Windows IT Pro is the leading independent community for IT professionals deploying Microsoft Windows server and client applications and technologies.
  
  
  Advanced Search 


November 05, 2003

Windows 2003 SP1 and Windows XP SP2: Not Your Average Service Packs

RSS
Subscribe to Windows IT Pro | See More Windows OSs Articles Here | Reprints | Or get the Monthly Online Pass—only $5.95 a month!

Last week, Microsoft held its epic Microsoft Professional Developers Conference (PDC) 2003 in Los Angeles. PDC 2003 was a coming out party for Longhorn, the next Windows client OS, and introduced developers to upcoming technologies such as Longhorn, Visual Studio .NET (code-named Whidbey), Microsoft SQL Server (code-named Yukon), and a Microsoft.NET-based Web services infrastructure (code-named Indigo). Because many of these technologies are several months away at best, this week I want to discuss some of the more understated announcements and products Microsoft revealed last week that will more directly affect IT in the short term. Specifically, I'd like to discuss Windows XP Service Pack 2 (SP2) and Windows Server 2003 SP1.

XP SP2
In August, Microsoft found itself in a bit of controversy when it quietly revealed through a Web site posting that it was delaying XP SP2 from fall 2003 until mid-2004. XP SP1, you might recall, shipped in August 2002, or about 10 months after the initial XP release; this new schedule means SP2 will follow SP1 by a whopping 20 months or more. When you factor in all the security hotfixes and other critical updates that Microsoft has released since SP1, that's a long wait, and new installations of XP SP1 face an installation of more than 100MB of updates from Windows Update on first boot. That's unacceptable.

To partially alleviate this problem, Microsoft recently unveiled the Security Rollup Package 1 (SRP1) for XP, a collection of more than 20 post-SP1 security patches for XP rolled into one package that requires just one reboot. But this package doesn't explain the SP2 delays.

XP SP2, as you might recall, was supposed to include all the post-XP SP1 hotfixes and a new feature called "concurrent user sessions." This feature, designed primarily for Windows Powered Smart Display users, allows two concurrent logons on XP Professional Edition machines: one interactive and one remote. Sadly, the concurrent user sessions feature won't be part of XP2; instead, Microsoft will roll this functionality into the software that ships with the next version of Smart Displays, due in early 2004.

XP SP2 will include a bevy of new features, in addition to the aforementioned patches, most of which are designed to make XP more secure. For this reason, XP SP2 is suddenly a much more important release to businesses of all sizes.

First, XP SP2 will mark the first product to come out of Microsoft's new "secure by default" initiative. This means that the Windows Messaging service will be disabled by default, the Internet Connection Firewall (ICF) will be enabled by default, and users will be able to configure multiple profiles safely, with different settings for work and home. Some of these changes will require subtle modifications to the way XP works. For example, Microsoft will enable home network-based file sharing on systems with the firewall turned on. Likewise, the update will contain small changes that enable boot-time protection and smart UIs for configuring Group Policies and unattended setup.

With SP2 installed, XP systems will be better able to fend off common electronic attacks. For example, Microsoft is reducing vulnerabilities to Distributed COM (DCOM) and remote procedure call (RPC) attacks by requiring authentication on default interfaces, restricting RPC interfaces to just the local machine, and disabling RPC over UDP, among other actions. The company will issue new RPC APIs for developers that help take advantage of these changes. For email attacks, Microsoft is creating a system-level mechanism, originally slated for Longhorn, that applications can use to determine whether email attachments are unsafe; this mechanism, called the Attachment Execution Services (AES) API, defaults to not trusting most attachments, and the company will add support for the service to Microsoft Outlook and Outlook Express. For Web-based attacks, Microsoft is locking down the local machine and local intranet zones in Microsoft Internet Explorer (IE), changing the way ActiveX controls and other Web-based applications are installed, and suppressing all non-user-initiated pop-up ads.

At a lower level, XP SP2 will take advantage of new memory-protection features in AMD and Intel microprocessors to reduce common buffer-overrun exploits. This feature is available in most modern 32-bit and 64-bit microprocessors, Microsoft says.

Windows 2003 SP1
Looking ahead to late 2004, Microsoft is planning a similarly major and safety-oriented service pack for Windows 2003. Windows 2003 SP1 will include the roles-based Security Configuration Wizard, along with a slew of as-yet-unnamed protection features aimed at enterprises. Additionally, the company will include support for client network isolation so that Windows 2003 SP1 machines can prevent clients from accessing a corporate network until their security state is verified. A VPN Quarantine feature will let remote Windows clients safely access network features.

Unlike XP SP2, the feature set for Windows 2003 SP1 is still in flux, so we'll know more soon. In the meantime, both XP SP2 and Windows 2003 SP1 are being delivered well after their original release schedules, but they'll be far more secure as a result. Whether the wait is worth it, I suppose, is up to the individual. I'd rather see the company deliver regular security rollups, as it did recently with XP SRP1, for all of its supported OSs. In this increasingly dangerous world, we need simpler and less intrusive ways to keep our new and existing systems up-to-date, and these service packs, along with Microsoft's wide-reaching plans to simplify patch management, will go a long way toward fixing the problems.

End of Article



Reader Comments
It is a long wait for SP2, but sounds like it will be worth the wait. Most of the impatience for SP2 is due to the security patches for new installations though, as you said - and the inability to slipstream hotfixes as you can do with service packs. Reloading a system from home means you're vulnerable online until all those downloads complete - sometimes several hours. If they keep up with SRPs then they can afford to take more time with SPs - and thus avoid another NT4 SP2 or 6/6a!

Rich November 05, 2003


Is the VPN Quarantine feature you mention an enhancement to the existing VPN Quarantine that you can use with Windows 2003 Server and the resource kit tools? (rqs.exe and rqc.exe)

I have attempted to deploy the current VPN Quarantine and the two white papers that Microsoft has on it are in depth, yet they don't seem to cover detail in the places that need it the most (such as the registry setting for the version number) and also more examples of quarantine scripts. Additionally, there is really no one at PSS that has experience with this feature. When I called them they were not familiar with the Quarantine VPN service but they were good enough to track down some guys from OTG to assist me indirectly via the PSS rep. Our MS rep is eager to work with us though and get us in contact with the right group. Overall, I think it is an excellent feature. Something that us VPN administrators have been thinking about for a long time. It is nice to see it making an appearance, even if it is still in its infancy.

Brian November 05, 2003


I found this article very clear and a pleasure to read it.

with kind regards


hans straat November 07, 2003


This article - InstantDoc #40766 suggests that Win2K3 SP1 will be available "late 2004"

Another article, also written in November, also by Paul Thurrott - InstantDoc #40440 states "Microsoft's first service pack for Windows Server 2003, which is due in the first half of 2004"

Any idea which date is more accurate? This would be of great interest.

Thanks in advance.

Joseph January 09, 2004


update windows 2003 server

morteza January 17, 2004


windows server 2003 sp1

hhtan1996 March 04, 2004


I'm actually kind of surprised that they aren't putting out Windows 2003 as the upgraded XP. I've been running it as my desktop/gaming/development/server OS on my one and only machine since December 2002 (when it was still .net RC1) It does everything XP does, and already comes out more secure than XP. It just seems to me, that they are more worried about loosing sales of XP than pushing the better OS.

Just my opinion of course.

But it’s really good to hear they are actually coming out with a Service Pack for 2003. Any word if it will turn on a firewall by default?

Millsy March 17, 2004


I found this article very helpful, as well as Millsy comments.
Thanks to you all.

Stefan April 17, 2004


No, it will only turn the firewall on by default for new installations

Kesh

Anonymous User December 22, 2004


Here's a quick little site on creating a Windows 2003 Slipstreamed CD with multiple versions of windows 2003 on it.... Its changed from previous versions of windows because Microsoft has now made the boot loader detect when its been changed, and flag itself as corrupt...

http://kelxin.myftp.org

Anonymous User April 01, 2005 (Article Rating: )


You must be a registered user or online subscriber to comment on this article. Please log on before posting a comment. Are you a new visitor? Register now




Top Viewed ArticlesView all articles
Command Prompt Tricks

One reader shares his tip for setting up the command prompt to reflect a remote path. ...

WinInfo Short Takes: Week of November 9, 2009

An often irreverent look at some of the week's other news, including some more Windows 7 sales momentum, some Sophos stupidity, Microsoft's cloud computing self-loathing, more whining from the browser makers, Zoho's "Fake Office," and much, much more ...

Where is Microsoft NetMeeting in Windows XP?

...


Related Events WinConnections and Microsoft® Exchange Connections

Check out our list of Free Email Newsletters!

Windows OSs eBooks Understanding and Leveraging Code Signing Technologies

A Guide to Windows Certification and Public Keys

SQL Server Administration for Oracle DBAs

Related Windows OSs Resources Introducing Left-Brain.com, the online IT bookstore
Looking for books, CDs, toolkits, eBooks? Prime your mind at Left-Brain.com

Discover Windows IT Pro eLearning Series!
Clear & detailed technical information and helpful how-to's, all in our trademark no-nonsense format


Windows IT Pro Home Register FAQ for Windows WinInfo News
Europe Edition About Us Contact Us/Customer Service Media Kit Affiliates / Licensing  
SQL Server Magazine Office & SharePoint Pro DevProConnections IT Job Hound
Left-Brain.com Technology Resource Directory asp.netPRO ITTV Windows SuperSite 
 
 Windows IT Pro is a Division of Penton Media Inc.
 © 2009 Penton Media, Inc. Terms of Use | Privacy Statement