PATCH MANAGEMENT · ON-PREM · LINUX & WINDOWS

Centralized update management

LSUS — enterprise software update management (patch management) for Linux and Windows workstations and servers.

A single control point for mixed fleets: Astra Linux, RedOS, ALT, Debian, Ubuntu, AlmaLinux, CentOS Stream, and Windows — with flexible policies, pre-deployment testing, and air-gapped operation.

9 OS families
3-tier architecture
Air-gapped / Offline

Controlled rollout

Testing updates before mass deployment, testing → stable channels, checklists and iterations — minimizing the risk of widespread failures.

Works in any environment

From open networks to fully isolated (air-gapped) environments, including offline package import from ISO images.

Multi-tier delivery

Edge → Master → Site → clients: updates reach every machine without overloading links. Clients can connect to Master and Site simultaneously.

Security by default

HTTPS at all levels, RBAC access model (8 roles), LDAP and Kerberos integration, audit log of all actions.

Supported platforms

One fleet — many operating systems

LSUS covers typical enterprise and public-sector landscapes: domestic distributions, popular DEB/RPM families, and Windows. Each OS family gets its own policies, repositories, sources options, and an agent with a native package manager.

Domestic OS

Registry and import substitution

  • APTAstra Linux — OS policies, extended/main, LVM snapshots
  • DNFRedOS — os/updates repositories, DNF policies
  • RPMALT Linux — APT-RPM, classic repositories, OVAL X-SOFT

Global Linux

DEB and RPM ecosystems

  • APTDebian, Ubuntu, Kubuntu — main/updates/security, standard release lines
  • DNFAlmaLinux, CentOS Stream — BaseOS, AppStream, CRB
  • Edge mirrors, local repositories, and policies are tied to the OS family — one Master manages the entire fleet

Windows

Workstations and servers

  • .NET agent: scanning via Windows Update API and wsusscn2.cab (offline)
  • KB catalog, MSU packages, pending reboot, Windows update policies
  • KB approvals at host, group, and global level; install batches and campaigns

Three package backends — one update process

The Linux client automatically detects the distribution and applies updates via APT, DNF/YUM, or APT-RPM. Policies, hold lists, schedules, and reports work the same across all OS families.

APT (deb) DNF / YUM APT-RPM Windows Update
Platform capabilities

10 functional modules

LSUS solves a key challenge: how to keep the entire fleet updated on time and securely without losing control. Instead of manually updating each server and workstation — a single management point with flexible policies, testing, and smart package delivery.

1

Host management

  • Auto-registration via SRV DNS
  • Heartbeat and LDAP sync
  • Host groups and auto-assignment
  • Update reports
2

Update policies

  • 5 types: schedule, repo, hold, OS, client
  • Priorities and hierarchy (global → OS → group)
  • 4 sources.list management modes
  • Weekly schedule with installation windows
3

Repositories and delivery

  • 8 Linux families + Windows
  • APT, DNF/YUM, APT-RPM formats
  • Local and external repositories
  • Import updates from ISO images
  • testing → stable → archive channels
4

Change testing

  • Areas, teams, and iterations
  • Checklists and focus groups
  • Auto-create iterations from testing
  • Promote-to-stable decision + PDF records
5

OVAL and package analysis

  • 6 OVAL sources (Debian, RH, ALT, Ubuntu, SUSE, Oracle)
  • Package-to-CVE matching
  • Bulk host scanning
  • dpkg, rpm, and Windows platforms
6

USB management

  • Inventory (vendor/product/serial)
  • Device registration and requests
  • Connection event log
  • Access rules and blocking
7

Windows Updates (KB)

  • KB catalog and wsusscn2.cab
  • Approvals (host/group/global)
  • Campaigns and install batches
  • MSU replication and caching
8

Reports and analytics

  • Updates and hosts summary
  • Distribution by OS
  • Update history and compliance
  • Charts and visualization
9

Local repositories and ISO import

LSUS lets you create local repositories inside your organization and use them as trusted update sources. Supports direct package import from ISO images for fully isolated environments.

  • Creating local repositories for internal package distribution
  • Import packages and updates from ISO images (structure copy or extraction)
  • testing, stable, archive channels and controlled stage transitions
  • Unified management of repository content and versions within the organization
10

Edge, smart replication, and proxy caching

The platform optimizes update delivery to branch offices and protected network segments, reducing link load and speeding up package delivery to clients. Edge → Master → Site model; clients can work with Master and Site simultaneously.

  • Edge server for secure update publication through the DMZ
  • Smart replication of only required repositories and data to sites
  • Proxy caching to reuse already downloaded packages
  • Update distribution for branch offices and isolated segments
WHY CHOOSE LSUS

Key advantages

LSUS solves a key organizational challenge: how to keep a mixed Linux and Windows fleet updated on time and securely without losing control. The platform is designed for any network conditions — from open networks to fully isolated (air-gapped) environments, with domestic and global distributions from a single console.

Single management point

All updates, policies, repositories, and reports — in one web interface. Centralized control over the entire fleet without scattered tools.

Multi-tier architecture

Edge → Master → Site: flexible scaling from a single office to a distributed branch network. Clients can connect to Master and Site simultaneously for fault tolerance.

Air-gapped / Offline

Full operation in closed and internet-isolated environments. Import updates from ISO images, offline deployment via Docker.

Security by default

HTTPS at all levels, RBAC roles (viewer to admin), LDAP/Kerberos authentication, action audit log, and package signing.

Pre-deployment testing

testing/stable channels, testing iterations, checklists, and step-by-step verification. Minimizing the risk of widespread failures.

Smart replication and cache

Only required repositories are replicated. Proxy caching speeds up repeat package delivery and saves bandwidth.

ROSPATENT
Cert. No. 2026615730 dated 27.02.2026
10 modules
Hosts, policies, repos, testing, OVAL, USB, KB
9 OS families
Astra, RedOS, ALT, Debian, Ubuntu, AlmaLinux…
8 RBAC roles
From viewer to admin, flexible permissions
Flexible deployment
Docker, DEB/RPM, offline images
Solution architecture

Reliable multi-tier architecture

Multi-tier update delivery model: Edge (DMZ) downloads from the internet → Master manages policies → Site caches for branch offices → Clients receive updates. Clients can connect to Master and Site simultaneously.

1

Edge server (DMZ)

Perimeter server for downloading updates from the internet and securely publishing them to clients without direct access to the internal network. Antivirus scanning, APT/DNF mirrors.

2

Master server

Control center: policies, repository catalog, OVAL sources, users, and RBAC. Administrator web interface, API, reports. Clients can connect directly.

3

Site (Locations)

Local update cache, proxy caching, and smart replication of required repositories for branch offices. Reduces load on Master and network links. Clients can work with Master and Site simultaneously.

Technology stack

Python 3 & Flask
PostgreSQL 15
Docker / Podman
9 OS families
Debian (slim)
LDAP / Kerberos
Ready deployment scenarios
  • Docker Compose for quick start
  • DEB/RPM packages and Docker for all supported Linux
  • Offline installation in isolated environments
Client applications

Agents for any platform

Native agents for Linux (Astra, RedOS, ALT, Debian, Ubuntu, Kubuntu, AlmaLinux, CentOS Stream) and Windows. Each agent runs as a system service: registers the machine, receives policies, checks for updates, and applies them strictly on schedule.

lsus-client (Linux)

System service (systemd + D-Bus). Auto-registration, policies, and installation via APT, DNF/YUM, or APT-RPM — depending on the distribution. Dry-run, LVM snapshots (Astra), hold lists.

lsus-client (Windows)

Windows Service on .NET. Scanning via Windows Update API and wsusscn2.cab (offline), MSU package installation via WUSA. Pending reboot and agent auto-update support.

GUI client (Linux)

PyQt5 graphical shell. System tray icon, update scheduling window, notifications. Connects to the lsus-client service via D-Bus.

lsus-usb-control

USB event monitoring service on Linux hosts. Tracks connections via udev, creates access rules, sends events to the Master server.

OVAL sources

Public OVAL data sources

LSUS uses public security descriptions and helps match them against installed packages and available updates. Designed for analyzing package and update composition using open data.

The list shows well-known public OVAL sources. The specific set of connected sources is determined by operational policy, data availability, and compatibility with the distributions in use.
Interface gallery

System interface

Screenshots of Master, Site, and Edge web interfaces. Select a server, then a category. Click a card for full-screen view.

Frequently asked questions

About update management and LSUS

Brief answers for administrators and information security specialists

What is LSUS and why do you need an update management system?

LSUS (Linux System Update Server) is a Russian patch management platform. It centralizes checking, testing, and installing updates across Linux and Windows fleets: instead of manually visiting servers and workstations, the administrator sets policies, repositories, and schedules from the Master web console.

Which OS and package managers are supported?

Astra Linux, RedOS, ALT Linux, Debian, Ubuntu, Kubuntu, AlmaLinux, CentOS Stream, and Windows. The Linux agent works via APT, DNF/YUM, or APT-RPM; Windows uses a .NET agent with Windows Update API and offline KB catalog.

Can updates be managed in an isolated (air-gapped) network?

Yes. LSUS is built for On-Prem and closed environments: local repositories, ISO package import, Edge server in the DMZ, Site replication, offline wsusscn2.cab for Windows. Updates are delivered without direct client internet access.

How does LSUS differ from Zoho ManageEngine Endpoint Central?

Zoho Endpoint Central is a mature general-purpose UEM product (including macOS, mobile devices, and third-party app catalogs), focused on cloud and the international market. LSUS is a specialized patch management platform built for controlled updates in Russian enterprise and isolated environments.

Criterion Zoho ME Endpoint Central LSUS
Focus UEM + patch management Centralized OS and package update management
Russian stack No Native support for Astra, Red OS, ALT Linux
Offline / critical infrastructure Limited Key scenario: local repos, ISO, wsusscn2.cab
Pre-production testing Test & Approve, auto-approval Testing module: areas, teams, checklists, testing → stable
Architecture Central server + agents Master / Site / Edge for branch offices and DMZ + agents
Deployment On-prem and Cloud SaaS On-prem only (Docker / packages), full control

LSUS is stronger when the priority is controlled patch management in a Russian environment (mixed fleet, critical infrastructure, offline, distributed infrastructure, import substitution). In essence, LSUS is closer to WSUS/SCCM + local repositories + compliance, adapted for the Russian stack.

How is security and attack protection organized?

The platform uses HTTPS at all levels (agents, Site, Edge, Master). Console access is protected against brute-force (lockout after 5 attempts in 15 minutes); authentication via LDAP/LDAPS and Kerberos SSO is supported. A detailed role-based model (RBAC) and full action audit (log, REST API, export) are implemented. SIEM integration via API or external log forwarding (native syslog/CEF on the roadmap).

How are fault tolerance and remote clients ensured?

Fault tolerance is achieved through distributed architecture: when the Site server is unavailable, clients can automatically fail over to Master. Remote clients and NAC VLAN use an Edge server in the DMZ. If a client was disconnected, after connectivity returns the agent catches up on the update backlog in the next allowed installation window.

Is the product registered with Rospatent?

Yes. The computer program "LSUS (Linux System Update Server)" is registered with Rospatent, certificate No. 2026615730 dated 27.02.2026.

Contact us

Ready to deploy LSUS in your organization?

Contact us for demo access, deployment cost estimates, or technical consultation. We will run an online demo, answer your questions, and help choose a configuration for your needs.

Email us

info@lsus.ru

We respond within one business day

Call us

+7 995 437-14-87

Mon–Fri, 9:00–18:00 MSK

We provide demo access to a test environment, help with pilot deployment, and recommend an optimal architecture for your organization's infrastructure.