I'm looking for feedback on the best way to handle deploying software that is also patched via KACE.

 

Example of patching issue:

A new workstation 'PC1' has the 'SOE - Standard' label added.

A distribution package for 'Mozilla Firefox 45.0.2 ESR' exists and has the 'SOE - Standard' label associated to it.

'Mozilla Firefox 45.0.2 ESR' is deployed to 'PC1' as it has the 'SOE - Standard' label associated to it.

The following day 'PC1' has Firefox update to 'Mozilla Firefox 45.1.0 ESR' due to KACE patching.

Next time 'PC1' is inventoried it detects 'Mozilla Firefox 45.0.2 ESR' is missing and re-installs the older version.

*Repeat cycle of patching and downgrading*



So to combat this I have a smart label assigned to the distribution package  'Mozilla Firefox 45.0.2 ESR':



Device Smart Label: Distribution - Firefox 45

Label Names = SOE - Standard AND

Software Titles does not contain 'Mozilla Firefox 45' OR

Label Names = 'Software - Mozilla Firefox 45' AND

Software Titles does not contain 'Mozilla Firefox 45'



If the PC then has the the label (SOE - Standard or Software - Mozilla Firefox 45 ) AND does not have a version of Firefox 45 already installed then the label will apply and the software will install otherwise it will not apply and patches are then handled by KACE without issue.



Is this the best way or handling this? KACE labels are not the most user friendly.

 

Cheers.

 

0 Comments   [ + ] Show Comments

Comments

Please log in to comment

Answers

2
Yes, this can be an issue when combining the two things. Your approach is pretty good. Another option that people have implemented is creating a smart label that gets applied to new computers and the managed installs are targeted at that label. Once machines are more than one or two days old they fall out of the new computer label and the K1000 no longer attempts to install software titles.

Another option is to be more aggressive about keeping your managed installs up to date. That way the most current version is being installed initially and patching doesn't come into play. That takes a fair amount of time, however.

Answered 05/23/2016 by: chucksteel
Red Belt

Please log in to comment
Answer this question or Comment on this question for clarity

Share