoft issues new patches, or do you bring them down to a local machine, check them out and then apply them yourself, preferably waiting a few days to see if others have problems?
Well, I would always advocate a managed patch implementation for a local network – it can dramatically reduce the download of updates to multiple identical machines, and gives you, the sysadmin, control over when updates are applied. This can be critically important to the business workflow, of course.
But for a remote server, sat out there in internet-land? Frankly it’s to easy to forget that it’s there, and that you need to keep it patched up, especially if the server isn’t connected to the local LAN via a VPN tunnel. So for such servers, the risk assessment says that its better to go with auto-patching than to forget to patch.
Which is just fine when it goes well. But this morning, I woke up to find my Exchange Server 2003 had no SMTP, no IMAP and no POP3 services running. It had patched itself at 3am as usual, rebooted and come up cleanly except for these services. Hence my inbox was empty. In the approximate words of Pooh, the more I looked, the more my email wasn’t there.
Chatting to mates on Twitter this morning suggests that others have had exactly the same problem, so it is not a localised problem with my box. It might be worth checking that those services are running. Just kick them into action manually, or reboot the server.
Tags: Microsoft, Server 2003
Posted in: Just in, Real World Computing
Follow any responses to this entry through the RSS 2.0 feed.
You can skip to the end and leave a response. Pinging is currently not allowed.
2 Responses to “ The perils of auto-patching ”
Leave a Reply
Categories
- About the bloggers
- Green
- Hardware
- How To
- Just in
- Microsoft Office 2010
- Newsdesk
- Online business
- Random
- Rant
- Real World Computing
- Software
- View from the Labs
- Windows 7
Authors
Archives
- November 2009
- October 2009
- September 2009
- August 2009
- July 2009
- June 2009
- May 2009
- April 2009
- March 2009
- February 2009
- January 2009
- December 2008
- November 2008
- October 2008
- September 2008
- August 2008
- July 2008
- June 2008
- May 2008
- April 2008
advertisement
Printed from www.pcpro.co.uk




























October 16th, 2009 at 4:54 pm
There have been other reports of problems with this glut of patches – Justin James at TechRepublic reports problems wrt KB974571 with OCS & LCS in this blag post comment:
http://techrepublic.com.com/5208-12843-0.html?forumID=102&threadID=319036&messageID=3181113&tag=leftCol;post-1666
Dave
October 21st, 2009 at 8:05 pm
Got caught out by an anti-virus upgrade on the DC this week… My first weeks holiday in the new job!
The software autoupdate, but needed to restart. The conflict between the version of the software on disk and the one in memory slowed the machine to a crawl!
So much for taking a week off!