Quantcast
Channel: WSUS Forum
Viewing all 12331 articles
Browse latest View live

Can you modify the roll-up schedule for child servers into the parent?

$
0
0

We have one parent server (which server some clients directly) and two child servers.  There appears to be a large delay (maybe 2 hours) between when a server reports into a child server and when that update reaches the parent server.  We would like to be able to query the master server on patch night and get an up to date accounting of patch status without having to wait for the roll-up.  Is there any way to change the roll up interval or to force a roll-up on demand (say right before generating a report of approved patches)?

Tom


WUA's async call to download file (BeginDownload) is getting fail.

$
0
0

Hi,

I am trying to download (kb2957503 & KB2939576) listed under "Windows updates", and install them using WUA APIs.

There are two windows updates with below GUID, (details are fetched from IUpdate in UpdateCollection.)

KB2957503: ced3293c-2613-41ff-bd6a-d8525504c035

KB2939576: 04cd23af-8a7b-40a3-a5f3-a9edcba7c7b6

I am able to download and install update specific to KB2957503 but getting below error during download in case of update of KB2939576:

return of BeginDownload (in HRESULT)=> 0x80240024

HRESULT_CODE(80240024) => 0x00000024 (Too many files opened for sharing.)

in WinError.h it is mentioned for "MessageId: ERROR_SHARING_BUFFER_EXCEEDED"

I fetched information about this error but not able to find solution for this issue. If I try with working set of GUID just after failure one, it works fine but any attempt with failure set of GUID remains as it is.

I have implemented call back interface IDownloadProgressChangedCallback & IDownloadCompletedCallback, initialized VARIENT variable as VariantInit(&state); which works properly in case of successful download.

Please let me know if someone had faced similar kind of prob earlier.

Thanks in advance.

WSUS 4.0 - WID or SQL database

$
0
0

I have 6 servers on different physical locations.

One is upstream, other are replicas.

Which database do you suggest and why ? WID or SQL ?

Until now I used WID and now I'm going to rebuild WSUS and would like to know what's better.

Updates Install without user intervention

$
0
0

Hi All,

I am currently using WSUS and GPO's to push updates to our Windows 2008 R2 Servers.  We just began doing this within the last couple of months and have created the GPO to "auto download updates and notify for install".  The only other relevant setting is "reschedule Automatic updates scheduled installations" is set to 15 minutes.  Based on our setting of "notify for install", I would not expect this setting to have any effect.

Now twice in the last week, individual server administrators have been working on their servers, rebooted for whatever reason and then they report to me that Windows Updates are installing without their approval.  Anyone have any ideas how this could happen?

Thanks

Most efficient WSUS strategy for basic Test and Production groups?

$
0
0

I'm trying to setup a basic WSUS update strategy with a Testing Computer group and Production Computer group. I'll just talk about Windows 7 to keep it simple.

I've created a custom Update View called Windows 7 to show me only updates for Windows 7 products (W7 updates, Office updates, Silverlight). I have also created two computer groups: Testing Computers and Production Computers (they're both nested under All Computers). What I want to do is through my custom Windows 7 update view, select the updates and approve them for the Testing Computer group, then once I've verified the updates are good, I then want to approve those same updates to the Production Computers group. So far I have not figured out an intuitive way to keep track of what updates have been approved for the Testing Computer group and Production Computer group.

So to make it easy to do this, I've created two custom update views named "Approved Updates for Testing Computers" and "Approved Updates for Production Computers." I've selected these custom update views to only show approved updates for the respective group. I then ideally can go into the Approved Updates for Testing Computers update view and select all of those updates and approve them for the Production Computers group once tested and verified. Is there a simpler way to set this up and accomplish the same thing?

Any help would be appreciated.



cannot get role and feature data server 2012

$
0
0
hello everyone, i am experiencing the above error every time i try to install WSUS on windows server 2012 R2.

Could you kindly give me insights on how to sort this and get the wsus role installed

WSUS update languages

$
0
0

Our users use several different languages in Exchange and Office.

Should we configure WSUS to download updates for all this languages ?

In which case more languages should be included ?

WSUS Server - Sync shows complete but under download status it states 5,050 files needed and only 661MB or 104,7000.82 downloaded

$
0
0
On my first attempt of installing a wsus server i was pointing to a network share, the sync would show complete but when looked into the network share there were two folders with no content in them.

I then removed the WSUS role from the server, rebooted re-installed the WSUS role and created a local folder on the server to house the updates. Ran the WSUS post install commands everything looked good but I was still missing the files. I then and ran C:\program files\Update Services\Tools in a admin command prompt with the syntax wsusutil -reset

The server is now getting new updates but missing a told of old updates as shown below:

http://imgur.com/mH3vsaQ

How can I get WSUS to re-download the approved missing updates?  As you can see the Sync is showing complete.



WSUS - All items were deleted

$
0
0

Hello,

WSUS:

We run Server Cleanup Wizard to delete computers not contacting the WSUS server, however, the wizard deleted all client computers list and servers as well.
The wizard should only delete client computers not contacting the WSUS server for 30 days or more.

Is there any way that we can recover the deleted list?

Thanks


error in wsus installation of other site locaton

$
0
0

Dear All,

below error getting when installing secondary wsus server at remote location.

please help out me.

Regards

jitendra singh

9871615296



Rajesh Khabar

Install updates on set date

$
0
0

Hi All,

I am trying to get some non critical servers to automatically install windows updates from WSUS and then reboot. I know in Group Policy I can set it to install updates on a particular day of the week, but I would like to install updates and reboot on the last weekend of the month.

I have tried creating a simple batch file with the following lines in it, attached to a scheduled task

wuauclt.exe /updatenow

shutdown /r /f /t 0

This works ok when logged in as a user but will not work when not logged in. I did set option "run whether user is logged on or not" The reboot command works ok, but it would appear that wuauclt.exe /updatenow will not work on the login screen even with the task set to use the local administrator account.

Can someone either tell me how I can set updates to install on a specific date, or tell me how to get the wuauclt.exe command to work under the login screen. This is for Windows 2008 R2 and above.

Thanks

Help Powershell and Wsus Approve Updates By Computer Group

$
0
0
I've found this script to ApproveUpdatesByComputerGroupt and it works, my problem is now, I only need to approve Classification  'Critical Updates' 'Security Updates' 'Updates', because I will not approve service packs for OS / SQL, etc. 

I'm using SCCM, but Failover Cluster should I use WSUS, and my support team is already running a script, to set maintenance mode. 

But no matter what I've tried, I can not really get it to work, so .. 


Help Help

# ApproveUpdatesByComputerGroup.ps1
 
[void][reflection.assembly]::LoadWithPartialName("Microsoft.UpdateServices.Administration")
 
$wsus = [Microsoft.UpdateServices.Administration.AdminProxy]::getUpdateServer()
 
$ComputerTargetGroups = $wsus.GetComputerTargetGroups()
Write-Host "Warning: This will approve all NotApproved updates for a Computer Group" -ForegroundColor Red
Write-Host "Computer Groups"
$Count = 0
foreach ($ComputerTargetGroup in $ComputerTargetGroups) {
    Write-Host $Count - $ComputerTargetGroup.Name
    $Count++
}
$ComputerGroupToUpdate = Read-Host "Select Computer Group to update. [0 - $($Count-1)]"
Write-Host "Finding all updates needing approval and approving them"
 
$ComputerGroupName = $ComputerTargetGroups[$ComputerGroupToUpdate].Name
$ComputerGroupId = $ComputerTargetGroups[$ComputerGroupToUpdate].Id
 
$ComputersToScan = $wsus.GetComputerTargetGroup($ComputerGroupId).GetComputerTargets()
foreach ($ComputerToScan in $ComputersToScan) {
 
    $ComputerTargetToUpdate = $wsus.GetComputerTargetByName($ComputerToScan.FullDomainName)
    # Get all Not Installed updates available to the computer
    $NeededAndNotInstalled = $ComputerTargetToUpdate.GetUpdateInstallationInfoPerUpdate() | where {
                                                                                                   ($_.UpdateInstallationState -eq "NotInstalled") `
                                                                                                   -and ($_.UpdateApprovalAction -eq "NotApproved")}
    foreach ($UpdateToApprove in $NeededAndNotInstalled)
    {
        Approve-WsusUpdate -Action Install -TargetGroupName $ComputerGroupName -Update $(Get-WsusUpdate -UpdateId $UpdateToApprove.UpdateId) -Verbose
    }
 
}
Write-Host "Done approving updates"
sleep -Seconds 5

WSUS roles install on Server 2012 Fails

$
0
0

Hi I m ananda I want to installed wsus server in 2012 server but its getting error

The MSSQL$MICROSOFT##WID service was unable to log on as NT SERVICE\MSSQL$MICROSOFT##WID with the currently configured password due to the following error:

Logon failure: the user has not been granted the requested logon type at this computer.

 Service: MSSQL$MICROSOFT##WID

Domain and account: NT SERVICE\MSSQL$MICROSOFT##WID

 This service account does not have the required user right "Log on as a service."

 User Action

 Assign "Log on as a service" to the service account on this computer. You can use Local Security Settings (Secpol.msc) to do this. If this computer is a node in a cluster, check that this user right is assigned to the Cluster service account on all nodes in the cluster.

 If you have already assigned this user right to the service account, and the user right appears to be removed, check with your domain administrator to find out if a Group Policy object associated with this node might be removing the right.

Please let me know if you have any ideas. Thanks!

Updating Windows Server 2003 R2 via WSUS

$
0
0

Hi

At present the majority of our servers are Windows Server 2003 R2.  I have started to implement WSUS installed on a Windows 2008 server.

The problem I have is that within Products and Classifications Server 2003 R2 is not listed.  The updates that need applying do not list Server 2003 R2 in the required operating system.

Does Server 2003 and Server 2003 R2 share the same updates or is Server 2003 R2 not supported via WSUS?

Could some body please help as we've had a security breach and part of our response is to ensure all servers are fully patched

Thanks in advance

Server 2012 WSUS Post-deployment configuration fails - comprehending the log file

$
0
0

After installing Server 2012 Standard on ESX 5.1 I completed all available Windows Updates and proceeded to add the WSUS role.  I chose the default WID database and the role addition was seemingly successful.  Unfortunately, the Post-deployment Configuration failed.  A log file had been created in the AppData\Local\Temp folder but at initial glance it seemed to imply that my error was likely due to skipping a step during installation via PowerShell.  However, I didn't install using PowerShell and I set off to surf the Internets for clues on resolving this issue.  I searched about a dozen forums that with similar, but different issues until a comment by Lawrence Garvin (http://social.technet.microsoft.com/profile/lawrence%20garvin/?ws=usercard-inline) convinced me to go back and look at my log. 

2013-07-23 11:03:18  Postinstall started
2013-07-23 11:03:18  Detected role services: Api, UI, WidDatabase, Services
2013-07-23 11:03:18  Start: LoadSettingsFromXml
2013-07-23 11:03:18  Start: GetConfigValue with filename=UpdateServices-Services.xml item=ContentLocal
2013-07-23 11:03:18  Value is true
2013-07-23 11:03:18  End: GetConfigValue
2013-07-23 11:03:18  Start: GetConfigValue with filename=UpdateServices-Services.xml item=ContentDirectory
2013-07-23 11:03:18  Config file did not contain a value "ContentDirectory"
2013-07-23 11:03:18  Microsoft.UpdateServices.Administration.CommandException: A required configuration value was not found in the system. This is usually caused by installing WSUS through PowerShell and not specifying a configuration file. Review the article Managing WSUS Using PowerShell at TechNet Library (http://go.microsoft.com/fwlink/?LinkId=235499) for more information on the recommended steps to perform WSUS installation using PowerShell.
   at Microsoft.UpdateServices.Administration.PostInstall.GetConfigValue(String filename, String item)
   at Microsoft.UpdateServices.Administration.PostInstall.LoadSettingsFromXml()
   at Microsoft.UpdateServices.Administration.PostInstall.Initalize(Parameters parameters)
   at Microsoft.UpdateServices.Administration.PostInstall.Execute(String[] arguments)
Fatal Error: A required configuration value was not found in the system. This is usually caused by installing WSUS through PowerShell and not specifying a configuration file. Review the article Managing WSUS Using PowerShell at TechNet Library (http://go.microsoft.com/fwlink/?LinkId=235499) for more information on the recommended steps to perform WSUS installation using PowerShell.

Upon closer inspection the specifics of my error were right there for me, I just had to look at it long enough to decipher the details.  What I now read is that Post-deployment configuration finds a file called UpdateServices-Services.xml (I found it in Windows\System32\ServerManager\ComponentConfiguration\).  It determines that ContentLocal=True which correctly indicates that my updates are to be stored locally.  It proceeds to inquire about the ContentDirectory, but comes back without a value.  Here are my UpdateServices-Services.xml file contents

<?xml version="1.0" encoding="utf-16"?><INSTANCE CLASSNAME="ServerComponent_UpdateServices_Services"><PROPERTY NAME="ContentDirectory" TYPE="string"></PROPERTY><PROPERTY NAME="ContentLocal" TYPE="boolean"><VALUE>true</VALUE></PROPERTY></INSTANCE>

I can see that the ContentLocal property did indeed have the value true, but the ContentDirectory property did not have a value.  I now needed to figure out if a String value could be specified in the same way a Boolean value was, or if it needed quotes around it, or was supposed to be specified more like an attribute (learned about that somewhere along the way).  I couldn't find any conclusive websites, and I didn't want to just try it for fear of the Post-deployment configuration running with an invalid ContentDirectory.  Once again I returned to my log file and searched for answers at the http://go.microsoft.com/fwlink/?LinkId=235499 that was indicated.  I didn't find any exact matches, but eventually I found a sample .xml file that specified a string value.  It specified it as <VALUE>string</VALUE> with no brackets, so I knew to specify mine as <VALUE>C:\LocalMSUpdateCache</VALUE> and saved it.  My UpdateServices-Services.xml now looks like this:

<?xml version="1.0" encoding="utf-16"?><INSTANCE CLASSNAME="ServerComponent_UpdateServices_Services"><PROPERTY NAME="ContentDirectory" TYPE="string"><VALUE>C:\LocalMSUpdateCache</VALUE></PROPERTY><PROPERTY NAME="ContentLocal" TYPE="boolean"><VALUE>true</VALUE></PROPERTY></INSTANCE>

I returned to Server Manager -> WSUS and re-attempted the Postdeployment configuration.  It completed successfully!

I'm glad that my fix was relatively simple and that Lawrence was particular about the details of the log file. 

1. My exact error isn't always going to be documented

2. Just because the log file looks unintelligible (I have thus far avoided both powershell and xml), doesn't mean it's useless.

Good luck to anyone with a similar issue.  You too may be able to figure it out yourself.


WUA's async call to download file (BeginDownload) is getting fail.

$
0
0

Hi,

I am trying to download (kb2957503 & KB2939576) listed under "Windows updates", and install them using WUA APIs.

There are two windows updates with below GUID, (details are fetched from IUpdate in UpdateCollection.)

KB2957503: ced3293c-2613-41ff-bd6a-d8525504c035

KB2939576: 04cd23af-8a7b-40a3-a5f3-a9edcba7c7b6

I am able to download and install update specific to KB2957503 but getting below error during download in case of update of KB2939576:

return of BeginDownload (in HRESULT)=> 0x80240024

HRESULT_CODE(80240024) => 0x00000024 (Too many files opened for sharing.)

in WinError.h it is mentioned for "MessageId: ERROR_SHARING_BUFFER_EXCEEDED"

I fetched information about this error but not able to find solution for this issue. If I try with working set of GUID just after failure one, it works fine but any attempt with failure set of GUID remains as it is.

I have implemented call back interface IDownloadProgressChangedCallback & IDownloadCompletedCallback, initialized VARIENT variable as VariantInit(&state); which works properly in case of successful download.

Please let me know if someone had faced similar kind of prob earlier.

Thanks in advance.

WSUS) Add new downstream replica server without data download.

$
0
0

I have 3 WSUS servers. A, B, C

Main WSUS(A) has internet access. but others(B, C) NOT.

I syncronized main WSUS(A) with MS. 

and link downstream server (B). 

now I add new downstream server (C), 

when I copy WSUS files(DB and Contents) from B to C.

It works Fine?

actually I already done.

it works. but,

(A) has only one downstream server linked. (B) or (C)

I think, (A) think (B) = (C). cause actually (B) and (C) have same DB, adn files...

when make downstream server, just only one way? 

It must sync, and download files?

KB2720211 and KB2734608 are they really required?

$
0
0

I understand KB2720211 was realeased some time back, later I believe due to some issues reported by KB2720211, KB2734608 was realsed to address them. I used to have 4 layers of WSUS servers, then after correcting the scenarios with discussions in this forum, I decided to go two layers (which is possibly more MS approved method). Due to geographic limitations, our setup now contains only one Upstream server, and 11 downstream servers in 11 locations or Data Centers.

I am gradually reducing the layers based on discussions I had on this earlier in this forum. To see if all works ok, I took out a WSUS server from layer 4 (lets call it Server-11), removed WSUS all together including internal DB, WSUSContent Folder. I then installed WSUS 3.2 SP2 as a role in this server (Windows 2008 R2 SP1), installed KB2720211 and KB2734608 (because the top level server has them) obviosuly the WSUS Content folder was populated with files with approved updates, computer groups got populated, also the internal DB became almost 15GB in size, similar to the top level server...and I got the following, and most of the time the console crashes as well..

"SqlException: Timeout expired.  The timeout period elapsed prior to completion of the operation or the server is not responding.
at System.Data.SqlClient.SqlConnection.OnError(SqlException exception, Boolean breakConnection)
   at System.Data.SqlClient.TdsParser.ThrowExceptionAndWarning(TdsParserStateObject stateObj)
   at System.Data.SqlClient.TdsParser.Run(RunBehavior runBehavior, SqlCommand cmdHandler, SqlDataReader dataStream, BulkCopySimpleResultSet bulkCopyHandler, TdsParserStateObject stateObj)
   at System.Data.SqlClient.SqlDataReader.ReadInternal(Boolean setTimeout)
   at Microsoft.UpdateServices.DatabaseAccess.DBConnection.ReadOneRow()
   at Microsoft.UpdateServices.Internal.DataAccess.HideUpdatesForReplicaSync(String xmlUpdateIds)
   at Microsoft.UpdateServices.ServerSync.CatalogSyncAgentCore.ProcessHiddenUpdates(Guid[] hiddenUpdates)
   at Microsoft.UpdateServices.ServerSync.CatalogSyncAgentCore.ReplicaSync()
   at Microsoft.UpdateServices.ServerSync.CatalogSyncAgentCore.ExecuteSyncProtocol(Boolean allowRedirect)

Question: I have 10 more servers to go with an expectation for the sync to work. Since the first one failed, is it because of KB2720211 or KB2734608? Should I uninstall these Hotfixes and try sync again? If yes what order should I uninstall them? or

Should I just try to pick up another downstream server, doing what I did before as in uninstalling WSUS etc, but not applying KB2720211 or KB2734608? Should I also unisntall IIS as part of WSUS removal before installing WSUS role etc again on a down stream server?


Shahidul

can not install kaspersky10

$
0
0

i use windows server2003 when i can not to install kaspersky security 10 i get this letter

connection to administration server faild administration server was impropertyvinstalled or invalid server address was specified try to specify another server address and connect again   what is the solution please ?

WSUS on windows server 2012 R2

$
0
0

Hello,

Previously i was using windows server 2003 - WSUS ,however after upgrading to 2012. I need guidance on how to transfer clients from the old WSUS running on windows server 2003 ..

Apart from installing wsus on the new server 2012..what else should i do so that clients can get updates from the new server - 2012

Viewing all 12331 articles
Browse latest View live


<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>