The recent Sobig virus and MSBlaster worm illustrate the importance of patch management in today’s sophisticated hacking environment. While not all patches relate to significant system vulnerability or stability issues, IT administrators need to quickly discern those that do — not to mention track which systems are patched and which ones aren’t.
St. Bernard Software’s UpdateExpert 6.1 and its competitors — Ecora, PatchLink and others — are addressing the problem with a combination of update tracking and management technologies.
Overall, UpdateExpert did not disappoint. The good news is that recently added features such as WAN and demilitarised zone (DMZ) administrative management capabilities, scalability improvements, and support for logical groupings of clients are primarily aimed at increasing enterprise functionality. Version 6.1 also extends support for the disconnected networks widely used in government and military organisations and has plug-in support for HP OpenView.
The bad news is that its abilities are limited to providing patch management for Windows products only, at least for now.
UpdateExpert consists of a management console and a machine agent. An optional Leaf Agent can be pressed into duty to handle systems in a highly secure environment where typical Remote Procedure Calls (RPCs) won’t do. These Leaf Agents can be a pain to use, since you have to perform single installations either using the Agent Installation wizard or through UpdateExpert’s command line interface. It would be great to see an easier way of deploying these in a future release.
Installation went smoothly on my test bed, an HP ProLiant ML530 server and LAN clients all running Windows 2000. I chose the typical installation that installs both the console and master agent on my server and later installs master agents on all of the clients. UpdateExpert gathers and validates patch information from client system files (a software inventory is also kept and updated), then monitors incoming updates from Microsoft and doles out appropriate patches.
The UpdateExpert management GUI was fairly intuitive, literally covering all the bases from one neatly organised, centralised window that compartmentalises into two main views, Research and Network. In the Research view, an admin can research the various available patches to find out more about what they correct. The Network view lets the admin easily manage client patches to the different systems on the network.
Administrators can now group systems by characteristics as well as by type or function.
But it’s the added features in Version 6.1 that make UpdateExpert ready for prime time. For example, it now supports multiple management consoles on the network and allows admins to view updates made from the other consoles, saving time and preventing redundant updates.
Contact can also be made between components via a configurable IP port, that makes patch management and updating possible through proxy servers or firewalls. If you want to download patches through a proxy server, I suggest authenticating the server beforehand because it’s possible the product will erroneously think the authentication page is the patch and not install the real patch.
The Windows-only focus does limit UpdateExpert’s range, but if you’ve got a Microsoft-heavy deployment, it will make managing updates less painful.