I'm looking into implementing WSUS on the office's sole domain controller (Win Server 2003, R2). A buddy told me, however, that -
1) The associated IIS activation creates security vulnerabilities on the server.
2) The vulnerabilities are associated with the lack of local user accounts on the a domain controller.
3) WSUS (and IIS) should not be installed on a domain controller.
What are the security issues associated with the lack of local user accounts and IIS? Are they surmountable? Or, should WSUS be installed on a separate server (for which, I have no money.)
Start Free Trial