Quantcast
Channel: WSUS forum
Viewing all 12874 articles
Browse latest View live

0x800706BE WUA ERROR

$
0
0

Hi,

I have Windows Server 2016 having this WUA error 0x800706BE

I am thinking that Resetting Microsoft Windows Update Components can fix this. 

https://support.microsoft.com/en-ca/help/971058/how-do-i-reset-windows-update-components

On step 11, it requires to reinstall Windows Update Agent, where can I download the Windows Update Agent for Windows Server 2016?


Thanks in advance!


Windows Server 2016 - WSUS Clients - WindowsUpdateFailure3, 1001, 0x8024500c

$
0
0
I've looked at everything I know to look at.

The WSUS Server itself is running Windows Server 2016 DataCenter.

The clients on our network are Windows 7 Enterprise, Windows 7 Professional, Windows 10 Professional, Windows 10 Enterprise, Windows Server 2016 Standard, Windows Server 2016 DataCenter and Windows Server 2008 R2 DataCenter.

Only my Windows Server 2016 clients are having this issue.

I've tried clearing the SoftwareDistrib folder, reregistering DLLs, re-indexing the SQL database, rebooting several times, etc.

Our AD Group Policies are as such that INTERnet-based WSUS are prohibited as we want all updates to come from the local server.

The WSUS server itself shows no signs of sync issues or issues downloading the actual updates.  I am at an absolute loss here.

****

Fault bucket 127883099475, type 5
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 10.0.14393.1198
P2: 8024500c
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 0
P7: 8024500b
P8: UpdateOrchestrator
P9: {9482F4B4-E343-43B6-B170-9A65BC822C77}
P10: 0

Attached files:

These files may be available here:
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\NonCritical_10.0.14393.1198_802d6847332aebf619279c14e8638fd2125bcdcc_00000000_1bf75f67

Analysis symbol: 
Rechecking for solution: 0
Report Id: 2aeac304-5ab2-11e7-90f5-70106fbf9c86
Report Status: 0
Hashed bucket: d1dff83bf57fb9291a38c9f8b68fde52


****

WER File Output

Version=1
EventType=WindowsUpdateFailure3
EventTime=131416677960233426
Consent=1
UploadTime=131429845363147214
ReportIdentifier=f50bdb53-4eb8-11e7-90ef-70106fbf9c86
AppSessionGuid=00000594-0000-0010-960c-34eea1cdd201
TargetAppId=W:0000f519feec486de87ed73cb92d3cac802400000000!00000dac68816ae7c09efc24d11c27c3274dfd147dee!svchost.exe
TargetAppVer=2016//07//16:02:25:32!d1ac!svchost.exe
BootId=4294967295
Response.type=4
Sig[0].Name=ClientVersion
Sig[0].Value=10.0.14393.1066
Sig[1].Name=Win32HResult
Sig[1].Value=8024402f
Sig[2].Name=UpdateID
Sig[2].Value=00000000-0000-0000-0000-000000000000
Sig[3].Name=Scenario
Sig[3].Value=Scan
Sig[4].Name=RevisionID
Sig[4].Value=0
Sig[5].Name=IsManaged
Sig[5].Value=0
Sig[6].Name=LastError
Sig[6].Value=801901f6
Sig[7].Name=CallerAppID
Sig[7].Value=UpdateOrchestrator
Sig[8].Name=ServiceUsed
Sig[8].Value={7971F918-A847-4430-9279-4A52D1EFE18D}
Sig[9].Name=MiscField2
Sig[9].Value=0
DynamicSig[1].Name=OS Version
DynamicSig[1].Value=10.0.14393.2.0.0.272.7
DynamicSig[2].Name=Locale ID
DynamicSig[2].Value=1033
State[0].Key=Transport.DoneStage1
State[0].Value=1
FriendlyEventName=Windows Update installation problem
ConsentKey=WindowsUpdateFailure3
AppName=Host Process for Windows Services
AppPath=C:\Windows\System32\svchost.exe
ReportDescription=A Windows update did not install properly. Sending the following information to Microsoft can help improve the software.
ApplicationIdentity=00000000000000000000000000000000
MetadataHash=410089339


WSUS 2019 Downstreamserver bug - Downstream Computers not available on Upstream

$
0
0

Hello,

I think there might be an issue with downstream servers in server wsus 2019.

First I did update my main WSUS to 2019. All Downstream were 2016. After that I was not able to view the complete computer list on the main server. As soon as you choose the “All Computers” or a computer group that is from a downstream server the console crashes. When you delete the downstream server from the “Downstream Servers” section I am able to browse the list again.

After that I decided to reinstall all WSUS Servers with server 2019 even including the main one. And I did again get the error.

Tried it via Powershell gives me the following error.

$wsusserver = "localhost"
[reflection.assembly]::LoadWithPartialName("Microsoft.UpdateServices.Administration")
$wsus = [Microsoft.UpdateServices.Administration.AdminProxy]::getUpdateServer($wsusserver,$False)
$computerScope = New-object Microsoft.UpdateServices.Administration.ComputerTargetScope
$computerScope.IncludeDownstreamComputerTargets = $true
$wsus.GetComputerTargets($computerScope)

Exception calling "GetComputerTargets" with "1" argument(s):"Unable to cast object of type 'System.Guid' to type 'System.String'."

At line:1 char:1

If I choose to not include Downstream Computer Targets it works.

Need Help Generating a PFX file

$
0
0

Evening!

I'm coming from a OpenSSL experience, so I need help in the windows world.

Windows Server is 2008 R2
I have some servers that I need to generate P12/PFX files.
I open MMC, add the Certificates snap-in and select local computer
I then go to Personal, but there is no subfolder called 'Certificates'
I assume it does not have any personal certificates installed.
I installed IIS 7 and created a REQ.
I submitted this REQ to our CA and got my CRT back.

In the OpenSSL world, when I generate a CSR request, it also generates a KEY file.
The KEY file is what allows me to generate a P12 when I get the CRT back from our CA

So how do I do this in the Windows world? I have the CRT and I even grabbed the P7b, but without the KEY file I am unable to generate the PFX/P12.


v/r

Joe

Adobe Flash Player Update - KB4480979

$
0
0

KB4480979 will not install due to Flash Player not being fully uninstalled leaving artifacts of a previous install. Apparently, for Server 2012r2 there is not a independent install/uninstall module. With that, Nessus vulnerabilities keeps popping because 1) it thinks Adobe is installed and 2) KB4480979 and other Adobe patches have not been installed. Adobe, the company, indicates that

"Microsoft embeds Flash Player for IE/Edge in Server 2012 and ALL Flash Player updates for IE/Edge are distributed by Microsoft via Windows Updates, thus you would to need to run Windows Updates to update Flash Player for IE/Edge on Server 2012." and

"Adobe has had this relationship with Microsoft since Windows 8 was released.  It's not a new process. Adobe provides Microsoft with the files and Microsoft integrate them with their product (IE/Edge) and their update mechanism.  Adobe has nothing to do with Microsoft's update mechanism, how it works, how it detects which updates to install, etc. .  If you're having difficulties installing a Microsoft Update, please contact Microsoft for assistance."

Thus, I am need of a method to fully install Adobe independently on Server 2012r2, then properly disable such that the patching will work or have a method to properly uninstall it such that no artifacts remain.  In some instances, disabling Desktop Experience corrects the problem but because my enclave was incorrectly managed on this matter, all the servers are not baseline.  This is why I am preferring to totally install it fully at this juncture then apply the mitigating remedy.

Please advise.

Servers are not moving into specific groups

$
0
0

Hello everyone,

Since November 2K18 I am deploying WSUS solution, but since last week I am facing another challenge and it is the problem that servers are not moving from Unassigned Computers or from other groups. 

Let me briefly show you the settings I am using and which are relevant for this case.

Enable-Side Targeting = Not using for specific Reasons.

1 - Master server and 1 Replica DownStream.....

And now describtion of the problem

I added 10 servers with following settings ... (Main WSUS download = Replica Downstream, Alternative = Master WSUS)

After Servers shows in Replica Console I moved them into specific groups like Windows Servers 2016 , etc ... then I pushed synchronization from WSUS Replica. After these steps, I opened console at Master WSUS to check if servers are in correct groups. 7 of them moved correctly, but 3 of them have not moved .. most of those problematic servers are 2016 Standart edition. 

Do you please guys have any idea, why some servers are not moving and some of them yes? (This issue is not just related to the Unassigned Computer group)



How to reinstall WSUS 3.0 in RODC (windows 2012)

$
0
0

Hi,

I'm trying to REINSTALL WSUS 3.0 in RODC (windows 2012). But I can't past the post installation and always getting the error:

2019-01-24 14:38:43  Postinstall started

2019-01-24 14:38:43  Detected role services: UI, WidDatabase, Services

2019-01-24 14:38:43  Start: LoadSettingsFromParameters

2019-01-24 14:38:43  Content local is: True

2019-01-24 14:38:43  Content directory is: c:\WSUS

2019-01-24 14:38:43  SQL instname is:

2019-01-24 14:38:43  End: LoadSettingsFromParameters

2019-01-24 14:38:43  Start: Run

2019-01-24 14:38:43  Configuring content directory...

2019-01-24 14:38:43  Configuring groups...

2019-01-24 14:38:43  Starting group configuration for WSUS Administrators...

2019-01-24 14:38:43  Group does not already exist in the registry

2019-01-24 14:38:43  Searching for existing group...

2019-01-24 14:40:28  Group was not fount attempt to create it...

2019-01-24 14:40:28  System.DirectoryServices.AccountManagement.PrincipalOperationException: The group already exists.

---> System.Runtime.InteropServices.COMException: The group already exists.

 

   at System.DirectoryServices.DirectoryEntry.CommitChanges()

   at System.DirectoryServices.AccountManagement.SDSUtils.ApplyChangesToDirectory(Principal p, StoreCtx storeCtx, GroupMembershipUpdater updateGroupMembership, NetCred credentials, AuthenticationTypes authTypes)

   --- End of inner exception stack trace ---

   at System.DirectoryServices.AccountManagement.SDSUtils.ApplyChangesToDirectory(Principal p, StoreCtx storeCtx, GroupMembershipUpdater updateGroupMembership, NetCred credentials, AuthenticationTypes authTypes)

   at System.DirectoryServices.AccountManagement.SDSUtils.InsertPrincipal(Principal p, StoreCtx storeCtx, GroupMembershipUpdater updateGroupMembership, NetCred credentials, AuthenticationTypes authTypes, Boolean needToSetPassword)

   at System.DirectoryServices.AccountManagement.SAMStoreCtx.Insert(Principal p)

   at Microsoft.UpdateServices.Administration.ConfigureGroups.FetchOrCreateGroup(PrincipalContext context, String name, String description)

   at Microsoft.UpdateServices.Administration.ConfigureGroups.SetupGroup(PrincipalContext context, String groupName, String description, String registryValue)

   at Microsoft.UpdateServices.Administration.ConfigureGroups.Run(Action`1 logWriter)

   at Microsoft.UpdateServices.Administration.PostInstall.Run()

   at Microsoft.UpdateServices.Administration.PostInstall.Execute(String[] arguments)


I already have the groups needed in RWDC.

1.      SQLServer2005MSFTEUser$Servername$Microsoft##SSEE

2.      SQLServer2005MSSQLUser$Servername$Microsoft##SSEE

3.      WSUS Administrators

4.      WSUS  Reporters

Already uninstalled IIS and WSUS, still no luck. Can some help me figure out this or send me step by step configuration for this. Thanks in advance.

Possible to select Windows upate server location depends on IP address ?

$
0
0

Hi,

As title, compnay have some laptop pc for management grade staffs use but not always in office.

I would like to monitor their update status from WSUS. But those laptop pc not always connect to company network.

Thus, they may not get the latest update constantly.

Therefore, is possible to configure to let those laptop pc update from internal WSUS and MS server if under different network ?


Thanks


Client-Side Targeting theory question

$
0
0

Hello!

Please help me to understand the following:

- why do I need to (manually) "add domain-member computers to that group" if the purpose of the Enable client-side targeting setting is to enable client computerto add themselves to the computer group(s) created on WSUS?

In other words, shouldn't it be enough to specify the name of the computer group in the Enable client-side targeting policy setting to auto-populate the computer group (for example Test Computers) on the WSUS server?

Thank you in advance,
Michael

Clients cannot download updates - fail Sync of Updates: 0x8024400d

$
0
0

Hello

I have many clients thats hav ebeen migrated to a different WSUS server and are not downloading updates, I have checkd the softwaredistribution log on the WSUS server and found the errors highlighted in bold,italic and underlined.

2017-08-07 13:30:03.274 UTC Warning w3wp.182 SoapUtilities.CreateException ThrowException: actor = https://MyServerName:8531/ClientWebService/client.asmx, ID=6cc34721-e75e-48ad-a9c4-8f162462661d, ErrorCode=InvalidParameters, Message=parameters.OtherCachedUpdateIDs, Client=750c86a9-fc38-4a9b-ba3e-0a4812a5c0b0
2017-08-07 13:30:12.149 UTC Info w3wp.187 ThreadEntry ThreadPoolWorkQueue.Dispatch
2017-08-07 13:30:12.149 UTC Warning w3wp.187 SoapUtilities.CreateException ThrowException: actor = https://MyServerName:8531/ClientWebService/client.asmx, ID=6de90e3f-14b5-4e2c-8ff0-85ad68003ea3, ErrorCode=InvalidParameters, Message=parameters.OtherCachedUpdateIDs, Client=1bcf222f-fe95-4c8e-a8cd-b1730bc9b84d
Start to poll cloud proxy service tasks from DB
TaskManager: 0 task(s) running, 1 task(s) waiting to start.
TaskWorker: Starting task: [CloudServicesTaskBuilder]
CloudServicesTaskBuilder: Starting.
CloudServicesTaskBuilder: Stopping.
TaskManager: 1 task(s) running, 0 task(s) waiting to start.
TaskManager: Task [CloudServicesTaskBuilder] status is RanToCompletion
TaskManager: Removing task [CloudServicesTaskBuilder] from running tasks.
2017-08-07 13:30:29.876 UTC Warning w3wp.191 SoapUtilities.CreateException ThrowException: actor = https://MyServerName:8531/ClientWebService/client.asmx, ID=8b12f7b3-5017-4284-bad8-a301435f716b, ErrorCode=InvalidParameters, Message=parameters.OtherCachedUpdateIDs, Client=1a69eb00-8faf-4947-8017-90a1ccdb7038
Maintaining connections...
There are 10 Tcp connections eastablished with proxy server MYCLOUDSERVER:10140
Wait 60 seconds to rescan the connections...
2017-08-07 13:30:44.376 UTC Warning w3wp.238 SoapUtilities.CreateException ThrowException: actor = https://MyServerName:8531/ClientWebService/client.asmx, ID=7bb2f603-5db3-498a-8fdc-b31fc437899c, ErrorCode=InvalidParameters, Message=parameters.OtherCachedUpdateIDs, Client=27b40b27-d6f0-4627-8d18-cac3ac11394f
Running Telemetry queries.
Found 0 telemetry queries to run.
Found 0 telemetry counts to run.
Successfully run 0 Telemetry queries.
2017-08-07 13:31:07.691 UTC Warning w3wp.174 SoapUtilities.CreateException ThrowException: actor = https://MyServerName:8531/ClientWebService/client.asmx, ID=d2bb4473-d3bc-4998-8618-b2afba9d3cd1, ErrorCode=InvalidParameters, Message=parameters.OtherCachedUpdateIDs, Client=750c86a9-fc38-4a9b-ba3e-0a4812a5c0b0
2017-08-07 13:31:14.255 UTC Warning w3wp.185 SoapUtilities.CreateException ThrowException: actor = https://MyServerName:8531/ClientWebService/client.asmx, ID=38e13a0e-a82f-485b-9bf8-2cd60e6bf3e7, ErrorCode=InvalidParameters, Message=parameters.OtherCachedUpdateIDs, Client=44d691cc-0513-48ff-a7c5-eb9e83a241e

ERROR LOG FROM CLIENT WINDOWSUPDATE.LOG

2017-08-07 15:54:36:369 1044 18fc AU ##  END  ##  AU: Search for updates [CallId = {C8D1B55F-1FCB-4B1A-A9FA-308087C7F50A}]
2017-08-07 15:54:36:369 1044 18fc AU #############
2017-08-07 15:54:36:379 1044 18fc AU Successfully wrote event for AU health state:0
2017-08-07 15:54:36:379 1044 18fc AU AU setting next detection timeout to 2017-08-07 18:54:36
2017-08-07 15:54:36:379 1044 18fc AU Setting AU scheduled install time to 2017-08-08 01:00:00
2017-08-07 15:54:36:379 1044 18fc AU Successfully wrote event for AU health state:0
2017-08-07 15:54:36:379 1044 18fc AU Successfully wrote event for AU health state:0
2017-08-07 15:54:41:351 1044 1a88 Report REPORT EVENT: {62FD1305-F3AF-46FA-AFE1-1D18AB78784A} 2017-08-07 15:54:36:349+0200 1 148 101 {00000000-0000-0000-0000-000000000000} 0 8024400d AutomaticUpdates Failure Software Synchronization Windows Update Client failed to detect with error 0x8024400d.
2017-08-07 15:54:41:381 1044 1a88 Report CWERReporter::HandleEvents - WER report upload completed with status 0x8
2017-08-07 15:54:41:381 1044 1a88 Report WER Report sent: 7.6.7601.23806 0x8024400d(0) 0000000-0000-0000-0000-000000000000 Scan 0 1 AutomaticUpdates {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7} 0
2017-08-07 15:58:37:208 9476 2368 COMAPI -------------
2017-08-07 15:58:37:208 9476 2368 COMAPI -- START --  COMAPI: Search [ClientId = CcmExec]
2017-08-07 15:58:37:208 9476 2368 COMAPI ---------
2017-08-07 15:58:37:213 1044 1a88 Agent *************
2017-08-07 15:58:37:213 1044 1a88 Agent ** START **  Agent: Finding updates [CallerId = CcmExec]
2017-08-07 15:58:37:213 9476 2368 COMAPI <<-- SUBMITTED -- COMAPI: Search [ClientId = CcmExec]
2017-08-07 15:58:37:213 1044 1a88 Agent *********
2017-08-07 15:58:37:213 1044 1a88 Agent   * Include potentially superseded updates
2017-08-07 15:58:37:213 1044 1a88 Agent   * Online = Yes; Ignore download priority = Yes
2017-08-07 15:58:37:213 1044 1a88 Agent   * Criteria = "(DeploymentAction=* AND Type='Software') OR (DeploymentAction=* AND Type='Driver')"
2017-08-07 15:58:37:213 1044 1a88 Agent   * ServiceID = {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7} Managed
2017-08-07 15:58:37:213 1044 1a88 Agent   * Search Scope = {Machine}
2017-08-07 15:58:37:647 1044 1a88 PT +++++++++++  PT: Synchronizing server updates  +++++++++++
2017-08-07 15:58:37:647 1044 1a88 PT   + ServiceId = {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}, Server URL = https://myservername:8531/ClientWebService/client.asmx
2017-08-07 15:58:37:662 1044 1a88 PT WARNING: Cached cookie has expired or new PID is available
2017-08-07 15:58:37:662 1044 1a88 PT Initializing simple targeting cookie, clientId = 750c86a9-fc38-4a9b-ba3e-0a4812a5c0b0, target group = , DNS name = nloinb382.intleurope.imptobnet.com
2017-08-07 15:58:37:662 1044 1a88 PT   Server URL = https://myservername:8531/SimpleAuthWebService/SimpleAuth.asmx
2017-08-07 15:58:39:775 1044 1a88 PT WARNING: SyncUpdates failure, error = 0x8024400D, soap client error = 7, soap error code = 300, HTTP status code = 200
2017-08-07 15:58:39:775 1044 1a88 PT WARNING: SOAP Fault: 0x00012c
2017-08-07 15:58:39:776 1044 1a88 PT WARNING:     faultstring:Fault occurred
2017-08-07 15:58:39:776 1044 1a88 PT WARNING:     ErrorCode:InvalidParameters(7)
2017-08-07 15:58:39:776 1044 1a88 PT WARNING:     Message:parameters.OtherCachedUpdateIDs
2017-08-07 15:58:39:776 1044 1a88 PT WARNING:     Method:"http://www.microsoft.com/SoftwareDistribution/Server/ClientWebService/SyncUpdates"
2017-08-07 15:58:39:776 1044 1a88 PT WARNING:     ID:130c7164-be39-4eec-8d66-4f7138bfa716
2017-08-07 15:58:39:776 1044 1a88 PT WARNING: PTError: 0x8024400d
2017-08-07 15:58:39:776 1044 1a88 PT WARNING: SyncUpdates_WithRecovery failed.: 0x8024400d
2017-08-07 15:58:39:776 1044 1a88 PT WARNING: Sync of Updates: 0x8024400d
2017-08-07 15:58:39:776 1044 1a88 PT WARNING: SyncServerUpdatesInternal failed: 0x8024400d
2017-08-07 15:58:39:776 1044 1a88 Agent   * WARNING: Failed to synchronize, error = 0x8024400D
2017-08-07 15:58:39:779 1044 1a88 Agent   * WARNING: Exit code = 0x8024400D
2017-08-07 15:58:39:779 1044 1a88 Agent *********
2017-08-07 15:58:39:779 1044 1a88 Agent **  END  **  Agent: Finding updates [CallerId = CcmExec]
2017-08-07 15:58:39:779 1044 1a88 Agent *************
2017-08-07 15:58:39:779 1044 1a88 Agent WARNING: WU client failed Searching for update with error 0x8024400d
2017-08-07 15:58:39:797 9476 2368 COMAPI >>--  RESUMED  -- COMAPI: Search [ClientId = CcmExec]
2017-08-07 15:58:39:798 9476 2368 COMAPI   - Updates found = 0
2017-08-07 15:58:39:798 9476 2368 COMAPI   - WARNING: Exit code = 0x00000000, Result code = 0x8024400D
2017-08-07 15:58:39:798 9476 2368 COMAPI ---------
2017-08-07 15:58:39:798 9476 2368 COMAPI --  END  --  COMAPI: Search [ClientId = CcmExec]
2017-08-07 15:58:39:798 9476 2368 COMAPI -------------
2017-08-07 15:58:39:799 9476 2368 COMAPI WARNING: Operation failed due to earlier error, hr=8024400D
2017-08-07 15:58:39:799 9476 2368 COMAPI FATAL: Unable to complete asynchronous search. (hr=8024400D)
2017-08-07 15:58:44:780 1044 1a88 Report REPORT EVENT: {1832479A-C11E-4A0B-916D-347DE82E052F} 2017-08-07 15:58:39:777+0200 1 148 101 {00000000-0000-0000-0000-000000000000} 0 8024400d CcmExec Failure Software Synchronization Windows Update Client failed to detect with error 0x8024400d.
2017-08-07 15:58:44:820 1044 1a88 Report CWERReporter::HandleEvents - WER report upload completed with status 0x8
2017-08-07 15:58:44:820 1044 1a88 Report WER Report sent: 7.6.7601.23806 0x8024400d(0) 0000000-0000-0000-0000-000000000000 Scan 0 1 CcmExec {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7} 0
2017-08-07 15:58:58:914 9476 2368 COMAPI -------------
2017-08-07 15:58:58:914 9476 2368 COMAPI -- START --  COMAPI: Search [ClientId = CcmExec]
2017-08-07 15:58:58:914 9476 2368 COMAPI ---------
2017-08-07 15:58:58:917 1044 1a88 Agent *************
2017-08-07 15:58:58:917 1044 1a88 Agent ** START **  Agent: Finding updates [CallerId = CcmExec]
2017-08-07 15:58:58:917 9476 2368 COMAPI <<-- SUBMITTED -- COMAPI: Search [ClientId = CcmExec]
2017-08-07 15:58:58:917 1044 1a88 Agent *********
2017-08-07 15:58:58:917 1044 1a88 Agent   * Include potentially superseded updates
2017-08-07 15:58:58:917 1044 1a88 Agent   * Online = Yes; Ignore download priority = Yes
2017-08-07 15:58:58:917 1044 1a88 Agent   * Criteria = "(DeploymentAction=* AND Type='Software') OR (DeploymentAction=* AND Type='Driver')"
2017-08-07 15:58:58:917 1044 1a88 Agent   * ServiceID = {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7} Managed
2017-08-07 15:58:58:917 1044 1a88 Agent   * Search Scope = {Machine}
2017-08-07 15:58:59:323 1044 1a88 PT +++++++++++  PT: Synchronizing server updates  +++++++++++
2017-08-07 15:58:59:323 1044 1a88 PT   + ServiceId = {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}, Server URL = https://myservername:8531/ClientWebService/client.asmx
2017-08-07 15:58:59:332 1044 1a88 PT WARNING: Cached cookie has expired or new PID is available
2017-08-07 15:58:59:332 1044 1a88 PT Initializing simple targeting cookie, clientId = 750c86a9-fc38-4a9b-ba3e-0a4812a5c0b0, target group = , DNS name = nloinb382.intleurope.imptobnet.com
2017-08-07 15:58:59:332 1044 1a88 PT   Server URL = https://myservername:8531/SimpleAuthWebService/SimpleAuth.asmx
2017-08-07 15:59:01:458 1044 1a88 PT WARNING: SyncUpdates failure, error = 0x8024400D, soap client error = 7, soap error code = 300, HTTP status code = 200
2017-08-07 15:59:01:458 1044 1a88 PT WARNING: SOAP Fault: 0x00012c
2017-08-07 15:59:01:458 1044 1a88 PT WARNING:     faultstring:Fault occurred
2017-08-07 15:59:01:458 1044 1a88 PT WARNING:     ErrorCode:InvalidParameters(7)
2017-08-07 15:59:01:458 1044 1a88 PT WARNING:     Message:parameters.OtherCachedUpdateIDs
2017-08-07 15:59:01:458 1044 1a88 PT WARNING:     Method:"http://www.microsoft.com/SoftwareDistribution/Server/ClientWebService/SyncUpdates"
2017-08-07 15:59:01:458 1044 1a88 PT WARNING:     ID:1d4d197b-3b67-4af7-97a4-8214a962c9c6
2017-08-07 15:59:01:458 1044 1a88 PT WARNING: PTError: 0x8024400d
2017-08-07 15:59:01:458 1044 1a88 PT WARNING: SyncUpdates_WithRecovery failed.: 0x8024400d
2017-08-07 15:59:01:458 1044 1a88 PT WARNING: Sync of Updates: 0x8024400d
2017-08-07 15:59:01:458 1044 1a88 PT WARNING: SyncServerUpdatesInternal failed: 0x8024400d
2017-08-07 15:59:01:459 1044 1a88 Agent   * WARNING: Failed to synchronize, error = 0x8024400D
2017-08-07 15:59:01:460 1044 1a88 Agent   * WARNING: Exit code = 0x8024400D
2017-08-07 15:59:01:460 1044 1a88 Agent *********
2017-08-07 15:59:01:460 1044 1a88 Agent **  END  **  Agent: Finding updates [CallerId = CcmExec]
2017-08-07 15:59:01:460 1044 1a88 Agent *************
2017-08-07 15:59:01:460 1044 1a88 Agent WARNING: WU client failed Searching for update with error 0x8024400d
2017-08-07 15:59:01:473 9476 2368 COMAPI >>--  RESUMED  -- COMAPI: Search [ClientId = CcmExec]
2017-08-07 15:59:01:474 9476 2368 COMAPI   - Updates found = 0
2017-08-07 15:59:01:474 9476 2368 COMAPI   - WARNING: Exit code = 0x00000000, Result code = 0x8024400D
2017-08-07 15:59:01:474 9476 2368 COMAPI ---------
2017-08-07 15:59:01:474 9476 2368 COMAPI --  END  --  COMAPI: Search [ClientId = CcmExec]
2017-08-07 15:59:01:474 9476 2368 COMAPI -------------
2017-08-07 15:59:01:474 9476 2368 COMAPI WARNING: Operation failed due to earlier error, hr=8024400D
2017-08-07 15:59:01:474 9476 2368 COMAPI FATAL: Unable to complete asynchronous search. (hr=8024400D)
2017-08-07 15:59:06:459 1044 1a88 Report REPORT EVENT: {C01FBDBB-7B31-464D-A100-0A3B16D432B3} 2017-08-07 15:59:01:459+0200 1 148 101 {00000000-0000-0000-0000-000000000000} 0 8024400d CcmExec Failure Software Synchronization Windows Update Client failed to detect with error 0x8024400d.
2017-08-07 15:59:06:479 1044 1a88 Report CWERReporter::HandleEvents - WER report upload completed with status 0x8
2017-08-07 15:59:06:479 1044 1a88 Report WER Report sent: 7.6.7601.23806 0x8024400d(0) 0000000-0000-0000-0000-000000000000 Scan 0 1 CcmExec {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7} 0
2017-08-07 15:59:39:960 9476 2368 COMAPI -------------
2017-08-07 15:59:39:960 9476 2368 COMAPI -- START --  COMAPI: Search [ClientId = CcmExec]
2017-08-07 15:59:39:960 9476 2368 COMAPI ---------
2017-08-07 15:59:39:962 1044 1a88 Agent *************
2017-08-07 15:59:39:962 9476 2368 COMAPI <<-- SUBMITTED -- COMAPI: Search [ClientId = CcmExec]
2017-08-07 15:59:39:962 1044 1a88 Agent ** START **  Agent: Finding updates [CallerId = CcmExec]
2017-08-07 15:59:39:962 1044 1a88 Agent *********
2017-08-07 15:59:39:962 1044 1a88 Agent   * Include potentially superseded updates
2017-08-07 15:59:39:962 1044 1a88 Agent   * Online = Yes; Ignore download priority = Yes
2017-08-07 15:59:39:962 1044 1a88 Agent   * Criteria = "(DeploymentAction=* AND Type='Software') OR (DeploymentAction=* AND Type='Driver')"
2017-08-07 15:59:39:962 1044 1a88 Agent   * ServiceID = {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7} Managed
2017-08-07 15:59:39:962 1044 1a88 Agent   * Search Scope = {Machine}
2017-08-07 15:59:40:374 1044 1a88 PT +++++++++++  PT: Synchronizing server updates  +++++++++++
2017-08-07 15:59:40:374 1044 1a88 PT   + ServiceId = {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}, Server URL = https://myservername:8531/ClientWebService/client.asmx
2017-08-07 15:59:40:387 1044 1a88 PT WARNING: Cached cookie has expired or new PID is available
2017-08-07 15:59:40:387 1044 1a88 PT Initializing simple targeting cookie, clientId = 750c86a9-fc38-4a9b-ba3e-0a4812a5c0b0, target group = , DNS name = nloinb382.intleurope.imptobnet.com
2017-08-07 15:59:40:387 1044 1a88 PT   Server URL = https://myservername:8531/SimpleAuthWebService/SimpleAuth.asmx
2017-08-07 15:59:42:283 1044 1a88 PT WARNING: SyncUpdates failure, error = 0x8024400D, soap client error = 7, soap error code = 300, HTTP status code = 200
2017-08-07 15:59:42:283 1044 1a88 PT WARNING: SOAP Fault: 0x00012c
2017-08-07 15:59:42:283 1044 1a88 PT WARNING:     faultstring:Fault occurred
2017-08-07 15:59:42:283 1044 1a88 PT WARNING:     ErrorCode:InvalidParameters(7)
2017-08-07 15:59:42:283 1044 1a88 PT WARNING:     Message:parameters.OtherCachedUpdateIDs
2017-08-07 15:59:42:283 1044 1a88 PT WARNING:     Method:"http://www.microsoft.com/SoftwareDistribution/Server/ClientWebService/SyncUpdates"
2017-08-07 15:59:42:283 1044 1a88 PT WARNING:     ID:ad6a100f-eee2-49b4-8453-1cc03456f647
2017-08-07 15:59:42:283 1044 1a88 PT WARNING: PTError: 0x8024400d
2017-08-07 15:59:42:283 1044 1a88 PT WARNING: SyncUpdates_WithRecovery failed.: 0x8024400d
2017-08-07 15:59:42:283 1044 1a88 PT WARNING: Sync of Updates: 0x8024400d
2017-08-07 15:59:42:283 1044 1a88 PT WARNING: SyncServerUpdatesInternal failed: 0x8024400d
2017-08-07 15:59:42:283 1044 1a88 Agent   * WARNING: Failed to synchronize, error = 0x8024400D
2017-08-07 15:59:42:285 1044 1a88 Agent   * WARNING: Exit code = 0x8024400D
2017-08-07 15:59:42:285 1044 1a88 Agent *********
2017-08-07 15:59:42:285 1044 1a88 Agent **  END  **  Agent: Finding updates [CallerId = CcmExec]
2017-08-07 15:59:42:286 1044 1a88 Agent *************
2017-08-07 15:59:42:286 1044 1a88 Agent WARNING: WU client failed Searching for update with error 0x8024400d
2017-08-07 15:59:42:304 9476 2368 COMAPI >>--  RESUMED  -- COMAPI: Search [ClientId = CcmExec]
2017-08-07 15:59:42:304 9476 2368 COMAPI   - Updates found = 0
2017-08-07 15:59:42:305 9476 2368 COMAPI   - WARNING: Exit code = 0x00000000, Result code = 0x8024400D
2017-08-07 15:59:42:305 9476 2368 COMAPI ---------
2017-08-07 15:59:42:305 9476 2368 COMAPI --  END  --  COMAPI: Search [ClientId = CcmExec]
2017-08-07 15:59:42:305 9476 2368 COMAPI -------------
2017-08-07 15:59:42:305 9476 2368 COMAPI WARNING: Operation failed due to earlier error, hr=8024400D
2017-08-07 15:59:42:306 9476 2368 COMAPI FATAL: Unable to complete asynchronous search. (hr=8024400D)
2017-08-07 15:59:47:284 1044 1a88 Report REPORT EVENT: {435ACCC7-734C-49C7-ADFE-71E5396E6AB2} 2017-08-07 15:59:42:284+0200 1 148 101 {00000000-0000-0000-0000-000000000000} 0 8024400d CcmExec Failure Software Synchronization Windows Update Client failed to detect with error 0x8024400d.
2017-08-07 15:59:47:316 1044 1a88 Report CWERReporter::HandleEvents - WER report upload completed with status 0x8
2017-08-07 15:59:47:316 1044 1a88 Report WER Report sent: 7.6.7601.23806 0x8024400d(0) 0000000-0000-0000-0000-000000000000 Scan 0 1 CcmExec {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7} 0
2017-08-07 16:00:00:847 9476 1454 COMAPI -------------
2017-08-07 16:00:00:847 9476 1454 COMAPI -- START --  COMAPI: Search [ClientId = CcmExec]
2017-08-07 16:00:00:847 9476 1454 COMAPI ---------
2017-08-07 16:00:00:849 1044 1a88 Agent *************
2017-08-07 16:00:00:849 1044 1a88 Agent ** START **  Agent: Finding updates [CallerId = CcmExec]
2017-08-07 16:00:00:849 1044 1a88 Agent *********
2017-08-07 16:00:00:849 1044 1a88 Agent   * Include potentially superseded updates
2017-08-07 16:00:00:849 1044 1a88 Agent   * Online = Yes; Ignore download priority = Yes
2017-08-07 16:00:00:849 1044 1a88 Agent   * Criteria = "(DeploymentAction=* AND Type='Software') OR (DeploymentAction=* AND Type='Driver')"
2017-08-07 16:00:00:849 1044 1a88 Agent   * ServiceID = {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7} Managed
2017-08-07 16:00:00:849 1044 1a88 Agent   * Search Scope = {Machine}
2017-08-07 16:00:00:849 9476 1454 COMAPI <<-- SUBMITTED -- COMAPI: Search [ClientId = CcmExec]
2017-08-07 16:00:01:277 1044 1a88 PT +++++++++++  PT: Synchronizing server updates  +++++++++++
2017-08-07 16:00:01:278 1044 1a88 PT   + ServiceId = {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}, Server URL = https://myservername:8531/ClientWebService/client.asmx
2017-08-07 16:00:01:286 1044 1a88 PT WARNING: Cached cookie has expired or new PID is available
2017-08-07 16:00:01:286 1044 1a88 PT Initializing simple targeting cookie, clientId = 750c86a9-fc38-4a9b-ba3e-0a4812a5c0b0, target group = , DNS name = nloinb382.intleurope.imptobnet.com
2017-08-07 16:00:01:286 1044 1a88 PT   Server URL = https://myservername:8531/SimpleAuthWebService/SimpleAuth.asmx
2017-08-07 16:00:04:344 1044 1a88 PT WARNING: SyncUpdates failure, error = 0x8024400D, soap client error = 7, soap error code = 300, HTTP stat

I found a few technet articles that relate to WSUS 3 but this is a 2016 server, I have performed maintenance on WSUS a couple of times now using the script from Coretech below

http://blog.coretech.dk/kea/house-of-cardsthe-configmgr-software-update-point-and-wsus/

I was wondering if anyone else has seen these errors and what was the fix?

thanks in advance


many thanks


Whats difference in Windows 10 Products WSUS?

$
0
0

In our enviroment we are rolling out Windows 10 Pro and I'm configuring WSUS to update those Windows 10 clients.

In the products categorie there are a lot Windows 10 options but what is the difference?
- Windows 10 and later drivers
- Windows 10 and later upgrade & Servicing drivers
- Windows 10 Feature On Demand
- Windows 10 GDR-DU
- Windows 10 Language Interface Packs
- Windows 10 Language Packs
- Windows 10 LTSB
- Windows 10

Also in the Classifications you can choose between "Update Rollups", "Updates" and "Upgrades". What is the difference and what I need to take?

Thanks in advance.

Technical query about Microsoft Quality Rollup for Windows 7 and Windows Server 2008

$
0
0

Good day !

I have following queries for Microsoft updates:

  1. I have STANDALONE Windows 7 machine (not connected to internet) which is not updated for more than 4 years. Now I am planning to do Microsoft security updates on this machine.If I download "Jan 2019 Security Monthly Quality Roll up" file only  and if I install this on that stand alone Windows 7 machine then all past 4 years microsoft updates will be installed automatically. No need to install anything else. Please correct me if I am wrong.
  2. And once microsoft updates are done how can I test to ensure that I have not missed any old microsoft security update? Any vulnerability scan application which can help me with this?

  3. If I have fresh Windows 7 STANDALONE Machine then what is the best way to patch this machine with latest microsoft updates in order to ensure that no past microsoft updates are missed on that STANDALONE machine.



WSUS - detection and scheduled install issue on server 2016

$
0
0

Hi

I have WSUS v10 installed on Server 2016 (build 1607).

Also have a Server 2016 as a client.

Now the client server was initially setup to be patched via windows update. So it will automatically download updates and await for an admin to hit the install button.

This server had a patch already downloaded and was awaiting action.

I then configured the GPO to have this server check-in to WSUS server.

- Detection time set for 8 hours

- Scheduled install and reboot (option4) for say 10pm on Friday.

- Disabled dual scan.

Here is my first issue.

- On the client, I did the usual, gpupdate /force, restart Updates service, BITS, trigger /detectnow, etc. This was during the day... nothing happens for hours. Left it for overnight, then the server showed up in WSUS console. Any ideas why it doesn't register quickly?

Secondly

- So the server is in WSUS and scans show it needs one patch. This is the same patch that is sitting pretty in Windows Updates awaiting action. I approve this patch from WSUS and scheduled it for 10pm as an example.

- Once again, I do the gpupdate, restart updates service, etc.

- 10pm pass, nothing... 11pm.. nothing. Left it overnight.. no good.

- WindowsUpdates log doesn't show anything obviously suspicious. I am wondering if the patch that was pre downloaded from internet has anything to do with this.

Any ideas anyone?

Thanks

DM

Issue with patch installation when service in manual state

$
0
0


We have a scenario, Windows update service is in manual(triggered) state and generally we push patches using WSUS. We have schedule defined so patches are installed at particular time of day.

We recently pushed some patch using SCCM before patches can be pushed using WSUS, but we saw the patch pushed using SCCM was installed and patches which were pushed using WSUS were downloaded but not installed.

The patches were installed next day. 

But when we changed the start type for windows Update service to Automatic then all patches were installed.

Can someone help me understand when in first scenario patches are installed in two days be second in one day.


Windows 10 1803 Language Pack , Language Interface Pack and Feature On Demand (FOD) support in WSUS

$
0
0
I don't see those in WSUS as non-dynamic Updates as with previous versions and cannot install them on clients as before. Installation during Upgrades works as expected, but not afterwards. Is there an announcement for the schedule ?


WSUS high read load of *.psf files

$
0
0

We have a persistent and very high read load of some *.psf files on our corporate WSUS server

And because of it a very high disk queue

How can we fix that?

Wsus Powershell AND Superceded updates

$
0
0

I'll have this 'updateScope' filtering to retrieve the list of updates from a single computer.

And I'm using 'LatestRevisionApproved', but when I run it I'm also getting  some superceded Updates, that I'm not interested on it, because I know that computer will never apply.

I may add an additional filter by each update, but Is this setting the good one to filter SuperCeded Updates? Why is not working as I expect?

$updatescope = New-Object Microsoft.UpdateServices.Administration.UpdateScope
$updateScope.ApprovedStates = [Microsoft.UpdateServices.Administration.ApprovedStates]::LatestRevisionApproved  # Includes updates whose latest revision is approved.
$updateScope.UpdateApprovalActions = [Microsoft.UpdateServices.Administration.UpdateApprovalActions]::Install
$updateScope.UpdateSources = [Microsoft.UpdateServices.Administration.UpdateSources]::MicrosoftUpdate;
$updatescope.ExcludedInstallationStates=@('NotApplicable','Installed')
$updatescope.ToCreationDate = (get-date).AddDays(-$days)


$wsus.GetComputerTargetbyName($computername) 

 $updatelist = $mycomputer.GetUpdateInstallationInfoPerUpdate($updateScope)  | where {$_.GetUpdate().IsSuperseded -eq $False}
  write-output "Number of Pending updates $($updatelist.count)""Search Range From: {0:dd-MMM-yyyy} To: {1:dd-MMM-yyyy} (-{2} Days)" -f $updatescope.FromCreationDate,$updatescope.ToCreationDate,$Days
  foreach ($update in $updatelist ) {
        $updateinfo=$update.Getupdate()
          [pscustomobject][Ordered]@{
            Status=$update.UpdateInstallationState
            Approval=$update.UpdateApprovalAction
            ArrivalDate=get-date $updateinfo.ArrivalDate -format dd-MMM-yyyy
          #  ApprovalTargetGroup=$update.GetUpdateApprovalTargetGroup().name
            PublicationState=$Updateinfo.PublicationState   # expired?
            Approved=$updateinfo.isapproved
            KB=$updateinfo | %{$_.KnowledgebaseArticles -join ","}
            SuperSeded=$updateinfo.IsSuperseded
            Declined=$updateinfo.IsDeclined
            Title=$updateinfo.title
          }
      }

Regards

Windows Update Stuck on Checking for updates

$
0
0

Hello,

Facing a annoying issue for windows update on windows server 2012 Essential.Its windows update stuck on Checking for updates.

Tried below steps ..

1- Sfc /scan reported corruption which fixed by DISM /Online /Cleanup-Image /RestoreHealth .

2- Reboot server and checked again.

3- Restart windows update,BITS and Cryptogrpahic service.Nothing helped to fix it.

Please advise.

Thanks in advance...

WSUS product requirements Windows 10

$
0
0

Hello, I have to say the WSUS product overview went sideways with the change from Windows 7 -> Windows 10! There are literally 30 entries relating to windows 10 in some sort and I dont really know which ones I need to download. For the servers I have Windows Server 2016 and Windows Server 2016 and later servicing drivers.

My Windows 10 instances always run on the latest version or before - so 1803/1809 maybe some that havent been updated on 1709. Now there are later upgrades and servicing drivers and laungage interface packs - language packs - GDR packages - Feature on Demand - Windows 10 and later stuff. Which ones Do I really need - well overwhelming!

Updates from another location?

$
0
0

Hi Guys,

I hope someone is able to help.

Last Wednesday we received a call from our offices in the North complaining of high Network Bandwidth issues logging in and general slowness. Upon investigation I noticed the users complaining were docked in a different office on Wednesday before returning to their normal offices on Thursday a.m. I checked the machines Registry around 11 a.m. and noticed it was the correct registry displayed. Our system is designed to update the computers GPO policy if it docks in a location other than its normal office and adjust the keys accordingly to pick updates from that location.

I have two theories here -

1. User docked at a different office than their normal one and were downloading updates when the undocked laptop and left office for day. They returned to their NORMAL office and WSUS immediately carried on with the update from the different office.

2. User docked at normal office and the GPO did not apply properly, so user picked updates from the set registry key. Then after some time the GPO updated key to the normal registry policy.

My question is - point 1. is WSUS designed to do this?

Any information would be greatly received.

Regards.

Viewing all 12874 articles
Browse latest View live