Quantcast
Channel: WSUS forum
Viewing all 12874 articles
Browse latest View live

Install Windows Update button missing

$
0
0

Hi Team,

I have one Server 2008R2 where the "Install Updates" button is missing, so is the "check online for updates" button.

This server is part of a Group policy to download but not install updates, next to about 40 other servers which all work as expected.

(See screenshot below)


I removed the server from the GP for testing but the behavior is the same.
I found a reg key:  

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\WindowsUpdate\DisableWindowsUpdateAccess Which was set to 1, I changed that to 0 but had the same behavior.

I am out of ideas?


Updates marked as need but not displayed on client

$
0
0

Hi,

I'm using WSUS on Windows Server 2016 Standard, with clients using Windows 10 or Windows Server 2016 Standard too.

Our WSUS is configured to not download any updates, but invite client to use Microsoft Update for their downloads.

So WSUS is just referencing updates who are validated and needed.

Now, some updates are marked as required (like language pack), but clients already have the language pack and WU client didn't list the language pack as required.

So why WSUS is still maintaining this package as required (and some tohers too) ?

If someone could explain it to me, please !

Best regards,

2008R2 WSUS v3.2.7600.283 sync error starting with September 5th 2018

$
0
0

Hi,

as of today synchronization fails on our 2008 R2 v3.x WSUS (2016 v10.x WSUS synced fine!) with following error:

SoapException: Fault occurred
at System.Web.Services.Protocols.SoapHttpClientProtocol.ReadResponse(SoapClientMessage message, WebResponse response, Stream responseStream, Boolean asyncCall)
   at System.Web.Services.Protocols.SoapHttpClientProtocol.Invoke(String methodName, Object[] parameters)
   at Microsoft.UpdateServices.ServerSyncWebServices.ServerSync.ServerSyncProxy.GetUpdateData(Cookie cookie, UpdateIdentity[] updateIds)
   at Microsoft.UpdateServices.ServerSync.CatalogSyncAgentCore.WebserviceGetUpdateData(UpdateIdentity[] updateIds, List`1 allMetadata, List`1 allFileUrls, Boolean isForConfig)
   at Microsoft.UpdateServices.ServerSync.CatalogSyncAgentCore.GetUpdateDataInChunksAndImport(List`1 neededUpdates, List`1 allMetadata, List`1 allFileUrls, Boolean isConfigData)
   at Microsoft.UpdateServices.ServerSync.CatalogSyncAgentCore.ExecuteSyncProtocol(Boolean allowRedirect)

Does any one have the same problem or a solution?

Windows 10 checking for updates shows "up to date" but no updates were installed

$
0
0

When I click on "Check for Updates" on Windows 10 I get the message "Your device is up to date" which is not true since updates for July and August are not installed.

I have WSUS Server and SCCM server which uses WSUS server as Software Update Point.

I checked disk spaces on both servers, there is enough space.

Also, synchronization to MS servers is working, I see the updates on WSUS server and SCCM server, but I cannot reach them with Windows 10 PC since few days back.

I don't know what could have gone wrong.

How can I troubleshoot this ?


How to check WSUS updates status on Windows 10 Client that is configured to update from SCCM server

$
0
0

Windows 10 clients are configured to receive WSUS updates from SCCM server and this was working fine for almost a year now.

SCCM server looks fine, ADR rules are configured and Last status for today is Success.

But there are some issues on the client side in last few weeks. It seems that clients are not receiving updates. I don't see any Updates available in Software Center. I run all the Actions from Configuration Manager but it didn't help.

Other applications (which are not related to WSUS) are being received correctly.

I would like to check what is going on Client side but not sure how should I troubleshoot.

How to check WSUS updates status on a client side in this case ?


WUAUCLT.exe vs. Check for Updates

$
0
0

I'm trying to find the difference between running WUAUCLT.exe /detectnow and going into Windows Update and selecting "Check for Updates".  When doing the wuauclt command I get the following error:

Windows Update Client failed to detect with error 0x80072ee2.

But when going into Windows Update and selecting Check for updates, things work.

We don't want to have to manually check for updates so maybe understanding what the difference between the two is will help determine where the issue is.

Also to note I've already used PSExec to change the IE proxy settings to be what they need to be for the IE with the "System" account.

Thanks,

Craig

WSUS on Server 2016 - File cert verification failure.

$
0
0

Hi all,

I have install a new WSUS on Windows 2016 Server and I cannot downlad 297 Updates from Microsoft.

see log:

Quelldatei: /d/msdownload/update/software/updt/2017/02/microsoft-windows-languagefeatures-fonts-deva-package_bde110b7b9d6cc14fb41b04ff02c80c602799bfa.cab
Zieldatei: e:\WSUS\WsusContent\FA\BDE110B7B9D6CC14FB41B04FF02C80C602799BFA.cab
2017-08-02 10:10:31.699 UTC Info WsusService.4 ContentSyncAgent.ProcessBITSNotificationQueue ContentSyncAgent recieved Transferred Event for Item: 89209423-d01f-40a0-bb94-4dac48d5c6e6
2017-08-02 10:10:31.715 UTC Info WsusService.4 ContentSyncAgent.ContentSyncSPFireStateMachineEvent ContentSyncAgent firing Event: FileDownloaded for Item: 89209423-d01f-40a0-bb94-4dac48d5c6e6
2017-08-02 10:10:31.779 UTC Info WsusService.4 ContentSyncAgent.VerifyCRC filelocalpath is e:\WSUS\WsusContent\FE\E5C04F92B33CF51BBE6D7037D86EAC5FFE72EAFE.cab, additionalHash is 752777D849E178CCCAF85B3E991076D9180A584EF690BDE2D19E3F9F8ABDBE04
2017-08-02 10:10:31.779 UTC Info WsusService.4 ContentSyncAgent.VerifyCRC calculated sha1 hash is E5C04F92B33CF51BBE6D7037D86EAC5FFE72EAFE
2017-08-02 10:10:31.793 UTC Info WsusService.4 ContentSyncAgent.VerifyCRC matched sha1 hash
2017-08-02 10:10:31.793 UTC Info WsusService.4 ContentSyncAgent.VerifyCRC calculated sha2 sha256 hash is 752777D849E178CCCAF85B3E991076D9180A584EF690BDE2D19E3F9F8ABDBE04
2017-08-02 10:10:31.793 UTC Info WsusService.4 CabUtilities.CheckCertificateSignature File cert verification failed for e:\WSUS\WsusContent\FE\E5C04F92B33CF51BBE6D7037D86EAC5FFE72EAFE.cab with 2148204801
2017-08-02 10:10:31.793 UTC Warning WsusService.4 ContentSyncAgent.ProcessBITSNotificationQueue Invalid file deleted: e:\WSUS\WsusContent\FE\E5C04F92B33CF51BBE6D7037D86EAC5FFE72EAFE.cab
2017-08-02 10:10:31.793 UTC Info WsusService.4 ContentSyncAgent.ContentSyncSPFireStateMachineEvent ContentSyncAgent firing Event: FileVerificationFailed for Item: 89209423-d01f-40a0-bb94-4dac48d5c6e6
2017-08-02 10:10:31.793 UTC Info WsusService.4 EventLogEventReporter.ReportEvent EventId=364,Type=Error,Category=Synchronization,Message=Fehler beim Herunterladen der Inhaltsdatei.
Ursache: File cert verification failure.

WSUS syncs files, but never downloads

$
0
0

Hello,

OS: Windows Server 2016 Standard

I have installed WSUS according to this guideline:

https://docs.microsoft.com/en-us/windows-server/administration/windows-server-update-services/deploy/1-install-the-wsus-server-role

I have approved the required updates, but I see this:

(forum doesn't allow me to include image or links)

In "Download status" I see: "Updates needing files; 224; Downloaded: 0.00Mb of 16,901.11 Mb".

SYSTEM account has full access to the WSUS data directory. Available disk space is far more than 16Gb. No piece of software blocks writing to that directory.

Where can I find directions - what to check - to make WSUS actually download the updates?


Windows client server showing WSUS as as NULL.

$
0
0

In Clients this path not available in regedit.

HKLM\software\policies\windows\WindwosUpdate\WUServer

HKLM\software\policies\windows\WindwosUpdate\Wuerverstatus

I am getting below path:

HKLM\software\policies\windows\ 

Logs:

2018-02-0100:56:52:856404925f0cAgent  * WSUS server: <NULL>
2018-02-0100:56:52:856404925f0cAgent  * WSUS status server: <NULL>
2018-02-0100:56:52:856404925f0cAgent  * Target group: (Unassigned Computers)
2018-02-0100:56:52:856404925f0cAgent  * Windows Update access disabled: No


Remote Connection to WSUS server failed for domain user, but not for in-built Admin account

$
0
0

Hi Guys, 

I am new to WSUS services and I need help on the below issue. This forum is the only hope for me now as I can't find a solution to this nowhere else.

Scenario:

I have a primary WSUS server X set up in Domain A and secondary WSUS server Y set up in Domain B. I have developed a tool which will synchronize the updates between these server. The tool is to be run on Server Y, it will connect to local server Y and remote server X, gets all the updates from server X and publishes them in server Y.

The connection between the servers must be a secure connection and I have enabled SSL connection in Server X and installed the SSL cert on server Y.  Also the domains are not set up to trust each other. It's just the SSL cert I am using.

When I log into server Y as in-built local Admin account(computer-name\administrator) and l run the tool (double-click) then the tool is working just fine. it connects to the remote server X and does all the actions.

Issue:

When I log into server Y as a domain Y user who is a part of local Administrators group, and run the tool(double-click), it won't do anything and throws the below exception:

"Unhandled Exception: System.Security.SecurityException: Request for principal permission failed"

If i run the tool as "Run as Administrator", it connects to the local WSUS server Y but won't connect to the remote server X and throws the following exception.

"Unhandled Exception: System.Net.WebException: The request failed with HTTP status 401: Unauthorized." 

But if I run the tool as "Run as different user" and provide the inbuilt Admin credentials , it works just fine again.

one last thing, I'd like to add here is that while I am trying to access the below URL through browser from server Y

https://<Server_X_FQDN>:8531/Selfupdate/wuident.cab

I can access the file without any issue.

So, i would like to remove the above exceptions. Any help is appreciated.

Thanks.


Microsoft PKI SHA1 to SHA2 integrating HSM

$
0
0

Current Env : 1 Online issuing/root server with SHA1 .... Not integrated with HSM

New Env : 1 offline root and 1 issuing CA with SHA256 and need to integrate with HSM

In new env , we want to utilize the existing CA server by upgrading the same server to SHA256 to avoid issuing manual certificates again.

Any suggestion on what should be our approach? also provide some useful links which can help in this.

Win10 Build 1803 Clients -- Monthly Cumulative Update Not Offered (May 2018 -- KB4103721)

$
0
0

Our organization rolled Windows 10 Build 1803 (x64) out a few days ago via WSUS.  Workstations were originally running 1607 1709.  All went well!

Now, for our first patch Tuesday since the deployment, we find that none of our Windows 10 clients are properly detecting as "needing" the Cumulative update released today for Windows 10 Build 1803 (KB4103721).  Yet, if we instruct each client to check with the Microsoft Update servers directly, they do detect, download, and install the update.

I have tried stopping the Windows Update service on one of the clients, deleting the "SoftwareDistribution" folder, and re-detecting.  But this did not resolve the issue.

Any other suggestions?  Anyone else experiencing this?

Bri

WSUS server fails to sync with Critical Updates checked

$
0
0
Our WSUS server will fail to sync every time with the Critical Updates checked under classifications. Is this an issue on Microsoft's side or ours?

How to configure and install MBAM.2.5

$
0
0

Hi,

kindly share the how to download MBAM.2.5 FULL version

How to configure and install MBAM.2.5

Regards,

Abdul


Updates Needing Files downloads but doesn't change the Updates needing files count.

$
0
0

Setting up a WSUS server on 2012 R2 Server...got > 80k files downloaded and got to the last 299 files (and about 1 gig in size) and it stopped. The only way I could get it to download these files this morning was to "approve" another 14 files (Defender definitions) and when I did that it saw everything and downloaded it.

The bad part is it was still showing 299 updates needing files, even though it showed all the 9,052 MB had downloaded. I re-synchronized and it again downloaded the 299 files and showed it had completed all, but once again showed 299 updates still needed files. I've got it going one more time now...and even though it's showing downloads happening (can even see it in the network traffic on the card) the counter for number of files never changes.

This is my first WSUS server...so I'm a little unsure where to go from here. Any ideas?


Joe Raymond


Feature update to Windows 10 (consumer edition), version 1709 and 1803 fails with an error when using WSUS to update a computer

$
0
0


Hi everyone, 

I've deployed WSUS on Windows 2012 R2 server. After initial synchronization and approval/download of updates, computers installed all of them without issues except those two updates. Computers can download them from WSUS but they fail immediately after <g class="gr_ gr_35 gr-alert gr_gramm gr_inline_cards gr_run_anim Grammar only-ins replaceWithoutSep" data-gr-id="35" id="35">installation</g> process. I’ve tested it on a laptop with win10 pro OS and a virtual machine with win10pro.

1709 fails with Error 0x80070032 

1803 fails with Error 0xc1900130

In the Event Viewer on the client <g class="gr_ gr_39 gr-alert gr_gramm gr_inline_cards gr_run_anim Punctuation only-ins replaceWithoutSep" data-gr-id="39" id="39">machines</g> I get Windows Error Reporting > Event Name: WindowsUpdateFailure3

WSUS server setup(only one WSUS server with WID)

Update Source and Proxy Server

Update Source:

Sync from Microsoft Update

Products and Classifications

Products:

Windows 10 Dynamic Update

Windows 10

Classifications

<Everything except drivers>

Update Files and Languages

Update Files:

Store update file locally on this server

Download update file to this server only when updates are approved

WSUS version – 6.3.9600.18838, port 8530

2012R2 server has <g class="gr_ gr_36 gr-alert gr_gramm gr_inline_cards gr_run_anim Grammar only-ins replaceWithoutSep" data-gr-id="36" id="36">latest</g> windows updates

Windows firewall is disabled 

I've set the MIME type on the IIS Server for the .esd, application/octet-stream

Restarted IIS Website

Restarted WSUS service

I’ve tried setting up WSUS on Windows server 2016 – the same <g class="gr_ gr_38 gr-alert gr_gramm gr_inline_cards gr_run_anim Punctuation only-del replaceWithoutSep" data-gr-id="38" id="38">issue,</g> stuck on 1709 update. Ran Windows Update Troubleshooter on client machines numerous times, did not help.

Tried running manually (did not help):

net stop <g class="gr_ gr_79 gr-alert gr_spell gr_inline_cards gr_run_anim ContextualSpelling" data-gr-id="79" id="79">wuauserv</g>

net stop <g class="gr_ gr_77 gr-alert gr_spell gr_inline_cards gr_run_anim ContextualSpelling ins-del multiReplace" data-gr-id="77" id="77">cryptSvc</g>

net stop bits

net stop <g class="gr_ gr_80 gr-alert gr_spell gr_inline_cards gr_run_anim ContextualSpelling" data-gr-id="80" id="80">msiserver</g>

ren C:\Windows\SoftwareDistribution SoftwareDistribution.old

ren C:\Windows\System32\catroot2 Catroot2.old

net start <g class="gr_ gr_81 gr-alert gr_spell gr_inline_cards gr_run_anim ContextualSpelling" data-gr-id="81" id="81">wuauserv</g>

net start <g class="gr_ gr_78 gr-alert gr_spell gr_inline_cards gr_run_anim ContextualSpelling ins-del multiReplace" data-gr-id="78" id="78">cryptSvc</g>

net start bits

net start <g class="gr_ gr_130 gr-alert gr_spell gr_inline_cards gr_run_anim ContextualSpelling" data-gr-id="130" id="130">msiserver</g>

   

Tried installing KB articles as per:

https://social.technet.microsoft.com/Forums/en-US/1b14f88f-3358-4cec-a210-c697763e09b6/wsus-on-w2k12r2-getting-windowsupdatefailure3-event-id-1001-and-error-code-80244018?forum=winserverwsus

KB3159706, KB3095113 – getting “This update is not applicable to your computer”

Tried all other suggestions from the same article, did not help, Server Cleanup Wizard, Re-Indexing the database…etc

Getting desperate at this point, anyone has any suggestions for what to try next or how to fix this? Thanks in advance!

 

 


Windows 2008 R2 updates not working since 16th July 2018 - failed status

$
0
0

Hi,

Can anyone help? Since 16th July 2018, my windows updates are no longer being installed on my Windows 2008 R2 server. This seems to correspond since KB890830 was installed in Jully, however the August KB890830 update did install. Screenshot below of updates which are failing. Any ideas how I resolve?

Updates failing to install are

KB4339093

KB4338818

KB4340556

KB4339093

Plus a whole host more.

Kind regards

Daf

Selecting product Office 2016 causes sync failure

$
0
0

I'm have SCCM 1802 and WSUS installed on a fully patched Windows Server 2012R2 VM. The Software Update Point role is installed and synchronizations work fine except if I select the product Office 2016. Selecting other versions of Office (2010, 2013) work but not 2016.

If I select Office 2016, these errors appear in wsyncmgr.log:

Sync failed: UssInternalError: SoapException: Fault occurred~~at System.Web.Services.Protocols.SoapHttpClientProtocol.ReadResponse(SoapClientMessage message, WebResponse response, Stream responseStream, Boolean asyncCall). Source: Microsoft.SystemsManagementServer.SoftwareUpdatesManagement.WsusSyncAction.WSyncAction.SyncWSUS
STATMSG: ID=6703 SEV=E LEV=M SOURCE="SMS Server" COMP="SMS_WSUS_SYNC_MANAGER" SYS=[SCCM-SERVER.FQDN] SITE=XXX PID=2012 TID=3404 GMTDATE=Thu Sep 06 20:56:32.583 2018 ISTR0="Microsoft.SystemsManagementServer.SoftwareUpdatesManagement.WsusSyncAction.WSyncAction.SyncWSUS" ISTR1="UssInternalError: SoapException: Fault occurred~~at System.Web.Services.Protocols.SoapHttpClientProtocol.ReadResponse(SoapClientMessage message, WebResponse response, Stream responseStream, Boolean asyncCall)" ISTR2="" ISTR3="" ISTR4="" ISTR5="" ISTR6="" ISTR7="" ISTR8="" ISTR9="" NUMATTRS=0
Sync failed. Will retry in 60 minutes

This is an excerpt from SoftwareDistribution.log

2018-09-06 20:56:29.801 UTC	Error	WsusService.53	SoapUtilities.LogException	USS ThrowException: Actor = https://fe2.update.microsoft.com/v6/ServerSyncWebService/ServerSyncWebService.asmx, Method = "http://www.microsoft.com/SoftwareDistribution/GetUpdateData", ID=7d349caf-0978-42cd-9460-e45ca5ec57a7, ErrorCode=InternalServerError, Message=
   at Microsoft.UpdateServices.Internal.SoapUtilities.LogException(SoapException e)
   at Microsoft.UpdateServices.Internal.WebServiceCommunicationHelper.ProcessWebServiceProxyException(SoapHttpClientProtocol& webServiceObject, Exception exceptionInfo)
   at Microsoft.UpdateServices.ServerSync.CatalogSyncAgentCore.WebserviceGetUpdateData(UpdateIdentity[] updateIds, List`1 allMetadata, List`1 allFileUrls, List`1& updatesWithSecureFileData, Boolean isForConfig)
   at Microsoft.UpdateServices.ServerSync.CatalogSyncAgentCore.GetUpdateDataInChunksAndImport(List`1 neededUpdates, List`1 allMetadata, List`1 allFileUrls, Boolean isConfigData)
   at Microsoft.UpdateServices.ServerSync.CatalogSyncAgentCore.ExecuteSyncProtocol(Boolean allowRedirect)
   at Microsoft.UpdateServices.ServerSync.CatalogSyncAgentCore.CatalogSyncThreadProcess()
   at System.Threading.ExecutionContext.RunInternal(ExecutionContext executionContext, ContextCallback callback, Object state, Boolean preserveSyncCtx)
   at System.Threading.ExecutionContext.Run(ExecutionContext executionContext, ContextCallback callback, Object state, Boolean preserveSyncCtx)
   at System.Threading.ExecutionContext.Run(ExecutionContext executionContext, ContextCallback callback, Object state)
   at System.Threading.ThreadHelper.ThreadStart()
2018-09-06 20:56:29.801 UTC	Error	WsusService.53	SoapUtilities.LogException	USS ThrowException: Actor = https://fe2.update.microsoft.com/v6/ServerSyncWebService/ServerSyncWebService.asmx, Method = "http://www.microsoft.com/SoftwareDistribution/GetUpdateData", ID=7d349caf-0978-42cd-9460-e45ca5ec57a7, ErrorCode=InternalServerError, Message=
   at Microsoft.UpdateServices.Internal.SoapUtilities.LogException(SoapException e)
   at Microsoft.UpdateServices.ServerSync.CatalogSyncAgentCore.ExecuteSyncProtocol(Boolean allowRedirect)
   at Microsoft.UpdateServices.ServerSync.CatalogSyncAgentCore.CatalogSyncThreadProcess()
   at System.Threading.ExecutionContext.RunInternal(ExecutionContext executionContext, ContextCallback callback, Object state, Boolean preserveSyncCtx)
   at System.Threading.ExecutionContext.Run(ExecutionContext executionContext, ContextCallback callback, Object state, Boolean preserveSyncCtx)
   at System.Threading.ExecutionContext.Run(ExecutionContext executionContext, ContextCallback callback, Object state)
   at System.Threading.ThreadHelper.ThreadStart()
2018-09-06 20:56:29.801 UTC	Info	WsusService.53	CatalogSyncAgentCore.UpdateSyncResultAndGenerateReportingEvent	CatalogSyncThreadProcess: report subscription USS internal error
2018-09-06 20:56:29.801 UTC	Info	WsusService.53	EventLogEventReporter.ReportEvent	EventId=386,Type=Error,Category=Synchronization,Message=Synchronization failed. Reason: Fault occurred.
2018-09-06 20:56:29.801 UTC	Info	WsusService.50	ThreadEntry	ThreadHelper.ThreadStart
2018-09-06 20:56:29.801 UTC	Info	WsusService.50	CatalogSyncAgent.WaitUntilSyncFinishedOrCancelled	Agent signalled done.
2018-09-06 20:56:29.801 UTC	Info	WsusService.50	CatalogSyncAgent.SetSubscriptionStateWithRetry	Firing event SyncFailToStart...
2018-09-06 20:56:29.817 UTC	Info	WsusService.50	CatalogSyncAgent.WakeUpWorkerThreadProc	Found no more jobs. CatalogSyncAgent quits but will run rollup before terminating ...
2018-09-06 20:56:29.817 UTC	Info	WsusService.50	CatalogSyncAgent.UpdateServerHealthStatusBasedOnError	ServerHealth: Updating Server Health for Component: CatalogSyncAgent, Marking as Not Running

I've tried running wsusutil.exe reset but it doesn't make any difference. I removed SUP role, uninstalled WSUS then added WSUS and SUP role again, this also didn't make a difference.

I do not have the Upgrades classification selected.

Any suggestions?


Windows 10 Cu updates

$
0
0

Hi,

multiple Cumulative updates 

Is there any way to automatically deny old cumulative update and keep the latest only ?

Thanks 

Windows 10 1803 Language Pack , Language Interface Pack and Feature On Demand (FOD) support in WSUS

$
0
0
I don't see those in WSUS as non-dynamic Updates as with previous versions and cannot install them on clients as before. Installation during Upgrades works as expected, but not afterwards. Is there an announcement for the schedule ?

Viewing all 12874 articles
Browse latest View live


<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>