Windows IT Pro is the authoritative and independent resource for windows nt, windows 2000, windows 2003, windows xp. Features a collection of resources and magazines for windows IT professionals.
  
  
  Advanced Search 


May 2005

SP1 RC2 Passes the Test

Network engineer Peter Chang gives the final Windows Server 2003 SP1 beta an A-
RSS
Subscribe to Windows IT Pro | See More Clustering and Load Balancing Articles Here | Reprints | Or get the Monthly Online Pass—only $5.95 a month!
Main Article    Microsoft Talks About Windows Server 2003 SP1

Many sites tried out Windows Server 2003 Service Pack 1 (SP1) in beta prior to SP1's release in late March. Early this year, Peter Chang, network systems engineer for the City of Redmond, Washington, installed Windows 2003 SP1 Release Candidate 2 (RC2), the final SP1 beta, on 10 servers in the city's 36-server network. In a recent conversation with Windows IT Pro senior editor Anne Grubb, Peter shared his thoughts about the city's experience installing and running SP1 RC2. Here are the highlights.

No-Surprises Installation
Peter and the network services staff installed SP1 RC2 on various file and print servers and other machines, including domain controllers (DCs) running Remote Authentication Dial-In User Service (RADIUS), DNS, DHCP, and WINS; a Windows Media Server system; several Microsoft Internet Information Services (IIS) 6.0 Web servers, and a system running Microsoft Systems Management Server 2003 (SMS 2003). Upgrading each dual-processor Pentium 3 and 4 server to SP1 RC2 took 15 to 20 minutes (excluding installing and running the Security Configuration Wizard—SCW—component). Peter says that the SP1 upgrade was significantly faster than upgrading a client system to Windows XP SP2. "We didn't have to add anything to our servers [e.g., disk, memory], and we didn't see any additional load placed on our servers as a result of the service pack upgrade."

Security Configuration Wizard Rocks!
Peter praises SP1's new Security Configuration Wizard (SCW), which is installed separately from the OS upgrade. As part of its security-configuration tasks, SCW identifies all the services that are running on a Windows 2003 server and lets you shut off individual services that you don't need. "You need to make sure that all the applications and services provided by the server are up and running at the time you run SCW," Peter says. "As long as they're running when you run SCW, it does a pretty good job of identifying open ports, open executables, services that are listening for requests, and so on, which makes my job a lot easier."

According to Peter, SCW is a boon for network administrators. "It's much easier to use than Security Configuration Editor (SCE)," he says. "What's great about SCW is that it helps you identify services that aren't required, which until now has been kind of a hit-or-miss undertaking. SCW checks service dependencies and tells you whether anything (e.g., an application or service) is dependent on this service, or whether the service is dependent on anything else," says Peter.

If you need more information about a particular service, you can find it in SCW's built-in knowledge base, an XML file that contains descriptions of the various services. "Because the knowledge base is in XML format, it's extendable, so we can customize it for the third-party applications we use," Peter says.

Another SCW plus is that you can use it to preconfigure services and even Windows Firewall on a Windows 2003 server. "SCW does a good job of analyzing what's currently running on the machine," says Peter. Administrators, he says, can use this knowledge to decide what services should run on a server and then configure the server accordingly via SCW, instead of using a security template or Group Policy Objects (GPOs) to set policies. "I'd like to see Microsoft offer this capability on the client side as well."

Performance Boost
Running SCW provided an unexpected performance benefit for several of the SP1 servers. "We found that, in some cases, memory and CPU utilization actually went down because we were shutting off so many unnecessary services," says Peter, who was able to stop five to 10 services on the various test servers. "Now, granted, because these are built-in services, you don't save a whole lot. But the point is, you save, and when you're trying to squeeze out as much performance as possible from your servers, that's definitely a plus," he says.

A Few "Gotchas"
Peter and his staff encountered several less-welcome surprises from the upgrade, although these gotchas were fairly easy to resolve. "Before the upgrade, we were distributing XP SP2 Windows Firewall settings via our default domain policy," says Peter. However, after IT had installed Windows 2003 SP1 on the first server and turned on the firewall on the server, something strange happened. "The first server that we put the firewall on sucked in all the firewall settings from Group Policy, which automatically blocked the server! It was available for remote administration, but all the services it provided were gone." he says. It turns out that a configured GPO setting related to remote administration was effectively blocking services for the rest of the network. At the time the GPO was configured, IT didn't anticipate adding a Windows-server­based firewall. Solving the problem simply required creating separate firewall settings for servers through a different GPO.

The second gotcha is really more of a constraint imposed by SP1 security. As you might expect, you can roll back any setting that you configure through SCW. However, says Peter, "If you export a configuration so it can be pushed out through Group Policy, you can't automatically roll back to a previous configuration setting."

Finally, Peter discovered an SMS-specific gotcha: SP1 makes changes to Distributed COM (DCOM), such as creating a new local DCOM group on the SMS server. "When we deployed SP1 to our SMS 2003 server, the SMS Administration Console could no longer connect to the server because the SMS administrators hadn't yet been added to the newly created local Distributed COM Users group," he says. "Other applications might also be affected, but we haven't found any yet. We're looking at the new DCOM security settings because they might affect new and existing applications."

Wish List
Of course, there are a few features that Peter would like to see in the SP1 release. "We're hoping that File Replication Service (FRS) version 2 will be an improvement over FRS version 1," he says. He especially would like Microsoft to add support for print services to FRS and Dfs. He also hopes that the new GPO wireless-networking settings in SP1 will make it easier for the city to provide secure wireless services to its employees.

Overall, Peter and the IT staff are satisfied with the improvements they've seen in SP1 and look forward to the final release. "There's a lot of nice new functionality, especially securitywise," he says. "The gotchas are basically the result of improved security, and we can live with that."

End of Article



Reader Comments

You must log on before posting a comment.

If you don't have a username & password, please register now.




Top Viewed ArticlesView all articles
VMware and the Future of Virtualization

What's next for virtualization and business IT? Windows IT Pro senior editor Jeff James speaks with VMware President and CEO Diane Greene on the future of virtualization technology. ...

WinInfo Short Takes: Week of September 8, 2008

An often irreverent look at some of the week's other news, including the long-awaited back to school season, Microsoft's first Seinfeld/Gates ad, some EU insights, another Netbook improvement, Opera silliness, and much, much more ...

The Memory-Optimization Hoax

Don't believe the hype. At best, RAM optimizers have no effect. At worst, they seriously degrade performance. ...


Windows OSs Whitepapers Why SaaS is the Right Solution for Log Management

Are You Satisfied?

A Preliminary Look at Deployment Plans for Microsoft Windows Vista

Related Events Check out our list of Free Email Newsletters!

Windows OSs eBooks Understanding and Leveraging Code Signing Technologies

A Guide to Windows Certification and Public Keys

SQL Server Administration for Oracle DBAs

Related Windows OSs Resources Become a VIP member of the Windows IT Pro community!
Get it all with the VIP CD and VIP access. A $500+ value for only $279!

Subscribe to Windows IT Pro!
Solve your toughest technical problems with our experts and access 10,000 + articles online. 30% off

Monthly Online Pass - Only $5.95!
Get instant access to 10,000+ articles from Windows IT Pro Magazine!

TechNet Virtual Labs
Evaluate and test Microsoft's newest products.

Job Openings in IT


ADS BY GOOGLE SPONSORED LINKS FEATURED LINKS

IT Connections
Dive into the new Microsoft platforms and products you implement and support with the experts from Microsoft, TechNet Magazine, Windows ITPro and industry gurus. There are 70+ sessions and interactive panels with networking opportunities.

Attention User Group Leaders...
Announcing the eNews Generator—a FREE HTML e-newsletter builder for user group leaders. Build your HTML and text e-newsletters in minutes and add Windows IT Pro & SQL Server Mag articles alongside your own message!.

Master SharePoint with 3 eLearning Seminars
Learn how to build a better SharePoint infrastructure and enable powerful collaboration with MVPs Dan Holme and Michael Noel. Register today!

Get SQL Server 2008 at WinConnections
Don’t miss Microsoft Exchange and Windows Connections conferences, the premier events for Microsoft IT Professionals in Las Vegas, November 10-13. Every attendee will receive a copy of SQL Server 2008 Standard Edition with one CAL.



Interested in Email Encryption?
Read about the advantages of identity-based encryption in this free report.

Order Your SQL Fundamentals CD Today!
Learn how to use SQL Server, understand Office integration techniques and dive into the essentials of SQL Express and Visual Basic with this free SQL Fundamentals CD.

Virtualization Congress Oct. 14-16 in London
Don't miss Virtualization Congress, the premiere EMEA conference dedicated to hardware, OS and application virtualization. Oct. 14-16.
Windows IT Pro Home Register FAQ for Windows WinInfo News
Europe Edition About Us Contact Us/Customer Service Media Kit Affiliates / Licensing  
SQL Server Magazine Office & SharePoint Pro Windows Dev Pro IT Job Hound ITTV
IT Library Technical Resources Directory Connected Home Windows Excavator Windows SuperSite 
 
 Windows IT Pro is a Division of Penton Media Inc.
 Copyright © 2008 Penton Media, Inc., All rights reserved. Terms and Use | Privacy Statement | Reprints and Licensing