Quantcast
Channel: WSUS Forum
Viewing all 12331 articles
Browse latest View live

MS Security Bulletin and the Microsoft update catalog do not show the same replace update info. Which is correct?

$
0
0
For Windows 2012 Server R2 KB3124001 is mentioned as superseded by kb3134214 on  MS bulletin but I don't see the same if I do a search for either KB3124001 or  kb3134214 on Microsoft update catalog. Internal WSUS server don't also show  KB3124001 as superseded. Which one is correct?

WSUS Stuck?

$
0
0

Really weird issue where the download stops at the same point... please see attached image.


Alex Olver

Updates not installing post KB3138615 on WS2012+WS2012R2

$
0
0

Hi!

On all my 2012 and 2012R2 servers updates are not installing after applying KB3138615.

Our WSUS server is on 2012R2.

In a secondary environment we have a WSUS server on 2008R2 and there all 2012R2 servers are correctly installing and rebooting as expected.

NOTE: in both environments the AlwaysAutoRebootAtScheduledTime setting is enabled.

Before applying KB3138615, updates were installing, but the servers were not rebooting as expected, now install and reboot does not work at all in the WSUS 2012R2 environment!

Does anyone have any idea as to what might have happend?

Perhaps the KB3138615 effectively kills off the WSUS agent when contacting WSUS 2012R2, and need a code review by MS?

Best regards,

Michael


MCP/MCTS/MCSA http://www.compugame.dk

Server 2012 WSUS Windows 10 showing as Vista Business

$
0
0

Hi,

I know to fix the Windows 10 showing as Vista Business in Server 2012 I can install https://support.microsoft.com/en-us/kb/3095113...

However I haven't installed the hotfix for Server 2012 R2 showing as Windows 6.3... If I install the windows 10 update will it update the Server 2012 R2 issue too, or do I need to run both hotfixes?

Wsus installation failed

$
0
0

Hi, trying to install WSUS on windows 2008 std sp2 64bit but it is failing. Please find attached screenshot of errors.

WSUS 2012 r2 computers not updating to correct computer group

$
0
0
In order to roll out windows 10 upgrades in small groups, I created new OU's in active directory and group by group I would approve the upgrade for each group. However, even after creating the new computer groups in the WSUS console, the computers are not moving from the original group. I have the setting right for client side and I have even gone to individual computers and ran gpupdate /force as well as wuauclt /resetauthorization wuauclt /detectnow wuauclt /updatenow but nothing. Not even after a reboot. I know it can take a while, I've even seen it take days, but nothing is changing this time at all. Where can I look to see what the issue is? RSOP shows everything is okay. Active Directory shows computers in the OU's I created. I'm not seeing any errors in event viewers either.

Roger Stumbaugh

WSUS GPO Setup

$
0
0

I am setting up GPO for the servers in WSUS. I would like for some of the servers to download directly from the Microsoft Update Website but still report to the WSUS. One of the option in the GPO is to setup the intranet. The intranet have two textboxes to fill

Set the intranet update service for detecting updates:


Set the intranet statistics server:


If I leave both empty the servers will download directly from the Microsoft Update Website. If I fill the second will it report to the WSUS and download from the Microsoft Update Website?

Thanks,

Ryan

question about WSUS content location

$
0
0

Here is the situation:

Currently we have wsus server on the local network. I am going to move wsus to cloud server which is microsoft azure server. I know the speed is going to be impacted. If I choose wsus content location at one of the server at local network, does it mean all the workstations can get windows updates faster or the speed is faster in general? 

Please advise! Thank you very much in advance!


Edge Browser Patching with WSUS

$
0
0
When will patching the Edge browser be available through WSUS?

Uninstall the WSUS role from Windows Server 2003

$
0
0

Hey all,

We have a WSUS downstream server which no computer is reporting to. This server is not being decommissioned at the moment because there are a few dependencies on it.

Removing WSUS would help us reclaim some space on the drive that it is installed on, and hence, we would like the WSUS role (not sure what the equivalent term for "role" is on WS2003) removed. We are not planning the complete decommission of the whole WSUS infrastructure at the moment; we just want the WSUS role and related data removed from that particular server alone.

I came across a TechNet blog post that spoke about the Microsoft Installer Cleanup Utility, but I see that the tool is no more available from Microsoft.

Please show us the right way to remove WSUS from this server without disturbing the other servers in the WSUS environment.

Thank you in advance!

-Ram

Microsoft Edge Updates for WSUS

$
0
0

Hey guys hopefully someone can help or has come across this issue.

We are currently running WSUS 3.2.7600.226 however when I try to search for Microsoft Edge updates it brings up no results. As a rule of thumb our organisation installs all critical and important updates. All other updates for other OS's and software come up fine it is never bringing up any results for Edge. Anyone come across this ?

Thanks :)

WSUS does not download already downloaded patches after wsusutil.exe reset

$
0
0

Hello, in order to get rid of unneeded patches on my WSUS server (srv 2012 R2), Ihave emptied my WsusContent folder and run wsusutil.exe RESET. I did this by following the post at http://blogs.technet.com/b/gborger/archive/2009/02/27/what-to-do-when-your-wsuscontent-folder-grows-too-large.aspx.

From what I understand it looks like, even though you deselect certain programs and claissificatoin, e.g. you do not need any updates for Office 2010 or windows Vista ... anymore, this does not mean that WSUS does DELETE the already downloaded patches related. Therefore you need to do this wsusutil RESET after one deleted all patches from WsusContent folder.

So far so good, I did all this, figuring out that after wsusutil.exe RESET I ran into this problem described by Keith https://social.technet.microsoft.com/Forums/office/en-US/300a580c-80c7-44e7-905d-9b3299ba0043/rebuild-of-wsus-failed-due-to-reset-process-in-progress?forum=winserverwsus search for "tbSingletonData" in that post. Every time I run wsusutil.exe RESET my field "ResetStateMachineNeeded" at [SUSDB].[dbo].[tbSingletonData] changes to 1. I have to update that table in order to set it back to 0,otherwise I always get such a warning "Cannot save configuration because the server is still processing a previous configuration change."

However, my server now runs fine again, it also downloads NEW patches every night, but it never re-downloads patches which where downloaded before I have deleted WsusContent folders and files. Also, I figured out, that it never manages to display All Updates in Admin GUI, it loads forever until it hangs at some time. But new comes come in as they are released by Microsoft. However, after about 3 days now I still only have 108 patches with a total amount of about 450 MB, while before I had 300 GB. I have unselected a few products, but this might be maybe 20 % or so.

How can I reliably force my WSUS to redownload all updates it is aware of based on it's database, except the ones I have deselected from products and classifications? This was my initial intention.

kind regards,

Dieter Tontsch

mobileX AG

WSUS console & service can't start. "Reason: Failed to open the explicitly specified database 'SUSDB'"

$
0
0

Our WSUS server (Windows Server 2012 R2) hanged when it was installing updates on itself. I rebooted it in a harsh way, it started normally and finished installing the updates. However, now I can't start the WSUS management console due to a connection error. The WSUS server service itself doesn't start as well.

The Application server contains multiple events 18456, source MSSQL$MICROSOFT##WID, message "Login failed for user 'NT AUTHORITY\NETWORK SERVICE'. Reason: Failed to open the explicitly specified database 'SUSDB'. [CLIENT: <named pipe>]" If I try to connect to the server using SQL Server Management Studio, it displays the following error: 

"Cannot connect to \\.\pipe\MICROSOFT##WID\tsql\query. Login failed for user 'MY-LOGIN'. (Microsoft SQL Server, Error: 18456)"

The Application even log contains the same event mentioned above, only the message is different: "Login failed for user 'MY-LOGIN'. Reason: Token-based server access validation failed with an infrastructure error. Check for previous errors. [CLIENT:<named pipe>]".

If I restart the Windows Internal Database service, it starts normally and doesn't throw any errors in the Application log. Among other things, it successfully mounts the SUSDB database. No other errors (including DCOM errors) can be found in the log.

Seems that security setting on the WID engine are damaged. Any ideas how to fix them? Besides reinstalling the server, of course? :)


Evgeniy Lotosh // MCSE: Server infrastructure, MCSE: Messaging


More WSUS updates than available online from Microsoft

$
0
0
I recently built a computer, and applied all the updates directly from Microsoft. I kept applying updates after restarting until it said that there are no new updates available. Then I joined my computer to a domain, and 58 new updates were available from WSUS. How can this happen?

WSUS and WIN10 Auto Reboot Behavior

$
0
0
I have several Windows 10  computer's connected to WSUS Version: 6.3.9600.18228.


I have setup two different test environments with the following registry settings - 

1)
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU]
"AUOptions"=dword:00000004
"DetectionFrequency"=dword:00000004
"DetectionFrequencyEnabled"=dword:00000001
"NoAutoRebootWithLoggedOnUsers"=dword:00000001
"NoAutoUpdate"=dword:00000000
"RebootRelaunchTimeout"=dword:000000f0
"RebootRelaunchTimeoutEnabled"=dword:00000001
"RescheduleWaitTime"=dword:00000014
"RescheduleWaitTimeEnabled"=dword:00000001
"ScheduledInstallDay"=dword:00000000
"ScheduledInstallTime"=dword:0000000b
"UseWuserver"=dword:00000001
"AutoInstallMinorUpdates"=dword:00000001

1) These registry settings are set to have updates automatically install.
I have noticed that some of the cumulative update's from Windows will alert you that you have a few minutes before the computer reboots. Your options are "Restart / Close"


So I went ahead and changed automatic reboot to notify to install - 
"AUOptions"=dword:00000003

Now when I have this set in the registry, once again..it appears to want to force a reboot and gives you a time - only a few minutes before a reboot.

I tested with KB3147458


I am curious as to what other's are doing in enterprise envrionments to stop this automatic reboot behavior?



wsus - synchronisation not working

$
0
0

Hi Team,

I got issue , recently on my wsus server c:\windows\system32\drivers\etc\hosts file is missing, and this is workgroup environment. Now the issue is synchronization was not happening on wsus server. Can any help on this to get the wsus server synchronization.

G Sravan

WSUS fails to download an update

$
0
0

I've got a WSUS 4.0 server that's failing to download a single update. The error message from EventID 364 is:

Content file download failed. Reason: File cert verification failure. Source File: /d/msdownload/update/software/crup/2016/04/windows10.0-kb3154879-x86_c7b4d1ac4829121785ae79b2df7550004eca089f.cab Destination File: c:\wsus\WsusContent\9F\C7B4D1AC4829121785AE79B2DF7550004ECA089F.cab

Thoughts?  I'm downloading directly from Microsoft, no proxy or upstream WSUS server.  It looks like the upstream file is corrupt or unsigned.

Not really a huge deal as I don't have any x86 Windows 10 clients, only x64, but still.

Are Remote SQL Installation Account Permissions Temporary?

$
0
0

I need to work with our database team and want to make sure I can tell them what to expect.

According to the deployment guide the user account that installs WSUS needs sysadmin rights on the remote SQL server. Once installed, can those rights be removed entirely or demoted to something with fewer rights?

Somewhat related, does the install process set up machine permissions on the SQL server for the WSUS server?  If so, is it just read/write to the database or something more?

Unable to run WSUS PowerShell commands - "could not establish trust relationship"

$
0
0

Hey guys.

I'm unable to run WSUS PowerShell commands on our upstream server. The error message states it "The underlying connection was closed: Could not establish trust relationship for the SSL/TLS secure channel". This isn't an issue on our downstream servers.

The upstream WSUS console is working fine and computers are able to download updates from it. Not sure when this started, but I did replace the SSL certs for all WSUS servers recently. Seems like if that was the issue, it'd effect the other servers as well.

Any help would be appreciated!

Latest WSUS version for Server 2008R2 Enterprise?

$
0
0

Hi All,

I am having issues with all my downstreams SBS servers not synhronising with my master WSUS which is on Server 2008R2. All of them come up with "error connecting to DataStore".  I have gone through all the forums and tried every suggestion without any luck. All of the Server 2012 downstream servers are working perfectly with the upstream 2008R2.

My next step is to make sure the upstream and all SBS downstreams are up to date ( they are currenlty all on  3.2.7600.226).

Which is the latest version and where can i find the update download? Is it possible to run WSUS 6 on previous server version or is this only compatable with 2012?

Thanks!

Viewing all 12331 articles
Browse latest View live


<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>