Windows IT Pro is the leading independent community for IT professionals deploying Microsoft Windows server and client applications and technologies.
  
  
  Advanced Search 


July 10, 2008

How to Avoid Exchange 2007 SP1 Rollup Installation Problems

RSS
Subscribe to Windows IT Pro | See More Hotfixes Articles Here | Reprints | Or get the Monthly Online Pass—only $5.95 a month!

To make it easier to keep your Microsoft Exchange Server software up to date, Microsoft regularly issues rollup releases that combine all of the hotfixes that are currently available for your Exchange version, including those from previous rollups. Update Rollup 3 (UR3) for Exchange Server 2007 Service Pack 1 was released on July 8, 2008. (If you're running Exchange 2007 RTM, your latest update is Update Rollup 7 for Exchange Server 2007.) It's generally a good idea to follow the installation of a service pack by installing the latest rollup so that your server is running the most current software. But sometimes the best laid plans go a tad amiss, and that’s the situation with UR3 and its predecessor, UR2. Here’s why.

UR3 and UR2 contain some Microsoft .NET Framework 2.0 managed assemblies that Microsoft applied a digital signature to using Authenticode. During the installation of these rollups, Windows attempts to validate that the key used to apply the digital signature to the assemblies is valid to ensure that you don’t load code that someone might have compromised in any way onto a server. During the validation process, the installation procedure attempts to make a connection to a certificate revocation list (CRL) at crl.microsoft.com/pki/crl/products/CSPCA.crl. If the installation procedure can’t access this site, it experiences a timeout that eventually passes—or it might cause the installation to fail. During a recent upgrade of fifteen Exchange 2007 servers to SP1 UR2 that I witnessed, the delay ranged from 40 minutes to an hour and the installation failed completely on two of the fifteen servers. This failure is painful because the only indication that anything bad has occurred is the fact that the Microsoft Exchange Service Host service isn't running.

The root cause of the problem is that many companies don't allow Exchange servers, especially those running the Mailbox or Client Access roles, to have direct access to the Internet: Those servers will never be able to connect to crl.microsoft.com to perform the check that the rollup installation procedure wants to perform. The solution is to make sure that your firewall lets your servers make a connection to crl.microsoft.com.

If this solution isn’t possible or is undesirable in your environment, the fastest workaround is to create an entry that points crl.microsoft.com to 127.0.0.1 in the local hosts file of the server before commencing the upgrade. This method forces a local lookup that quickly fails and lets the installation complete. It’s reasonably safe to assume that the key used by Microsoft to sign the managed code assemblies is valid, so it should be safe to use this hack. Microsoft offers some other advice and explains the background to the problem in the articles "Exchange 2007 managed code services do not start after you install an update rollup for Exchange 2007" and "FIX: A .NET Framework 2.0 managed application that has an Authenticode signature takes longer than usual to start."

Apart from being a real pain to manually update a hosts file just so a server can install a set of patches, this problem highlights an issue that Microsoft needs to solve: Its scheme of validating the keys used to sign managed code assemblies can't work if it requires servers to check a particular Internet location that might be blocked or otherwise inaccessible. The word from the Exchange engineering group is that they're considering how best to disable the validation for future rollups, but for now the best idea is to make the change in your hosts file (through gritted teeth) before proceeding to install UR3.

End of Article



Reader Comments

You must be a registered user or online subscriber to comment on this article. Please log on before posting a comment. Are you a new visitor? Register now




Top Viewed ArticlesView all articles
Microsoft, News Corp. Discuss Locking Out Google

Microsoft and Rupert Murdoch's News Corp. recently discussed an alliance that would counter Google's fledgling online news service. ...

2009 Windows IT Pro Editors' Best and Community Choice Awards

Picking a favorite product from an impressive crowd of competitive offerings is never an easy task, and such was the case with our Editors' Best and Community Choice awards this year. ...

Command Prompt Tricks

One reader shares his tip for setting up the command prompt to reflect a remote path. ...


Related Articles Exchange Server News: Rollup Roundup

Top 12 Features of Exchange Server 2007 SP1

The Role of Exchange Server Rollups

Upgrading to Exchange 2007 SP1

Exchange Server and Outlook Whitepapers Email Controls and Regulatory Compliance

Take Control of Your Email: Understand the Business Reasons for Email Storage Management

Related Events Bail Out Your Exchange Environment

Check out our list of Free Email Newsletters!

Exchange Server and Outlook eBooks Spam Fighting and Email Security for the 21st Century

Understanding and Leveraging Code Signing Technologies

The Expert's Guide for Exchange 2003: Preparing for, Moving to, and Supporting Exchange Server 2003

Related Exchange Server and Outlook Resources Introducing Left-Brain.com, the online IT bookstore
Looking for books, CDs, toolkits, eBooks? Prime your mind at Left-Brain.com

Discover Windows IT Pro eLearning Series!
Clear & detailed technical information and helpful how-to's, all in our trademark no-nonsense format

Exchange & Outlook UPDATE eNewsletter
News, strategies, products, and developments in Exchange Server and Outlook messaging.

Windows IT Pro Home Register FAQ for Windows WinInfo News
Europe Edition About Us Contact Us/Customer Service Media Kit Affiliates / Licensing  
SQL Server Magazine Office & SharePoint Pro DevProConnections IT Job Hound
Left-Brain.com Technology Resource Directory asp.netPRO ITTV Windows SuperSite 
 
 Windows IT Pro is a Division of Penton Media Inc.
 © 2009 Penton Media, Inc. Terms of Use | Privacy Statement