Why isn’t SQL Server included in Windows Critical Update notifications? Many of our readers noted that they are part-time DBAs and simply don’t have the time to stay up-to-date on what patches and service packs should be applied to all the software that runs on their servers. What are the technical and practical implications of including SQL Server in Windows Critical Updates, and are there plans to do so?
The Microsoft Trustworthy Computing team, led by Mike Nash, has patch management as a top priority. WU is a great method for Windows, but there may be better ways to deliver updates for multiple products. The Trustworthy Computing team is looking at the best way to implement updates through a single system.
We certainly want to give customers more-effective tools to monitor and lock down their servers from a security perspective. We see the latest version of the tools we released as part of our SQL Critical Update Kit to be a first step toward achieving this goal. Currently, we’re gathering customer feedback about how we can improve these tools going forward and plan to add functionality to these tools to make them as effective as possible.
Part of this process is also education, and we’re updating existing white papers to focus more on security best practices. We’ll also continue to invest in and grow MBSA to include more SQL Server-specific vulnerability checks.
How does MBSA and the SQL Critical Update Kit tools work together?
We recommend running MBSA 1.1 to analyze potential vulnerabilities in your systems, then use SQL Scan to look for the particular vulnerabilities inside your environment. Version 1.1 is the second release of MBSA and includes a graphical and a command-line interface that can perform local or remote scans of Windows systems. MBSA runs on Windows 2000 and Windows XP systems and will scan for common system misconfigurations and missing security updates in SQL Server 2000 and 7.0 and other Microsoft products. If MBSA finds a vulnerability, it points you to the proper patch to download. In contrast, the SQL Update tools actually go and apply the patch that protects against Slammer. Customers interested in finding out more about MBSA can visit http://www.microsoft.com/technet/security/tools/tools/mbsahome.asp.
We developed the SQL Critical Update Kit tools because we needed to quickly develop specific tools to help SQL Server customers understand what’s going on in their environment. But as I noted earlier, our long-term goal is to bring all these tools together under the MBSA umbrella and offer customers a single tool that scans for all products in their infrastructure.
Slammer affected a large number of MSDE installations. How can Microsoft help people stay up-to-date with patches when many applications install MSDE by default and administrators might not even be aware that MSDE is on the box? What has Slammer taught Microsoft about the advisability of installing a product like MSDE by default without notification?
We’re working on a more simple patch application specifically for MSDE that would let users patch MSDE from a GUI application. We still believe that MSDE is important as a light data store, and we’ll continue to make it better, more secure, and easier to patch and administer.
As I mentioned earlier, we’re looking to improve our SQL Scan and SQL Check tools as well as other tools to detect SQL Server instances including MSDE. We’re also working closely with MSDE partners to ensure that they follow recommended procedures of minimalist installation and secure defaults and to make sure that MSDE is installed only when absolutely needed and through customer choice. In addition, we’re working to better document applications that install MSDE and working to better highlight in those applications’ documentation that they install MSDE. Our goal is to be very explicit with the installation of MSDE going forward, not only in posting on our Web site which applications use MSDE but making end users aware that they are about to install MSDE as part of their application.
Prev. page
1
2
[3]
4
5
next page