Quantcast
Channel: WSUS forum
Viewing all 12874 articles
Browse latest View live

IE 11 is not installing via WSUS

$
0
0

Hi,

Some time ago, when I deployed WSUS server, I also imported IE 11 (+updates) via Update Catalog - it was working flawlessly. From yesterday IE doesn't update to v11 on new computers. I guess it's MS14-035 critical update is blocking our IE 11 installation, but I've also imported the newest IE updates from update catalog.

Any solution for this problem?


WSUS Fails to complete post-installation tasks

$
0
0

When trying to complete the post-installation tasks Windows Server Update Services 4.0 (Windows Server 2012 Role) cannot seem to complete them. This is a member server with Default Roles, WDS, NAP, IIS, and (attempting) WSUS. It is intended to be a Network Management Server.

I get a variety of errors and it appears to be related to the attempt to sync with the Windows Update server on the Internet. I also see an error indicating it does not have permissions to the %Install Directory%\Update Services folder. I looked at the security permissions and the folder I designated to use for the update cache had my account and CREATOR/OWNER permissions invisible on the main tab. Going into advanced, I was able to see permissions and grant full control to that directory.

The 'Update Services' directory was owned by Trusted Installer and I observed the same condition with the permissions invisible in the main dialog and visible in the advanced dialog. I was unable to modify those since I was not the owner.

I have uninstalled the Role Service and Re-installed, with the same results. I did the same thing again but deleted all the folders I could find used by the Service, and no help there either.

When I attempt the post-installation tasks my error logs come up blank now? There are some things recorded in the event logs too if anyone wants to see them. Here is one of the error logs from an early attempt at this Role Install:

2013-02-05 15:54:59  Setting WSUSService to autostart...
2013-02-05 15:54:59  WSUSService is set to autostart.
2013-02-05 15:54:59  Starting WSUSService...
2013-02-05 15:54:59  WSUSService is now started.
2013-02-05 15:54:59  Importing default detectoids.
2013-02-05 15:54:59  Importing CriticalUpdates.xml...
2013-02-05 15:57:29  ImportDefaultDetectoids failed. Exception: System.Data.SqlClient.SqlException (0x80131904): Timeout expired.  The timeout period elapsed prior to completion of the operation or the server is not responding.
Warning: The join order has been enforced because a local join hint is used. ---> System.ComponentModel.Win32Exception (0x80004005): The wait operation timed out
   at Microsoft.UpdateServices.DatabaseAccess.DBConnection.DrainObsoleteConnections(SqlException e)
   at Microsoft.UpdateServices.DatabaseAccess.DBConnection.ExecuteCommandNoResult()
   at Microsoft.UpdateServices.Internal.DatabaseAccess.CommonDataAccess.ExecuteSPImportUpdate(Int32 upstreamServerLocalId, String xmlUpdateBlob, Byte[] xmlUpdateBlobCompressed, Int32& localRevisionId)
   at Microsoft.UpdateServices.Internal.DatabaseAccess.CommonDataAccess.ImportUpdate(Int32 ussRevLocalId, String xmlUpdateBlob, Byte[] xmlUpdateBlobCompressed, String xmlSdpBlob, Int32& localRevisionId)
   at Microsoft.UpdateServices.Internal.DatabaseAccess.CommonDataAccess.ImportUpdate(Int32 ussRevLocalId, String xmlUpdateBlob, Byte[] xmlUpdateBlobCompressed)
   at Microsoft.UpdateServices.Setup.StartServer.StartServer.ImportDefaultDetectoids()
ClientConnectionId:8cfc8c46-eba0-4c41-bb2a-6930f8e68ece
2013-02-05 15:57:29  StartServer encountered errors. Exception=Timeout expired.  The timeout period elapsed prior to completion of the operation or the server is not responding.
Warning: The join order has been enforced because a local join hint is used.
2013-02-05 15:57:29  Microsoft.UpdateServices.Administration.CommandException: Failed to start and configure the WSUS service
   at Microsoft.UpdateServices.Administration.PostInstall.Run()
   at Microsoft.UpdateServices.Administration.PostInstall.Execute(String[] arguments)

Why WSUS cann't download Microsoft® SQL Server® 2008 R2 Service Pack 2?

$
0
0
Why WSUS cann't download Microsoft® SQL Server® 2008 R2 Service Pack 2? 
Search here :catalog.update.microsoft.com/v7/site/Search.aspx?q=KB2630458,no this patch,please help me,thanks a lot!

Scheduling Windows Updates once a month

$
0
0

Any way to schedule updates once a month?

Options are only to do once a week


Eimis

wuauserv service not operational

$
0
0

Hi,

I have a problem of clients not reporting to WSUS Server. As a solution received from u guys, i had to stop wuauserv, then remove the update entires in the registries and start the wuauserv. But i cannot stop the wuauserv. Also i was given a solution to run PSEXEC but it has to be run from the WSUS server itself ?

Waiting for your expert solution.  I am facing many issue since i have started the WSUS server. out of 419 systems, only 16 are upto date. Pl guide

Naeem Qureshi


Naeem Qureshi TPL Surat


WSUS issues

$
0
0

Hey there!

I'm configuring a WSUS server for our business and I've run into some problems.

The WSUS server is set up on a standalone server, apart from the domain controller.

On the domain controller I've used the GP manager to direct the user groups that we need to have updated to the WSUS server (specify intranet Microsoft update service location) and I've configured Automatic updates.

The problem is that no computers have connected to the server, and I don't understand why. I think there might be a problem with some permissions. Earlier, at a Windows Server course we gave the users some "apply to" permissions, but I can't remember in what context.

I look forward to the answers I get from you guys. Thanks!

How to remove red X status from the WSUS console

$
0
0

We have one machine which is unable to install update KB2847077. After many unsuccessful attempts we decided to simply hide it on the user's laptop Windows Update screen, as it is not a crucial update to install.

My question is, now that we told Windows to ignore the update on the local machine, how do I remove the failed "red x" status in the WSUS management console?

Thanks!


Hank Vare

Domain Group Policy changes causes clients to be unable to connect to WSUS for Windows Updates

$
0
0

Domain Controller is Windows Server 2008 R2 64-bit, Group Policy Management version 6.0.0.1. WSUS server is Windows Server 2008 Enterprise 32-bit, Update Services version 3.2.7600.226. Client machines are Windows 7, some are 64-bit and some are 32-bit.

Every time we make any changes to any of our Group Policies most of our clients stop getting their Windows Updates from the WSUS server within 2-3 days. This occurs when we add a new policy for a group of users, temporarily disable a policy or edit a policy. Check of the WindowsUpdate.log on affected client machines shows:

2014-06-25 13:40:44:976  760 1610 PT WARNING: GetAuthorizationCookie failure, error = 0x80072EE2, soap client error = 5, soap error code = 0, HTTP status code = 200
2014-06-25 13:40:44:977  760 1610 PT WARNING: Failed to initialize Simple Targeting Cookie: 0x80072ee2
2014-06-25 13:40:44:977  760 1610 PT WARNING: PopulateAuthCookies failed: 0x80072ee2
2014-06-25 13:40:44:977  760 1610 PT WARNING: RefreshCookie failed: 0x80072ee2
2014-06-25 13:40:44:977  760 1610 PT WARNING: RefreshPTState failed: 0x80072ee2
2014-06-25 13:40:44:977  760 1610 PT WARNING: PTError: 0x80072ee2
2014-06-25 13:40:44:977  760 1610 Report WARNING: Reporter failed to upload events with hr = 80072ee2.

A further check of the log files shows:

2014-06-21 19:36:06:995  156 1b0c Misc WARNING: SendRequest failed with hr = 80072ee2. Proxy List used: <proxy server name:8080> Bypass List used : <(null)> Auth Schemes used : <>

We do not use a proxy except for Internet connections. We configure IE with a pac file. This is set through Group Policy since we restrict user accounts from being able to set it. 

The clients that are connecting to the WSUS server have these entries instead:

2014-06-24 09:12:16:779  992 270 Agent Setting download properties on call A20329BC-3467-4B7E-B9F4-6AC6ACBA23E1: priority=3, interactive=1, owner is system=0, proxy settings=1, proxy session id=2

I have a routine that will fix the problem but it is time-consuming and pulls me away from other things I should be doing:

Run registry files on client machine (WindowsUpdate and AU) This is not always necessary and is already set by Group Policy and the affected clients already have the registry settings. No idea why it is necessary to do but it the steps below don't always work unless it is.

netstop bits and netstop wuauserv

ipconfig /flushdns

Delete qmgr*.* files from Downloader folder

Delete Software Distribution folder

Run from command prompt:

sc.exe sdset bits D:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;AU)(A;;CCLCSWRPWPDTLOCRRC;;;PU)

sc.exe sdset wuauserv D:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;AU)(A;;CCLCSWRPWPDTLOCRRC;;;PU)

netstart bits and netstart wuauserv

wuauclt /resetauthorization /detectnow

Run Windows Updates again from Control Panel

This routine always fixes the problem but I've found that I must do each step to guarantee success.

How or where is the proxy setting being changed for WSUS that we see in the WindowsUpdate logs and how do I prevent this from happening? It is also curious that it happens to most but not all of the client machines. When it does happen it's not always the same client machines.


WSUS 3.2 displays new Windows 2012 R2 machines as being Windows 2000

$
0
0
anyone have a good link to any patch or setting update that I need to get my WSUS 3.2 system running on Windows 2008 R2 to recognize my new Windows 2012 R2 servers correctly? Right now they show up in the system list but are detecting as Windows 2000.

wsusutil export

$
0
0

we're exporting data and metadata to an offline wsus. The initial export and import ran fine and the offline wsus server is running fine. We then did an incremental backup of the wsuscontent directory in preparation for the metadata export. When we executed the "wsusutil export export.xml.gz we received the following error message:

"Fatal error: the gzip stream can't contain more than 4 GB".

The export command is EXACTLY the same command we used when we performed the initial export. Any ideas?

Server tries to download updates from MS instead of configured WSUS server

$
0
0

Hey all,

I got some strange behaviour of a server that I try to update with our WSUS server. Both the client and the WSUS server are Win2k12, not R2. A policy is applied on all servers in which the WSUS server is set. Actually, the update procedure and the policy works on all servers but this one.
I am able to find and select updates for the target server on my WSUS server and the server is able to find the server. When I try "Install now" on the target server, nothing happens. According to the log the server is communicating with the WSUS server, but is not downloading the updates from it, instead it tries to download them from MS itself what is not possible. I inserted my proxy user and then it worked so I nailed it down.
How can I reset all the configuration or where is the registry key that leads to the download source?

Thanks in advance and kind regards,

Azreth

WSUS hangs on Cleanup wizard for Unused Updates, then disconnects from console.

$
0
0
I am running WSUS 3.0 SP1 on Windows 2003 and recently have found that running the Cleanup Wizard works with all of the selectable options except the "Unused Updates" option. It hangs about 1\2 way through and then disconnects from the console. Up until now it has worked.
I am using the Windows Internal Database and the size of the MDF is 3193024kb.
Everything other than this wizard is working fine. Please help.

Best Practice to clean up WSUS content no longer needed

$
0
0

I have been researching this for days and probably have about 10 hours invested in trying to come to a conclusion and now want some feedback from this group. Below you will find everything I think you might need about my current configuration. I originally installed my first WSUS server in 2006.Over the years I added new products as needed, changed to express files (seems to have been a bad decision), unselected products no longer needed, and when version 3 came out began running the cleanup wizard monthly. I have never declined any updates myself and only approved those showing as needed. I watched my content grow to about 65 GB then decided to migrate to a new server. I followed this procedure which worked very well:

http://exchangeserverpro.com/how-to-move-wsus-30-to-a-new-server

After the migration I tested a round of updates and everything was working fine. Then I added Windows Server 2008 (only have one server with this OS) and SQL Server 2008 R2 (only have one server with this OS) products and was amazed when my content went up to over 100 GB. I decided to remove those two products since only one server needs them and I could update it direct from MS instead thinking it would be easy to recover the space. Was I in for a surprise. No real easy way to do that. From my research these seem to be the options to do a good clean up on all unneeded content. What do you suggest as the best way for me to proceed?

Option 1: uninstall and re-install fresh

Option 2: reset the content following this procedure:

http://blogs.technet.com/b/gborger/archive/2009/02/27/what-to-do-when-your-wsuscontent-folder-grows-too-large.aspx

Option 3: reset the content following this procedure: (I tested this on my old server and steps 1-4 took about 90 minutes)

1. Decline all previously approved updates. (Yes, all of them. Even the ones you want.)
2. Run the cleanup wizard -- this will remove files in the WsusContent folder.
3. Change the approval of all DECLINED updates from declined to "Not Approved" (and apply inheritance).
4. Run the cleanup wizard again -- this will decline all expired updates.
5. Re-approve needed updates. Content will be re-downloaded.

I do plan to remove the express files option first to reduce the amount of space needed for storage. If you see anything else in my config that should be tweaked please let me know. Thanks for any and all feedback. I appreciate you taking the time to read this and respond.

My configuration follows:

1 Gbps switched network infrastructure with 10/10 fiber internet access

WSUS – current environment – 1 physical server also used as a file share server for user files

Windows Server 2008 Enterprise (x86)

Dual Intel Xeon 2.8 Ghz

2 GB Ram

1 Gbps Nic

136 GB hard drive for DB and WSUS Content files (currently DB=1.5 GB, Content = 108 GB)

WSUS Server version: 3.2.7600.226

Using the Windows Internal Database (I do have a SQL Server 2008 R2 server available now)

128 Computers in 13 groups manually assigned but computers are directed to this server via GP

(all Servers and 90% of workstations are current on updates through last month)

3189 Updates installed/NA

139 Updates needed

919 Updates with no status

Configuration options:

Update source – Microsoft

Products – Office 2003, Office 2010, Windows 7, Windows Defender, Windows Server 2003, Windows Server 2008 R2, Windows XP (previously selected but no longer needed: Office 2002/XP, SQL Server 2008 R2, Windows 2000, Windows Server 2008)

Classifications – critical, definition, security, service packs, update rollups, updates

Update files and languages – store locally, download only when approved, download express installation files, English

Automatic approvals – above classifications for test group which includes one computer with each of the following OS’s: Windows 7, Windows Server 2003, Windows Server 2008 R2, Windows XP

After those machines are tested then I approve and install needed updates for the server group (8 machines total) which include Windows Server 2003, Windows Server 2003 R2, Windows Server 2008 R2, Windows XP

After those machines are tested then I approve needed updates for all computers and let the users install them


Clients are not reporting to WSUS Server

$
0
0

Hi,

we have 41`9 computers. till now only 320 have reported to WSUS server. daily one or 2 computers report to wsus. is this normal ?

Wsus role and feature addition on 2012 R2 fails to install logging this message:

$
0
0

Fatal Error: Cannot start service MSSQL$MICROSOFT##WID on computer '.'.

The specified account has not been given login as a service right.

Now, I'm assuming they create that goofy named account to run the instance of the internal db, but they have apparently forgot to add automation to set the right to logon as a service. This is a bug, I have the same results on two different server 2012 R2 installs. Is there a manual fix for this somewhere I can try? Very irritating.


KB2607607 for all languages showing on WSUS

$
0
0
KB2607607 arrived on my WSUS server on the 23rd, but I received the meta for all languages. I double checked my options in WSUS and English is the only language checked. Does anyone else have this problem? Is it possible that Microsoft  classified them as English? Thanks.

WSUS install on Server 2012 Fails

$
0
0

Attempting to install WSUS onto server 2012 Standard, with AD roles, all else Vanilla:

The isntall consistently fails with this error:

2012-09-03 15:48:46  Importing default detectoids succeeded.
2012-09-03 15:48:46  Creating default subscription.
2012-09-03 15:48:46  Instantiating UpdateServer
2012-09-03 15:48:49  CreateDefaultSubscription failed. Exception: System.Net.WebException: The request failed with HTTP status 503: Service Unavailable.
   at System.Web.Services.Protocols.SoapHttpClientProtocol.ReadResponse(SoapClientMessage message, WebResponse response, Stream responseStream, Boolean asyncCall)
   at System.Web.Services.Protocols.SoapHttpClientProtocol.Invoke(String methodName, Object[] parameters)
   at Microsoft.UpdateServices.Internal.ApiRemoting.GetServerVersion()
   at Microsoft.UpdateServices.Internal.DatabaseAccess.AdminDataAccessProxy.GetServerVersion()
   at Microsoft.UpdateServices.Internal.BaseApi.UpdateServer.CreateUpdateServer(String serverName, Boolean useSecureConnection, Int32 portNumber)
   at Microsoft.UpdateServices.Internal.BaseApi.UpdateServer..ctor(Boolean bypassApiRemoting)
   at Microsoft.UpdateServices.Setup.StartServer.StartServer.CreateDefaultSubscription()
2012-09-03 15:48:49  StartServer encountered errors. Exception=The request failed with HTTP status 503: Service Unavailable.
2012-09-03 15:48:49  Microsoft.UpdateServices.Administration.CommandException: Failed to start and configure the WSUS service
   at Microsoft.UpdateServices.Administration.PostInstall.Run()
   at Microsoft.UpdateServices.Administration.PostInstall.Execute(String[] arguments)
Fatal Error: Failed to start and configure the WSUS service

The server is a secondary DC with the other DC also being the primary WSUS server (to be decommissioned as is only 2012 Beta)


asdgfsdf

WSUS 2012 R2 totally dead

$
0
0

Hello,

I have a single Windows Server 2012 R2 server which runs AD and all other basic services, as well as WSUS with Windows Internal Database.

WSUS has been working fine for several months until it stopped working completely: all clients stopped receiving updates. Opening the WSUS console would show a hung session and after about a minute would time out with "Error: Connection Error"

I tried restarting the services and server.

Tried removing the WSUS role and reinstalling, no difference.

Tried manually deleting the WSUS website after uninstalling WSUS.

The result is that the Post Installation Task fails completely.

Tried deleting the WID susdb files but realized that broke things even further so I restored the files and I'm back to square one.

Some articles suggest uninstalling and reinstalling WID but this doesn't seem possible with 2012 R2.

Does anyone know how I can fix WSUS?

Thanks in advance!





The WSUS Content Directory is not accessible

$
0
0

Single Primary Site running SCCM 2012 R2 on Windows Server 2012 R2.

WSUS on same server using Ports Http: 8530 and HTTPS: 8531 and is using SUSDB as database.

No Proxy in place.

Everything was working and issue started last week. No changes were made.

We get following WSUS errors 

System.net.webException: The request failed with HTTP status 503: Sevice Unavailable~~~ Failures reported during periodic health check by the WSUS server. will retry check in 1 mins

I then ran the WSUSutil.exe checkhealth command and in event viewer, get a few different errors:

Event ID 13042: Self-update is not working.

Event ID 10021: The catalog was last synchronized successfully 1 or more days ago.

Event ID 12002: The Reporting Web Service is not working.

Event ID 12012: The API Remoting Web Service is not working.

Event ID 12032: The Server Synchronization Web Service is not working.

Event ID 12022: The Client Web Service is not working.

Event ID 12042: The SimpleAuth Web Service is not working.

Event ID 12052: The DSS Authentication Web Service is not working.

Event ID 12072: The WSUS content directory is not accessible.

System.Net.WebException: The remote server returned an error: (503) Server Unavailable.

   at System.Net.HttpWebRequest.GetResponse()

   at Microsoft.UpdateServices.Internal.HealthMonitoring.HmtWebServices.CheckContentDirWebAccess(EventLoggingType type, HealthEventLogger logger)

Please suggest.

Run windows update against specific wsus server

$
0
0
Is it possible to run windows update from a specific wsus server using cmdline or powershell? Eventually I am trying to do something with powershell but without using the WSUS API for versions 4 and above.
Thanks 
Viewing all 12874 articles
Browse latest View live


<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>