Quantcast
Channel: WSUS Forum
Viewing all 12331 articles
Browse latest View live

The server certificate did not comply with the following policy: WindowsUpdateCertificatePolicy

$
0
0

Please explain me this WSUS error:

ErrorWsusService.20ServerCertificateValidator.VerifyServerCertificate
The server certificate did not comply with the following policy: WindowsUpdateCertificatePolicy

   in Microsoft.UpdateServices.Internal.ServerCertificateValidator.VerifyServerCertificate(Object sender, X509Certificate certificate, X509Chain chain, SslPolicyErrors sslPolicyErrors)

I can not find any description. What WSUS certificate must have to comply with WindowsUpdateCertificatePolicy? Where are any description about WSUS WindowsUpdateCertificatePolicy?


Thank you


WSUS Computers cannot change membership

$
0
0
I have setup WSUS, all computers are under 'Unassigned Computers' (default), I have created new groups, but I am unable to change the membersip of the computers when right clickong the required computer. The selection is 'greyed out'......and ideas????

Windows 10 upgrade with WSUS, upgrades won`t show up at a clients

$
0
0

Hi,

i am trying to setup upgrades of various Windows 10 versions to latest 1909 with WSUS. WSUS is installed on Windows Server 2016.

Have synced and approved both business and consumer editions, all available versions, they are already downloaded.

On IIS have added .esd MIME type: application/octet-stream. But my two testing group clients don`t  even see the upgrades. 

What might be still wrong? Any ideas are appreciated.

Unable to start/stop any services in Windows server 2012 R2 -- timely fashion

$
0
0

Hi Guys,

     While doing the SQL Migration 2012 to 2017 , we are get the below error . Kindly help to resolve the issue  

     After reboot we unable to start or  stop any services in server.

Event ID 7024 

The description for Event ID 7024 from source Service Control Manager cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

SQL Server (MSSQLSERVER)
%%3417

The locale specific resource for the desired message is not present

Regards,

V.P.Neelakandan

1909 Machines Reporting to WSUS as Build 18362 Instead of 18363

$
0
0

I'm running WSUS (standalone) on Server 2019.  All of our pilot machines on Windows 10 1909 are reporting to WSUS with build numbers of 18362 (1903) instead of 18363 (1909).

I understand that 1903/1909 share the same baseline and that the difference between them is basically a feature enablement package, but the different build numbers still need to be properly reported in WSUS. Otherwise, a whole bunch of reporting that I do just goes out the window.

All WSUS Clients present "Not Yet Reported"

$
0
0

Hi

We have 2 WSUS server 2012 R2, Versión: 6.3.9600.18324, when We made test with 6 machines recently installed, it worked like a charm, yesterday I put 25 machines in the OU where it worked, but today I made a check and it shows that the last contact was today 22:05 (some earlier..), but the last status report continue Not yet reported, so Failed count, needed count, installed and so on are in 0

Any idea where to search, if were only one or two computers, I can check it, but all these computers are not yet reported... or what I missed in the WSUS server, all worked right in the test computers...

Thanks in advance


Doc MX

The WSUS content directory is not accessible. System.Net.WebException: The remote server returned an error: (401) Unauthorized.

$
0
0
The WSUS content directory is not accessible.
System.Net.WebException: The remote server returned an error: (401) Unauthorized.
   at System.Net.HttpWebRequest.GetResponse()
   at Microsoft.UpdateServices.Internal.HealthMonitoring.HmtWebServices.CheckContentDirWebAccess(EventLoggingType type, HealthEventLogger logger)


Can someone please clarify which folder this error relates to and which account needs permissions? The server is sync'ing fine, no issues with SCCM connecting to it.

Cheers

How to uncheck "Microsoft Update Improvement Program" registry or powershell

$
0
0

I can not find this ANYWHERE on google. How on earth do you uncheck the box for WSUS to not join the Microsoft Update Improvement Program via registry or powershell?

I need an automated deployment and this one little thing is driving me nuts. I have looked at process monitor to try and see what this checkbox is doing. Everytime you click apply, the process will read values from 

HKLM\Software\Microsoft\Update Services\Server\Setup

but there are no keys in there that look to have anything to do with an improvement program. How on earth do you check/uncheck this box programmatically

?


WSUS best troubleshooting for Code 80072ef3

$
0
0

Hi to all

Which is the best troubleshooting for this message?


Warm regards MeVs

Import WSUS approval to security offline environmet

$
0
0

Hi there,

I have a problem with a WSUS Solution on Windows Server 2019. We have one online WSUS with Internet connections.

One Offline WSUS in Site A and one Replica WSUS in site B as a Test environment without Internet connection.

The Productive WSUS is also one at site A and one on site B but without network connection to the test environment.

With the online WSUS we get the Microsoft updates and copy all include the wsusutil export metadata and the WsusContent Folder to the Test WSUS on site A. Here we do the approvals. WSUS on site B is configured as a replica, this works fine. After the Test we will Copy the WsusContent folder the exported metadate (with wsusutil) and the APPROVALS to the productive environment.

I could not find a solution to export and import the APPROVALS from the Test to the Productive WSUS Server. We Use Windows Server 2019.

Did you guys have any idear

THX Gerd


Herzlichen Dank

WSUS Install

$
0
0

Guys,

I am trying to install WSUS onto a standaline server (Offline) but encountering some issues, do you know of which patches are required after the base install of WSUS onto a windows 2008 R2 server?

Nathan

WSUS Setup and Minimize Catalogue

$
0
0

During the WSUS setup, If I connect to the Internet, by default it selects all the products which I do not want. (I do not want even the catalog for all the products)

I just need the catalog of Windows 10. How can I achieve this? If I dont sync for the first time, I dont see Win10 product selection. Is there a way around?

Issue with KB4513696 on WIndows Server 2008 R2 WSUS 3.2

$
0
0

Hi,

I have encountered issue with KB4513696 not able to download.

Synchronization is successful but Download Status keep stuck with Downloaded 3.36 MB of 3.36 MB

Tested on both normal and replica WSUS 3.2.7600.324

Info WsusService.12 CabUtilities.CheckCertificatesSignature File cert verification failed for d:\Program Files\WSUS\WsusContent\A9\2559A958D9D7EFECD5E5156E3948E7E88473A0A9.exe with 2148204548

Warning WsusService.12 ContentSyncAgent.ProcessBITSNotificationQueue Invalid file deleted: d:\Program Files\WSUS\WsusContent\A9\2559A958D9D7EFECD5E5156E3948E7E88473A0A9.exe

error installing KB890830 nov 2019 on Win 7 computers

$
0
0

Hi,

I got errors on installing the november 2019 MRST update (KB809830) on windows 7 computers.

on individual computers I get this errors in windows update

"WindowsUpdate_800B0004" "WindowsUpdate_dt000"

the MRST packages are only for installation on server 2008 and 2008 R2 and Windows 7

There are no related events in the eventviewer.

something wrong here?

on all other Windows versions no problems installing MRST. 

love to hear about it, regards, Fons


Fons system and network engineer Balie Amsterdam

Errorr In wsus server 2016

$
0
0

Hi I am getting error in wsus server when I am opening wsus for update approve or anyting

Help me there

Thanks in advance !!!

Error:-

The WSUS administration console was unable to connect to the WSUS Server via the remote API.

Verify that the Update Services service, IIS and SQL are running on the server. If the problem persists, try restarting IIS, SQL, and the Update Services Service.

System.Net.WebException -- The operation has timed out

Source
System.Web.Services

Stack Trace:
   at System.Web.Services.Protocols.WebClientProtocol.GetWebResponse(WebRequest request)
   at Microsoft.UpdateServices.Internal.DatabaseAccess.ApiRemotingCompressionProxy.GetWebResponse(WebRequest webRequest)
   at System.Web.Services.Protocols.SoapHttpClientProtocol.Invoke(String methodName, Object[] parameters)
   at Microsoft.UpdateServices.Internal.ApiRemoting.ExecuteSPGetUpdateServerStatus(Int32 updateSources, Boolean includeDownstreamComputers, String updateScopeXml, String computerTargetScopeXml, String preferredCulture, Int32 publicationState, Int32 propertiesToGet)
   at Microsoft.UpdateServices.Internal.DatabaseAccess.AdminDataAccessProxy.ExecuteSPGetUpdateServerStatus(UpdateSources updateSources, Boolean includeDownstreamComputers, String updateScopeXml, String computerTargetScopeXml, String preferredCulture, ExtendedPublicationState publicationState, UpdateServerStatusPropertiesToGet propertiesToGet)
   at Microsoft.UpdateServices.Internal.BaseApi.UpdateServer.GetStatus(UpdateSources updateSources, Boolean includeDownstreamComputers, UpdateScope updatesToInclude, ComputerTargetScope computersToInclude, UpdateServerStatusPropertiesToGet propertiesToGet)
   at Microsoft.UpdateServices.Internal.BaseApi.UpdateServer.GetReplicaStatus(UpdateSources updateSources)
   at Microsoft.UpdateServices.UI.AdminApiAccess.CachedObject.RefreshCache()
   at Microsoft.UpdateServices.UI.AdminApiAccess.CachedObject.GetFromCache()
   at Microsoft.UpdateServices.UI.SnapIn.Pages.ServerSummaryPage.backgroundWorker_DoWork(Object sender, DoWorkEventArgs e)


Does WSUS 2016 support 2003 clients?

$
0
0

Hi,

 Does WSUS 2016 support Windows Server 2003 clients?

We have a bunch of legacy servers which need patching.

Thanks

1909 for Server 2019 currently rolled out..?

$
0
0

Hello,

We have enabled 1903 updates for Win 10 in WSUS and also tried to update via internet but all our 2019 servers still yell 'You're up to date' ...

Are we missing something or do we just need some patience...?

Thanks for comments

Windows Update Error 0x80070057 - Windows 10 Pro 1903

$
0
0
Hi Guys. I've been struggling to resolve a Windows update issue affecting 100's of Windows 10 machines running version 1903 for some time with no luck... We are using WSUS 10.0.14393.2969 on Windows 2016.

What I'm seeing on the client machines is:

There were problems installing some updates, but we'll try again later.
2019-09 Cumulative Update for .NET Framework 3.5 and 4.8 for Windows 10 Version 1903 for x64 (KB4514359) -Error 0x80070057
2019-09 Security Update for Adobe Flash Player for Windows 10 Version 1903 for x64-based Systems (KB4516115) -Error 0x80070057
2019-11 Cumulative Update for Windows 10 Version 1903 for x64-based Systems (KB4524570) -Error 0x80070057
2019-11 Servicing Stack Update for Windows 10 Version 1903 for x64-based Systems (KB4524569) -Error 0x80070057

The corresponding wuetl.log shows errors as follows:

2019/11/19 11:14:46.7408537 6940  7144  DownloadManager * START * Begin Downloading Updates [CallerId = UpdateOrchestrator] [Call ID = {913F56DF-0776-41E0-8FFB-E311BB0812E2}]
2019/11/19 11:14:46.7408615 6940  7144  DownloadManager Priority = 3, NetworkCostPolicy = 0, Interactive = 1, Download on Battery = 1, Bypass Regulation = 1, Owner is system = 1, Proxy session id = 1, ServiceId = 3DA21691-E39D-4DA6-8A4B-B43877BCB1B7.
2019/11/19 11:14:46.7408633 6940  7144  DownloadManager Updates to download = 1
2019/11/19 11:14:46.7408667 6940  7144  Agent             Title = 2019-09 Security Update for Adobe Flash Player for Windows 10 Version 1903 for x64-based Systems (KB4516115)
2019/11/19 11:14:46.7408711 6940  7144  Agent             UpdateId = AB7DE211-6754-4207-B166-708A59E42C24.200
2019/11/19 11:14:46.7408722 6940  7144  Agent               Bundles 1 updates:
2019/11/19 11:14:46.7408759 6940  7144  Agent                 AB11DCBD-AD0E-4CB4-B143-3527DCF2BF7C.200
2019/11/19 11:14:46.7409319 6940  7144  DownloadManager No locked revisions found for update AB11DCBD-AD0E-4CB4-B143-3527DCF2BF7C.200 (SessionData = (null)); locking the user-specified revision.
2019/11/19 11:14:46.7412183 6940  7148  DownloadManager *FAILED* [80070057] Error occurred while downloading update 5EEB98CF-4531-4FD7-9C24-8EC7A084AE6F.200; notifying dependent calls.
2019/11/19 11:14:46.7726672 6940  7144  DownloadManager Queueing update AB11DCBD-AD0E-4CB4-B143-3527DCF2BF7C.200 for download handler request generation.
2019/11/19 11:14:46.7741041 6940  7144  Handler         Loaded state: cCompleteIterations: 0, pt: Unknown, nNextRequestID: 0.
2019/11/19 11:14:46.8115038 6940  7144  Agent           Effective power state: AC; IsOnAC: Yes.
2019/11/19 11:14:46.8115135 6940  7144  IdleTimer       WU operation (DL.UpdateOrchestrator, operation # 54) stopped; does use network; is not at background priority
2019/11/19 11:14:46.8115182 6940  7144  Agent           Released network PDC reference for callId {913F56DF-0776-41E0-8FFB-E311BB0812E2}; ActivationID: 54
2019/11/19 11:14:46.8115278 6940  7144  IdleTimer       WU operation (DL.UpdateOrchestrator) started; operation # 55; does use network; is not at background priority
2019/11/19 11:14:46.8115329 6940  7144  Agent           Obtained a network PDC reference for callID {913F56DF-0776-41E0-8FFB-E311BB0812E2} with No-Progress-Timeout set to 4294967295; ActivationID: 55.
2019/11/19 11:14:46.8115421 6940  7144  DownloadManager * END * Download Call Complete. Call 6 for caller UpdateOrchestrator has completed; signaling completion.
2019/11/19 11:14:46.8119116 6940  12012 Agent           WU client calls back to download call {913F56DF-0776-41E0-8FFB-E311BB0812E2} with code Call progress and error 0
2019/11/19 11:14:46.8123422 6940  7144  Agent           Effective power state: AC; IsOnAC: Yes.
2019/11/19 11:14:46.8123509 6940  7144  IdleTimer       WU operation (DL.UpdateOrchestrator, operation # 53) stopped; does use network; is not at background priority
2019/11/19 11:14:46.8123550 6940  7144  Agent           Released network PDC reference for callId {3D2428CD-D14B-4016-AFD9-43BC0CD56078}; ActivationID: 53
2019/11/19 11:14:46.8129793 12220 12256 ComApi          *RESUMED* Download ClientId = UpdateOrchestrator
2019/11/19 11:14:46.8129850 12220 12256 ComApi          Download call complete (succeeded = 0, succeeded with errors = 0, failed = 1, cancelled = 0, unaccounted = 0)
2019/11/19 11:14:46.8130070 12220 12256 ComApi          ClientId = UpdateOrchestrator: Exit code = 0x00000000; Call error code = 0x80240022
2019/11/19 11:14:46.8130845 12220 12256 ComApi          * END *   Download ClientId = UpdateOrchestrator
2019/11/19 11:14:46.8131207 6940  12012 Agent           WU client calls back to download call {3D2428CD-D14B-4016-AFD9-43BC0CD56078} with code Call complete and error 0x80070057
2019/11/19 11:14:46.8135080 6940  7144  DownloadManager * END * Begin Downloading Updates [CallerId = UpdateOrchestrator] [Call ID = {913F56DF-0776-41E0-8FFB-E311BB0812E2}] [hr = 0x00000000]
2019/11/19 11:14:46.8135121 12220 1300  ComApi          Download call complete (succeeded = 0, succeeded with errors = 0, failed = 1, cancelled = 0, unaccounted = 0)
2019/11/19 11:14:46.8135198 12220 1300  ComApi          * END *   All federated downloads have completed. ClientId = UpdateOrchestrator (cV = cuWy0hDQXE6z306T.1.1)
2019/11/19 11:14:46.8135422 6940  7148  Handler         Loaded state: cCompleteIterations: 0, pt: SelfContainedNoExpressPayload, nNextRequestID: 1.
2019/11/19 11:14:46.8135527 6940  7144  Agent           Effective power state: AC; IsOnAC: Yes.
2019/11/19 11:14:46.8135648 6940  7144  IdleTimer       WU operation (DL.UpdateOrchestrator) started; operation # 57; does use network; is not at background priority
2019/11/19 11:14:46.8135701 6940  7144  Agent           Obtained a network PDC reference for callID {1B242816-1944-4D90-8F34-AB54279C5735} with No-Progress-Timeout set to 4294967295; ActivationID: 57.
2019/11/19 11:14:46.8136045 6940  7148  DownloadManager Generating download request for update AB11DCBD-AD0E-4CB4-B143-3527DCF2BF7C.200.
2019/11/19 11:14:46.8146630 6940  7148  Misc            *FAILED* [80070003] Method failed [SusMoveOrCopyDirectoryContentsHelperRecursive:1650]
2019/11/19 11:14:46.8146671 6940  7148  Misc            *FAILED* [80070003] Method failed [SusMoveOrCopyDirectoryContentsHelper:1731]
2019/11/19 11:14:46.8146747 6940  7148  DownloadManager Calling into handler 0x8 to generate download request for update AB11DCBD-AD0E-4CB4-B143-3527DCF2BF7C.200.
2019/11/19 11:14:46.8146818 6940  7148  Handler         Generating request for CBS update AB11DCBD-AD0E-4CB4-B143-3527DCF2BF7C in sandbox C:\Windows\SoftwareDistribution\Download\54200965aa41c556f4acff41ed855e47
2019/11/19 11:14:46.8147166 6940  7148  Handler         Loaded state: cCompleteIterations: 0, pt: Unknown, nNextRequestID: 0.
2019/11/19 11:14:46.8147199 6940  7148  Handler         Selecting self-contained because update does not have express payload.
2019/11/19 11:14:46.8147216 6940  7148  Handler         Selected payload type is SelfContainedNoExpressPayload
2019/11/19 11:14:46.8147493 6940  7148  Handler         Detected download state is dsStart
2019/11/19 11:14:46.8147560 6940  7148  Handler         Adding Windows10.0-KB4516115-x64.cab (entire file) to request list.
2019/11/19 11:14:46.8153041 6940  7148  Handler         Saved state: cCompleteIterations: 0, pt: SelfContainedNoExpressPayload, nNextRequestID: 1.
2019/11/19 11:14:46.8153093 6940  7148  Handler         Request generation for CBS update complete with hr=0x0 and pfResetSandbox=0 
2019/11/19 11:14:46.8166001 6940  7148  DownloadManager *FAILED* [80070057] Method failed [CAgentDownloadManager::EnsureSufficientFreeSpace:23356]
2019/11/19 11:14:46.8166050 6940  7148  DownloadManager *FAILED* [80070057] Method failed [CAgentDownloadManager::HandleUpdateDownloadVolume:23302]
2019/11/19 11:14:46.8166117 6940  7148  DownloadManager *FAILED* [80070057] GDR
2019/11/19 11:14:46.8174621 6940  7148  Handler         Loaded state: cCompleteIterations: 0, pt: Unknown, nNextRequestID: 0.

I've tried the usual fixes, i.e. renaming SoftwareDistribution folder, "UxOption"=dword:00000000, "IsConvergedUpdateStackEnabled"=dword:00000000 but with no luck... 

The following referenced article suggests that 0x80070057 may be caused by a proxy issue - however for testing purposes I've completely blanked the IE internet proxy settings, and ensured that 'netsh winhttp show proxy' is showing 'direct'...

http://woshub.com/all-windows-update-error-codes/

So with all this said - would somebody be able to provide a clue as to where I should look next?

Thanks, Ash.

Some Tips to help WSUS Install Perfectly Every Time

$
0
0

This is a list of tips I'd like to submit for the sake of anyone planning to install WSUS or having trouble getting WSUS to install successfully.  These few tips are the result of hours and hours of researching I've done in trying to get WSUS installed on our own servers.  I hope this information helps in some way.  Our servers are all Server 2016, and I make no claims as to the effectiveness on earlier versions of Windows Server, though I have no reason to expect them not to help in at least 2012. 

1.   The most prevalent issue I encountered was, when attempting to install the WSUS feature through Server Manager, the installation would fail with the error, “one or several parent features are disabled so current feature can not be enabled.”  After some digging, I found this to be most likely related to .NET 3.5 and/or .NET 4.5 or 4.6 not being installed. To verify whether or not it is installed, run a PowerShell prompt with elevated credentials and type the following:

Get-WindowsFeature

After a moment of processing, there should be a list displayed of all available features and whether or not those features have been installed, removed, or are simply available for install. If one or both of these are showing either “available” or “removed”, and not “Installed,” install them by typing the following from the same PowerShell prompt:

dism /Online /Enable-Feature /All /FeatureName=NetFX3

 or, for .NET 4, type:

dism /Online /Enable-Feature /All /FeatureName=NetFX4

This will eliminate this particular error.  (NOTE: if you run the PowerShell command and get a “not found in library” error, reboot the server and try again.)

2.      On some occasions, I was able to install the WSUS feature, but was unable to either install the Windows Internal Database (WID) or WAS able to install it, but unable to start the service due to a login error. The WID uses SQL, and as such the service for it uses a special SQL account under the login tab in Services. If this account is not granted the “Log on as a service” right, the WID may not install correctly. To fix this issue, I added the following to the “Log on as a service” policy in the Default Domain Controller GPO: NT SERVICE\ALL SERVICES. Once I did this and waited for policy to apply, I was able to both install WID and start the WID service. 

3.      A third issue I experienced when I first began this process was when I was setting up the primary upstream WSUS server. It’s absolutely necessary to grant the NETWORK SERVICE account Full Control in both share permissions and NTFS permissions for the update software repository folder. I did not do this at first, and had to completely wipe out my installation and start over once I had set those permissions.

4.      When running the installation of WSUS from Server Manager, It will ask the location of the software repository. This must be a local path (e.g., C:\<folder>), NOT a UNC path (e.g.,\\<server>\<share>). I’m not sure why this won’t work, but it absolutely would not work.   

 

2 out of 3 (virtual) Windows 2012 R2 not updating, stuck on Checking for updates

$
0
0

I have 3 servers total, one is updating correctly, but the other 2 have never updated.  Decided to see how updates were being installed (automatically) and they have NEVER updated.

I tried the instructions of stopping the update service and deleting windows\software-distribution but that didin't work.

Any ideas?  The working server is an exact copy of one that is not updating.  It's funny because I installed Windows 2012 R2 and all the software needed on the one that doesn't update, then cloned it, then activated them with their licenses and the second one is updating fine.  The 3rd server was an update from 2008 R2 to 2012 R2 and everything went well and all the software worked fine, but it has never updated either.

Viewing all 12331 articles
Browse latest View live


Latest Images

<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>