Roll-up Security patches or Patches required and order to install?

  • Thread starter Thread starter Karen Gallaghar
  • Start date Start date
K

Karen Gallaghar

I run a small network on a college campus with about 200
XP Pro workstations (corporate versions and OEM versions,
RTM and SP1a versions). I was trying to build an MSI
package to apply the security patches when I build a new
or rebuild an old machine, which I do often enough. But,
I can't install XP Pro, and patch it before it is already
hit. I've actually tried this three times in the last
three days. So, my questions are:

1. Can you release an msi that will contain all the
critical update rollups for a clean XP Pro install?

2. If not, can you release a security roll-up with all
the critical update patches for both rtm and sp1a?

3. If not, can you give us (XP users and techs) a windows
(critical updates only)update(with the web functionality)
we can download and burn to CD? One that would actually
function like the web one (ie, check to see which patches
are installed, and allow multiple patch selection)? I
downloaded the patches from the the Windows update site's
catalog, but there is nothing indicating the order to
apply, and many of them require other patches first, most
require reboots and there are 60 of them.

4. If not, can you give us a list of what order to apply
them, and which, if any, are superceeded if you apply
other ones?

I really am serious that with a T3 on our college campus,
we can't install windows and then patch it without being
infected before we're done. And that is WITH our IT
department blocking any machines they scan that are
infected or vulnerable (the one I've been working with is
blocked before I can finish).

Thanks

Karen Gallaghar
WSU
 
This info may help
You use qchain to allow many patches without having to reboot in between
each one.
http://support.microsoft.com/default.aspx?scid=kb;[LN];296861

You could then build the patches and commands into an .msi

Have you thought of using an image, build one machine, apply all service
packs and patches, create an image of this, and then build machines using
the image?

Regards
Mark Dormer
 
Back
Top