Symantec Management Platform (Notification Server)

 View Only
Expand all | Collapse all

Patch package not deploying

  • 1.  Patch package not deploying

    Posted May 09, 2011 05:45 AM

    Dear All,

    We have an issue with Patch management solution. There is a bulletin MS10-046. According to the Compliance list the patch only applies to 2 clients, which almost for sure is wrong!

    I have deleted the software package and all the patch files on the NS server. I staged again the bulletin and created the software package. I was hoping it will fix it, but it didn't.

    Well I have distributed the patch using the deployment Win32 console in the meantime. But I'm wondering how can I fix the issue in NS patch management solution. The solution is at latest release 7.0.4409.

    Any thought why this bulletion doesn't distribute properly?

    Thank you

    Edy

     

     

     

     

     

     



  • 2.  RE: Patch package not deploying

    Posted May 09, 2011 10:34 AM

    What OS are your clients? Can you verify that at least one client you feel should be vulnerable is indeed patched?



  • 3.  RE: Patch package not deploying

    Posted May 09, 2011 04:32 PM

    Client OS is Windowx XP SP3 and no there were not patched using the Patch management solution for this bulletin. We läter patched them using Deployment console

     

    Thanks



  • 4.  RE: Patch package not deploying

    Posted May 10, 2011 11:18 AM

    what I meant was - are there systems, if you ran something like MBSA or Windows Update that show at vulnerable to the patch, and Altiris does not?



  • 5.  RE: Patch package not deploying

    Posted May 12, 2011 08:47 AM

    Sorry about my late reply.

    We have found out since we had a WORM incident in April and MS10-046 was not deploye to some computers.

    The compliance reports shows that this patch only applies to 2 computers, which were patched. We have checked some computers manually and discovered that the patch was deployed back in August when the bulletin was released. We never used any other deployment method than Altiris. So I assume the patches were deployed with Altiris.

    It appears that it is a reporting issue of the patch management solution. False reporting. I don't know how can I fix the issue.

    Thanks

    Edy

     

     



  • 6.  RE: Patch package not deploying

    Posted May 12, 2011 09:45 AM

    If Altiris is saying it only applies to 2 systems, it sounds like applicability rules aren't firing properly for MS10-046.  Do you really mean applies to, or do you mean vulnerable?



  • 7.  RE: Patch package not deploying

    Posted May 12, 2011 10:06 AM

    I mean the reports says

    Applicable to 3 systems

    Installed to 3 systems

    Vulnerable to 0 systems

    Compliance 100%

    Thanks



  • 8.  RE: Patch package not deploying

    Posted May 12, 2011 10:59 AM

    And how does this differ from what you expect to see?  For example, do you have 12,000 nodes and 11,000 of those are Windows and 10,500 of those are running Patch Management?  I'm not sure how large the environment is -- if this is a test or eval environment this could be normal.



  • 9.  RE: Patch package not deploying

    Posted May 13, 2011 06:26 AM

    No, we are a shop of 200 users,

    I would expect to see a report that the patch is applicable to 180 computers as I do for other patch bulletins.

    I believe there is indeed a reporting issue. We have checked some computer manually and the patch was deployed in August 2010, wihich means when it come out. Since we don't use any other method to deploy patches it must have been installed by Altiris.

    I just don't know how to fix the reporting issue.

    Thank you

    Edy

     



  • 10.  RE: Patch package not deploying

    Posted May 13, 2011 08:15 AM

    Could you please provide a screenshot (with Grid and report menu bar shown) of the report?



  • 11.  RE: Patch package not deploying

    Posted May 15, 2011 08:08 AM
      |   view attached

    Hi Robert,

    Attached is a screenshot you were requesting. I hope it is what you were looking for.

    Thanks,



  • 12.  RE: Patch package not deploying

    Posted May 15, 2011 11:06 AM

    Yes, that was the screen shot i was looking for. Just one more thing, could you please attach similar screen shot of the "Software Update Delivery Summary" report, with required update shown?

    Thanks.



  • 13.  RE: Patch package not deploying

    Posted May 15, 2011 01:25 PM
      |   view attached

    Here is the requested report.  I don't understand the low number for targeted computers.

    Thanks,

    Edy



  • 14.  RE: Patch package not deploying

    Posted May 15, 2011 11:08 PM

    Is the issue:

    A) You have PCs missing MS10-046 (e.g. WSUS, windowsupdate.microsoft.com), but Altiris says they have MS10-046 already installed and are not vulnerable

    B) You have PCs with MS10-046 (e.g. WSUS shows as patched or windowsupdate.microsoft.com does not offer update), but Altiris says they need MS10-046

    C) Something else entirely?



  • 15.  RE: Patch package not deploying

    Posted May 16, 2011 02:51 PM

    No, I believe the issue is that reports show that the patch is only for two computers applicable. I think report pull the data wrong from the SQL database.



  • 16.  RE: Patch package not deploying

    Posted May 18, 2011 08:30 AM

    1. All the policies you have created for MS10-046 contain expected computers in their targets.

    2. All the expected computers have SWU Plug-in installed and of valid version (in case upgrade was performed).



  • 17.  RE: Patch package not deploying

    Posted May 19, 2011 02:50 PM

    Seems that these are all WinXP computers...are they on SP3?  Most of the patches from late last year will not apply unless the target PCs are on XP SP3 as XP SP2 support was dropped mid-summer I think (if not earlier).  If the patch requires XP SP3 (which it does) but the machine is on XP SP2, then they will not appear as applicable as they don't meet the system/OS-level requirements for the patch, even though they are technically vulnerable.

    This would actually be a nice improvement to Patch Management, to report machines as vulnerable due to down-level service packs, etc.