Quantcast
Channel: WSUS forum
Viewing all 12874 articles
Browse latest View live

How does Orchestrator determine which updates should apply to my computer?

$
0
0

I found this post "How Windows Update works"(https://docs.microsoft.com/en-us/windows/deployment/update/how-windows-update-works#downloading-updates), It really helped me a lot, but I still have some questions about it.

1.How does Orchestrator(or might be Arbiter) determine which updates should apply to my computer? According to what? The manifest files? And what's inside the manifest files?

2.Is there any "sequence" of updating windows patches from WU or WSUS? Will it run automatically in sequence?

3.Are there any "dependency" issues between Bundle update and Child update? If WU client has already downloaded/installed one of Bundle update, but hasn't done reboot yet, will it's Children(Child update) be downloaded/installed?

I would appreciate any help.

 


WSUS content folder & synchronization problem

$
0
0

Actually, our WSUS content folder was full and that's why to reduce the size of the folder I tried the following steps and after that I am in a big trouble.

1. Close any open WSUS consoles.

2. Go to Administrative Tools – Services and STOP the Update Services service.

3. In Windows Explorer browse to the WSUSContent folder (typically D:\WSUS\WSUSContent or C:\WSUS\WSUSContent)

4. Delete ALL the files and folders in the WSUSContent folder.

5. Go to Administrative Tools – Services and START the Update Services service.

6. Open a command prompt and navigate to the folder: C:\Program Files\Update Services\Tools.

7. Run the command WSUSUtil.exe RESET.

After all the above steps, our WSUS is not synchronizing and no updates are being downloaded at all. Every time showing "Reset Server Node"

Please help me out as soon as possible.

Thanks

Yousuf

WSUS 3.0SP2 Content file download failed. Reason: File cert verification failure

$
0
0

Hi,

We have a problem wtih an Upstream WSUS 3.0SP2 on Windows server 2008 Enterprise SP2.

Since june 12, several Updates approved for Windows 7 or for Windows 8.1 or IE 11 are not downloaded by our Upstream.

On this Upstream, I have test a donwload of update with Interner Explorer and the same Proxy server and its OK.

Any suggestions please ? 

UPstream server version  : 3.2.7600.307 (hotfix KB2720211 + KB2828185 + KB4484071)

In SoftwareDistribution.log, an exemple of download failed :

2019-06-19 03:43:43.647 UTCInfoWsusService.22ContentSyncAgent.ProcessBITSNotificationQueueContentSyncAgent recieved Transferred Event for Item: d0777547-6cfb-4f12-aed1-91ec38d56e33
2019-06-19 03:43:43.647 UTCInfoWsusService.22ContentSyncAgent.ContentSyncSPFireStateMachineEventContentSyncAgent firing Event: FileDownloaded for Item: d0777547-6cfb-4f12-aed1-91ec38d56e33
2019-06-19 03:43:43.694 UTCErrorWsusService.22ContentSyncAgent.ProcessBITSNotificationQueueDownloaded file e:\DATA\WSUS\WsusContent\E3\A2CB0FBB26057B1C0815E92687C838E14B7A03E3.cab caught exception at VerifyFile: System.IO.FileNotFoundException: Could not load file or assembly 'System.Core, Version=3.5.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089' or one of its dependencies. The system cannot find the file specified.
File name: 'System.Core, Version=3.5.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089'
   at Microsoft.UpdateServices.ServerSync.ContentSyncAgent.VerifyCRC(String fileLocalPath, String additionalHash)
   at Microsoft.UpdateServices.ServerSync.ContentSyncAgent.VerifyFile(String fileLocalPath, String additionalHash)
   at Microsoft.UpdateServices.ServerSync.ContentSyncAgent.ProcessBITSNotificationQueue()

=== Pre-bind state information ===
LOG: User = NT AUTHORITY\NETWORK SERVICE
LOG: DisplayName = System.Core, Version=3.5.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089
 (Fully-specified)
LOG: Appbase = file:///C:/Program Files/Update Services/Service/bin/
LOG: Initial PrivatePath = NULL
Calling assembly : Microsoft.UpdateServices.ContentSyncAgent, Version=3.1.6001.1, Culture=neutral, PublicKeyToken=31bf3856ad364e35.
===
LOG: This bind starts in default load context.
LOG: Using application configuration file: C:\Program Files\Update Services\Service\bin\WsusService.exe.Config
LOG: Using machine configuration file from C:\Windows\Microsoft.NET\Framework\v2.0.50727\config\machine.config.
LOG: Post-policy reference: System.Core, Version=3.5.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089
LOG: The same bind was seen before, and was failed with hr = 0x80070002.

   at Microsoft.UpdateServices.ServerSync.ContentSyncAgent.ProcessBITSNotificationQueue()
   at Microsoft.UpdateServices.ServerSync.ContentSyncAgent.WakeUpWorkerThreadProc()
   at System.Threading.ThreadHelper.ThreadStart_Context(Object state)
   at System.Threading.ExecutionContext.runTryCode(Object userData)
   at System.Runtime.CompilerServices.RuntimeHelpers.ExecuteCodeWithGuaranteedCleanup(TryCode code, CleanupCode backoutCode, Object userData)
   at System.Threading.ExecutionContext.RunInternal(ExecutionContext executionContext, ContextCallback callback, Object state)
   at System.Threading.ExecutionContext.Run(ExecutionContext executionContext, ContextCallback callback, Object state)
   at System.Threading.ThreadHelper.ThreadStart()
2019-06-19 03:43:43.694 UTCWarningWsusService.22ContentSyncAgent.ProcessBITSNotificationQueueInvalid file deleted: e:\DATA\WSUS\WsusContent\E3\A2CB0FBB26057B1C0815E92687C838E14B7A03E3.cab
2019-06-19 03:43:43.694 UTCInfoWsusService.22ContentSyncAgent.ContentSyncSPFireStateMachineEventContentSyncAgent firing Event: FileVerificationFailed for Item: d0777547-6cfb-4f12-aed1-91ec38d56e33
2019-06-19 03:43:43.694 UTCInfoWsusService.22EventLogEventReporter.ReportEventEventId=364,Type=Error,Category=Synchronization,Message=Content file download failed. Reason: File cert verification failure. Source File: /c/msdownload/update/software/updt/2019/06/windows8.1-kb4502567-x86_a2cb0fbb26057b1c0815e92687c838e14b7a03e3.cab Destination File: e:\DATA\WSUS\WsusContent\E3\A2CB0FBB26057B1C0815E92687C838E14B7A03E3.cab.
2019-06-19 03:43:43.710 UTCInfoWsusService.22ContentSyncAgent.WakeUpWorkerThreadProcContentSyncAgent found no more Jobs, thread exitting
2019-06-19 03:43:43.710 UTCInfoWsusService.22EventLogEventReporter.ReportEventEventId=363,Type=Information,Category=Synchronization,Message=Content synchronization succeeded.

4 of latest updates fail to download with status "The update failed to download":

$
0
0

We are running Server 2012R2 and W10.

WSUS is mostly working fine and has downloaded most of the last batch of files without problem however there are four that are marked "The update failed to download":

2019-11 CU for W10 1809 (KB4523205) and 1903 (KB4524570)

2019-11 SSU for W10 1809 (KB4523204) and 1903 (KB4524569)

Other files download OK.

There are event log entries such as:

Content file download failed.

Reason: HTTP status 403: The client does not have sufficient access rights to the requested server object.

Source File: /filestreamingservice/files/4d1472e2-297a-42a9-b658-a172787be72b/public/windows10.0-kb4524569-x64_72c34125e50af4c16828d2688dc33dbc2af1b5f4.cab

Destination File: E:\WSUS\WsusContent\F4\72C34125E50AF4C16828D2688DC33DBC2AF1B5F4.cab

What is happening here - is it just a case of waiting and it will sort itself out as all other files have downloaded OK?

Thanks,

Julian

WSUS not reporting to WSUS until they have done an initial download online

$
0
0

Hi, hoping someone call help me. Recently we built some new servers (same image we used on older servers). The servers are put in a GP in AD and appear in WSUS console with the number of updates outstanding etc. However the last 5 servers built are appearing in WSUS but with a status of not yet reported. When I kick off the "check for updates" on the server, it will keep checking and checking but never actually pulls any down and the status in WSUS remains the same. If I pull down some updates online and install, the server will change the status in WSUS and from that point on I can install updates from WSUS (managed by admin). This is a recent issue and nothing has changed in either WSUS or how the servers are built. Obviously I would prefer if all the updates installed on servers are managed. I have tried everything like stop and start wuauserv and bits. I have checked registry to ensure the correct WSUS server is displaying. I have tried numerous things. I would be very grateful if anyone could help out

thanks in advance

Sharon

Feature Update to Windows 10 - 1809 using WSUS

$
0
0

Hello,

I am using WSUS  10.0.14393.2007 on windows server 2016 Ent edition. We are running Windows 10 version 1803 enterprise edition. Now i want to upgrade windows 10 1803 enterprise version to 1809 enterprise version. But when i goes to WSUS console updates there is feature update for Business edition and consumer edition.

We are running enterprise edition of windows 10. What should i select now. Can anybody help me in this.

Error with install windows 10 1903

$
0
0

Hello and sorry for my english,

I try to deploy windows 10 1903 and i have a lot of failure upgrade on my computer.

The error is : 
(Resource not found :) ReportingEvent.Client.167; Settings: Update features to Windows 10 (consumer editions), version 1903, en-us x64

i tried this, change mimetype from "application/vnd.ms-cab-compressed" to "application/octet-stream" : http://pgeorgiev.com/unable-to-find-resource-while-trying-to-upgrade-to-windows-10-1709-enterprise-through-wsus/

but not better :-(

thanks for help

WSUS 4 on w2012 server with Replica mode on WSUS 3.2 W2008 server

$
0
0

Hello, 

We need to  put in place a new Upstream WSUS server in W2012 , so with WSUS 4.0.

But I have two downstream servers for replica mode in W2008 with WSUS 3.2

Could the new server in WSUS 4.0 replicate on the 2 servers in W2008 WSUS 3.2  ?

Thanks 

Stephane


windows 10 feature update via WSUS 2012

$
0
0

Hi

I got 90 + computers with collection of windows 7,8,8.1 and 10. I approved few feature updates via WSUS and it is not downloaded. error 0x80d02002

 then i google this and found this link but cannot download the said KB update. 

 https://support.microsoft.com/en-us/help/3095113/update-to-enable-wsus-support-for-windows-10-feature-upgrades

is there any thing i can do to fix this issue


Thank you 

WSUS - Notification to restart to complete installation - Windows 10 1809

$
0
0

I need to configure a WSUS GPO to schedule the installation of updates at a specific time. I will have a test group before pushing to production workstations/laptops. 

I am unable to force deadlines or to restart computers so I am left with having to push the updates and relying on users to restart their computers to complete the installation or to log off so that the updates will complete.

My problem is that the restarts notification for updates is not displaying for users that are logged in. 

My GPO setup is below:



Questions:

  1. Can anyone tell me what is missing in the GPO why the notifications are not displaying for admin or non-admin logged on users? 
  2. Is there a way to have the notification pop up every e.g. 30 mins to remind users of the required restart?
  3. If no users are logged in, will the updates get installed and the computer restarted with this current GPO?

I am running a Windows 2016 WSUS.  The clients are mosltly Windows 10 ver 1809.

Any help would be much appreciated.

CJ



WSUS Backup Server

$
0
0

Hi Guys,

One of my customer wants Secondary Server for WSUS Server Similar to Secondary ( Backup ) Active Directory in case of Failure.       

Consider a scenario : There are two WSUS Server on same network One is active and other is Redundant(Cold Spare or Backup). Widows Update Patches are received from Upstream Server. Both will be synchronized simultaneously . When Active Fails due to Power or Server Failure then Redundant as to come in to action until other is recovered. 

Can we provide such solution . If yes can anyone explain how and If not tell me best solution like WSUS Database backup etc.

Note : All are physical servers no virtualization.

Wsus not reflecting pending updates from computers

$
0
0
We are running WSUS on a Server 2019 Standard server and haven't had any issues. But a couple weeks back we noticed several computers had a download now option for some Office updates. But these updates weren't reflected in any reports in WSUS when checking the computer. So we have no idea why this is happening and we are wanting the machines to install these but its only showing up as a download now option. All computers are set to call home to the WSUS server and not to go out to Microsoft itself for updates. This is the first time this has happened. Does anyone have any ideas?

Automatically install Defender definitions and not rest of update through GPO

$
0
0
Hello, 

we are moving from WSUS and would like to use GPO instead, we only want to install definitions update for antivirus.
Is it possible to only push and install definitions updates through GPO?

Install all windows update beside Feature update through GPO

$
0
0

Hello,

We want to roll out windows update on all clients through windows update controlled in GPO.
Is it possible to allow all beside feature update?

Windows Server 2012 R2 Foundation still reboots after last update

$
0
0
Good morning!
It will not start after yesterday's update and server restart. It only loads, then displays "Install Update 2 of 5", then displays "Notifying services that Windows is shutting down" And the server will restart over and over. Please get advice on how to fix the problem, Thank you.

run offine wsus server

$
0
0

hi,

I have a local domain, my dc os is windows server 2008r2 ,

I want run a offline wsus server in network. but thise errore is show (the update could not be found. there may be a network connection issue)

please help.

Windows 10 machines not pulling approved updates

$
0
0

I have a brand new 2019 WSUS server deployed but my Windows 10 machines are not pulling updates

A manual check for updates reports "You're up to date" while WSUS reports the machine has 290+ updates needed.

Machines are registering to WSUS just fine, and seem to be reporting in, but they can't seem to identify that there are patches available for them.

WSUS Setting

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate]
"DoNotConnectToWindowsUpdateInternetLocations"=dword:00000000
"DisableWindowsUpdateAccess"=dword:00000000
"DisableDualScan"=dword:00000001
"WUServer"="http://wsus2019:8530"
"WUStatusServer"="http://wsus2019:8530"
"UpdateServiceUrlAlternate"="http://wsus2019:8530"
"TargetGroupEnabled"=dword:00000001
"TargetGroup"="Computers"

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU]
"NoAutoRebootWithLoggedOnUsers"=dword:00000001
"RebootRelaunchTimeoutEnabled"=dword:00000001
"RebootRelaunchTimeout"=dword:000001b8
"RebootWarningTimeoutEnabled"=dword:00000001
"RebootWarningTimeout"=dword:0000001e
"AutoInstallMinorUpdates"=dword:00000000
"UseWUServer"=dword:00000001
"DetectionFrequencyEnabled"=dword:00000001
"DetectionFrequency"=dword:0000000c
"NoAutoUpdate"=dword:00000000

2019/12/14 10:45:37.0474453 5804  11408 ComApi          * START *   Federated Search ClientId = UpdateOrchestrator (cV: nRDIbm1v0k2E3P2d.1.1.0)
2019/12/14 10:45:37.0507151 11588 12228 IdleTimer       WU operation (SR.UpdateOrchestrator ID 5) started; operation # 20; does use network; is not at background priority
2019/12/14 10:45:37.0535179 11588 11940 IdleTimer       WU operation (SR.UpdateOrchestrator ID 5, operation # 20) stopped; does use network; is not at background priority
2019/12/14 10:45:37.0541495 5804  4264  ComApi          Federated Search: Starting search against 1 service(s) (cV = nRDIbm1v0k2E3P2d.1.1.0)
2019/12/14 10:45:37.0543877 5804  4264  ComApi          * START *   Search ClientId = UpdateOrchestrator, ServiceId = 3DA21691-E39D-4DA6-8A4B-B43877BCB1B7, Flags: 0X40010410 (cV = nRDIbm1v0k2E3P2d.1.1.0.0)
2019/12/14 10:45:37.0571995 11588 1432  IdleTimer       WU operation (CSearchCall::Init ID 6) started; operation # 23; does use network; is not at background priority
2019/12/14 10:45:37.0654719 11588 1432  Agent           * START * Queueing Finding updates [CallerId = UpdateOrchestrator  Id = 6]
2019/12/14 10:45:37.0654986 11588 1432  Agent           Removing service 3DA21691-E39D-4DA6-8A4B-B43877BCB1B7 from sequential scan list
2019/12/14 10:45:37.0655099 11588 1432  Agent           Service 3DA21691-E39D-4DA6-8A4B-B43877BCB1B7 is not in sequential scan list
2019/12/14 10:45:37.0655208 11588 1432  Agent           Added service 3DA21691-E39D-4DA6-8A4B-B43877BCB1B7 to sequential scan list
2019/12/14 10:45:37.0656967 11588 11820 Agent           Service 3DA21691-E39D-4DA6-8A4B-B43877BCB1B7 is in sequential scan list
2019/12/14 10:45:37.0700457 11588 10868 Agent           * END * Queueing Finding updates [CallerId = UpdateOrchestrator  Id = 6]
2019/12/14 10:45:37.0751100 11588 10868 Agent           * START * Finding updates CallerId = UpdateOrchestrator  Id = 6 (cV = nRDIbm1v0k2E3P2d.1.1.0.0.2)
2019/12/14 10:45:37.0751253 11588 10868 Agent           Online = Yes; Interactive = Yes; AllowCachedResults = No; Ignore download priority = No
2019/12/14 10:45:37.0751354 11588 10868 Agent           Criteria = IsInstalled=0 and DeploymentAction='Installation' or IsInstalled=0 and DeploymentAction='OptionalInstallation' or IsPresent=1 and DeploymentAction='Uninstallation' or IsInstalled=1 and DeploymentAction='Installation' and RebootRequired=1 or IsInstalled=0 and DeploymentAction='Uninstallation' and RebootRequired=1""
2019/12/14 10:45:37.0751442 11588 10868 Agent           ServiceID = {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7} Managed
2019/12/14 10:45:37.0751477 11588 10868 Agent           Search Scope = {Machine}
2019/12/14 10:45:37.0751602 11588 10868 Agent           Caller SID for Applicability: S-1-5-21-3156452373-2460497579-2355296147-500
2019/12/14 10:45:37.0751628 11588 10868 Agent           ProcessDriverDeferrals is set
2019/12/14 10:45:37.2100562 11588 10868 Misc            Got WSUS Client/Server URL: http://wsus2019:8530/ClientWebService/client.asmx""
2019/12/14 10:45:37.2188540 11588 10868 Driver          Skipping printer driver 5 due to incomplete info or mismatched environment - HWID[microsoftmicrosoft_musd] Provider[Microsoft] MfgName[Microsoft] Name[Microsoft enhanced Point and Print compatibility driver] pEnvironment[Windows NT x86] LocalPrintServerEnv[Windows x64]
2019/12/14 10:45:38.0594723 11588 10868 ProtocolTalker  ServiceId = {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}, Server URL = http://wsus2019:8530/ClientWebService/client.asmx
2019/12/14 10:45:38.0598619 11588 10868 ProtocolTalker  OK to reuse existing configuration
2019/12/14 10:45:38.0598950 11588 10868 ProtocolTalker  Existing cookie is valid, just use it
2019/12/14 10:45:38.0599029 11588 10868 ProtocolTalker  PTInfo: Server requested registration
2019/12/14 10:45:39.8280010 4016  5472  Misc            *FAILED* [80010106] ReadPolicy: failed
2019/12/14 10:45:48.2159840 11588 10868 Misc            Update B32E464F-2E4A-4109-9018-33583A079A8A is sticky.
2019/12/14 10:45:48.3850582 11588 10868 IdleTimer       WU operation (CAgentProtocolTalker::SyncUpdates_WithRecover) started; operation # 24; does use network; is at background priority
2019/12/14 10:45:48.3851510 11588 10868 WebServices     Auto proxy settings for this web service call.
2019/12/14 10:45:48.7734683 11588 10868 IdleTimer       WU operation (CAgentProtocolTalker::SyncUpdates_WithRecover, operation # 24) stopped; does use network; is at background priority
2019/12/14 10:45:48.8932102 11588 10868 Misc            Update B32E464F-2E4A-4109-9018-33583A079A8A is sticky.
2019/12/14 10:45:49.0357711 11588 10868 IdleTimer       WU operation (CAgentProtocolTalker::SyncUpdates_WithRecover) started; operation # 25; does use network; is at background priority
2019/12/14 10:45:49.0886584 11588 10868 IdleTimer       WU operation (CAgentProtocolTalker::SyncUpdates_WithRecover, operation # 25) stopped; does use network; is at background priority
2019/12/14 10:45:49.0886866 11588 10868 ProtocolTalker  SyncUpdates round trips: 2
2019/12/14 10:47:28.2021201 11588 10868 Agent           Found 0 updates and 102 categories in search; evaluated appl. rules of 3966 out of 5580 deployed entities
2019/12/14 10:47:28.2236935 11588 10868 Agent           * END * Finding updates CallerId = UpdateOrchestrator, Id = 6, Exit code = 0x00000000 (cV = nRDIbm1v0k2E3P2d.1.1.0.0.2)


Update for Windows Server 2012 R2 (KB3172614)

$
0
0

Hi All,

I am trying to install Windows update on Windows Server 2012 R2 (KB3172614) unable to install, instalation failing. could you please help me on this.

Installation status: Failed

Error details: Code 800F0831

Thanks,

Venkat.


Ramana rao

Security Monthly Quality Rollup patches not installing on the Servers

$
0
0

Hi,

In our Monthly patching we have troubling to install Security Monthly Quality Rollup patches on Windows server 2012 R2.

Some severs getting keep failed to install ecurity Monthly Quality Rollup patches.

For Example last month patches KB4520005 failed like we have last  4 months patches.

Error code which we getting is 0X800F0831 in SCCM console.

we have installed latest servicing patches to this machines and all back troubleshooting link system file corruption, Rename software distribution folder, manual installation everything got unsuccessful.

Thanks,

Mohanbabu

Windows Server 2008 R2 - WSUS Sychronization Failing with "...Could not establish trust relationship..."

$
0
0

Our WSUS is running on a Windows server 2008 R2 Standard VM server. WSUS sychronization has been failing consistently for the past few days with following error message

WebException: The underlying connection was closed: Could not establish trust relationship for the SSL/TLS secure channel. ---> System.Security.Authentication.AuthenticationException: The remote certificate is invalid according to the validation procedure.
at System.Web.Services.Protocols.WebClientProtocol.GetWebResponse(WebRequest request)
   at System.Web.Services.Protocols.HttpWebClientProtocol.GetWebResponse(WebRequest request)
   at Microsoft.UpdateServices.ServerSync.ServerSyncCompressionProxy.GetWebResponse(WebRequest webRequest)
   at System.Web.Services.Protocols.SoapHttpClientProtocol.Invoke(String methodName, Object[] parameters)
   at Microsoft.UpdateServices.ServerSyncWebServices.ServerSync.ServerSyncProxy.GetAuthConfig()
   at Microsoft.UpdateServices.ServerSync.ServerSyncLib.InternetGetServerAuthConfig(ServerSyncProxy proxy, WebServiceCommunicationHelper webServiceHelper)
   at Microsoft.UpdateServices.ServerSync.ServerSyncLib.Authenticate(AuthorizationManager authorizationManager, Boolean checkExpiration, ServerSyncProxy proxy, Cookie cookie, WebServiceCommunicationHelper webServiceHelper)
   at Microsoft.UpdateServices.ServerSync.CatalogSyncAgentCore.SyncConfigUpdatesFromUSS()
   at Microsoft.UpdateServices.Serve

Any help or advice in resolving this error will be greatly appreciated. We will be upgrading our server OS soon as Windows Server 2008 R2 is approaching its end of life early in 2020. But till would need WSUS to be working if possible. 
Viewing all 12874 articles
Browse latest View live