Windows IT Pro is the authoritative and independent resource for windows nt, windows 2000, windows 2003, windows xp. Features a collection of resources and magazines for windows IT professionals.
  
  
  Advanced Search 


July 10, 2008

How to Avoid Exchange 2007 SP1 Rollup Installation Problems

RSS
Subscribe to Windows IT Pro | See More Hotfixes Articles Here | Reprints | Or get the Monthly Online Pass—only $5.95 a month!

To make it easier to keep your Microsoft Exchange Server software up to date, Microsoft regularly issues rollup releases that combine all of the hotfixes that are currently available for your Exchange version, including those from previous rollups. Update Rollup 3 (UR3) for Exchange Server 2007 Service Pack 1 was released on July 8, 2008. (If you're running Exchange 2007 RTM, your latest update is Update Rollup 7 for Exchange Server 2007.) It's generally a good idea to follow the installation of a service pack by installing the latest rollup so that your server is running the most current software. But sometimes the best laid plans go a tad amiss, and that’s the situation with UR3 and its predecessor, UR2. Here’s why.

UR3 and UR2 contain some Microsoft .NET Framework 2.0 managed assemblies that Microsoft applied a digital signature to using Authenticode. During the installation of these rollups, Windows attempts to validate that the key used to apply the digital signature to the assemblies is valid to ensure that you don’t load code that someone might have compromised in any way onto a server. During the validation process, the installation procedure attempts to make a connection to a certificate revocation list (CRL) at crl.microsoft.com/pki/crl/products/CSPCA.crl. If the installation procedure can’t access this site, it experiences a timeout that eventually passes—or it might cause the installation to fail. During a recent upgrade of fifteen Exchange 2007 servers to SP1 UR2 that I witnessed, the delay ranged from 40 minutes to an hour and the installation failed completely on two of the fifteen servers. This failure is painful because the only indication that anything bad has occurred is the fact that the Microsoft Exchange Service Host service isn't running.

The root cause of the problem is that many companies don't allow Exchange servers, especially those running the Mailbox or Client Access roles, to have direct access to the Internet: Those servers will never be able to connect to crl.microsoft.com to perform the check that the rollup installation procedure wants to perform. The solution is to make sure that your firewall lets your servers make a connection to crl.microsoft.com.

If this solution isn’t possible or is undesirable in your environment, the fastest workaround is to create an entry that points crl.microsoft.com to 127.0.0.1 in the local hosts file of the server before commencing the upgrade. This method forces a local lookup that quickly fails and lets the installation complete. It’s reasonably safe to assume that the key used by Microsoft to sign the managed code assemblies is valid, so it should be safe to use this hack. Microsoft offers some other advice and explains the background to the problem in the articles "Exchange 2007 managed code services do not start after you install an update rollup for Exchange 2007" and "FIX: A .NET Framework 2.0 managed application that has an Authenticode signature takes longer than usual to start."

Apart from being a real pain to manually update a hosts file just so a server can install a set of patches, this problem highlights an issue that Microsoft needs to solve: Its scheme of validating the keys used to sign managed code assemblies can't work if it requires servers to check a particular Internet location that might be blocked or otherwise inaccessible. The word from the Exchange engineering group is that they're considering how best to disable the validation for future rollups, but for now the best idea is to make the change in your hosts file (through gritted teeth) before proceeding to install UR3.

End of Article



Reader Comments

You must log on before posting a comment.

If you don't have a username & password, please register now.




Top Viewed ArticlesView all articles
Command Prompt Tricks

One reader shares his tip for setting up the command prompt to reflect a remote path. ...

How can I stop and start services from the command line?

...

Where is Microsoft NetMeeting in Windows XP?

...


Related Articles Exchange Server News: Rollup Roundup

Top 12 Features of Exchange Server 2007 SP1

The Role of Exchange Server Rollups

Upgrading to Exchange 2007 SP1

Exchange Server and Outlook Whitepapers Protecting (You and) Your Data with Exchange Server 2007

StoreVault SnapManagers for Microsoft Exchange and SQL Server

Related Events Storage Consolidation for Your Microsoft Applications: Reducing Cost and Complexity

The Myths & Truths of Email Management with SharePoint

Top 10 Email Security Challenges and Solutions

Check out our list of Free Email Newsletters!

Exchange Server and Outlook eBooks Spam Fighting and Email Security for the 21st Century

Understanding and Leveraging Code Signing Technologies

The Expert's Guide for Exchange 2003: Preparing for, Moving to, and Supporting Exchange Server 2003

Related Exchange Server and Outlook Resources Become a VIP member of the Windows IT Pro community!
Get it all with the VIP CD and VIP access. A $500+ value for only $279!

Subscribe to Windows IT Pro!
Solve your toughest technical problems with our experts and access 10,000 + articles online. 30% off

Monthly Online Pass - Only $5.95!
Get instant access to 10,000+ articles from Windows IT Pro Magazine!

TechNet Virtual Labs
Evaluate and test Microsoft's newest products.

Exchange & Outlook UPDATE eNewsletter
News, strategies, products, and developments in Exchange Server and Outlook messaging.

Windows IT Pro Home Register FAQ for Windows WinInfo News
Europe Edition About Us Contact Us/Customer Service Media Kit Affiliates / Licensing  
SQL Server Magazine Office & SharePoint Pro Windows Dev Pro IT Job Hound ITTV
IT Library Technology Resource Directory Connected Home Windows Excavator Windows SuperSite 
 
 Windows IT Pro is a Division of Penton Media Inc.
 Copyright © 2008 Penton Media, Inc., All rights reserved. Terms and Use | Privacy Statement | Reprints and Licensing