<rss version="2.0"><channel><title>TRCB.com RSS Feed</title><description>Configure Software Updates on Earlier Operating SystemsFor earlier Windows operating systems, Group Policy will not be effective. For Windows NT, Microsoft recommends using the System Policy editor. For all down level, clients use registry edits. Use these edits with caution because they can cause serious problems on a machine. The registry settings are stored in HKLM\Software\Policies\ Microsoft\Windows\WindowsUpdate\AU. </description><link>http://www.trcb.com/</link><language>en-Us</language><ttl>60</ttl><lastBuildDate>Sat, 26 May 2012 07:46:47 EST</lastBuildDate><copyright>Copyright 2012 Deborah Timmons, TRCB.com All Right Reserved</copyright><item><title>Windows Server 2003 Configure Software Updates on Earlier Operating Systems</title><link>http://www.trcb.com/computers-and-technology/windows-server-2003/windows-server-2003-configure-software-updates-on-earlier-operating-systems-2464.htm</link><description>&lt;p&gt;&lt;strong&gt;Configure Software Updates on Earlier Operating Systems:&lt;/strong&gt;&lt;br /&gt;For earlier Windows operating systems, Group Policy will not be effective. For Windows NT, Microsoft recommends using the System Policy editor. For all down level, clients use registry edits. Use these edits with caution because they can cause serious problems on a machine. The registry settings are stored in HKLM\Software\Policies\ Microsoft\Windows\WindowsUpdate\AU. &amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Entry Name &amp;nbsp;&amp;nbsp;Value Range and MeaningsData Type&lt;/strong&gt;&lt;br /&gt;NoAutoUpdateRange = 0|1&lt;br /&gt;0 = Automatic Updates is enabled (default), 1 = Automatic Updates is disabled.Reg_DWORD&lt;br /&gt;AUOptionsRange = 2|3|4&lt;br /&gt;2 = notify of download and installation, 3 = automatically download and notify of installation, 4 = automatic download and scheduled installation. All options notify the local administrator.Reg_DWORD&lt;br /&gt;ScheduledInstallTimeRange = n; where n = the time of day in 24-hour format (0-23).Reg_DWORD&lt;br /&gt;UseWUServerSet this to 1 to enable Automatic Updates to use the Windows Update server as specified in WUServer.Reg_DWORD&lt;br /&gt;ScheduledInstallDayRange = 0|1|2|3|4|5|6|7&lt;br /&gt;0 = every day; 1 through 7 = the days of the week from Sunday (1) to Saturday (7).Reg_DWORD&lt;br /&gt;RescheduleWaitTimeRange = n; where n = time in minutes (1-60).Reg_DWORD&lt;br /&gt;NoAutoRebootWithLoggedOnUsers0 to 1; set this value to 1 if you want logged on users to choose whether or not to reboot their system.Reg_DWORD&amp;nbsp;To specify the server running SUS that you want your clients and servers to connect to for their Windows updates, you need to add two entries to the registry in the subkey HKLM\Software\Policies\Microsoft\Windows\WindowsUpdate. For the required entries, &amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Entry NameValuesData Type&lt;/strong&gt;&lt;br /&gt;WUServer The HTTP name for the Windows Update intranet server (for example, http://intranetsus).Reg_SZ&lt;br /&gt;WUStatusServerThe HTTP name for the Windows Update intranet server (for example, http://intranetsus).Reg_SZ&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Pop Quiz Questions&lt;/strong&gt;&lt;br /&gt;1. What two steps are needed to install Software Update Services on a Windows Server 2003?&lt;br /&gt;2. What is the Security.inf template used for on a Windows Server 2003?&lt;br /&gt;3. Where are the client SUS files for Windows 2000 client machine?&lt;br /&gt;4. What is the WUServer registry key used for on older Window client machines?&lt;br /&gt;5. Does a local or group policy setting take precedence on a Windows Server 2003?&lt;/p&gt;&lt;p&gt;&lt;strong&gt; Pop Quiz Answers:&lt;/strong&gt;&lt;br /&gt;1. Download the software from the Microsoft site and then run the update configuration.&lt;br /&gt;2. The Security.inf template represents the default security settings applied during installation of the operating system, including the file permissions for the root of the system drive.&lt;br /&gt;3. Client components for SUS are contained in Windows 2000 SP3 as an msi file. This holds true as well for Windows XP SP 1, and in all Windows 2003 installations.&lt;br /&gt;4. WUServer is used to enable Automatic Updates on the client server. Set the key to 1 to allow the client to use the Windows Update server for updates.&lt;br /&gt;5. Group Policy settings always take precedence over local settings.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Monitor Network Protocol Security:&lt;/strong&gt;&lt;br /&gt;For this Microsoft exam, there are two main areas of monitoring that you need to be familiar with: IPSec and Kerberos authentication. The IPSec snap-in for MMC provides a complete monitoring tool for IPSec issues, while for Kerberos authentication, there are numerous tools. First, we will look at the IPSec Monitor.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;The IP Security Monitor Microsoft Management Console (MMC) Snap-in:&amp;nbsp;&lt;/strong&gt;&lt;br /&gt;The IPSec Monitor snap-in for MMC provides extensive monitoring and troubleshooting capabilities for the network administrator. You can view details about the IPSec process, and also examine IPSec policies in effect both locally and in the domain.&amp;nbsp;&lt;br /&gt;The first node, Active Policy, shows information relating to the active IPSec policy currently in effect. The other nodes allow for advanced troubleshooting of the IPSec process.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Kerberos Support Tools:&amp;nbsp;&lt;/strong&gt;Auditing logon events and viewing with Event Viewer can provide some insight into Kerberos issues. The Microsoft Windows 2000 Resource Kit provided a troubleshooting tool, kerbtray.exe. Kerbtray allows you to see the ticket-granting process, and is also considered an advanced tool for network support.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Troubleshoot Network Protocol Security:&lt;/strong&gt;Troubleshooting in this area can be extensive, but for this discussion, we will only look at two tools: Event Viewer and Network Monitor.&lt;br /&gt;Event Viewer&lt;br /&gt;Event Viewer is one of the best-known tools in Microsoft's Administrative Tools folder. For troubleshooting network protocol security, this centers on the configuration of auditing, and the subsequent examination of the security log. As we noted above, auditing account logon events can give us information about Kerberos issues. For Kerberos-related troubleshooting, some of the more common problems are Event 672-Authentication service ticket successful, Event 673-A ticket granting service ticket was granted, Event 675-Pre-authentication failed; user typed in wrong password and Event 678-An account was successfully mapped to a domain account. If the server is running RRAS and is being used as a remote access server, then auditing can be used to troubleshoot access issues.&lt;br /&gt;&lt;strong&gt;&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Network Monitor:&lt;/strong&gt;Network Monitor is a very advanced tool, as is any packet analysis utility. Captured traffic can be analyzed for a wide variety of purposes. Even Microsoft concedes that most administrators will need to send packet captures to an expert for analysis.&amp;nbsp;&lt;/p&gt;</description><pubDate>Sun, 23 Nov 2008 22:02:05 EST</pubDate><guid>http://www.trcb.com/computers-and-technology/windows-server-2003/windows-server-2003-configure-software-updates-on-earlier-operating-systems-2464.htm</guid><source url="http://www.trcb.com/rss/article/windows-server-2003-configure-software-updates-on-earlier-operating-systems-2464.xml">TRCB.com</source><category>Computers and Technology / Windows Server 2003 </category></item></channel></rss>
