It would be great if we could include the latest "best practices" registry patch to schannel for Cipher Suites from Nartac IISCrypto
https://www.tenable.com/plugins/nessus/42873...
ntlite dev team:
What do you think about my original sequence-of-events question?:
If NTLite applies CU KBs before adding components, and those components fail to receive updates from the CU, would that be considered a bug or a Caveat/Errata?
Additionally, just for hypothetical discussion...
I've yet to successfully integrate KB4052623 ; It just silently fails to run.
Need to debug parse CBS.log etc., see what is causing failure.
And obviously, it cannot be merged via NTLite, as its an .exe and not .msi.
Found it:
Removing WinNAT will break WinSvr2016 v1607 Cumulative Update.
Remove removing it, everything builds fine.
The hint here was HyperV; and a shot-in-the-dark-guess (HyperV relies on WinNAT for NAT Mode networking)
<RemoveComponents>
<!-- <c>winnat 'Windows NAT...
Hi all. Something else in my Preset is causing the problem with CU rollback on first boot.
( Something other than DotNet3.5 feature addition/activation.)
If I run the two-step process:
1) Load the image and add DotNet3.5, save close
2) Strip my preset down to <updates> section only, apply...
Hi all: A quick update. I've been trying to get you test results on this to determine if I've found a bug in NTLite or not.
I'm now building my WinSvr2016 Image in two phases ( as described above ).
However, the resulting images, built with either of the most recent Svr2106/v1607 cumulative...
A quick status update before C.O.B. (Manual testing in VMWare env finished faster than I expected):
I dont have this problem if I build/patch manually:
-> Add DotNet3.5 Manually (dism/windows server mgr)
-> kb5001402 - SSU - Latest
-> kb5005043 - CU - Latest (The DLLs Nessus wants are patched...
All:
I've been chasing down some vulnerabilities found by Nessus scans of my NTLite resultant image.
Nessus Plugins 139598 & 138464 keep firing, complaining that the version of "system.web.dll" in [C:\windows\microsoft.net\platform\v2.xxx\] is not patched, and the remediation recommendation...
I can see now that Microsoft is in the process of releasing cumulative updates for August.
The official announcement is not there, but I an see they're uploading them to the catalog server index now.
So this may be resolved soon...
Has anyone else had difficulty integrating KB5005394 (or the equivalent for non-1809 builds?)
This is:
KB5005394 July 27, 2021—KB5005394 (OS Build 17763.2091) Out-of-band ---- NOTE: This is the final hotfix for PrintNightmare
Even if I just run with KB5004422 (Latest SSU for 1809) and...
Hi all.
I'm trying to integrate FTDI v2.12.28 (direct from FTDIChip.com).
It fails during integration of both the main image, and the WinRE image, with error 0x80070002.
Exact same files work fine on a system built w/o the integration, but installed manually.
Moreover, FTDIPort.inf/cat loads...
I'm seeing this for KB5005394 (The latest out-of-band Cumulative Update for LTSC/1809, the one that finally addresses PrintNightmare correctly)
Any ideas how to debug?
It would be nice to automatically build a crypto checksum for ISO files; encouraging best practices on redistribution for security conscious environments.
Right, if I didn't have a work-around, I'm beginning to think that, strategically, its better to handle drivers (and firmware) as a series of post-install scripts.
For offline/air-gapped environments, without WSUS or Windows Update, its 50/50 where to do it.
I'm thinking to write a series of...
Setup; I'm deleting PE per the previous threads.
FYI I'm observing this in NT Lite Version [v2.0.0.7797]
With v1809 LTSC Ent 64bit environment, and winsvr 2018/entLTSC v1809 target OS (as per XLS)
This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
By continuing to use this site, you are consenting to our use of cookies.