Quantcast
Channel: WSUS Forum
Viewing all 12331 articles
Browse latest View live

WSUS updating is using up all my internet bandwidth. How can I control this?

$
0
0
My Server 2016 WSUS server is downloading new updates because I recently added some additional classifications.  It is using up basically 100% of my internet bandwidth making browsing for users very slow.  How can I throttle this back or control it?  thank U

I don't have a Central PolicyDefinitions Store - help me set it up.

$
0
0
I am running Server 2016 domain controllers.  I don't have a Central PolicyDefinitions folder and I need to set that up.

Please take a look at the steps below and let me know if I am leaving anything out.

1 - I need to create the folder under C:\Windows\SYSVOL\sysvol\corp.domain.com\Policies
     Is that correct?

2 - As far as the templates go, should I download one of the later versions from the links in the MS article or should I copy the
     templates from my  Win 10 computer (Win 10 ver 1909);  I believe the newer templates are backwards compatible with
     the older versions of Win 10

3 - Finally I need to copy over the admx files and adml (language) folder into the PolicyDefinitions folder.
   

Windows 10 computer not reporting to wsus periodically.

$
0
0

Hello Friends,

I have WSUS Server on Windows Server 2016 .

Since a few months I have observed that our Windows 10 computer not reporting to wsus server periodically.

I have checked wuauclt /detectnow ,wuauclt /reportnow but no luck.

Someone please advice.

 


Amit Kumar

No update for July 2020, and no change in WSUSscn2.cab? Windows 2012 R2 / Win2012

$
0
0

Hi all,

I downloaded wsusscn2.cab from  http://go.microsoft.com/fwlink/?LinkID=74689, on 11 July 2020. When I compare (FC) it with the download on 22 June 2020, there is no difference.

Link above is from https://support.microsoft.com/en-sg/help/926464/a-new-version-of-the-windows-update-offline-scan-file-wsusscn2-cab-is

From a newly installed WSUS server (on a Win2012R2, version 6.3.9600.18694), I did not find update released in July 2020. 

from the catalog.update.microsoft.com, did a search using "2012 R2", the latest update is 17 June 2020.

As I'm very new to this topic, so I wonder is it correct. There is no update for Win2012 r2 and Win2012 from 17 June onward?

Regards

SUSDB and SUSDB_Log Files Missing

$
0
0

I hope I can get assistance with this.  I had a corrupt version of WSUS 3.0 on a VM Win Server 2012 R2 that was only running IIS and WSUS.  I walked through the uninstall process completely from a post from https://ittherapist.net/2013/12/17/how-to-fix-windows-server-2012-and-2012-r2-wsus-post-install-fails-immediately/. I also followed the install process using PowerShell to install WSUS again.  Everything worked fine until the post installation taks happened, from which I used Power Shell again.  

PS C:\Users\administrator> & 'C:\Program Files\Update Services\Tools\WsusUtil.exe' postinstall contentdir=C:\WSUS
Log file is located at C:\Users\administrator\AppData\Local\Temp\2\tmp94DF.tmp
Post install is starting
Fatal Error: Unable to open the physical file "C:\Windows\WID\Data\SUSDB.mdf". Operating system error 2: "2(The system c
annot find the file specified.)".
Unable to open the physical file "C:\Windows\WID\Data\SUSDB.mdf". Operating system error 2: "2(The system cannot find th
e file specified.)".
Could not restart database "SUSDB". Reverting to the previous status.
ALTER DATABASE statement failed.
File activation failure. The physical file name "C:\Windows\WID\Data\SUSDB_log.ldf" may be incorrect.
File activation failure. The physical file name "C:\Windows\WID\Data\SUSDB_log.ldf" may be incorrect.
PS C:\Users\administrator> & 'C:\Program Files\Update Services\Tools\WsusUtil.exe' postinstall contentdir=C:\WSUS
Log file is located at C:\Users\administrator\AppData\Local\Temp\2\tmp225F.tmp
Post install is starting
Fatal Error: Unable to open the physical file "C:\Windows\WID\Data\SUSDB.mdf". Operating system error 2: "2(The system c
annot find the file specified.)".
Could not restart database "SUSDB". Reverting to the previous status.
ALTER DATABASE statement failed.
File activation failure. The physical file name "C:\Windows\WID\Data\SUSDB_log.ldf" may be incorrect.
PS C:\Users\administrator>

When I go into the directory holding the SUSDBs, they are not there.  However, the XML states it found the DBs and they exist.  How can that be?  I am stuck in the water now trying to get our WSUS working properly with a fresh install again. I do not have the deleted SUSDB files because this is a VM and we only backup MetaData, not disk Images for VM not holding company files.  I need to find a way for WSUS to fully create new SUSDBs and log files for this work.  Any guidance would be appreciated.

2016-04-14 09:13:24  Postinstall started
2016-04-14 09:13:24  Detected role services: UI, WidDatabase, Services
2016-04-14 09:13:24  Start: LoadSettingsFromParameters
2016-04-14 09:13:24  Content local is: False
2016-04-14 09:13:24  SQL instname is: 
2016-04-14 09:13:24  End: LoadSettingsFromParameters
2016-04-14 09:13:24  Start: Run
2016-04-14 09:13:24  Configuring content directory...
2016-04-14 09:13:24  Configuring groups...
2016-04-14 09:13:24  Starting group configuration for WSUS Administrators...
2016-04-14 09:13:24  Found group in regsitry, attempting to use it...
2016-04-14 09:13:26  Writing group to registry...
2016-04-14 09:13:26  Finished group creation
2016-04-14 09:13:26  Starting group configuration for WSUS Reporters...
2016-04-14 09:13:26  Found group in regsitry, attempting to use it...
2016-04-14 09:13:26  Writing group to registry...
2016-04-14 09:13:26  Finished group creation
2016-04-14 09:13:26  Configuring permissions...
2016-04-14 09:13:27  Fetching content directory...
2016-04-14 09:13:27  Fetching ContentDir from registry store
2016-04-14 09:13:27  Value is C:\Program Files\Update Services
2016-04-14 09:13:27  Fetching group SIDs...
2016-04-14 09:13:27  Fetching WsusAdministratorsSid from registry store
2016-04-14 09:13:27  Value is S-1-5-21-1885657281-318972376-3258134598-1006
2016-04-14 09:13:27  Fetching WsusReportersSid from registry store
2016-04-14 09:13:27  Value is S-1-5-21-1885657281-318972376-3258134598-1007
2016-04-14 09:13:27  Creating group principals...
2016-04-14 09:13:27  Granting directory permissions...
2016-04-14 09:13:27  Granting permissions on content directory...
2016-04-14 09:13:27  Granting registry permissions...
2016-04-14 09:13:27  Granting registry permissions...
2016-04-14 09:13:27  Granting registry permissions...
2016-04-14 09:13:27  Configuring shares...
2016-04-14 09:13:27  Configuring network shares...
2016-04-14 09:13:27  Fetching content directory...
2016-04-14 09:13:27  Fetching ContentDir from registry store
2016-04-14 09:13:27  Value is C:\Program Files\Update Services
2016-04-14 09:13:27  Fetching WSUS admin SID...
2016-04-14 09:13:27  Fetching WsusAdministratorsSid from registry store
2016-04-14 09:13:27  Value is S-1-5-21-1885657281-318972376-3258134598-1006
2016-04-14 09:13:27  Content directory is local, creating content shares...
2016-04-14 09:13:27  Creating share "UpdateServicesPackages" with path "C:\Program Files\Update Services\UpdateServicesPackages" and description "A network share to be used by client systems for collecting all software packages (usually applications) published on this WSUS system."
2016-04-14 09:13:27  Deleting existing share...
2016-04-14 09:13:27  Creating share...
2016-04-14 09:13:27  Share successfully created
2016-04-14 09:13:27  Creating share "WsusContent" with path "C:\Program Files\Update Services\WsusContent" and description "A network share to be used by Local Publishing to place published content on this WSUS system."
2016-04-14 09:13:27  Deleting existing share...
2016-04-14 09:13:27  Creating share...
2016-04-14 09:13:27  Share successfully created
2016-04-14 09:13:27  Creating share "WSUSTemp" with path "C:\Program Files\Update Services\LogFiles\WSUSTemp" and description "A network share used by Local Publishing from a Remote WSUS Console Instance."
2016-04-14 09:13:27  Deleting existing share...
2016-04-14 09:13:27  Creating share...
2016-04-14 09:13:27  Share successfully created
2016-04-14 09:13:27  Finished creating content shares
2016-04-14 09:13:27  Configuring WID database...
2016-04-14 09:13:27  Configuring the database...
2016-04-14 09:13:27  Establishing DB connection...
2016-04-14 09:13:27  Checking to see if database exists...
2016-04-14 09:13:28  Database exists
2016-04-14 09:13:28  Switching database to single user mode...
2016-04-14 09:13:28  System.Data.SqlClient.SqlException (0x80131904): Unable to open the physical file "C:\Windows\WID\Data\SUSDB.mdf". Operating system error 2: "2(The system cannot find the file specified.)".
Could not restart database "SUSDB". Reverting to the previous status.
ALTER DATABASE statement failed.
File activation failure. The physical file name "C:\Windows\WID\Data\SUSDB_log.ldf" may be incorrect.
   at Microsoft.UpdateServices.DatabaseAccess.DBConnection.DrainObsoleteConnections(SqlException e)
   at Microsoft.UpdateServices.DatabaseAccess.DBConnection.ExecuteCommandNoResult()
   at Microsoft.UpdateServices.Administration.ConfigureDB.ConnectToDB()
   at Microsoft.UpdateServices.Administration.ConfigureDB.Configure()
   at Microsoft.UpdateServices.Administration.PostInstall.Run()
   at Microsoft.UpdateServices.Administration.PostInstall.Execute(String[] arguments)
ClientConnectionId:863e187a-8e23-4875-a6d7-207959d0ff4b
Error Number:5120,State:101,Class:16

WSUS Patching - Windows 10 - Failed - 0x80070005

$
0
0

Hi,

I’m looking for some advice for Windows 10 patching please.

Last month (Dec), we aimed to get 99% of our estate fully patched, but ran into issues with specific updates installing. The error code we have is 0x80070005, which is access denied.

We logged a ticket with Microsoft, but so far haven't had a solution

We had hoped that the new batch of updates out for Jan may override the Dec patches that had issues, but this hasn’t been the case. We’re now getting the access denied error code on the newer patches.

Microsoft was able to fix one machine, but to do that fix for 100+ machines, it isn’t suitable. To give a description of the behaviour of the PCs when patching. They scan for the updates, download them and install them. The PC then reboots as required. When going into Windows Update, it states that it is up to date. If you do a scan, it will redownload the same patches again and do the same cycle. Looking at the history, they all have the 0x80070005 error. An example of some of the WSUS reports we have:

Installation Failure: Windows failed to install the following update with

error 0x80070005: 2019-12 Cumulative Update for .NET Framework 3.5 and 4.8 for Windows 10 Version 1909 for x64 (KB4533002)

Installation Failure: Windows failed to install the following update with

error 0x80070005: 2019-12 Cumulative Update for Windows 10 Version 1909 for x64-based Systems (KB4530684)

A workaround  that we have found is to download the latest Windows 10 Upgrade tool and reinstall Windows on top of that. It can be time consuming, but can easily be done.

But with that, I can’t be hopeful that this error won’t happen every month.

Any advice you can provide would be appreciated.

BITS fails to download update - error 0x40008?

$
0
0

Hello everybody,

I'm trying to resolve a problem with Windows Server 2016, where BITS attempts to redownload several updates again and again but fails with error 0x40008. This doesn't seem to be a very common problem because I have found almost no reference to this error on the internet. Also I'm not a Windows Server expert, so there may be something I'm missing. I think this is caused by WSUS, since it tries to download the update in several languages.

In the Event viewer I see BITS starting downloads for http://b1.download.windowsupdate.com/d/upgr/2019/10/18363.418.191007-0143.19h2_release_svc_refresh_clientbusiness_vol_a64fre_en-gb-<long hex> (2.1GB).

5 minutes later I get 

BITS stopped transferring the <long hex> transfer job that is associated with the http://b1.download.windowsupdate.com/d/upgr/2019/10/18363.418.191007-0143.19h2_release_svc_refresh_clientbusiness_vol_a64fre_en-gb_<long hex>.esd URL. The status code is 0x40008. Afterwards it restarts the download immediately and it fails with the same error, eating all our bandwidth.

As a workaround I do:

bitsadmin /reset /allusers

as the system user and this stops the downloads for 6-12 hours.

Anyone has an idea what else I could try? THanks!

The server is failing to download some updates

$
0
0

This is kind of a double-post but my other post is an add-on to an earlier, similar post and it's not getting any hits.

Good afternoon, my WSUS server was working fine until about a month ago. I now have a lot of workstations that aren't getting their updates and the only pertinent message showing up in the WSUS server's Event Log is Event ID 10032 and the only text is "The server is failing to download some updates." That message shows up daily at 0200, 0800, 1400 and 2000 and the data in the error doesn't help me much either: 

-<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">-<System><ProviderName="Windows Server Update Services"/><EventIDQualifiers="0">10032</EventID> <Level>2</Level><Task>7</Task> <Keywords>0x80000000000000</Keywords><TimeCreatedSystemTime="2020-06-09T09:00:49.000000000Z"/><EventRecordID>841646</EventRecordID> <Channel>Application</Channel><Computer>srv-Appy.link.com</Computer> <Security /></System>
- <EventData><Data>The server is failing to download some updates.</Data></EventData></Event>

I use Nexpose to find workstations with vulnerabilities and when I run Windows Update Online from those workstations I find several to many updates that need to be installed. I've looked for errors in those workstation's Event Logs under WindowsUpdateClient but I've never found errors in that log. 

Anybody have any ideas on what to look for?

Thanks,

Joe B


[Announcement] "WSUS" Forum will be migrating to a new home on Microsoft Q&A!

$
0
0

 
This "WSUS" Forum will be migrating to a new home on Microsoft Q&A!

We've listened to your feedback on how we can enhance the forum experience. Microsoft Q&A allows us to add new functionality and enables easier access to all the technical resources most useful to you, like Microsoft Docs and Microsoft Learn.  

 
Now until July 26, 2020:
 
From July 27, 2019 until August 10, 2020:
  • New posts – We invite you to post new questions in the "WSUS" forum's new home on Microsoft Q&A. The current forum will not allow any new questions.
  • Existing posts – Interact here with existing content, answer questions, provide comments, and so on.
 
August 10, 2020 onward:
  • This forum will be closed to all new and existing posts and all interactions will be in Microsoft Q&A.
We are excited about moving to Microsoft Q&A and seeing you there. Learn More



Windows 2012 R2, KB4561666 will not apply (ntprint.inf)

$
0
0

I have been unable to apply rollups for a few months. The latest, KB4561666, will not apply. 


cbs.log

2020-07-13 20:08:06, Info                  CBS    Startup: Initializing advanced operation queue.
2020-07-13 20:08:07, Info                  CSI    00000002 CSI Store 841863726032 (0x000000c402fd03d0) initialized
2020-07-13 20:08:07, Info                  CBS    Obtained poqexec from PoqexecCmdline: C:\Windows\System32\poqexec.exe /display_progress \SystemRoot\WinSxS\pending.xml
2020-07-13 20:08:07, Info                  CBS    SetProgressMessage: progressMessageStage: -1, ExecuteState: CbsExecuteStatePrimitives, SubStage: 0
2020-07-13 20:08:07, Info                  CBS    Setting ExecuteState key to: CbsExecuteStatePrimitives
2020-07-13 20:08:07, Info                  CBS    SetProgressMessage: progressMessageStage: -1, ExecuteState: CbsExecuteStatePrimitives, SubStage: 2
2020-07-13 20:08:07, Info                  CBS    Startup: Processing non-critical driver operations queue, Count 6.
2020-07-13 20:08:07, Info                  CBS    Doqe: Resetting result: 0x00000000, for Inf: ntprint.inf
2020-07-13 20:08:07, Info                  CBS    Doqe: Locking driver updates, Count 8
2020-07-13 20:08:07, Info                  CSI    00000003 Performing 1 operations; 1 are not lock/unlock and follow:
  (0)  LockComponentPath (10): flags: 0 comp: {l:16 b:4400799d8359d60101000000e002ec02} pathid: {l:16 b:4400799d8359d60102000000e002ec02} path: [l:172{86}]"\SystemRoot\WinSxS\amd64_cpu.inf_31bf3856ad364e35_6.3.9600.19678_none_4e174d17c34cb3ea" pid: 2e0 starttime: 132391660857983175 (0x01d659839caa00c7)
2020-07-13 20:08:07, Info                  CSI    00000004 Performing 1 operations; 1 are not lock/unlock and follow:
  (0)  LockComponentPath (10): flags: 0 comp: {l:16 b:3527809d8359d60103000000e002ec02} pathid: {l:16 b:3527809d8359d60104000000e002ec02} path: [l:180{90}]"\SystemRoot\WinSxS\amd64_ntprint.inf_31bf3856ad364e35_6.3.9600.18790_none_2bb006008eb5c61f" pid: 2e0 starttime: 132391660857983175 (0x01d659839caa00c7)
2020-07-13 20:08:07, Info                  CSI    00000005 Performing 1 operations; 1 are not lock/unlock and follow:
  (0)  LockComponentPath (10): flags: 0 comp: {l:16 b:8c89829d8359d60105000000e002ec02} pathid: {l:16 b:8c89829d8359d60106000000e002ec02} path: [l:176{88}]"\SystemRoot\WinSxS\x86_ntprint.inf_31bf3856ad364e35_6.3.9600.18790_none_cf916a7cd65854e9" pid: 2e0 starttime: 132391660857983175 (0x01d659839caa00c7)
2020-07-13 20:08:07, Info                  CSI    00000006 Performing 1 operations; 1 are not lock/unlock and follow:
  (0)  LockComponentPath (10): flags: 0 comp: {l:16 b:e3eb849d8359d60107000000e002ec02} pathid: {l:16 b:e3eb849d8359d60108000000e002ec02} path: [l:172{86}]"\SystemRoot\WinSxS\amd64_cpu.inf_31bf3856ad364e35_6.3.9600.19724_none_4e495d71c327c000" pid: 2e0 starttime: 132391660857983175 (0x01d659839caa00c7)
2020-07-13 20:08:07, Info                  CSI    00000007 Performing 1 operations; 1 are not lock/unlock and follow:
  (0)  LockComponentPath (10): flags: 0 comp: {l:16 b:3e4e879d8359d60109000000e002ec02} pathid: {l:16 b:3e4e879d8359d6010a000000e002ec02} path: [l:182{91}]"\SystemRoot\WinSxS\amd64_prnms003.inf_31bf3856ad364e35_6.3.9600.19728_none_43d27c99a7a30b45" pid: 2e0 starttime: 132391660857983175 (0x01d659839caa00c7)
2020-07-13 20:08:07, Info                  CSI    00000008 Performing 1 operations; 1 are not lock/unlock and follow:
  (0)  LockComponentPath (10): flags: 0 comp: {l:16 b:3e4e879d8359d6010b000000e002ec02} pathid: {l:16 b:3e4e879d8359d6010c000000e002ec02} path: [l:178{89}]"\SystemRoot\WinSxS\x86_prnms003.inf_31bf3856ad364e35_6.3.9600.19728_none_e7b3e115ef459a0f" pid: 2e0 starttime: 132391660857983175 (0x01d659839caa00c7)
2020-07-13 20:08:07, Info                  CSI    00000009 Performing 1 operations; 1 are not lock/unlock and follow:
  (0)  LockComponentPath (10): flags: 0 comp: {l:16 b:bcb0899d8359d6010d000000e002ec02} pathid: {l:16 b:bcb0899d8359d6010e000000e002ec02} path: [l:180{90}]"\SystemRoot\WinSxS\amd64_ntprint.inf_31bf3856ad364e35_6.3.9600.19728_none_2c03a0fc8e75e6e1" pid: 2e0 starttime: 132391660857983175 (0x01d659839caa00c7)
2020-07-13 20:08:07, Info                  CSI    0000000a Performing 1 operations; 1 are not lock/unlock and follow:
  (0)  LockComponentPath (10): flags: 0 comp: {l:16 b:bcb0899d8359d6010f000000e002ec02} pathid: {l:16 b:bcb0899d8359d60110000000e002ec02} path: [l:176{88}]"\SystemRoot\WinSxS\x86_ntprint.inf_31bf3856ad364e35_6.3.9600.19728_none_cfe50578d61875ab" pid: 2e0 starttime: 132391660857983175 (0x01d659839caa00c7)
2020-07-13 20:08:07, Info                  CBS    Doqe:   q-install: Inf: prnms003.inf, Ranking: 2, Device-Install: 0, Key: 35, Identity: prnms003.inf, Culture=neutral, Type=driverUpdate, Version=6.3.9600.19728, PublicKeyToken=31bf3856ad364e35, ProcessorArchitecture=amd64, versionScope=NonSxS
2020-07-13 20:08:07, Info                  CBS    Doqe:   q-install: Inf: prnms003.inf, Ranking: 2, Device-Install: 0, Key: 36, Identity: prnms003.inf, Culture=neutral, Type=driverUpdate, Version=6.3.9600.19728, PublicKeyToken=31bf3856ad364e35, ProcessorArchitecture=x86, versionScope=NonSxS
2020-07-13 20:08:07, Info                  CBS    Doqe:   q-install: Inf: ntprint.inf, Ranking: 2, Device-Install: 0, Key: 37, Identity: ntprint.inf, Culture=neutral, Type=driverUpdate, Version=6.3.9600.19728, PublicKeyToken=31bf3856ad364e35, ProcessorArchitecture=amd64, versionScope=NonSxS
2020-07-13 20:08:07, Info                  CBS    Doqe:   q-install: Inf: ntprint.inf, Ranking: 2, Device-Install: 0, Key: 38, Identity: ntprint.inf, Culture=neutral, Type=driverUpdate, Version=6.3.9600.19728, PublicKeyToken=31bf3856ad364e35, ProcessorArchitecture=x86, versionScope=NonSxS
2020-07-13 20:08:07, Info                  CBS    Perf: Doqe: Install started.
2020-07-13 20:08:07, Info                  CBS    Doqe: [Forward] Installing driver updates, Count 4
2020-07-13 20:08:07, Info                  CBS            INSTALL index: 4, phase: 1, result 0, inf: prnms003.inf
2020-07-13 20:08:07, Info                  CBS            INSTALL index: 5, phase: 1, result 0, inf: prnms003.inf
2020-07-13 20:08:07, Info                  CBS            INSTALL index: 6, phase: 1, result 3, inf: ntprint.inf
2020-07-13 20:08:07, Info                  CBS    Doqe: Recording result: 0x80070003, for Inf: ntprint.inf
2020-07-13 20:08:07, Info                  CBS    DriverUpdateInstallUpdates failed [HRESULT = 0x80070003 - ERROR_PATH_NOT_FOUND]
2020-07-13 20:08:07, Info                  CBS    Doqe: Failed installing driver updates [HRESULT = 0x80070003 - ERROR_PATH_NOT_FOUND]
2020-07-13 20:08:07, Info                  CBS    Perf: Doqe: Install ended.
2020-07-13 20:08:07, Info                  CBS    Failed installing driver updates [HRESULT = 0x80070003 - ERROR_PATH_NOT_FOUND]
2020-07-13 20:08:07, Error                 CBS    Startup: Failed while processing non-critical driver operations queue. [HRESULT = 0x80070003 - ERROR_PATH_NOT_FOUND]
2020-07-13 20:08:07, Info                  CBS    Startup: Rolling back KTM, because drivers failed.


setupapi.dev.log

>>>  [Setup Import Driver Package - C:\Windows\system32\spool\DRIVERS\x64\{E5059964-01C3-457E-9A4A-890C83197DE1}\tsprint.inf]>>>  Section start 2020/07/13 20:08:32.140
      cmd: C:\Windows\System32\spoolsv.exe
     inf: Provider: Microsoft
     inf: Class GUID: {4D36E979-E325-11CE-BFC1-08002BE10318}
     inf: Driver Version: 06/21/2006,6.3.9600.17415
     pol: {Driver package policy check} 20:08:32.328
     pol: {Driver package policy check - exit(0x00000000)} 20:08:32.328
     sto: {Stage Driver Package: C:\Windows\system32\spool\DRIVERS\x64\{E5059964-01C3-457E-9A4A-890C83197DE1}\tsprint.inf} 20:08:32.343
     inf:      {Query Configurability: C:\Windows\system32\spool\DRIVERS\x64\{E5059964-01C3-457E-9A4A-890C83197DE1}\tsprint.inf} 20:08:32.343
     inf:           Driver package 'tsprint.inf' is configurable.
     inf:      {Query Configurability: exit(0x00000000)} 20:08:32.343
     flq:      Copying 'C:\Windows\system32\spool\DRIVERS\x64\{E5059964-01C3-457E-9A4A-890C83197DE1}\tsprint.inf' to 'C:\Windows\System32\DriverStore\Temp\{4550f12c-0e6b-044c-9d3f-8c29b21ea080}\tsprint.inf'.
     flq:      Copying 'C:\Windows\system32\spool\DRIVERS\x64\{E5059964-01C3-457E-9A4A-890C83197DE1}\tsprint-PipelineConfig.xml' to 'C:\Windows\System32\DriverStore\Temp\{4550f12c-0e6b-044c-9d3f-8c29b21ea080}\tsprint-PipelineConfig.xml'.
     flq:      Copying 'C:\Windows\system32\spool\DRIVERS\x64\{E5059964-01C3-457E-9A4A-890C83197DE1}\tsprint-datafile.dat' to 'C:\Windows\System32\DriverStore\Temp\{4550f12c-0e6b-044c-9d3f-8c29b21ea080}\tsprint-datafile.dat'.
     flq:      Copying 'C:\Windows\system32\spool\DRIVERS\x64\{E5059964-01C3-457E-9A4A-890C83197DE1}\amd64\tsprint.dll' to 'C:\Windows\System32\DriverStore\Temp\{4550f12c-0e6b-044c-9d3f-8c29b21ea080}\amd64\tsprint.dll'.
     sto:      {DRIVERSTORE IMPORT VALIDATE} 20:08:32.359
!!!  sig:           Driver package does not contain a catalog file, and Code Integrity is enforced.
!!!  sig:           Driver package failed signature validation. Error = 0xE000022F
     sto:      {DRIVERSTORE IMPORT VALIDATE: exit(0xe000022f)} 20:08:32.390
!!!  sig:      Driver package failed signature verification. Error = 0xE000022F
!!!  sto:      Failed to import driver package into Driver Store. Error = 0xE000022F
     sto: {Stage Driver Package: exit(0xe000022f)} 20:08:32.390<<<  Section end 2020/07/13 20:08:32.390<<<  [Exit status: FAILURE(0xe000022f)]


[Boot Session: 2020/07/13 20:09:32.584]

>>>  [Setup Import Driver Package - C:\Windows\system32\spool\DRIVERS\x64\{09278BEB-F80D-4C5E-8CB3-45E756F96FDD}\tsprint.inf]>>>  Section start 2020/07/13 20:10:07.917
      cmd: C:\Windows\System32\spoolsv.exe
     inf: Provider: Microsoft
     inf: Class GUID: {4D36E979-E325-11CE-BFC1-08002BE10318}
     inf: Driver Version: 06/21/2006,6.3.9600.17415
     pol: {Driver package policy check} 20:10:08.105
     pol: {Driver package policy check - exit(0x00000000)} 20:10:08.105
     sto: {Stage Driver Package: C:\Windows\system32\spool\DRIVERS\x64\{09278BEB-F80D-4C5E-8CB3-45E756F96FDD}\tsprint.inf} 20:10:08.121
     inf:      {Query Configurability: C:\Windows\system32\spool\DRIVERS\x64\{09278BEB-F80D-4C5E-8CB3-45E756F96FDD}\tsprint.inf} 20:10:08.136
     inf:           Driver package 'tsprint.inf' is configurable.
     inf:      {Query Configurability: exit(0x00000000)} 20:10:08.136
     flq:      Copying 'C:\Windows\system32\spool\DRIVERS\x64\{09278BEB-F80D-4C5E-8CB3-45E756F96FDD}\tsprint.inf' to 'C:\Windows\System32\DriverStore\Temp\{33a54c21-3608-fe43-b603-be9f34e89dda}\tsprint.inf'.
     flq:      Copying 'C:\Windows\system32\spool\DRIVERS\x64\{09278BEB-F80D-4C5E-8CB3-45E756F96FDD}\tsprint-PipelineConfig.xml' to 'C:\Windows\System32\DriverStore\Temp\{33a54c21-3608-fe43-b603-be9f34e89dda}\tsprint-PipelineConfig.xml'.
     flq:      Copying 'C:\Windows\system32\spool\DRIVERS\x64\{09278BEB-F80D-4C5E-8CB3-45E756F96FDD}\tsprint-datafile.dat' to 'C:\Windows\System32\DriverStore\Temp\{33a54c21-3608-fe43-b603-be9f34e89dda}\tsprint-datafile.dat'.
     flq:      Copying 'C:\Windows\system32\spool\DRIVERS\x64\{09278BEB-F80D-4C5E-8CB3-45E756F96FDD}\amd64\tsprint.dll' to 'C:\Windows\System32\DriverStore\Temp\{33a54c21-3608-fe43-b603-be9f34e89dda}\amd64\tsprint.dll'.
     sto:      {DRIVERSTORE IMPORT VALIDATE} 20:10:08.167
!!!  sig:           Driver package does not contain a catalog file, and Code Integrity is enforced.
!!!  sig:           Driver package failed signature validation. Error = 0xE000022F
     sto:      {DRIVERSTORE IMPORT VALIDATE: exit(0xe000022f)} 20:10:08.199
!!!  sig:      Driver package failed signature verification. Error = 0xE000022F
!!!  sto:      Failed to import driver package into Driver Store. Error = 0xE000022F
     sto: {Stage Driver Package: exit(0xe000022f)} 20:10:08.199<<<  Section end 2020/07/13 20:10:08.214<<<  [Exit status: FAILURE(0xe000022f)]

Is this a signing issue? A missing file issue?


Batch script to extract updates from WSUS content folder

$
0
0

Hi Team,

We are having WSUS 6.3 running on Windows Server 2012 R2 STD Edition, can someone please suggest applicable batch script to extract updates from WSUS content folder.

Move WSUS database from root partition to another drive

$
0
0

Hi, 

Running wsus on Win 2012 R2, would like to know how we can move wsus database (WID) from root partition to another partition on the same server as its consuming lot of space on the root partition. 

Please suggest how this can be achieved. 


I have already referred URL (https://4sysops.com/archives/move-wsus-database-and-content-updates-to-a-different-drive-or-folder/),

But post performing the steps it completed successfully without any errors but getting below errors in Event logs.

1] System Logs: The WSUS Service service entered the stopped state. (Event ID: 7036)

2] Application Logs: Update Services failed its initialization and stopped. (Event ID: 507)

WSUS not installing updates as expected

$
0
0

I have a few sites where Windows 10 policies are not effective.  Even when I enable immediate installation, often times users have to click "install now" to install the update.  This is true right now for the cumulative updates for .Net and win10 2004.  I approve the update but when I visit the workstation, it is waiting for someone to click "install now".   This is totally new to me

Question is, how can I set group policies such that if an update is available, it installs immediately without requiring users to click a button?

Microsoft Windows Server Patches not installing on 2008 R2 Standard (SP1).

$
0
0


Hi Team,

1) While installing patches manually on 2008 R2 servers Getting message as 

"The Windows Modules Installer must be updated before you can install this package. 
Please update the windows modules installer on your computer , then retry setup. "

Even viewer error: 

The Windows Modules Installer must be updated before you can install this package (Command line: ""C:\Windows\system32\wusa.exe" "C:\temp\win 2008R2\win 2008R2\windows6.1-kb4550905-x64_ec45614587de8c5caeeaddce84ab2d1b0ac918d7.msu"       ")


2) We have downloaded MSU instaler from below MS link and try to install the KB2533552 on server but it's not installing 

Getting message as " The update is not applicable to your computer"


URL:  https://support.microsoft.com/en-us/help/925316/error-message-when-you-install-a-msu-update-package-on-a-computer-that


Is Microsoft supporting 2008 R2 OS?
if not, why we have 2008 R2 patches available for these servers. 
How can we fix this patches not installing on 2008 R2 servers?

Could you please help me on this issue?

Thanks in Advance!


Thanks & Regards, Balaji G (from microsoft alert forum)


Driver updates have multiple listings in WSUS

$
0
0

Server2102 R@ - Hyper-V 

I separated the type of updates by category. Only in "drivers" do I see multiple instances of the same update:

How do I get this to one instance?


John Lenz


Client Not reporting

$
0
0

Hello all,

I am having issues, in the following scenario:

  • WSUS server in domain A and i am trying to patch servers in domain B, there is no trust with those domain.
  • WSUS is in SSL

I can see servers from domain B in the WSUS but they are only contacting and not reporting.

I have tried running this script

#############

net stop wuauserv
cd %systemroot%
ren SoftwareDistribution SoftwareDistribution.old
reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate" /v AccountDomainSid /f
reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate" /v PingID /f
reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate" /v SusClientId /f
reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate" /v SusClientIDValidation /f
net start wuauserv
net stop bits
net start bits
net stop cryptsvc
cd %systemroot%\system32
ren catroot2 catroot2old
net start cryptsvc
Wuauclt.exe /resetauthorization /detectnow /reportnow

################################

But with no luck, the servers are not reporting, another thing i found and not sure if it's related with the issue, is that when i restart the cryptsvc service the catroot2 folder is not recreated.

Did anyone had this issues or this scenario?

Thanks,

Rui

Make sure Updates are downloading from Internal WSUS server or Internet.

$
0
0

Hi All,

Recently there are some updates installed on a client computer but when I login and checked on WSUS, WSUS server got crashed and  it seems IIS server is not functioning well. below is the error message on event viewer with event ID: 12042.

"The SimpleAuth Web service is not working."

Once I reset IIS, WSUS console is working back. However, Here I want to get to know my client PC is got installed updates from Internet or WSUS. I have confused here since all settings are in place properly interns of WSUS configurations. 

Below is a few setting which I refereed,

GPO Settings:

WindowsUpdate.log1:

2020/05/30 10:31:05.1244338 1252  2112  Shared          * END * Service exit Exit code = 0x240001
2020/05/31 05:48:17.0040650 1252  1996  Agent           WU client version 10.0.14393.3564
2020/05/31 05:48:17.0045053 1252  1996  Agent           SleepStudyTracker: Machine is non-AOAC. Sleep study tracker disabled.
2020/05/31 05:48:17.0046047 1252  1996  Agent           Base directory: C:\Windows\SoftwareDistribution
2020/05/31 05:48:17.0053034 1252  1996  Agent           Datastore directory: C:\Windows\SoftwareDistribution\DataStore\DataStore.edb
2020/05/31 05:48:17.0462665 1252  1996  Shared          UpdateNetworkState Ipv6, cNetworkInterfaces = 0.
2020/05/31 05:48:17.0463099 1252  1996  Shared          UpdateNetworkState Ipv4, cNetworkInterfaces = 1.
2020/05/31 05:48:17.0471887 1252  1996  Shared          Network state: Connected
2020/05/31 05:48:17.0521744 1252  1996  Misc            LoadHistoryEventFromRegistry completed, hr = 8024000C
2020/05/31 05:48:17.0579432 1252  1996  Shared          UpdateNetworkState Ipv6, cNetworkInterfaces = 0.
2020/05/31 05:48:17.0579528 1252  1996  Shared          UpdateNetworkState Ipv4, cNetworkInterfaces = 1.
2020/05/31 05:48:17.0579624 1252  1996  Shared          Power status changed
2020/05/31 05:48:17.0594057 1252  1996  Agent               Timer: 29A863E7-8609-4D1E-B7CD-5668F857F1DB, Expires 2020-05-30 23:55:54, not idle-only, not network-only
2020/05/31 05:48:17.0646937 1252  208   Agent           Initializing global settings cache
2020/05/31 05:48:17.0646949 1252  208   Agent           WSUS server: http://***WSUS01:8530
2020/05/31 05:48:17.0646961 1252  208   Agent           WSUS status server: http://***WSUS01:8530
2020/05/31 05:48:17.0646967 1252  208   Agent           Alternate Download Server: NULL
2020/05/31 05:48:17.0646973 1252  208   Agent           Fill Empty Content Urls: No
2020/05/31 05:48:17.0646980 1252  208   Agent           Target group: Servers
2020/05/31 05:48:17.0646986 1252  208   Agent           Windows Update access disabled: No
2020/05/31 05:48:17.0676483 1252  1996  Agent           Initializing Windows Update Agent
2020/05/31 05:48:17.0677766 1252  1996  DownloadManager Download manager restoring 0 downloads
2020/05/31 05:48:17.0678760 1252  1996  Agent           CPersistentTimeoutScheduler | GetTimer, returned hr = 0x00000000
2020/05/31 05:48:17.0948976 1252  4680  DownloadManager PurgeExpiredFiles::Found 1 expired files to delete.
2020/05/31 05:48:17.0949048 1252  4680  DownloadManager PurgeExpiredFiles::Deleting expired file at C:\Windows\SoftwareDistribution\Download\8be86a04c19878b4eae28e71a2ec8cc3a33cffa0.
2020/05/31 05:48:17.1126803 2288  1408  ComApi          * START *   Init Search ClientId = Windows Defender
2020/05/31 05:48:17.1126959 2288  1408  ComApi          * START *   Search ClientId = Windows Defender

WindowsUpdate.log2:

2020/05/31 05:48:29.3177361 1252  4680  Agent               Bundles 1 updates:
2020/05/31 05:48:29.3177415 1252  4680  Agent                 1B85A067-FD82-4EBC-9A2E-09DB7CED0E1F.200
2020/05/31 05:48:29.3177939 1252  4680  DownloadManager No locked revisions found for update 97B6A577-D90D-4A5F-9772-D236364C64D2; locking the user-specified revision.
2020/05/31 05:48:29.3183137 1252  4680  DownloadManager No locked revisions found for update 1B85A067-FD82-4EBC-9A2E-09DB7CED0E1F; locking the user-specified revision.
2020/05/31 05:48:29.3188836 1252  4680  DownloadManager Regulation: {7971F918-A847-4430-9279-4A52D1EFE18D} - Loaded sequence number 65535 for regulation category PerUpdate.
2020/05/31 05:48:29.3188854 1252  4680  DownloadManager Regulation: {7971F918-A847-4430-9279-4A52D1EFE18D} - Loaded sequence number 65535 for regulation category Low.
2020/05/31 05:48:29.3188860 1252  4680  DownloadManager Regulation: {7971F918-A847-4430-9279-4A52D1EFE18D} - Loaded sequence number 65535 for regulation category Normal.
2020/05/31 05:48:29.3188872 1252  4680  DownloadManager Regulation: {7971F918-A847-4430-9279-4A52D1EFE18D} - Loaded sequence number 65535 for regulation category High.
2020/05/31 05:48:29.3480291 1252  4680  DownloadManager Failed to connect to the DO service; (hr = 80040154)
2020/05/31 05:48:29.3480303 1252  4680  DownloadManager GetDOManager() failed, hr=80246008, hrExtended=80040154
2020/05/31 05:48:29.3480321 1252  4680  DownloadManager Failed creating DO job with hr 80246008
2020/05/31 05:48:29.3533394 1252  4680  DownloadManager DO download failed with error 80246008[Extended: 80040154], falling back to BITS and retrying with new Download Job.
2020/05/31 05:48:29.5259175 1252  4680  DownloadManager BITS job initialized: JobId = {318F9140-221B-46B4-BB21-4A82120C8C08}
2020/05/31 05:48:29.5325609 1252  4680  DownloadManager Downloading from http://au.download.windowsupdate.com/d/msdownload/update/software/defu/2020/05/am_delta_patch_1.317.212.0_5043713139f26290dbee3ab1ea6cf22eba1cc280.exe to C:\Windows\SoftwareDistribution\Download\a9067bc45ff8dfbf288e566668ed8a0a\5043713139f26290dbee3ab1ea6cf22eba1cc280 (full file)
2020/05/31 05:48:29.5348323 1252  4680  DownloadManager New download job {318F9140-221B-46B4-BB21-4A82120C8C08} for UpdateId 1B85A067-FD82-4EBC-9A2E-09DB7CED0E1F.200
2020/05/31 05:48:29.5466632 1252  4680  DownloadManager Download job 318F9140-221B-46B4-BB21-4A82120C8C08 resumed.
2020/05/31 05:48:29.5869432 1252  4680  Shared          Effective power state: AC
2020/05/31 05:48:29.5869480 1252  4680  Agent           Released network PDC reference for callId {13DB53CD-EA24-4527-9ABD-5790C2B526BC}; ActivationID: 32
2020/05/31 05:48:29.5869558 1252  4680  Agent           Obtained a network PDC reference for callID {13DB53CD-EA24-4527-9ABD-5790C2B526BC} with No-Progress-Timeout set to 4294967295; ActivationID: 33.
2020/05/31 05:48:29.5873883 1252  5044  Agent           WU client calls back to download call {13DB53CD-EA24-4527-9ABD-5790C2B526BC} with code Call progress and error 0
2020/05/31 05:48:29.6302145 1252  4680  DownloadManager * END * Begin Downloading Updates CallerId = Windows Defender
2020/05/31 05:48:29.6387559 1252  4680  DownloadManager Download job 318F9140-221B-46B4-BB21-4A82120C8C08 resumed.
2020/05/31 05:48:47.7733007 1252  3156  DownloadManager BITS job {318F9140-221B-46B4-BB21-4A82120C8C08} completed successfully
2020/05/31 05:48:47.7791917 1252  3156  DownloadManager CUpdateDownloadJob::GetNetworkCostSwitch() Unrestricted cost used, but current cost is restricted
2020/05/31 05:48:47.7909756 1252  3156  Misc            Validating signature for C:\Windows\SoftwareDistribution\Download\a9067bc45ff8dfbf288e566668ed8a0a\5043713139f26290dbee3ab1ea6cf22eba1cc280 with dwProvFlags 0x00000080:
2020/05/31 05:48:47.8186236 1252  3156  Misc             Microsoft signed: Yes
2020/05/31 05:48:47.8202452 1252  3156  DownloadManager   Download job completion. Progress for update {1B85A067-FD82-4EBC-9A2E-09DB7CED0E1F} - total = 1390008, transferred = 1390008 bytes. Transfer time=13128, connect time=5062 (ms)
2020/05/31 05:48:47.8601301 1252  4680  SLS             Retrieving SLS response from server using ETAG f2dAyzSAXLAz7XI7tUppQAzeh4mYqtC/h1zNY+Fz0IU=_1440"..."
2020/05/31 05:48:47.8604168 1252  4680  SLS             Making request with URL HTTPS://sls.update.microsoft.com/SLS/{9482F4B4-E343-43B6-B170-9A65BC822C77}/x64/10.0.14393.0/0?CH=272&L=en-US&P=&PT=0x7&WUA=10.0.14393.3564
2020/05/31 05:48:48.9710885 1252  4680  Misc            StatusCode for transaction returned from WinHttpQueryHeaders is 304
2020/05/31 05:48:49.0306649 1252  4680  DownloadManager All files for update {1B85A067-FD82-4EBC-9A2E-09DB7CED0E1F}.200 were already downloaded and are valid.
2020/05/31 05:48:49.0318106 1252  4680  DownloadManager * END * Download Call Complete Call 2 for caller Windows Defender has completed; signaling completion.
2020/05/31 05:48:49.0358205 1252  4680  Shared          Effective power state: AC
2020/05/31 05:48:49.0358259 1252  4680  Agent           Released network PDC reference for callId {13DB53CD-EA24-4527-9ABD-5790C2B526BC}; ActivationID: 33
2020/05/31 05:48:49.0361060 2288  1492  ComApi          *RESUMED* Download ClientId = Windows Defender
2020/05/31 05:48:49.0361090 2288  1492  ComApi          Download call complete (succeeded = 1, succeeded with errors = 0, failed = 0, unaccounted = 0)
2020/05/31 05:48:49.0361144 2288  1492  ComApi          * END *   Download ClientId = Windows Defender

Thanks in advance,

Dilan





windows server essentials weekly shutdown

$
0
0

Hello,

we installed WSUS on multiple windows server 2019 essentials to serve as down-streamer to our Main WSUS (server 2016 standard) , one for each branch to reduce network traffic (maximum 10 computers in every branch)

our ADDC is running on  (server 2016 standard) with all FSMO rules

but our essentials servers shutdown automatically every week with these events:

Event 38

The User Count Check detected a condition in your environment that is out of compliance with the licensing policy. This server will be automatically shut down if the issue is not corrected in 10 day(s) 0 hour(s) 0 minute(s). Please look for additional events for User Count Check to troubleshoot.

Event 74

The User Count Check detected a condition in your environment that is out of compliance with the licensing policy. This server does not comply with the End User License Agreement (EULA). The EULA permits a maximum of 25 user accounts. This Active Directory forest has 529 user accounts.

Event 20

The Forest Trust Check detected a condition in your environment that is out of compliance with the licensing policy. A trust relationship exists outside your forest. Please remove the trust now.

Event 38

The Non-domain Member Check detected a condition in your environment that is out of compliance with the licensing policy. This server will be automatically shut down if the issue is not corrected in 10 day(s) 0 hour(s) 0 minute(s). Please look for additional events for Non-domain Member Check to troubleshoot.

Event 57

The Non-domain Member Check policy detected a condition in your environment that is out of compliance with the licensing policy. This server can only be in a workgroup or be a domain controller.

essentials are member of large domain (Full data center environment).

how to solve this issue ?

Unable to Download windows 10 security updates (Retry Download)

$
0
0

Hi Guys,

We recently installed WSUS on Windows server 2012 R2, but are unable to download security updates which we approved and it keeps showing the rex cross (X) and retry download. We only need windows 10 updates for our end user machines. Can any one please help us with the detailed procedure how to update our windows 10 machines and other servers through WSUS.

Note: We have not yet activated our server 2012 R2 license, is that the reason why we are unable to get the updates? please guide?

Many Thanks

SSU update using WSUS not reflecting under Windows Update List

$
0
0

I am facing problem while I approve June 2020 monthly rollup along with remaining patches and SSU Update. I have noticed that if I approved Monthly rollup then SSU update is stopped reflecting in Windows update list. I have selected option 2 to select for download and install. As of now I am facing this problem in windows 2012 R2.

If I remove Monthly Rollup of June 2020 for windows 2012 R2, SSU update of 06-2020 KB4562253 start reporting under Windows Update and I can select it for download and install.

I have seen one forum which explain to approve this update first and then approve another updates but it wont help me because I have to finish patching in defined time line. Even I can not select day -1 as deadline, else it will start installing this KB forcefully without planned downtime / maintenance window.

Is there any fix required on windows 2012 R2?

As per log it is reflecting under total count but in GUI -> Control Panel -> Windows Update SSU is not listed in pending list.

Viewing all 12331 articles
Browse latest View live


<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>