Deploying Microsoft Windows Server Update Services
Total Page:16
File Type:pdf, Size:1020Kb
Deploying Microsoft Windows Server Update Services Microsoft Corporation Published: June 3, 2005 Author: Tim Elhajj Editor: Sean Bentley Abstract This paper describes how to deploy Microsoft® Windows Server™ Update Services (WSUS). You will find a comprehensive description of how WSUS functions, as well as descriptions of WSUS scalability and bandwidth management features. This paper also offers step-by-step procedures for installation and configuration of the WSUS server. You will read how to update and configure Automatic Updates on client workstations and servers that will be updated by WSUS. Also included are steps for migrating from Microsoft Software Update Services (SUS) to WSUS, as well as steps for setting up a WSUS server on an isolated segment of your network and manually importing updates. The information contained in this document represents the current view of Microsoft Corporation on the issues discussed as of the date of publication. Because Microsoft must respond to changing market conditions, it should not be interpreted to be a commitment on the part of Microsoft, and Microsoft cannot guarantee the accuracy of any information presented after the date of publication. This White Paper is for informational purposes only. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS DOCUMENT. Complying with all applicable copyright laws is the responsibility of the user. Without limiting the rights under copyright, no part of this document may be reproduced, stored in or introduced into a retrieval system, or transmitted in any form or by any means (electronic, mechanical, photocopying, recording, or otherwise), or for any purpose, without the express written permission of Microsoft Corporation. Microsoft may have patents, patent applications, trademarks, copyrights, or other intellectual property rights covering subject matter in this document. Except as expressly provided in any written license agreement from Microsoft, the furnishing of this document does not give you any license to these patents, trademarks, copyrights, or other intellectual property. Unless otherwise noted, the example companies, organizations, products, domain names, e-mail addresses, logos, people, places, and events depicted herein are fictitious, and no association with any real company, organization, product, domain name, e-mail address, logo, person, place, or event is intended or should be inferred. © 2005 Microsoft Corporation. All rights reserved. Microsoft, SQL Server, Windows, and Windows Server are either registered trademarks or trademarks of Microsoft Corporation in the United States and/or other countries. The names of actual companies and products mentioned herein may be the trademarks of their respective owners. Contents Deploying Microsoft Windows Server Update Services ..................................................... 1 Abstract ....................................................................................................................... 1 Contents ............................................................................................................................. 5 Deploying Microsoft Windows Server Update Services ......................................... 8 Introduction to Deploying Windows Server Update Services ................................ 9 Design the WSUS Deployment ............................................................................. 9 Choose a Type of Deployment ......................................................................... 10 Simple WSUS Deployment ........................................................................................ 10 Chain of WSUS Servers ............................................................................................ 12 Networks Disconnected from the Internet .................................................................. 13 Choose a Management Style ........................................................................... 14 Centralized Management .......................................................................................... 14 Distributed Management ........................................................................................... 16 Choose the Database Used for WSUS ............................................................ 16 Selecting a Database ................................................................................................ 17 Database Authentication, Instance, and Database Name ......................................... 18 Determine Where to Store Updates ................................................................. 18 Local Storage ............................................................................................................ 19 Remote Storage ........................................................................................................ 19 Determine Bandwidth Options to Use for Your Deployment ............................. 21 Deferring the Download of Updates ........................................................................... 21 Filtering Updates ....................................................................................................... 22 Using Express Installation Files ................................................................................. 23 Background Intelligent Transfer Service .................................................................... 24 Determine Capacity Requirements .................................................................. 25 Install the WSUS Server ...................................................................................... 25 Configure the Firewall Between the WSUS Server and the Internet ................ 26 Prepare Disks and Partitions ............................................................................ 27 Install Required Software ................................................................................. 28 Windows Server 2003 ............................................................................................... 28 Windows 2000 Server ............................................................................................... 28 Install and Configure IIS ................................................................................... 29 IIS Lockdown Tool ..................................................................................................... 29 Client Self-Update ..................................................................................................... 31 Using the WSUS Custom Web Site ........................................................................... 31 Run WSUS Server Setup ................................................................................. 32 Configure the WSUS Server ............................................................................... 38 Access the WSUS Administration Console ...................................................... 38 Configure WSUS to Use a Proxy Server .......................................................... 39 Select Products and Classifications ................................................................. 40 Synchronize the WSUS Server ........................................................................ 40 Configure Advanced Synchronization Options ................................................. 41 Update Storage Options ............................................................................................ 41 Deferred Downloads Options .................................................................................... 41 Express Installation Files Options .............................................................................. 42 Filtering Updates Options .......................................................................................... 42 Chain WSUS Servers Together ........................................................................ 43 Create a Replica Group ................................................................................... 43 Create Computer Groups for Computers ......................................................... 45 Setting up Computer Groups ..................................................................................... 45 Approve Updates ............................................................................................. 46 Verify Update Deployment ............................................................................... 47 Secure Your WSUS Deployment ...................................................................... 47 Hardening your Windows Server 2003 running WSUS ............................................. 48 Adding Authentication Between Chained WSUS Servers in an Active Directory Environment ........................................................................................................... 48 Securing WSUS with Secure Sockets Layer ............................................................. 50 Update and Configure the Automatic Updates Client Component ....................... 55 Client Component Requirements ..................................................................... 55 Update Automatic Updates .............................................................................. 55 Automatic Updates Client Self-Update Feature ......................................................... 56 Determine a Method to Configure Automatic Updates Clients ......................... 57 Configure Automatic Updates by Using Group Policy ..................................