It seems there's at least one more step involved - some of the security updates have been superceded by ordinary updates, so the version information I extracted is not sufficient. I will have to use the security update list to grep the list of current updates. That "crank up the firewall" idea is sounding better and better. Dave