Quantcast
Channel: WSUS forum
Viewing all 12874 articles
Browse latest View live

WSUS and server patching

$
0
0

Hello,

We are looking at using WSUS for server patching.

Ideally I'd like the servers to download the patches and install them but not reboot. I see from the policies that there's an option to "3 - auto download and notify (i.e. don't install)" or "4 - auto download and install". Additionally there's an option to allow updates that don't require an install to install automatically.

So if I want servers to download patches but not reboot it looks like I must choose option 3 and allow updates that don't require a reboot to install. Is that correct? After that is it enough to remotely reboot all servers at a set time for the remaining patches to install or must I connect to each server, install the patches, and then reboot? The latter seems to be a lot work (we have some 200+ servers) so I was wondering how others do this or whether there's any best practices.

Thanks,

Rakhesh


Computer Client (win 8.1) doesn´t update - Server win 2008 R2

$
0
0
2015-07-0105:59:45:75811361404Service** START **  Service: Service startup
2015-07-0105:59:45:75811361404Service*********
2015-07-0105:59:45:76311361404IdleTmrNon-AoAc machine.  Aoac operations will be ignored.
2015-07-0105:59:45:76311361404Agent * WU client version 7.9.9600.17195
2015-07-0105:59:45:76311361404AgentWARNING: SleepStudyTracker: Machine is non-AOAC. Sleep study tracker disabled.
2015-07-0105:59:45:76311361404Agent * Base directory: C:\Windows\SoftwareDistribution
2015-07-0105:59:45:76311361404Agent * Access type: No proxy
2015-07-0105:59:45:76311361404ServiceUpdateNetworkState Ipv6, cNetworkInterfaces = 1.
2015-07-0105:59:45:76311361404ServiceUpdateNetworkState Ipv4, cNetworkInterfaces = 1.
2015-07-0105:59:45:76311361404Agent * Network state: Connected
2015-07-0105:59:45:76511361404ServiceUpdateNetworkState Ipv6, cNetworkInterfaces = 1.
2015-07-0105:59:45:76511361404ServiceUpdateNetworkState Ipv4, cNetworkInterfaces = 1.
2015-07-0105:59:45:78111361404Agent***********  Agent: Initializing global settings cache  ***********
2015-07-0105:59:45:78111361404Agent * Endpoint Provider: 00000000-0000-0000-0000-000000000000
2015-07-0105:59:45:78111361404Agent * WSUS server: http://.
2015-07-0105:59:45:78111361404Agent * WSUS status server: http://.
2015-07-0105:59:45:78111361404Agent * Target group: Teste-noc
2015-07-0105:59:45:78111361404Agent * Windows Update access disabled: No
2015-07-0105:59:45:785113625fcWuTaskWuTaskManager delay initialize completed successfully..
2015-07-0105:59:45:785113625fcAU   Timer: 31DA7559-FE27-4810-8FF6-987195B1FD98, Expires 2015-07-02 02:45:57, not idle-only, not network-only
2015-07-0105:59:45:785113625fcAU   Timer: CF1ABEC6-7887-4964-BB93-B2E21B31CEC1, Expires 2015-07-01 10:33:03, not idle-only, not network-only
2015-07-0105:59:45:785113625fcAU   Timer: 29A863E7-8609-4D1E-B7CD-5668F857F1DB, Expires 2015-07-01 10:33:02, not idle-only, not network-only
2015-07-0105:59:45:788113625fcReportWARNING: CSerializationHelper:: InitSerialize failed : 0x80070002
2015-07-0105:59:45:788113625fcReportCWERReporter::Init succeeded
2015-07-0105:59:45:788113625fcAgent***********  Agent: Initializing Windows Update Agent  ***********
2015-07-0105:59:45:788113625fcDnldMgrDownload manager restoring 0 downloads
2015-07-0105:59:45:78911361404AU###########  AU: Initializing Automatic Updates  ###########
2015-07-0105:59:45:78911361404AUAdditional Service {117CAB2D-82B1-4B5A-A08C-4D62DBEE7782} with Approval type {Scheduled} added to AU services list
2015-07-0105:59:45:78911361404AUAIR Mode is disabled
2015-07-0105:59:45:78911361404AU # Policy Driven Provider: http://.
2015-07-0105:59:45:78911361404AU # Detection frequency: 22
2015-07-0105:59:45:78911361404AU # Target group: Teste-noc
2015-07-0105:59:45:78911361404AU # Approval type: Scheduled (Policy)
2015-07-0105:59:45:78911361404AU # Auto-install minor updates: Yes (User preference)
2015-07-0105:59:45:78911361404AU # ServiceTypeDefault: Service 117CAB2D-82B1-4B5A-A08C-4D62DBEE7782 Approval type: (Scheduled)
2015-07-0105:59:45:78911361404AU # Will interact with non-admins (Non-admins are elevated (User preference))
2015-07-0105:59:45:791118722b64Misc===========  Logging initialized (build: 7.9.9600.17195, tz: -0300)  ===========
2015-07-0105:59:45:791118722b64Misc = Process: C:\Program Files\Windows Defender\MpCmdRun.exe
2015-07-0105:59:45:791118722b64Misc = Module: C:\Windows\System32\wuapi.dll
2015-07-0105:59:45:790118722b64COMAPI-------------
2015-07-0105:59:45:791118722b64COMAPI-- START --  COMAPI: Init Search [ClientId = Windows Defender (77BDAF73-B396-481F-9042-AD358843EC24)]
2015-07-0105:59:45:791118722b64COMAPI---------
2015-07-0105:59:45:791118722b64COMAPI-------------
2015-07-0105:59:45:791118722b64COMAPI-- START --  COMAPI: Search [ClientId = Windows Defender (77BDAF73-B396-481F-9042-AD358843EC24)]
2015-07-0105:59:45:791118722b64COMAPI---------
2015-07-0105:59:45:791113625fcIdleTmrWU operation (CSearchCall::Init ID 1) started; operation # 8; does use network; is not at background priority
2015-07-0105:59:45:791113625fcIdleTmrIncremented idle timer priority operation counter to 1
2015-07-0105:59:45:81211361404AUWARNING: Failed to get Wu Exemption info from NLM, assuming not exempt, error = 0x80070032
2015-07-0105:59:46:041113625fcReport***********  Report: Initializing static reporting data  ***********
2015-07-0105:59:46:041113625fcReport * OS Version = 6.3.9600.0.0.65792
2015-07-0105:59:46:041113625fcReport * OS Product Type = 0x00000030
2015-07-0105:59:46:04411361404AUAU finished delayed initialization
2015-07-0105:59:46:050113625fcReport * Computer Brand = 
2015-07-0105:59:46:050113625fcReport * Computer Model = 
2015-07-0105:59:46:050113625fcReport * Platform Role = 1
2015-07-0105:59:46:051113625fcReport * AlwaysOn/AlwaysConnected (AOAC) = 0
2015-07-0105:59:46:053113625fcReport * Bios Revision = 
2015-07-0105:59:46:053113625fcReport * Bios Name = 
2015-07-0105:59:46:053113625fcReport * Bios Release Date = 
2015-07-0105:59:46:053113625fcReport * Bios Sku Number = 
2015-07-0105:59:46:053113625fcReport * Bios Vendor = 
2015-07-0105:59:46:053113625fcReport * Bios Family = To be filled by O.E.M.
2015-07-0105:59:46:053113625fcReport * Bios Major Release = 4
2015-07-0105:59:46:053113625fcReport * Bios Minor Release = 6
2015-07-0105:59:46:053113625fcReport * Locale ID = 1046
2015-07-0105:59:46:11011361404AUAdding timer: 
2015-07-0105:59:46:11011361404AU   Timer: E25CADF6-86A6-4569-BCDF-89BE66B0CA66, Expires 2015-06-22 06:38:12, not idle-only, not network-only
2015-07-0105:59:46:110113688cDnldMgrAsking handlers to reconcile their sandboxes
2015-07-0105:59:46:178113625fcAgent*** START ***  Queueing Finding updates [CallerId = Windows Defender (77BDAF73-B396-481F-9042-AD358843EC24)  Id = 1]
2015-07-0105:59:46:178118722b64COMAPI<<-- SUBMITTED -- COMAPI: Search [ClientId = Windows Defender (77BDAF73-B396-481F-9042-AD358843EC24)]
2015-07-0105:59:46:178113631b4Agent***  END  ***  Queueing Finding updates [CallerId = Windows Defender (77BDAF73-B396-481F-9042-AD358843EC24)  Id = 1]
2015-07-0105:59:46:178113631b4Agent*************
2015-07-0105:59:46:178113631b4Agent** START **  Agent: Finding updates [CallerId = Windows Defender (77BDAF73-B396-481F-9042-AD358843EC24)  Id = 1]
2015-07-0105:59:46:178113631b4Agent*********
2015-07-0105:59:46:178113631b4Agent * Online = Yes; Ignore download priority = No
2015-07-0105:59:46:178113631b4Agent * Criteria = "(IsInstalled = 0 and IsHidden = 0 and CategoryIDs contains '8c3fcc84-7410-4a95-8b89-a166a0190486' and CategoryIDs contains 'e0789628-ce08-4437-be74-2495b842f43b')"
2015-07-0105:59:46:178113631b4Agent * ServiceID = {7971F918-A847-4430-9279-4A52D1EFE18D} Third party service
2015-07-0105:59:46:178113631b4Agent * Search Scope = {Machine}
2015-07-0105:59:46:178113631b4Agent * Caller SID for Applicability: S-1-5-18
2015-07-0105:59:46:178113631b4Agent * RegisterService is set
2015-07-0105:59:46:179113631b4SLSRetrieving SLS response from server using ETAG "4V8nqvoeoxgpu+6kKNNNGpLr4BCvPTmaz82CIDm5o5g=_1440"...
2015-07-0105:59:46:179113631b4SLSMaking request with URL HTTPS://sls.update.microsoft.com/SLS/{9482F4B4-E343-43B6-B170-9A65BC822C77}/x64/6.3.9600.0/0?CH=516&L=pt-BR&P=&PT=0x30&WUA=7.9.9600.17195
2015-07-0105:59:47:070113631b4EPFATAL: EP: Failed to obtain element node, error = 0x80245002
2015-07-0105:59:47:070113631b4EPFATAL: Failed to obtain 9482F4B4-E343-43B6-B170-9A65BC822C77 redir SecondaryServiceAuth URL, error = 0x80245002
2015-07-0105:59:47:070113631b4AgentWARNING: Failed to obtain the authorization cab URL for service 855e8a7c-ecb4-4ca3-b045-1dfa50104289, hr=0
2015-07-0105:59:47:070113631b4SLSRetrieving SLS response from server using ETAG "4V8nqvoeoxgpu+6kKNNNGpLr4BCvPTmaz82CIDm5o5g=_1440"...
2015-07-0105:59:47:070113631b4SLSMaking request with URL HTTPS://sls.update.microsoft.com/SLS/{9482F4B4-E343-43B6-B170-9A65BC822C77}/x64/6.3.9600.0/0?CH=516&L=pt-BR&P=&PT=0x30&WUA=7.9.9600.17195
2015-07-0105:59:47:204113631b4EPGot 9482F4B4-E343-43B6-B170-9A65BC822C77 redir SecondaryServiceAuth URL: "7971f918-a847-4430-9279-4a52d1efe18d"
2015-07-0105:59:47:206113631b4EPGot 7971F918-A847-4430-9279-4A52D1EFE18D redir Client/Server URL: "https://fe2.update.microsoft.com/v6/ClientWebService/client.asmx"
2015-07-0105:59:47:399113631b4PT+++++++++++  PT: Starting category scan  +++++++++++
2015-07-0105:59:47:399113631b4PT + ServiceId = {7971F918-A847-4430-9279-4A52D1EFE18D}, Server URL = https://fe2.update.microsoft.com/v6/ClientWebService/client.asmx
2015-07-0105:59:47:399113631b4IdleTmrWU operation (CAgentProtocolTalker::StartCategoryScan_WithRecovery) started; operation # 88; does use network; is at background priority
2015-07-0105:59:48:428113631b4IdleTmrWU operation (CAgentProtocolTalker::StartCategoryScan_WithRecovery, operation # 88) stopped; does use network; is at background priority
2015-07-0105:59:48:441113631b4PT+++++++++++  PT: Synchronizing server updates  +++++++++++
2015-07-0105:59:48:441113631b4PT + ServiceId = {7971F918-A847-4430-9279-4A52D1EFE18D}, Server URL = https://fe2.update.microsoft.com/v6/ClientWebService/client.asmx
2015-07-0105:59:48:441113631b4AgentReading cached app categories using lifetime 604800 seconds
2015-07-0105:59:48:441113631b4AgentRead 0 cached app categories
2015-07-0105:59:48:441113631b4AgentSyncUpdates adding 0 visited app categories
2015-07-0105:59:48:442113631b4IdleTmrWU operation (CAgentProtocolTalker::SyncUpdates_WithRecover) started; operation # 89; does use network; is at background priority
2015-07-0105:59:48:787113631b4IdleTmrWU operation (CAgentProtocolTalker::SyncUpdates_WithRecover, operation # 89) stopped; does use network; is at background priority
2015-07-0105:59:48:787113631b4IdleTmrWU operation (CAgentProtocolTalker::GetExternalCabFileLocations) started; operation # 90; does use network; is at background priority
2015-07-0105:59:48:958113631b4IdleTmrWU operation (CAgentProtocolTalker::GetExternalCabFileLocations, operation # 90) stopped; does use network; is at background priority
2015-07-0105:59:48:970113631b4MiscWARNING: WinHttp: SendRequestToServerForFileInformation failed with 0x80190193
2015-07-0105:59:48:970113631b4MiscWARNING: WinHttp: ShouldFileBeDownloaded failed with 0x80190193
2015-07-0105:59:48:970113631b4MiscWARNING: WinHttp: WinHttpQueryHeaders(WINHTTP_QUERY_CONTENT_TYPE) for X-CID failed. error 0x80072f76
2015-07-0105:59:48:970113631b4PTWARNING: ECP: DownloadCabFile: failed to get CDN Provider for error reporting, hr = 0X80072F76
2015-07-0105:59:48:970113631b4MiscWARNING: WinHttp: WinHttpQueryHeaders(WINHTTP_QUERY_CONTENT_TYPE) for X-CCC failed. error 0x80072f76
2015-07-0105:59:48:970113631b4PTWARNING: ECP: DownloadCabFile: failed to get CDN Country for error reporting, hr = 0X80072F76
2015-07-0105:59:48:970113631b4PTWARNING: ECP: Failed to download cab file from http://download.windowsupdate.com/d/msdownload/update/others/2015/07/18179058_08d499a32266b9f7912dd726c62f03429ce6e5db.cab with error 0x80190193
2015-07-0105:59:48:970113631b4PTWARNING: ECP: This roundtrip contained some optimized updates which failed. New Update count = 4, Old Count = 9
2015-07-0105:59:48:976113631b4PT + SyncUpdates round trips: 1
2015-07-0105:59:48:976113631b4PTWARNING: Sync of Updates: 0x8024402f
2015-07-0105:59:48:976113631b4PTWARNING: SyncServerUpdatesInternal failed: 0x8024402f
2015-07-0105:59:48:976113631b4Agent * WARNING: Failed to synchronize, error = 0x8024402F
2015-07-0105:59:48:977113631b4Agent * WARNING: Exit code = 0x8024402F
2015-07-0105:59:48:977113631b4Agent*********
2015-07-0105:59:48:977113631b4Agent**  END  **  Agent: Finding updates [CallerId = Windows Defender (77BDAF73-B396-481F-9042-AD358843EC24)  Id = 1]

WSUS 2012 R2 in DMZ

$
0
0

Hi We have to setup a New WSUS server in DMZ 

I wanted to check the following:

Can we deploy Server 2012 R2 / WSUS v6  and make it the Upstream server for 2 of our Windows 2008 (WSUS 3.0) server

We wish to Use the new 2012 R2 server to just get Updates from MS and then Have the existing WSUS 3.0 servers get it from the Upstream Server in Autonomous mode.

I am hoping we only need to open following ports on firewall (80/443) between the 2 existing WSUS 3.0 to the new 2012R2 WSUS 

I need to move a WSUS dB to another server

$
0
0
We are currently consolidating many SQL instances and I was wondering if the following can be accomplished.

Is it possible to move the SUSDB dB from its original server to a shared instance of SQL on another server, so that the instance residing on the original server can be retired?  The owner of the dB is a non-standard account in that it is the ASPNET IIS system account.  I need to determine if the dB can actually be separated from its original server running the web front end of the application along with changing the owner of the dB. 

Any help would be greatly appreciated.

Thanks!!

Andrea

Where do I put my WSUS?

$
0
0

Hi There,

A little help needed over here.

Consider the following scenario:

Small envrionment with 70 clients. 4 2012R2 servers: DC, Ex2013, SPF2013, SQL2014.

Now on which of those 4 servers should I put WSUS on ? Dedicated is not an option. And is SQL2014 supported for WSUS database?

Thanks in advance.

Server 2008 R2 WSUS change port from 80 to 8530

$
0
0

I have been reading different threads on making this change, but wanted to try to get a definitive answer on how this is accomplished.  I found a thread for changing the other direction from 8530 to 80.

Run this command wsusutil usecustomwebsite true

After this some say you need to go into the registry and change this setting:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Update Services\Server\Setup  Change"Port Number" Value to Required Port No in my case 8530

My clients receive their configuration via GPO, so do I just update that, or do I need to do this registry stuff on the WSUS server itself?

Then some are saying to run this "cscript"c:\Program Files\Update Services\setup\installselfupdateonport80.vbs" by I am wondering #1 if it is necessary and #2 if so, is the por80 portion of the file significant, or do I need to set the port number in the script somewhere?

Other's were talking about IIS bindings.

The truth of the matter is all I wanna do is change the port on my WSUS server and have my clients report afterwards.  I have wondered if it is as simple as running the

wsusutil usecustomwebsite true

Update my WSUS GPO that I use for client settings.

Windows 10 Reservation Icon Not Visible

$
0
0

Hi,

We are running domain environment and configured local windows update server for deploying windows updates on client PC but as many PC outside the company or at my home  are getting "windows 10 free reservation icon" at taskbar but in my environment  none of any pc shows this icon.

I check all PC are updated and also windows update servers is also updated

All our windows are genuine

can some one pls help me how to display this icon across all pc with the help of windows update server.

WSUS Pop-up msg

$
0
0
When updates are push out via WSUS the workstations are getting the pop-up message "Restart your computer to finish installing important updates."  It displays a remind me in 10 minutes and if you click the down triangle you can be reminded in 1,2 or 4 hours.  You also have the option to Restart Now.  My question is, if that pop-up is ignored, what will happen?  Will the workstation reboot after the ten minutes are up??  WSUS is configured not to restart automatically upon installing updates.  I am running 2008R2

Francisco Mercado Jr.


WSUS stop working after rebooting of the computer after a while

$
0
0

Hi everybody!

Sorry for my bad English.

We have Windows Server 2012 Core with WSUS installed role.

After loading of the computer the service WSUS works normally. But after several hours ceases to work. But all services is working. It is impossible to be connected to service through WSUS snap-in.

In the event log on the server events register:

Source: WAS

ID: 5002

Application pool "WsusPool" is being automatically disabled due to a series of failures in the process(es) serving that application pool.

Source: Windows Server Update Services

Category: 6

ID: 13042

Self-update is not working.

Source: Windows Server Update Services

Category: 6

ID: 12002

The Reporting Web Service is not working.

Source: Windows Server Update Services

Category: 6

ID: 12012

The API Remoting Web Service is not working.

Source: Windows Server Update Services

Category: 6

ID: 12032

The Server Synchronization Web Service is not working.

Source: Windows Server Update Services

Category: 6

ID: 12022

The Client Web Service is not working.

Source: Windows Server Update Services

Category: 6

ID: 12042

The SimpleAuth Web Service is not working.

Source: Windows Server Update Services

Category: 6

ID: 12052

The DSS Authentication Web Service is not working.

Source: Windows Server Update Services

Category: 6

ID: 12072

The WSUS content directory is not accessible.

System.Net.WebException: The remote server returned an error: (503) The server unavailable.

in System.Net.HttpWebRequest.GetResponse()

   in Microsoft.UpdateServices.Internal.HealthMonitoring.HmtWebServices.CheckContentDirWebAccess(EventLoggingType type, HealthEventLogger logger)

What's the problem? What it is possible to undertake to get rid of a problem?

WSUS roles install on Server 2012 Fails

$
0
0

Hi I m ananda I want to installed wsus server in 2012 server but its getting error

The MSSQL$MICROSOFT##WID service was unable to log on as NT SERVICE\MSSQL$MICROSOFT##WID with the currently configured password due to the following error:

Logon failure: the user has not been granted the requested logon type at this computer.

 Service: MSSQL$MICROSOFT##WID

Domain and account: NT SERVICE\MSSQL$MICROSOFT##WID

 This service account does not have the required user right "Log on as a service."

 User Action

 Assign "Log on as a service" to the service account on this computer. You can use Local Security Settings (Secpol.msc) to do this. If this computer is a node in a cluster, check that this user right is assigned to the Cluster service account on all nodes in the cluster.

 If you have already assigned this user right to the service account, and the user right appears to be removed, check with your domain administrator to find out if a Group Policy object associated with this node might be removing the right.

Please let me know if you have any ideas. Thanks!

wsus wont install on server 2012r2

$
0
0

i have a new 2012r2 server and try to install wsus through server manager.  after i do this i get 

feature installation

the request to add or remove features on the specified server failed.  the operation cannot be completed because the server that you specified requires a restart.  i tried to restart multiple times with no luck.

i saw

http://henkhoogendoorn.blogspot.com.br/2014/06/wsus-role-failed-on-windows-server-2012.html

and tried the fix but still this doesnt work.  any ideas?

WSUS disappears after a reboot.

$
0
0

After I install WSUS on my Window 2012 R2 Standard server and reboot the role disappears.

WID also disappears. My server is a DC, and yes I know I should not run it on a DC but I have no choice.

I have now tried to install this role maybe 5 times now and get the same result. Also for some reason the Windows Installer service is greyed out in the start type and set to manual.

I have also run sfc /scannow without any lucky.

My e:\WSUS is also intact.


Raymond W. Rio

Cant approve patches

$
0
0
<p>I have been using WSUS 3.2 for a while now and a couple of weeks ago, I started having problems approving patches. So the follwoing error I get when I try to approve just one Windows 7 patch to both All Computers and also the Windows 7 pcs. "Removing of  (patch) Success. Approving of (patch name/info) Unknown Error: see logs for more information</p><p>I dont see anything in the logs. I am at a loss. Any suggestions?</p><p></p>

No client computers have contacted WSUS server

$
0
0

Hi All,

I stood up a 2012R2 WSUS server several weeks ago and although synchronizations are going well "no client PCs or servers have contacted the server."  I looked in the Application log and it verified this situation displaying a warning event ID 13051.  What did I fail to configure?


Francisco Mercado Jr.

uninstall ipv6 breaks my wsus - address shows as ::1 in wsus

$
0
0

I recently turned off IPV6 on my WSUS server and had very strange results.

In the WSUS management console, all computers, the IP address for the WSUS box now showed the IP address as just ::1 and the box would no longer get updates from itself.

Here's a log snippet.

2015-07-02	23:53:20:496	 844	bbc	EP	Got WSUS SimpleTargeting URL: "http://dpwsus02:8530"
2015-07-02	23:53:20:516	 844	bbc	PT	Initializing simple targeting cookie, clientId = 5b3f62e4-2e8b-4978-adf1-8301ab0bcbb3, target group = , DNS name = dpwsus02
2015-07-02	23:53:20:516	 844	bbc	PT	  Server URL = http://dpwsus02:8530/SimpleAuthWebService/SimpleAuth.asmx
2015-07-02	23:54:39:579	 844	bbc	WS	WARNING: Nws Failure: errorCode=0x803d0006
2015-07-02	23:54:39:579	 844	bbc	WS	WARNING: Original error code: 0x80072ee2
2015-07-02	23:54:39:579	 844	bbc	WS	WARNING: There was an error communicating with the endpoint at 'http://dpwsus02:8530/ClientWebService/client.asmx'.
2015-07-02	23:54:39:579	 844	bbc	WS	WARNING: There was an error receiving the HTTP reply.
2015-07-02	23:54:39:579	 844	bbc	WS	WARNING: The operation did not complete within the time allotted.
2015-07-02	23:54:39:717	 844	bbc	WS	WARNING: The operation timed out
2015-07-02	23:54:39:717	 844	bbc	WS	WARNING: Web service call failed with hr = 8024401c.
2015-07-02	23:54:39:717	 844	bbc	WS	WARNING: Current service auth scheme='None'.
2015-07-02	23:54:39:717	 844	bbc	WS	WARNING: Proxy List used: '(null)', Bypass List used: '(null)', Last Proxy used: '(null)', Last auth Schemes used: 'None'.
2015-07-02	23:54:39:717	 844	bbc	WS	FATAL: OnCallFailure(hrCall, m_error) failed with hr=0x8024401c
2015-07-02	23:54:39:718	 844	bbc	PT	WARNING: PTError: 0x8024401c
2015-07-02	23:54:39:724	 844	bbc	PT	WARNING: GetCookie_WithRecovery failed : 0x8024401c
2015-07-02	23:54:39:724	 844	bbc	PT	WARNING: RefreshCookie failed: 0x8024401c
2015-07-02	23:54:39:724	 844	bbc	PT	WARNING: RefreshPTState failed: 0x8024401c
2015-07-02	23:54:39:724	 844	bbc	PT	WARNING: Sync of Updates: 0x8024401c
2015-07-02	23:54:39:724	 844	bbc	PT	WARNING: SyncServerUpdatesInternal failed: 0x8024401c
2015-07-02	23:54:39:725	 844	bbc	Agent	  * WARNING: Failed to synchronize, error = 0x8024401C
2015-07-02	23:54:39:797	 844	bbc	Agent	  * WARNING: Exit code = 0x8024401C
2015-07-02	23:54:39:797	 844	bbc	Agent	*********
2015-07-02	23:54:39:797	 844	bbc	Agent	**  END  **  Agent: Finding updates [CallerId = AutomaticUpdatesWuApp]
2015-07-02	23:54:39:798	 844	bbc	Agent	*************
2015-07-02	23:54:39:798	 844	bbc	Agent	WARNING: WU client failed Searching for update with error 0x8024401c
2015-07-02	23:54:39:805	 844	470	AU	>>##  RESUMED  ## AU: Search for updates [CallId = {AEE50FEA-6D61-4048-881F-DCF89C100A4E} ServiceId = {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}]
2015-07-02	23:54:39:805	 844	470	AU	  # WARNING: Search callback failed, result = 0x8024401C
2015-07-02	23:54:39:805	 844	470	AU	#########
2015-07-02	23:54:39:805	 844	470	AU	##  END  ##  AU: Search for updates  [CallId = {AEE50FEA-6D61-4048-881F-DCF89C100A4E} ServiceId = {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}]
2015-07-02	23:54:39:805	 844	470	AU	#############
2015-07-02	23:54:39:806	 844	470	AU	All AU searches complete.
2015-07-02	23:54:39:806	 844	470	AU	  # WARNING: Failed to find updates with error code 8024401c
2015-07-02	23:54:39:812	 844	470	AU	AU setting next detection timeout to 2015-07-03 09:54:39


Things I tried include ipconfig /flushdns, waiting several days and trying again, multiple reboots, deleting the WSUS server from its own database and deleting the client registry entries and doing wuauclt /resetauthorization /detectnow.  When I reran wuauclt, the server was added again to the management console again with ::1 as the IP address but all the same errors occurred trying to update.

If I restore IPV6 then the updates work for updating itself.  Updates continued to work for all other clients throughout.

Any suggestions how to fix this?


WSUS post installation failed with error Request for principal permission failed.

$
0
0
2015-07-04 14:17:53  Postinstall started
2015-07-04 14:17:53  Detected role services: Api, Database, UI, Services
2015-07-04 14:17:53  Start: LoadSettingsFromParameters
2015-07-04 14:17:53  Content local is: True
2015-07-04 14:17:53  Content directory is: E:\Sources\wsus
2015-07-04 14:17:53  SQL instname is: p01
2015-07-04 14:17:53  End: LoadSettingsFromParameters
2015-07-04 14:17:53  Start: Run
2015-07-04 14:17:53  Fetching WsusAdministratorsSid from registry store
2015-07-04 14:17:53  Value is S-1-5-21-4005366517-1302196345-1970331482-1013
2015-07-04 14:17:53  Fetching WsusReportersSid from registry store
2015-07-04 14:17:53  Value is S-1-5-21-4005366517-1302196345-1970331482-1014
2015-07-04 14:17:53  Configuring content directory...
2015-07-04 14:17:53  Configuring groups...
2015-07-04 14:17:53  Starting group configuration for WSUS Administrators...
2015-07-04 14:17:53  Found group in regsitry, attempting to use it...
2015-07-04 14:17:55  Writing group to registry...
2015-07-04 14:17:55  Finished group creation
2015-07-04 14:17:55  Starting group configuration for WSUS Reporters...
2015-07-04 14:17:55  Found group in regsitry, attempting to use it...
2015-07-04 14:17:55  Writing group to registry...
2015-07-04 14:17:55  Finished group creation
2015-07-04 14:17:55  Configuring permissions...
2015-07-04 14:17:55  Fetching content directory...
2015-07-04 14:17:55  Fetching ContentDir from registry store
2015-07-04 14:17:55  Value is E:\Sources\wsus
2015-07-04 14:17:55  Fetching group SIDs...
2015-07-04 14:17:55  Fetching WsusAdministratorsSid from registry store
2015-07-04 14:17:55  Value is S-1-5-21-4005366517-1302196345-1970331482-1013
2015-07-04 14:17:55  Fetching WsusReportersSid from registry store
2015-07-04 14:17:55  Value is S-1-5-21-4005366517-1302196345-1970331482-1014
2015-07-04 14:17:55  Creating group principals...
2015-07-04 14:17:55  Granting directory permissions...
2015-07-04 14:17:55  Granting permissions on content directory...
2015-07-04 14:17:55  Granting registry permissions...
2015-07-04 14:17:55  Granting registry permissions...
2015-07-04 14:17:55  Granting registry permissions...
2015-07-04 14:17:55  Configuring shares...
2015-07-04 14:17:55  Configuring network shares...
2015-07-04 14:17:55  Fetching content directory...
2015-07-04 14:17:55  Fetching ContentDir from registry store
2015-07-04 14:17:55  Value is E:\Sources\wsus
2015-07-04 14:17:55  Fetching WSUS admin SID...
2015-07-04 14:17:55  Fetching WsusAdministratorsSid from registry store
2015-07-04 14:17:55  Value is S-1-5-21-4005366517-1302196345-1970331482-1013
2015-07-04 14:17:55  Content directory is local, creating content shares...
2015-07-04 14:17:55  Creating share "UpdateServicesPackages" with path "E:\Sources\wsus\UpdateServicesPackages" and description "A network share to be used by client systems for collecting all software packages (usually applications) published on this WSUS system."
2015-07-04 14:17:55  Deleting existing share...
2015-07-04 14:17:55  Creating share...
2015-07-04 14:17:55  Share successfully created
2015-07-04 14:17:55  Creating share "WsusContent" with path "E:\Sources\wsus\WsusContent" and description "A network share to be used by Local Publishing to place published content on this WSUS system."
2015-07-04 14:17:55  Deleting existing share...
2015-07-04 14:17:55  Creating share...
2015-07-04 14:17:56  Share successfully created
2015-07-04 14:17:56  Creating share "WSUSTemp" with path "C:\Program Files\Update Services\LogFiles\WSUSTemp" and description "A network share used by Local Publishing from a Remote WSUS Console Instance."
2015-07-04 14:17:56  Deleting existing share...
2015-07-04 14:17:56  Creating share...
2015-07-04 14:17:56  Share successfully created
2015-07-04 14:17:56  Finished creating content shares
2015-07-04 14:17:56  Stopping service WSUSService
2015-07-04 14:17:56  Stopping service W3SVC
2015-07-04 14:17:57  Configuring database...
2015-07-04 14:17:57  Configuring the database...
2015-07-04 14:17:57  Establishing DB connection...
2015-07-04 14:17:57  Checking to see if database exists...
2015-07-04 14:17:57  Database exists
2015-07-04 14:17:57  Switching database to single user mode...
2015-07-04 14:18:00  Loading install type query...
2015-07-04 14:18:00  DECLARE @currentDBVersion       int
DECLARE @scriptMajorVersion     int = (9600)
DECLARE @scriptMinorVersion     int = (16384)
DECLARE @databaseMajorVersion   int 
DECLARE @databaseMinorVersion   int 
DECLARE @databaseBuildNumber    nvarchar(10)
IF NOT EXISTS(SELECT * FROM sys.databases WHERE name='SUSDB')
BEGIN
    SELECT 1
END
ELSE
BEGIN
    SET @currentDBVersion = (SELECT SchemaVersion FROM SUSDB.dbo.tbSchemaVersion WHERE ComponentName = 'CoreDB')
    SET @databaseBuildNumber = (SELECT BuildNumber FROM SUSDB.dbo.tbSchemaVersion WHERE ComponentName = 'CoreDB')
    DECLARE @delimiterPosition INT = CHARINDEX('.', @databaseBuildNumber)
    IF (@delimiterPosition = 0)
    BEGIN
        RAISERROR('Invalid schema version number', 16, 1) with nowait
        return 
    END 
    SET @databaseMajorVersion = SUBSTRING(@databaseBuildNumber, 1, @delimiterPosition - 1)
    SET @databaseMinorVersion = SUBSTRING(@databaseBuildNumber, (@delimiterPosition + 1), (10 - @delimiterPosition))
    IF @currentDBVersion < 926
    BEGIN
        SELECT 3
    END
    ELSE
    BEGIN
        IF (@scriptMajorVersion > @databaseMajorVersion OR
           (@scriptMajorVersion = @databaseMajorVersion AND @scriptMinorVersion > @databaseMinorVersion))
        BEGIN
            SELECT 2
        END
        ELSE IF (@scriptMajorVersion = @databaseMajorVersion AND
                 @scriptMinorVersion = @databaseMinorVersion)
        BEGIN
            SELECT 0
        END
        ELSE
        BEGIN
            SELECT 4
        END
    END
END

2015-07-04 14:18:00  Install type is: Reinstall
2015-07-04 14:18:00  Creating logins...
2015-07-04 14:18:00  Fetching account info for S-1-5-20
2015-07-04 14:18:00  Found principal
2015-07-04 14:18:00  Found account
2015-07-04 14:18:00  Got binary SID
2015-07-04 14:18:00  Fetching WsusAdministratorsSid from registry store
2015-07-04 14:18:00  Value is S-1-5-21-4005366517-1302196345-1970331482-1013
2015-07-04 14:18:00  Fetching account info for S-1-5-21-4005366517-1302196345-1970331482-1013
2015-07-04 14:18:00  Found principal
2015-07-04 14:18:00  Found account
2015-07-04 14:18:00  Got binary SID
2015-07-04 14:18:00  Setting content location...
2015-07-04 14:18:00  Fetching ContentDir from registry store
2015-07-04 14:18:00  Value is E:\Sources\wsus
2015-07-04 14:18:00  Swtching DB to multi-user mode......
2015-07-04 14:18:00  Finished setting multi-user mode
2015-07-04 14:18:00  Writing DB settings to registry...
2015-07-04 14:18:00  Marking PostInstall done for UpdateServices-Database in the registry...
2015-07-04 14:18:00  Starting service W3SVC
2015-07-04 14:18:00  Configuring IIS...
2015-07-04 14:18:00  Start: ConfigureWebsite
2015-07-04 14:18:01  Configuring website on port 8530
2015-07-04 14:18:59  2015-07-04 14:18:12  Info      IISCustomAction    Performing Setup Action, Command /Install 
2015-07-04 14:18:56  Info      IISCustomAction    Command /Install Succeeded

2015-07-04 14:18:59  End: ConfigureWebsite
2015-07-04 14:18:59  Configuring performance counters...
2015-07-04 14:18:59  Configuring Stats.NET perf counter...
2015-07-04 14:18:59  Configuring reporting perf counter...
2015-07-04 14:18:59  Configuring client webservice perf counter...
2015-07-04 14:18:59  Configuring server sync webservice perf counter...
2015-07-04 14:18:59  Configuring API remoting perf counter...
2015-07-04 14:18:59  Bringing services online...
2015-07-04 14:18:59  Checking initialization status... 
2015-07-04 14:18:59  Database needs initialization.
2015-07-04 14:18:59  StartServer starting...
2015-07-04 14:18:59  Generating encryption key to write to the registry...
2015-07-04 14:18:59  Generating encryption key to write to the database...
2015-07-04 14:18:59  Generating encryption key succeeded...
2015-07-04 14:18:59  Setting WSUSService to autostart...
2015-07-04 14:18:59  WSUSService is set to autostart.
2015-07-04 14:18:59  Starting WSUSService...
2015-07-04 14:18:59  WSUSService is now started.
2015-07-04 14:18:59  Importing default detectoids.
2015-07-04 14:18:59  Importing CriticalUpdates.xml...
2015-07-04 14:19:00  Importing Drivers.xml...
2015-07-04 14:19:00  Importing FeaturePacks.xml...
2015-07-04 14:19:00  Importing MicrosoftCorporation.xml...
2015-07-04 14:19:00  Importing SecurityUpdates.xml...
2015-07-04 14:19:00  Importing ServicePacks.xml...
2015-07-04 14:19:00  Importing Tools.xml...
2015-07-04 14:19:00  Importing UpdateRollups.xml...
2015-07-04 14:19:00  Importing Updates.xml...
2015-07-04 14:19:00  Importing Windows.xml...
2015-07-04 14:19:00  Importing Windows2000family.xml...
2015-07-04 14:19:00  Importing WindowsServer2003DatacenterEdition.xml...
2015-07-04 14:19:00  Importing WindowsServer2003Family.xml...
2015-07-04 14:19:00  Importing WindowsXPfamily.xml...
2015-07-04 14:19:00  Importing LocalPublisher.xml...
2015-07-04 14:19:00  Importing LocallyPublishedPackages.xml...
2015-07-04 14:19:00  Importing Applications.xml...
2015-07-04 14:19:00  Importing Exchange.xml...
2015-07-04 14:19:00  Importing Office.xml...
2015-07-04 14:19:00  Importing SQL.xml...
2015-07-04 14:19:00  Importing Exchange2000Server.xml...
2015-07-04 14:19:00  Importing ExchangeServer2003.xml...
2015-07-04 14:19:00  Importing OfficeXP.xml...
2015-07-04 14:19:00  Importing Office2003.xml...
2015-07-04 14:19:00  Importing SQLServer.xml...
2015-07-04 14:19:00  Importing WindowsXP64BitEditionVersion2003.xml...
2015-07-04 14:19:01  Importing DefinitionUpdateSusXml.xml...
2015-07-04 14:19:01  Importing ClientServicingApiDetectoid.xml...
2015-07-04 14:19:01  Importing default detectoids succeeded.
2015-07-04 14:19:01  Creating default subscription.
2015-07-04 14:19:01  Instantiating UpdateServer
2015-07-04 14:19:03  CreateDefaultSubscription failed. Exception: System.Security.SecurityException: Request for principal permission failed.
   at Microsoft.UpdateServices.Internal.BaseApi.SoapExceptionProcessor.DeserializeAndThrow(SoapException soapException)
   at Microsoft.UpdateServices.Internal.DatabaseAccess.AdminDataAccessProxy.GetServerVersion()
   at Microsoft.UpdateServices.Internal.BaseApi.UpdateServer.CreateUpdateServer(String serverName, Boolean useSecureConnection, Int32 portNumber)
   at Microsoft.UpdateServices.Internal.BaseApi.UpdateServer..ctor(Boolean bypassApiRemoting)
   at Microsoft.UpdateServices.Setup.StartServer.StartServer.CreateDefaultSubscription()
The Zone of the assembly that failed was:
MyComputer
2015-07-04 14:19:03  StartServer encountered errors. Exception=Request for principal permission failed.
2015-07-04 14:19:03  Microsoft.UpdateServices.Administration.CommandException: Failed to start and configure the WSUS service
   at Microsoft.UpdateServices.Administration.PostInstall.Run()
   at Microsoft.UpdateServices.Administration.PostInstall.Execute(String[] arguments)

Pralhad

WSUS Disconnected server - Files not downloaded error

$
0
0

I have two WSUS servers - both Server 2003 R2 running WSUS. The first one is connected to the Internet and works without problems. The second is in a secure area with no Internet connection. The only obvious difference between the two, apart from the Internet connection, is that the offline server has its files on a seperate drive (W:\WSUS) and with the online one they are on the local drive (C:\WSUS).

I have copied all of the files from the WSUSContent directory and copied them to the equivalent directory on the offline machine - being careful not to copy the WSUScontent directory itself having read the warnings on this and other sites about permissions. I performed an export from the online server and import on the offline and all patches are shown but are marked as "File not yet downloaded" File details can be checked and files are in the correct place and can be seen in the IIS directories. I have wiped the install and repeted the process with great care, but still cannot make any progress on this.

Any help would be VERY gratefully received!

WSUS No Longer Downloading Updates

$
0
0

I deployed WSUS on Windows Server 2012 R2 since April last year and everything has been working well since then until some weeks ago when I noticed that approved updates were no longer being downloaded. The update files had accumulated to several gigabytes but the download status remained at approximately 34 MB for days.

I checked everything and no event log errors, Windows update works fine; Synchronization works fine as well on the WSUS server. I  have uninstalled and installed again twice. Removed the Windows Internal Database folder and content, changed the download location, etc and yet its not working.

Now, based on my lean approvals, I have just 42 files to download which just a over 300 MB in total, yet download status remains 0.00 MB.

Any suggestions please.


BPK


Clients cannot get windows updates from WSUS server, error id:0x8024400d

$
0
0

Hi WSUS experts

we got some clients cannot get windows updates from internal WSUS server, it get the error id 0x8024400d when check updates.

i tried many ways but no luck

1. i tried to delete the distribution folder as below, but no luck. 

Stop the "Windows Updates" service

Rename the \Windows\SoftwareDistribution folder

Restart the "Windows Updates" service

Open a Command Prompt and enter wuauclt /resetauthorization followed by wuauclt /detectnow

2. i used "windows update troubleshooter" on microsoft, it said "Thank you for running an automated troubleshooter from Microsoft, we did not detect any problems and ...."

http://windows.microsoft.com/en-us/windows/troubleshoot-problems-installing-updates#1TC=windows-7

3. Tired to re-create user profile, no luck.

4. some update logs i found, see below

2015-06-18  14:37:54:566      1184  1aec  PT    +++++++++++  PT: Synchronizing server updates  +++++++++++

2015-06-18  14:37:54:566      1184  1aec  PT      + ServiceId = {7971F918-A847-4430-9279-4A52D1EFE18D}, Server URL = https://fe2.update.microsoft.com/v6/ClientWebService/client.asmx

2015-06-18  14:37:54:566      1184  1aec  PT    WARNING: Cached cookie has expired or new PID is available

2015-06-18  14:50:36:574      1184  1aec  PT    WARNING: SyncUpdates failure, error = 0x8024400D, soap client error = 7, soap error code = 300, HTTP status code = 200

2015-06-18  14:50:36:574      1184  1aec  PT    WARNING: SOAP Fault: 0x00012c

2015-06-18  14:50:36:574      1184  1aec  PT    WARNING:     faultstring:Fault occurred

2015-06-18  14:50:36:574      1184  1aec  PT    WARNING:     ErrorCode:InvalidParameters(7)

2015-06-18  14:50:36:574      1184  1aec  PT    WARNING:     Message:parameters.OtherCachedUpdateIDs

2015-06-18  14:50:36:574      1184  1aec  PT    WARNING:     Method:"http://www.microsoft.com/SoftwareDistribution/Server/ClientWebService/SyncUpdates"

2015-06-18  14:50:36:574      1184  1aec  PT    WARNING:     ID:6bbf5af7-b7d6-4e92-8824-98fc8d122999

2015-06-18  14:50:36:574      1184  1aec  PT    WARNING: PTError: 0x8024400d

2015-06-18  14:50:36:574      1184  1aec  PT    WARNING: SyncUpdates_WithRecovery failed.: 0x8024400d

2015-06-18  14:50:36:574      1184  1aec  PT    WARNING: Sync of Updates: 0x8024400d

2015-06-18  14:50:36:574      1184  1aec  PT    WARNING: SyncServerUpdatesInternal failed: 0x8024400d

2015-06-18  14:50:36:574      1184  1aec  Agent   * WARNING: Failed to synchronize, error = 0x8024400D

2015-06-18  14:50:36:605      1184  1aec  Agent   * WARNING: Exit code = 0x8024400D

2015-06-18  14:50:36:605      1184  1aec  Agent *********

2015-06-18  14:50:36:605      1184  1aec  Agent **  END  **  Agent: Finding updates [CallerId = AutomaticUpdates]

2015-06-18  14:50:36:605      1184  1aec  Agent *************

2015-06-18  14:50:36:605      1184  1aec  Agent WARNING: WU client failed Searching for update with error 0x8024400d

2015-06-18  14:50:36:824      1184  19e8  AU    >>##  RESUMED  ## AU: Search for updates [CallId = {525A2A26-09CA-44B0-B820-F02EC51D513F}]

2015-06-18  14:50:36:824      1184  19e8  AU      # WARNING: Search callback failed, result = 0x8024400D

2015-06-18  14:50:36:824      1184  19e8  AU      # WARNING: Failed to find updates with error code 8024400D

2015-06-18  14:50:36:824      1184  19e8  AU    #########

2015-06-18  14:50:36:824      1184  19e8  AU    ##  END  ##  AU: Search for updates [CallId = {525A2A26-09CA-44B0-B820-F02EC51D513F}]

2015-06-18  14:50:36:824      1184  19e8  AU    #############

Any ideas?

thanks in advance

Bruce chen

WSUS 2012 R2 in DMZ

$
0
0

Hi We have to setup a New WSUS server in DMZ 

I wanted to check the following:

Can we deploy Server 2012 R2 / WSUS v6  and make it the Upstream server for 2 of our Windows 2008 (WSUS 3.0) server

We wish to Use the new 2012 R2 server to just get Updates from MS and then Have the existing WSUS 3.0 servers get it from the Upstream Server in Autonomous mode.

I am hoping we only need to open following ports on firewall (80/443) between the 2 existing WSUS 3.0 to the new 2012R2 WSUS 

Viewing all 12874 articles
Browse latest View live


<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>