Patch Management –Pedro Carrasquilla –Sean Garrett –Jeni Li Arizona State University East Information Technology October 2, 2003 By Presented to WNUG/CCC.

Slides:



Advertisements
Similar presentations
Auditing Microsoft Active Directory
Advertisements

1 Web Servers / Deployment Alastair Dawes Original by Bhupinder Reehal.
1 Configuring Internet- related services (April 22, 2015) © Abdou Illia, Spring 2015.
MCITP Guide to Microsoft Windows Server 2008, Server Administration (Exam #70-646) Chapter 2 Installing Windows Server 2008.
Delivering Windows OS Updates at Yale with SUS EDUCAUSE Security Professionals Workshop May 17, 2004 Washington DC Ken Hoover, Systems Programmer
70-290: MCSE Guide to Managing a Microsoft Windows Server 2003 Environment, Enhanced Chapter 9: Implementing and Using Group Policy.
1 Configuring Web services (Week 15, Monday 4/17/2006) © Abdou Illia, Spring 2006.
70-290: MCSE Guide to Managing a Microsoft Windows Server 2003 Environment Chapter 10: Server Administration.
Exchange server Mail system Four components Mail user agent (MUA) to read and compose mail Mail transport agent (MTA) route messages Delivery agent.
70-290: MCSE Guide to Managing a Microsoft Windows Server 2003 Environment Chapter 9: Implementing and Using Group Policy.
Module 6 Windows 2000 Professional 6.1 Installation 6.2 Administration/User Interface 6.3 User Accounts 6.4 Managing the File System 6.5 Services.
Lesson 18: Configuring Application Restriction Policies
7.1 © 2004 Pearson Education, Inc. Exam Managing and Maintaining a Microsoft® Windows® Server 2003 Environment Lesson 7: Introducing Group Accounts.
Microsoft Baseline Security Analyzer INLS 187 Security Software Presentation by Hinár György Polczer
Patching MIT SUS Services IS&T Network Infrastructure Services Team.
Module 6: Patches and Security Updates 1. Overview Installing Patches and Security Updates Recent patches and security updates for IIS Recent patches.
Patch management using Microsoft Software Update Service 1.0 SP1 Chris Hughes, Systems Architect Warrington College of Business
Reliability and Performance Application protection IIS Reliable Restart Socket pooling Multisite hosting Process throttling Bandwidth throttling.
Group Policy in Microsoft Windows Active Directory.
SUS Services ECE Computer Facilities. SUS Services Software Update Services Microsoft Security And Critical Update Service Microsoft Security And Critical.
Module 16: Software Maintenance Using Windows Server Update Services.
Guide to MCSE , Enhanced 1 Activity 10-1: Restarting Windows Server 2003 Objective: to restart Windows Server 2003 Start  Shut Down  Restart Configure.
Microsoft October 2004 Security Bulletins Briefing for Senior IT Managers updated October 20, 2004 Marcus H. Sachs, P.E. The SANS Institute October 12,
11 SHARING FILE SYSTEM RESOURCES Chapter 9. Chapter 9: SHARING FILE SYSTEM RESOURCES2 CHAPTER OVERVIEW Create and manage file system shares and work with.
Principles of Computer Security: CompTIA Security + ® and Beyond, Second Edition © 2010 Baselines Chapter 14.
SOE and Application Delivery Gwenael Moreau, Abbotsleigh.
9.1 © 2004 Pearson Education, Inc. Exam Planning, Implementing, and Maintaining a Microsoft Windows Server 2003 Active Directory Infrastructure.
Module 9 Configuring Server Security Compliance. Module Overview Securing a Windows Infrastructure Overview of EFS Configuring an Audit Policy Overview.
1 Infrastructure Hardening. 2 Objectives Why hardening infrastructure is important? Hardening Operating Systems, Network and Applications.
70-290: MCSE Guide to Managing a Microsoft Windows Server 2003 Environment, Enhanced Chapter 9: Implementing and Using Group Policy.
Configuring a Web Server. Overview Overview of IIS Preparing for an IIS Installation Installing IIS Configuring a Web Site Administering IIS Troubleshooting.
Chapter 7: Using Windows Servers to Share Information.
Raven Services Update December 2003 David Wallis Senior Systems Consultant Raven Computers Ltd.
Module 13: Maintaining Software by Using Windows Server Update Services.
Section 2: Using Group Policy Management Tools Local vs. Domain Policies Editing Local Policies Managing Domain Policies Understanding Group Policy Refresh.
Microsoft Internet Information Services 5.0 (IIS) By: Edik Magardomyan Fozi Abdurhman Bassem Albaiady Vince Serobyan.
Module 14: Configuring Server Security Compliance
11 MANAGING AND DISTRIBUTING SOFTWARE BY USING GROUP POLICY Chapter 5.
Course ILT Internet/intranet support Unit objectives Use the Internet Information Services snap-in to manage IIS, Web sites, virtual directories, and WebDAV.
Internet Information Server © N. Ganesan, Ph.D. All Rights Reserved.
FNAL System Patching Design Jack Schmidt, Al Lilianstrom, Andy Romero, Troy Dawson, Connie Sieh (Fermi National Accelerator Laboratory) Introduction FNAL.
IIS Security Sridurga Mavram. Contents -Introduction -Security Consideration -Creating a web page -Drawbacks -Security Tools -Conclusion -References.
INSTALLATION HANDS-ON. Page 2 About the Hands-On This hands-on section is structured in a way, that it allows you to work independently, but still giving.
Managing Groups, Folders, Files and Security Local Domain local Global Universal Objects Folders Permissions Inheritance Access Control List NTFS Permissions.
Module 2: Installing and Maintaining ISA Server. Overview Installing ISA Server 2004 Choosing ISA Server Clients Installing and Configuring Firewall Clients.
70-290: MCSE Guide to Managing a Microsoft Windows Server 2003 Environment, Enhanced Chapter 10: Server Administration.
1 Chapter Overview Publishing Resources in Active Directory Service Redirecting Folders Using Group Policies Deploying Applications Using Group Policies.
Managing Windows Software & Updates SUS Server MS Baseline Security Analyzer Software and Group Policy Paul “The Yellow Dart” Peterson University of Minnesota.
1 Objectives Windows Firewalls with Advanced Security Bit-Lock Update and maintain your clients using Windows Server Update Service Microsoft Baseline.
Section 11: Implementing Software Restriction Policies and AppLocker What Is a Software Restriction Policy? Creating a Software Restriction Policy Using.
PLANNING A MICROSOFT EXCHANGE SERVER 2003 INFRASTRUCTURE Chapter 2.
IS 4506 Establishing Microsoft NNTP Service.  Overview NNTP Service benefits How the NNTP Service works Configuring and managing NNTP Service.
Module 4 Planning for Group Policy. Module Overview Planning Group Policy Application Planning Group Policy Processing Planning the Management of Group.
Microsoft Management Seminar Series SMS 2003 Change Management.
Principles of Computer Security: CompTIA Security + ® and Beyond, Third Edition © 2012 Principles of Computer Security: CompTIA Security+ ® and Beyond,
11 PLANNING A GROUP POLICY MANAGEMENT AND IMPLEMENTATION STRATEGY Chapter 10.
Vlad Mazek Own Web Now Corp CEO, MCSE, MCSA, CISSP (877) Portions reproduced with permission from Dean Calvert.
1 Chapter Overview Creating Web Sites and FTP Sites Creating Virtual Directories Managing Site Security Troubleshooting IIS.
17 Establishing Dial-up Connection to the Internet Using Windows 9x 1.Install and configure the modem 2.Configure Dial-Up Adapter 3.Configure Dial-Up Networking.
Windows Administration How to protect your computer.
GROUP POLICY. Group Policy is a hierarchical infrastructure which allows systems administrators to configure computer and user settings from a central.
Unit 9 ITT TECHNICAL INSTITUTE NT1330 Client-Server Networking II Date: 2/17/2016 Instructor: Williams Obinkyereh.
NETWORK SECURITY LAB 1170 REHAB ALFALLAJ CT1406. Introduction There are a number of technologies that exist for the sole purpose of ensuring that the.
11 DEPLOYING AN UPDATE MANAGEMENT INFRASTRUCTURE Chapter 6.
Chapter 7: Using Windows Servers
الخطوات المطلوب القيام بها قبل انشاء الموقع
Unit 9 NT1330 Client-Server Networking II Date: 8/9/2016
Configuring Internet-related services
Web Servers / Deployment
Designing IIS Security (IIS – Internet Information Service)
Presentation transcript:

Patch Management –Pedro Carrasquilla –Sean Garrett –Jeni Li Arizona State University East Information Technology October 2, 2003 By Presented to WNUG/CCC

 GOAL: prevent client downtime due to critical patch issues  OUTCOME: patch management for domain clients

METHODS  GPO / MSI Packages – Script out, use existing server (GPO) – Potential for hiccups with different models – More background time for building package(s)  SUS server – Requires W2k server and IIS – Ease, point and click – Less admin time overall unless (until ?) compromised

HARDWARE  Dell Power Edge 4300  6 drives  2 Raid Containers  -RAID 1 mirrored (2 drives), OS only (C)  -RAID 5 (4 drives), SUS installation (F)

SOFTWARE  Windows 2000 server with SP3  IIS 5.0  SUS 1.0  Upgrade to SP4 + critical patches  AV (Netshield)

SUS setup  Setup for weekly downloads from Microsoft  Approved only the post SP4 updates  Set client to request reboot after downloading updates from SUS server  Client will apply update next time computer reboots in 24 hr period

Client GPO

WINDOWS LOCKDOWN  Windows Security – CIS Gold Standard template – How Get it from cisecurity.org Security Configuration & Analysis snap-in Review changes before applying!!! – Afterward, clean up the gotchas Set LSA_RestrictAnonymous as required if you have Backup Exec or some other reason it can’t be set to 2 Remove Web anonymous users (IUSR, IWAM) from Guests group Ensure Web anonymous users have permission to logon as batch jobs Ensure Web services are Started and set to Automatic (CIS template disables them) – IIS Admin Service – World Wide Web Publishing Service

WINDOWS LOCKDOWN  Other Security issues – IIS components not installed FTP, SMTP, NNTP, Internet Services Manager (HTML) – IIS tweaks: delete default IIS sites removed directory c:\inetpub\ Bind site to eastsus1.east.ad.asu.edu Allow only ASU subnet to see site Auto-update / administration: no indexing, server IP only Edit URLScan.ini, change RemoveServerHeader to 1 Shared: no indexing, no read, no execute (global.asp, used only by other ASP scripts Modified ACLs for the e:\ Changed encryption level to high (128) LSA restrict anonymous to 1

SUS LOCKDOWN Special IIS Lockdown template for SUS 1. Built in to SUS installation 2. Better than standard IIS Lockdown  What it does – Disallows Web service userid’s from running key system commands – Sets reasonable default settings in URLscan.ini  Caution 1. May break existing Web services on multifunction servers

IIS LOCKDOWN CONT…  Bind Web service to host name – How IIS snap-in Properties, Web Site Identification, Advanced Specify IP address and host header name (FQDN) – Why Keeps IIS from responding to requests without HTTP Host request header Makes your server less vulnerable to worms which find targets by generating random IP addresses Even unpatched Web servers, with this one setting, would have been invulnerable to Code Red, Code Blue, and Nimda worms  Set directory permissions on Web home directory

Deployment  -Testing Production Environment with test OU and several 2000 & XP clients  -Communication with our users. ( )  -GPO Applied WUAU.ADM to production OU for domain PCs

Future Updates  SUS 2.0 system & application (Office, SQL, and Exchange) patching In Beta, but posponed  Staging second server for testing patches initialy  Restricting IPs  Firewall

Web Resources  SUS10sp1.exe 6E41-4F54-972C-AE66A4E4BF6C&displaylang=en  CIS Gold Standard Template  Client GPO wuau.adm D274-42E C667B4C94E9&displaylang=en  Microsoft Solutions for Management: Patch Management Using Microsoft Systems Management Server (SMS) and Microsoft Software Update Services (SUS) yid=7d8999af-7e88-416c f886e8d  Microsofts Software Update Services  Software Update Services Deployment White Paper ment.asp  SUS with SP1 Release Notes and Installation Instructions