Notices
Computer & Technology Related Post here for help and discussion of computing and related technology. Internet, TVs, phones, consoles, computers, tablets and any other gadgets.

SUS server for applying patches - problemo..

Thread Tools
 
Search this Thread
 
Old 11 June 2004, 02:41 PM
  #1  
what would scooby do
Scooby Senior
Thread Starter
 
what would scooby do's Avatar
 
Join Date: Aug 2002
Location: 52 Festive Road
Posts: 28,311
Likes: 0
Received 0 Likes on 0 Posts
Default SUS server for applying patches - problemo..

One of our techies is having a problem with a SUS server - it keeps saying it can't push down the updates to the PC's (XP PRO) as the user does not have admin rights. Now never having seen SUS server meself can someone please give me an idea on how it is supposed to work i.e. do you create an admin equiv account on each pc and give the SUS server that account to use ??
Old 11 June 2004, 03:26 PM
  #2  
ozzy
Scooby Regular
 
ozzy's Avatar
 
Join Date: Nov 1999
Location: Scotland, UK
Posts: 10,504
Likes: 0
Received 1 Like on 1 Post
Default

IIRC, the user needs local admin permissions (i.e. member of local admin group) to interact with AU service.

If the local user doesn't have admin permissions, then the AU needs to be scheduled using a Global Policy.

The SUS server interacts with the AU service on each client PC. It's the AU service that initiates the update queries not the other way around.

Have a look at the SUS White Paper for more detailed info.

Stefan
Old 11 June 2004, 03:36 PM
  #3  
what would scooby do
Scooby Senior
Thread Starter
 
what would scooby do's Avatar
 
Join Date: Aug 2002
Location: 52 Festive Road
Posts: 28,311
Likes: 0
Received 0 Likes on 0 Posts
Default

Cheers, I've already downloaded the paper so I'll take a look
Old 11 June 2004, 03:36 PM
  #4  
NickAdams
Scooby Regular
iTrader: (5)
 
NickAdams's Avatar
 
Join Date: Mar 2001
Location: Cheshire
Posts: 2,895
Likes: 0
Received 0 Likes on 0 Posts
Default

Yep,as per what Stefan is saying...
MBSA (Microsoft Baseline Security Analyser) won't allow you to scan a remote client either unless you have admin rights on that particular machine.Easy enough to grant yourselves admin rights on the remote machines though!!

Good luck

Nick
Old 11 June 2004, 03:48 PM
  #5  
what would scooby do
Scooby Senior
Thread Starter
 
what would scooby do's Avatar
 
Join Date: Aug 2002
Location: 52 Festive Road
Posts: 28,311
Likes: 0
Received 0 Likes on 0 Posts
Default

.. yup Nick, only problem is this is a corportate environment where admin rights are never granted to local users /workstations
Old 11 June 2004, 03:53 PM
  #6  
ozzy
Scooby Regular
 
ozzy's Avatar
 
Join Date: Nov 1999
Location: Scotland, UK
Posts: 10,504
Likes: 0
Received 1 Like on 1 Post
Default

You should be able to manipulate the AU using a policy so that the workstations pull the updates from the SUS server.

Or you should really consider something along the lines of SMS Server in a large Corporate environment. SUS is really for small businesses.

Stefan
Old 11 June 2004, 04:18 PM
  #7  
what would scooby do
Scooby Senior
Thread Starter
 
what would scooby do's Avatar
 
Join Date: Aug 2002
Location: 52 Festive Road
Posts: 28,311
Likes: 0
Received 0 Likes on 0 Posts
Default

Sure, yes in a Microsoft environment we would use SMS but here there be netware and Linux

Trending Topics

Old 11 June 2004, 04:38 PM
  #8  
darlodge
Scooby Regular
 
darlodge's Avatar
 
Join Date: Oct 2001
Location: Lovely Lancing in West Sussex
Posts: 3,449
Likes: 0
Received 0 Likes on 0 Posts
Thumbs up

I'm still playing with an SUS server (running on Server 2003). Its distributing updates to Windows 2000 and XP machines running Novell.

Have you loaded the updated adm file called wuau.adm on each machine? This enables you and me () to schedule the updates at different times (we are going to do ours at 11am). If the user on the machine is an Administrator they receive a 'balloon' to tell them there are updates to install. If the user is a 'normal user' it just install it without asking, exactly how we wanted it to work

I am still playing with it and am not 100% how it works but its free so I like it

Darren
Old 11 June 2004, 04:48 PM
  #9  
what would scooby do
Scooby Senior
Thread Starter
 
what would scooby do's Avatar
 
Join Date: Aug 2002
Location: 52 Festive Road
Posts: 28,311
Likes: 0
Received 0 Likes on 0 Posts
Default

Originally Posted by darlodge
I'm still playing with an SUS server (running on Server 2003). Its distributing updates to Windows 2000 and XP machines running Novell.

Have you loaded the updated adm file called wuau.adm on each machine? This enables you and me () to schedule the updates at different times (we are going to do ours at 11am). If the user on the machine is an Administrator they receive a 'balloon' to tell them there are updates to install. If the user is a 'normal user' it just install it without asking, exactly how we wanted it to work

I am still playing with it and am not 100% how it works but its free so I like it

Darren
Sounds good - I'm gonna set one up and have a play
Old 11 June 2004, 04:58 PM
  #10  
darlodge
Scooby Regular
 
darlodge's Avatar
 
Join Date: Oct 2001
Location: Lovely Lancing in West Sussex
Posts: 3,449
Likes: 0
Received 0 Likes on 0 Posts
Default

No worries,

E-mail me, PM me or post here for any assiatance. I might be able to help. Its really cool once you get going. Easy administration, simple (once you get your head round it).

Saves running around 300 machines all at once. I am sure we will go over to SMS at some point as its apparently better designaed and there are more functions but we needed something ASAP and from what I read, SMS was/is a b|tch to set-up.

Darren

Last edited by darlodge; 11 June 2004 at 05:03 PM.
Old 11 June 2004, 08:01 PM
  #11  
what would scooby do
Scooby Senior
Thread Starter
 
what would scooby do's Avatar
 
Join Date: Aug 2002
Location: 52 Festive Road
Posts: 28,311
Likes: 0
Received 0 Likes on 0 Posts
Default

cheers Darren
Old 12 June 2004, 07:56 PM
  #12  
Puff The Magic Wagon!
Moderator
Support Scoobynet!
iTrader: (2)
 
Puff The Magic Wagon!'s Avatar
 
Join Date: May 2000
Location: From far, far away...
Posts: 16,978
Received 15 Likes on 9 Posts
Default

<kicks memory>

Its all about having a Global GP set up for every user that runs MS Update but checks with SUS instead.

The "howto"s are all in TechNet or KB but each machine (irrespective of user) checks itself against the latest specs (either @ 03:00 for me or on boot) then d/loads the relevant files and installs them. I have not had to muck about with permissions.

The only problem I have is that I need to click the tray icon to install (my first attempt) as opposed to auto-install. Can't seem to change that though I have tried to amend the defaults...
Old 13 June 2004, 12:56 AM
  #13  
darlodge
Scooby Regular
 
darlodge's Avatar
 
Join Date: Oct 2001
Location: Lovely Lancing in West Sussex
Posts: 3,449
Likes: 0
Received 0 Likes on 0 Posts
Default

Puff,

If you have added the updated adm file (have you done this?) onto each machine and the user is logged on a normal user you should not receive the sys tray icon.

Once you have loaded the adm file there are a few extra registry entires that have to be added and then the updates will install sliently, proving you are a USER on the machine. If you are logged in as an Administrator, you will receive the systray icon.

I can't remember what the options are but they are something like these DWORD values
AUOptions = 4 (This is vital and makes the updates install at the scheduled time)
AUSCHE = 0

There are more but I can't remember the exact keys but I'll whack them up on Monday. I've also got the adm file at work if you need that.

DArren
Old 13 June 2004, 08:10 PM
  #14  
WRX_Rich
Scooby Regular
iTrader: (5)
 
WRX_Rich's Avatar
 
Join Date: Feb 2003
Location: Worcester
Posts: 2,625
Likes: 0
Received 0 Likes on 0 Posts
Default

u will get the tray icon if you are a admin on the local pc, none admins will just install at the time set in the group policy

www.susserver.com

we use it along side sms 2003, they both have there strengths but as sus is so easy to set up we stick with it and I only set sms up 2 weeks ago

can you use sms 2003 just the same as sus with regular downloads ?
Old 14 June 2004, 07:55 AM
  #15  
darlodge
Scooby Regular
 
darlodge's Avatar
 
Join Date: Oct 2001
Location: Lovely Lancing in West Sussex
Posts: 3,449
Likes: 0
Received 0 Likes on 0 Posts
Default

WRX_Rich,

We have not got a group policy running yet so we added these command line entries in the

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\WindowsUpdate\Auto Update]

"AUOptions"=dword:00000004 (4)
"AUState"=dword:00000002 (2)
"ScheduledInstallDay"=dword:00000000 (0)
"ScheduledInstallTime"=dword:0000000b (11)
"LastWaitTimeout"="2004.05.29 01:51:10"

Darren
Related Topics
Thread
Thread Starter
Forum
Replies
Last Post
JimBowen
ICE
5
02 July 2023 01:54 PM
KAS35RSTI
Subaru
27
04 November 2021 07:12 PM
oilman
Trader Announcements
15
01 October 2015 11:55 AM
An0n0m0us
Computer & Technology Related
0
28 September 2015 09:58 PM
oilman
Trader Announcements
0
23 September 2015 12:35 PM



Quick Reply: SUS server for applying patches - problemo..



All times are GMT +1. The time now is 05:56 PM.