Jump to content

Recommended Posts

Posted
You haven't got a proxy wormed it's way into the clients somehow? can you run netsh winhttp show proxy and check that?

 

We do use a proxy with exceptions for all local servers, but nothing has changed in that sense to cause all of our Wsus clients to fail. In fact the only thing that changed was I did a p2v of the server. I've since tried two new vms but they get the same result.

 

If I hadn't wiped the old physical server I would have brought that back online!

Posted
Out of curiosity how did you deploy this? My Wsus clients register in the console but never report in so I'd have to use a GPO to dish this out.

 

I've run it manually on some machines to test, and added it to our SCCM OSD task sequence for new builds. I will be deploying it to the rest of the school as a package through SCCM.

Posted
I'm now on another brand new physical server, which has all of my clients showing, but only about 1/5 are reporting in. Theres no rhyme nor reason to the ones that are compared to the ones that aren't! They've all had their SUS ID reset to try and reconnect them and were all working fine until a few weeks ago!
Posted

You've been back and forth on a lot of things - so it may help to go over the basics of where things are at now.

Server OS?

 

WSUS build number?

 

Error code being thrown?

 

Can you post a (sterilized) Windowsupdate.log - just the last complete run off one of the problem children -should shed some light on the subject - doesn't make sense that identical hardware, that I take it is on the same VLAN, one works and the one next to it doesn't.

Posted (edited)
You've been back and forth on a lot of things - so it may help to go over the basics of where things are at now.

Server OS?

 

WSUS build number?

 

Error code being thrown?

 

Can you post a (sterilized) Windowsupdate.log - just the last complete run off one of the problem children -should shed some light on the subject - doesn't make sense that identical hardware, that I take it is on the same VLAN, one works and the one next to it doesn't.

 

My current attempt is on Server 2012 R2, build of WSUS is 10.0.10514.4. Most are failing with the following error log in WindowsUpdate.log - as recent as this morning they are failing. I can't seem to find any way around this. 100% of our W7 clients were working until some point a few weeks ago when the WSUS server was P2V'd and from that point they won't connect to any WSUS server, which makes me think its a client fault now.

 

2016-09-28 08:20:13:232 648 cf0 AU #############

2016-09-28 08:20:13:232 648 cf0 AU ## START ## AU: Search for updates

2016-09-28 08:20:13:232 648 cf0 AU #########

2016-09-28 08:20:13:239 648 cf0 AU <<## SUBMITTED ## AU: Search for updates [CallId = {8F7D1A2A-6C86-488B-84AA-7D81C9502F82}]

2016-09-28 08:20:13:297 648 e04 Agent *************

2016-09-28 08:20:13:297 648 e04 Agent ** START ** Agent: Finding updates [CallerId = AutomaticUpdates]

2016-09-28 08:20:13:297 648 e04 Agent *********

2016-09-28 08:20:13:297 648 e04 Agent * Online = Yes; Ignore download priority = No

2016-09-28 08:20:13:297 648 e04 Agent * Criteria = "IsInstalled=0 and DeploymentAction='Installation' or IsPresent=1 and DeploymentAction='Uninstallation' or IsInstalled=1 and DeploymentAction='Installation' and RebootRequired=1 or IsInstalled=0 and DeploymentAction='Uninstallation' and RebootRequired=1"

2016-09-28 08:20:13:298 648 e04 Agent * ServiceID = {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7} Managed

2016-09-28 08:20:13:298 648 e04 Agent * Search Scope = {Machine}

2016-09-28 08:20:13:299 648 e04 Setup Checking for agent SelfUpdate

2016-09-28 08:20:13:299 648 e04 Setup Client version: Core: 7.6.7601.18804 Aux: 7.6.7601.18804

2016-09-28 08:20:13:306 648 e04 Misc WARNING: WinHttp: SendRequestToServerForFileInformation failed with 0x801901f7

2016-09-28 08:20:13:307 648 e04 Misc WARNING: WinHttp: ShouldFileBeDownloaded failed with 0x801901f7

2016-09-28 08:20:13:309 648 e04 Misc WARNING: WinHttp: SendRequestToServerForFileInformation failed with 0x801901f7

2016-09-28 08:20:13:309 648 e04 Misc WARNING: WinHttp: ShouldFileBeDownloaded failed with 0x801901f7

2016-09-28 08:20:13:310 648 e04 Misc WARNING: WinHttp: SendRequestToServerForFileInformation failed with 0x801901f7

2016-09-28 08:20:13:310 648 e04 Misc WARNING: WinHttp: ShouldFileBeDownloaded failed with 0x801901f7

2016-09-28 08:20:13:312 648 e04 Misc WARNING: WinHttp: SendRequestToServerForFileInformation failed with 0x801901f7

2016-09-28 08:20:13:312 648 e04 Misc WARNING: WinHttp: ShouldFileBeDownloaded failed with 0x801901f7

2016-09-28 08:20:13:312 648 e04 Misc WARNING: DownloadFileInternal failed for http://suserver:8530/selfupdate/wuident.cab: error 0x801901f7

2016-09-28 08:20:13:312 648 e04 Setup FATAL: DownloadCab failed, err = 0x801901F7

2016-09-28 08:20:13:312 648 e04 Setup WARNING: SelfUpdate check failed to download package information, error = 0x80244022

2016-09-28 08:20:13:312 648 e04 Setup FATAL: SelfUpdate check failed, err = 0x80244022

2016-09-28 08:20:13:313 648 e04 Agent * WARNING: Skipping scan, self-update check returned 0x80244022

2016-09-28 08:20:13:907 648 e04 Agent * WARNING: Exit code = 0x80244022

2016-09-28 08:20:13:907 648 e04 Agent *********

2016-09-28 08:20:13:907 648 e04 Agent ** END ** Agent: Finding updates [CallerId = AutomaticUpdates]

2016-09-28 08:20:13:907 648 e04 Agent *************

2016-09-28 08:20:13:907 648 e04 Agent WARNING: WU client failed Searching for update with error 0x80244022

2016-09-28 08:20:13:907 648 df4 AU >>## RESUMED ## AU: Search for updates [CallId = {8F7D1A2A-6C86-488B-84AA-7D81C9502F82}]

2016-09-28 08:20:13:907 648 df4 AU # WARNING: Search callback failed, result = 0x80244022

2016-09-28 08:20:13:907 648 df4 AU # WARNING: Failed to find updates with error code 80244022

2016-09-28 08:20:13:907 648 df4 AU #########

2016-09-28 08:20:13:907 648 df4 AU ## END ## AU: Search for updates [CallId = {8F7D1A2A-6C86-488B-84AA-7D81C9502F82}]

2016-09-28 08:20:13:907 648 df4 AU #############

2016-09-28 08:20:13:908 648 df4 AU Need to show Unable to Detect notification

2016-09-28 08:20:13:908 648 df4 AU Successfully wrote event for AU health state:1

2016-09-28 08:20:13:908 648 df4 AU AU setting next detection timeout to 2016-09-28 12:20:13

2016-09-28 08:20:13:908 648 df4 AU Successfully wrote event for AU health state:1

2016-09-28 08:20:18:235 648 e04 Report REPORT EVENT: {AC4F0F49-3122-455D-83A5-DE15DD7856E5} 2016-09-28 08:20:13:313+0100 1 148 101 {D67661EB-2423-451D-BF5D-13199E37DF28} 1 80244022 SelfUpdate Failure Software Synchronization Windows Update Client failed to detect with error 0x80244022.

2016-09-28 08:20:18:265 648 e04 Report CWERReporter::HandleEvents - WER report upload completed with status 0x8

2016-09-28 08:20:18:265 648 e04 Report WER Report sent: 7.6.7601.18804 0x80244022(0) 67661EB-2423-451D-BF5D-13199E37DF28 Scan 1 0 SelfUpdate {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7} 0

2016-09-28 08:21:18:050 648 cf0 AU AU setting next sqm report timeout to 2016-09-29 07:21:18

2016-09-28 08:22:01:341 648 e04 PT WARNING: Cached cookie has expired or new PID is available

2016-09-28 08:22:01:341 648 e04 PT Initializing simple targeting cookie, clientId = dee6e332-8181-4ca5-8499-d412aef09d12, target group = , DNS name = SFL54.domain.org

2016-09-28 08:22:01:341 648 e04 PT Server URL = http://susever:8530/SimpleAuthWebService/SimpleAuth.asmx

2016-09-28 08:22:01:346 648 e04 PT WARNING: GetAuthorizationCookie failure, error = 0x80244022, soap client error = 10, soap error code = 0, HTTP status code = 503

2016-09-28 08:22:01:346 648 e04 PT WARNING: Failed to initialize Simple Targeting Cookie: 0x80244022

2016-09-28 08:22:01:346 648 e04 PT WARNING: PopulateAuthCookies failed: 0x80244022

2016-09-28 08:22:01:346 648 e04 PT WARNING: RefreshCookie failed: 0x80244022

2016-09-28 08:22:01:346 648 e04 PT WARNING: RefreshPTState failed: 0x80244022

2016-09-28 08:22:01:346 648 e04 PT WARNING: PTError: 0x80244022

2016-09-28 08:22:01:346 648 e04 Report WARNING: Reporter failed to upload events with hr = 80244022.

2016-09-28 08:29:37:758 648 cf0 AU Forced install timer expired for AUInstallType = 4

2016-09-28 08:29:37:758 648 cf0 AU UpdateDownloadProperties: 0 download(s) are still in progress.

2016-09-28 08:29:37:758 648 cf0 AU Setting AU scheduled install time to 2016-09-28 16:00:00

2016-09-28 08:29:37:758 648 cf0 AU Successfully wrote event for AU health state:1

2016-09-28 08:44:45:629 648 a5c PT WARNING: Cached cookie has expired or new PID is available

2016-09-28 08:44:45:630 648 a5c PT Initializing simple targeting cookie, clientId = dee6e332-8181-4ca5-8499-d412aef09d12, target group = , DNS name = SFL54.domain.org

2016-09-28 08:44:45:630 648 a5c PT Server URL = http://susever:8530/SimpleAuthWebService/SimpleAuth.asmx

2016-09-28 08:44:45:633 648 a5c PT WARNING: GetAuthorizationCookie failure, error = 0x80244022, soap client error = 10, soap error code = 0, HTTP status code = 503

2016-09-28 08:44:45:633 648 a5c PT WARNING: Failed to initialize Simple Targeting Cookie: 0x80244022

2016-09-28 08:44:45:633 648 a5c PT WARNING: PopulateAuthCookies failed: 0x80244022

2016-09-28 08:44:45:633 648 a5c PT WARNING: RefreshCookie failed: 0x80244022

2016-09-28 08:44:45:633 648 a5c PT WARNING: RefreshPTState failed: 0x80244022

2016-09-28 08:44:45:633 648 a5c PT WARNING: PTError: 0x80244022

2016-09-28 08:44:45:633 648 a5c Report WARNING: Reporter failed to upload events with hr = 80244022.

2016-09-28 08:56:58:847 648 a5c PT WARNING: Cached cookie has expired or new PID is available

2016-09-28 08:56:58:847 648 a5c PT Initializing simple targeting cookie, clientId = dee6e332-8181-4ca5-8499-d412aef09d12, target group = , DNS name = SFL54.domain.org

2016-09-28 08:56:58:847 648 a5c PT Server URL = http://susever:8530/SimpleAuthWebService/SimpleAuth.asmx

2016-09-28 08:56:58:859 648 a5c PT WARNING: GetAuthorizationCookie failure, error = 0x80244022, soap client error = 10, soap error code = 0, HTTP status code = 503

2016-09-28 08:56:58:859 648 a5c PT WARNING: Failed to initialize Simple Targeting Cookie: 0x80244022

2016-09-28 08:56:58:859 648 a5c PT WARNING: PopulateAuthCookies failed: 0x80244022

2016-09-28 08:56:58:859 648 a5c PT WARNING: RefreshCookie failed: 0x80244022

2016-09-28 08:56:58:859 648 a5c PT WARNING: RefreshPTState failed: 0x80244022

2016-09-28 08:56:58:859 648 a5c PT WARNING: PTError: 0x80244022

2016-09-28 08:56:58:859 648 a5c Report WARNING: Reporter failed to upload events with hr = 80244022.

 

I can download the iuident.cab from the client and also telnet from the client to the WSUS server on port 8530, but when I close the telnet connection I get an HTML error that may just be a red herring:

 

HTTP/1.1 400 Bad Request

Content-Type: text/html; charset=us-ascii

Server: Microsoft-HTTPAPI/2.0

Date: Wed, 28 Sep 2016 08:25:59 GMT

Connection: close

Content-Length: 326

 

Bad Request

Bad Request - Invalid Verb


HTTP Error 400. The request verb is invalid.

Edited by Sheridan
Posted
Have you tried building a new W7 client and seeing if that checks in?

 

I have been using https://support.microsoft.com/en-us/kb/3172605

 

It can take an age to install, unless you restart the Windows Update service just before running the installer. WSUS updates etc have been working much better for me since. You can push this update out site-wide if your testing shows it helps.

 

I did try that update on a few of the failing clients and it says its not applicable - these clients were bang up to date with updates as of mid August.

Posted (edited)

Did you bump up the private memory limit for wsuspool, also check to be sure wsuspool is not in a stopped state.

 

All those errors go back to 503 - service unavailable

 

How much RAM did you give the VM?

Edited by KevinH
Posted

Check the server for KB3148812 and/or KB3159706 also and check if either or both are installed.

If you have either/both, post back which one/s, if you completed the post-install configuration steps, and if you modified the web.config file.

 

Trying to avoid writing an essay - but if you didn't do the post-install or modify the web.config, and you don't currently have windows 10 clients - I would remove the update(s) and hide them for now. If you did the post-install and the web.config edits, different kettle of fish.

Posted
I'd also run nslookup for the WSUS server name on a functioning client and a broken one - just to rule out DNS, which has broken a WSUS or 3.
Posted

I've given up with WSUS on 2012 as I got sick of the constant Reset Server errors. I've tried 2012 on a VM and physical server but have gone back to the original 2008 VM, which has 8 cores and 16gb ram. I've set the memory limit to 8GB as well.

 

Still most clients are Not yet reported. Neither of those updates relate to 2008 server so I think thats ok. The windows 10 clients show up as Vista as before (not an issue as they're being rolled back to 7 in the next holiday)

 

I'm stumped now, I had a perfectly working WSUS and I cannot get it to work even on a fresh new server install, I'm probably going to have to set each client to run automatic updates directly from MS now.

Posted

You HAD a perfectly functioning WSUS - then virtualized it.

 

I'm not trying to be cheeky - just highlighting the change event that broke your universe. Not knowing what platform you're using and how you set it up, here's what I'd look at.

Be sure the WSUS VM retained its static address through the P2V process. Look in the adapter properties on the guest and be sure what you're seeing makes sense.

 

Be sure you gave it enough CPU/RAM resources to handle the number of clients you have. Task manager on the guest will show if either CPU or RAM are overtaxed. SQL is a RAM hog - and if you're tight to the top, it's going to have to page - not good on queries that are timeout governed.

 

My WSUS is on a physical box but I do have 3 VMs in hyper-v hanging off a different server. If the host has adequate NICs to do so, I would not allow the host to share the WSUS machine's NIC, but I have that option because that particular host has 6 NICs and the host won't get cut off from the world by doing it.

 

Depending on your GPO structure, it wouldn't be a bad idea to take a single (smaller) OU and set the WSUS GPO to the dotted decimal IP address of the WSUS server rather than the name (taking DNS resolution out of the picture)

 

Apologies for the replies not really fitting your schedule - but I've been on the wrong side of the clock so what you're seeing me post with your morning coffee I'm posting at 2AM and right now I'm having my morning coffee.

Posted
You HAD a perfectly functioning WSUS - then virtualized it.

 

I'm not trying to be cheeky - just highlighting the change event that broke your universe. Not knowing what platform you're using and how you set it up, here's what I'd look at.

Be sure the WSUS VM retained its static address through the P2V process. Look in the adapter properties on the guest and be sure what you're seeing makes sense.

 

Be sure you gave it enough CPU/RAM resources to handle the number of clients you have. Task manager on the guest will show if either CPU or RAM are overtaxed. SQL is a RAM hog - and if you're tight to the top, it's going to have to page - not good on queries that are timeout governed.

 

My WSUS is on a physical box but I do have 3 VMs in hyper-v hanging off a different server. If the host has adequate NICs to do so, I would not allow the host to share the WSUS machine's NIC, but I have that option because that particular host has 6 NICs and the host won't get cut off from the world by doing it.

 

Depending on your GPO structure, it wouldn't be a bad idea to take a single (smaller) OU and set the WSUS GPO to the dotted decimal IP address of the WSUS server rather than the name (taking DNS resolution out of the picture)

 

Apologies for the replies not really fitting your schedule - but I've been on the wrong side of the clock so what you're seeing me post with your morning coffee I'm posting at 2AM and right now I'm having my morning coffee.

 

No offence taken! I appreciate any ideas as I'm out!

 

Our VM has more ram and more cpu cores than the old physical server. I also installed 2012 on the old physical server but that brought more problems (reset server node all the time) so I've decided to concentrate on the original VM. It has a single gigabit nic and only shares the host with 2 other VMs, both of which are very low usage. DNS queries all resolve nice and quick, fixed IPs on the servers makes sure of no mistakes.

 

I'm about ready to reinstall 2008 on the old physical server as that was the last know working solution (with its only Xeon processor and 4gb of RAM!) but I have about a fifth of the pcs reporting in so its not completely dead, and thats the part I find confusing

Posted

What does your products and classifications list look like?

 

All is bad news, as every client then has to check every single update MS ever made, which makes the query God-awful and can throw timeouts as a result. That list is best kept well-pruned. And if you have drivers selected, that would be the first item I would take off the list.

Posted (edited)

If you haven't flattened the 2012 install yet - I would run OverDrive's maintenance script on it. Think of it as the server cleanup wizard on steroids. It really works - reindexes the WSUS database and sped up the approvals process on a working unit by orders of magnitude.

 

Right now, it's a nothing to lose scenario - once you get past the rest node issue, the latest WSUS does work quite well.

 

https://community.spiceworks.com/topic/1264229-wsus-console-crashing

Edited by KevinH
Forgot link the first time
Posted (edited)

Thinking more about ways to isolate this:

 

Can you create a GPO for a test OU and try setting the WSUS server to dotted decimal IP? It may do nothing - but easily undone and then you can rule out DNS. Be sure it's in the right place in the GPO structure to "win" and verify with RSOP.

 

A ways upthread, it was suggested to run proxycfg - and ruling out your proxy server trashing winhttp would also be progress.

 

You need to rule stuff out here - knowing what it isn't is an important step to finding out what it is

Edited by KevinH
Posted

Proxycfg on the clients shows no proxy being used which is correct. The product catalogue on the current WSUS is the basic Security/Critical for W7/10 only until I get them working - I used to have servers and other products but took them out whilst this is failing.

 

All the clients resolve dns to the WSUS server instantly - I've also run a maintenance script on that but its pretty much a brand new system now. Each client can get to the iuident.cab file, and open the SimpleAuthWebService/SimpleAuth.asmx page so dns resolution is working ok. I've changed the application memory pool to unlimited as well to see if that helps!

Posted
Since we're back to 2008 again - post up a log of a current detect off one of the clients. This is very odd - not that you didn't know that ...
Posted

This is the windowsupdate log froma failing client (that was working originally)

 

2016-09-30 08:36:23:312 1004 d28 AU #############

2016-09-30 08:36:23:312 1004 d28 AU ## START ## AU: Search for updates

2016-09-30 08:36:23:312 1004 d28 AU #########

2016-09-30 08:36:23:313 1004 d28 AU <<## SUBMITTED ## AU: Search for updates [CallId = {C813C481-5C44-4007-BBCE-B1546CCCD40D}]

2016-09-30 08:36:23:317 1004 dac Agent *************

2016-09-30 08:36:23:317 1004 dac Agent ** START ** Agent: Finding updates [CallerId = AutomaticUpdates]

2016-09-30 08:36:23:317 1004 dac Agent *********

2016-09-30 08:36:23:317 1004 dac Agent * Online = Yes; Ignore download priority = No

2016-09-30 08:36:23:317 1004 dac Agent * Criteria = "IsInstalled=0 and DeploymentAction='Installation' or IsPresent=1 and DeploymentAction='Uninstallation' or IsInstalled=1 and DeploymentAction='Installation' and RebootRequired=1 or IsInstalled=0 and DeploymentAction='Uninstallation' and RebootRequired=1"

2016-09-30 08:36:23:317 1004 dac Agent * ServiceID = {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7} Managed

2016-09-30 08:36:23:317 1004 dac Agent * Search Scope = {Machine}

2016-09-30 08:36:23:317 1004 dac Setup Checking for agent SelfUpdate

2016-09-30 08:36:23:317 1004 dac Setup Client version: Core: 7.6.7601.18804 Aux: 7.6.7601.18804

2016-09-30 08:36:23:324 1004 dac Misc Validating signature for C:\Windows\SoftwareDistribution\SelfUpdate\wuident.cab with dwProvFlags 0x00000080:

2016-09-30 08:36:23:352 1004 dac Misc Microsoft signed: NA

2016-09-30 08:36:23:354 1004 dac Misc Validating signature for C:\Windows\SoftwareDistribution\SelfUpdate\TMPFDDE.tmp with dwProvFlags 0x00000080:

2016-09-30 08:36:23:367 1004 dac Misc Microsoft signed: NA

2016-09-30 08:36:23:370 1004 dac Misc Validating signature for C:\Windows\SoftwareDistribution\SelfUpdate\wsus3setup.cab with dwProvFlags 0x00000080:

2016-09-30 08:36:23:373 1004 dac Misc Microsoft signed: NA

2016-09-30 08:36:23:374 1004 dac Misc Validating signature for C:\Windows\SoftwareDistribution\SelfUpdate\wsus3setup.cab with dwProvFlags 0x00000080:

2016-09-30 08:36:23:377 1004 dac Misc Microsoft signed: NA

2016-09-30 08:36:23:411 1004 dac Setup Determining whether a new setup handler needs to be downloaded

2016-09-30 08:36:23:411 1004 dac Setup SelfUpdate handler is not found. It will be downloaded

2016-09-30 08:36:23:411 1004 dac Setup Evaluating applicability of setup package "WUClient-SelfUpdate-ActiveX~31bf3856ad364e35~amd64~~7.6.7600.320"

2016-09-30 08:36:23:835 1004 dac Setup Setup package "WUClient-SelfUpdate-ActiveX~31bf3856ad364e35~amd64~~7.6.7600.320" is already installed.

2016-09-30 08:36:23:836 1004 dac Setup Evaluating applicability of setup package "WUClient-SelfUpdate-Aux-TopLevel~31bf3856ad364e35~amd64~~7.6.7600.320"

2016-09-30 08:36:23:847 1004 dac Setup Setup package "WUClient-SelfUpdate-Aux-TopLevel~31bf3856ad364e35~amd64~~7.6.7600.320" is already installed.

2016-09-30 08:36:23:847 1004 dac Setup Evaluating applicability of setup package "WUClient-SelfUpdate-Core-TopLevel~31bf3856ad364e35~amd64~~7.6.7600.320"

2016-09-30 08:36:23:863 1004 dac Setup Setup package "WUClient-SelfUpdate-Core-TopLevel~31bf3856ad364e35~amd64~~7.6.7600.320" is already installed.

2016-09-30 08:36:23:863 1004 dac Setup SelfUpdate check completed. SelfUpdate is NOT required.

2016-09-30 08:36:23:903 1004 dac PT +++++++++++ PT: Synchronizing server updates +++++++++++

2016-09-30 08:36:23:903 1004 dac PT + ServiceId = {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}, Server URL = http://susserver/ClientWebService/client.asmx

2016-09-30 08:36:23:909 1004 dac PT WARNING: Cached cookie has expired or new PID is available

2016-09-30 08:36:23:909 1004 dac PT Initializing simple targeting cookie, clientId = 3d1cd7a4-7c1a-4b9a-a494-c921fd0e3fe5, target group = , DNS name = PC110.domain.org

2016-09-30 08:36:23:909 1004 dac PT Server URL = http://susserver/SimpleAuthWebService/SimpleAuth.asmx

2016-09-30 08:36:45:811 1004 dac PT WARNING: GetCookie failure, error = 0x8024400D, soap client error = 7, soap error code = 300, HTTP status code = 200

2016-09-30 08:36:45:811 1004 dac PT WARNING: SOAP Fault: 0x00012c

2016-09-30 08:36:45:811 1004 dac PT WARNING: faultstring:Fault occurred

2016-09-30 08:36:45:811 1004 dac PT WARNING: ErrorCode:ConfigChanged(2)

2016-09-30 08:36:45:811 1004 dac PT WARNING: Message:(null)

2016-09-30 08:36:45:811 1004 dac PT WARNING: Method:"http://www.microsoft.com/SoftwareDistribution/Server/ClientWebService/GetCookie"

2016-09-30 08:36:45:811 1004 dac PT WARNING: ID:e6dc89ea-5c1b-4ed6-9dfc-83e6ddf9fa69

2016-09-30 08:37:13:596 1004 dac PT WARNING: Cached cookie has expired or new PID is available

2016-09-30 08:37:13:596 1004 dac PT Initializing simple targeting cookie, clientId = 3d1cd7a4-7c1a-4b9a-a494-c921fd0e3fe5, target group = , DNS name = PC110.domain.org

2016-09-30 08:37:13:596 1004 dac PT Server URL = http://susserver/SimpleAuthWebService/SimpleAuth.asmx

2016-09-30 08:45:41:011 1004 d28 AU Forced install timer expired for AUInstallType = 4

2016-09-30 08:45:41:011 1004 d28 AU UpdateDownloadProperties: 0 download(s) are still in progress.

2016-09-30 08:45:41:011 1004 d28 AU Setting AU scheduled install time to 2016-09-30 16:00:00

2016-09-30 08:45:41:011 1004 d28 AU Successfully wrote event for AU health state:0

2016-09-30 08:47:00:094 1004 dac PT WARNING: SyncUpdates failure, error = 0x8024400E, soap client error = 7, soap error code = 400, HTTP status code = 200

2016-09-30 08:47:00:094 1004 dac PT WARNING: SOAP Fault: 0x000190

2016-09-30 08:47:00:094 1004 dac PT WARNING: faultstring:Fault occurred

2016-09-30 08:47:00:094 1004 dac PT WARNING: ErrorCode:InternalServerError(5)

2016-09-30 08:47:00:094 1004 dac PT WARNING: Message:(null)

2016-09-30 08:47:00:094 1004 dac PT WARNING: Method:"http://www.microsoft.com/SoftwareDistribution/Server/ClientWebService/SyncUpdates"

2016-09-30 08:47:00:094 1004 dac PT WARNING: ID:98fb5e2d-1056-4000-bddc-da98e00fb905

2016-09-30 08:47:00:094 1004 dac PT WARNING: PTError: 0x8024400e

2016-09-30 08:47:00:094 1004 dac PT WARNING: SyncUpdates_WithRecovery failed.: 0x8024400e

2016-09-30 08:47:00:094 1004 dac PT WARNING: Sync of Updates: 0x8024400e

2016-09-30 08:47:00:094 1004 dac PT WARNING: SyncServerUpdatesInternal failed: 0x8024400e

2016-09-30 08:47:00:094 1004 dac Agent * WARNING: Failed to synchronize, error = 0x8024400E

2016-09-30 08:47:00:096 1004 dac Agent * WARNING: Exit code = 0x8024400E

2016-09-30 08:47:00:096 1004 dac Agent *********

2016-09-30 08:47:00:096 1004 dac Agent ** END ** Agent: Finding updates [CallerId = AutomaticUpdates]

2016-09-30 08:47:00:096 1004 dac Agent *************

2016-09-30 08:47:00:096 1004 dac Agent WARNING: WU client failed Searching for update with error 0x8024400e

2016-09-30 08:47:00:101 1004 8a0 AU >>## RESUMED ## AU: Search for updates [CallId = {C813C481-5C44-4007-BBCE-B1546CCCD40D}]

2016-09-30 08:47:00:101 1004 8a0 AU # WARNING: Search callback failed, result = 0x8024400E

2016-09-30 08:47:00:101 1004 8a0 AU # WARNING: Failed to find updates with error code 8024400E

2016-09-30 08:47:00:101 1004 8a0 AU #########

2016-09-30 08:47:00:101 1004 8a0 AU ## END ## AU: Search for updates [CallId = {C813C481-5C44-4007-BBCE-B1546CCCD40D}]

2016-09-30 08:47:00:101 1004 8a0 AU #############

2016-09-30 08:47:00:101 1004 8a0 AU Successfully wrote event for AU health state:0

2016-09-30 08:47:00:101 1004 8a0 AU AU setting next detection timeout to 2016-09-30 12:47:00

2016-09-30 08:47:00:102 1004 8a0 AU Setting AU scheduled install time to 2016-09-30 16:00:00

2016-09-30 08:47:00:102 1004 8a0 AU Successfully wrote event for AU health state:0

2016-09-30 08:47:00:102 1004 8a0 AU Successfully wrote event for AU health state:0

2016-09-30 08:47:05:095 1004 dac Report REPORT EVENT: {6507F6BE-6A7E-46AF-841E-89C3FDC09F92} 2016-09-30 08:47:00:096+0100 1 148 101 {00000000-0000-0000-0000-000000000000} 0 8024400e AutomaticUpdates Failure Software Synchronization Windows Update Client failed to detect with error 0x8024400e.

2016-09-30 08:47:05:116 1004 dac Report CWERReporter::HandleEvents - WER report upload completed with status 0x8

2016-09-30 08:47:05:116 1004 dac Report WER Report sent: 7.6.7601.18804 0x8024400e(0) 0000000-0000-0000-0000-000000000000 Scan 0 1 AutomaticUpdates {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7} 0

2016-09-30 08:50:31:318 1004 dac PT WARNING: Cached cookie has expired or new PID is available

2016-09-30 08:50:31:318 1004 dac PT Initializing simple targeting cookie, clientId = 3d1cd7a4-7c1a-4b9a-a494-c921fd0e3fe5, target group = , DNS name = PC110.domain.org

2016-09-30 08:50:31:318 1004 dac PT Server URL = http://susserver/SimpleAuthWebService/SimpleAuth.asmx

2016-09-30 08:50:48:297 1004 dac PT WARNING: GetCookie failure, error = 0x8024400D, soap client error = 7, soap error code = 300, HTTP status code = 200

2016-09-30 08:50:48:297 1004 dac PT WARNING: SOAP Fault: 0x00012c

2016-09-30 08:50:48:298 1004 dac PT WARNING: faultstring:Fault occurred

2016-09-30 08:50:48:298 1004 dac PT WARNING: ErrorCode:ConfigChanged(2)

2016-09-30 08:50:48:298 1004 dac PT WARNING: Message:(null)

2016-09-30 08:50:48:298 1004 dac PT WARNING: Method:"http://www.microsoft.com/SoftwareDistribution/Server/ClientWebService/GetCookie"

2016-09-30 08:50:48:298 1004 dac PT WARNING: ID:5c783559-9fa5-400c-8297-d5618b5cc0a0

2016-09-30 08:51:17:795 1004 dac PT WARNING: Cached cookie has expired or new PID is available

2016-09-30 08:51:17:795 1004 dac PT Initializing simple targeting cookie, clientId = 3d1cd7a4-7c1a-4b9a-a494-c921fd0e3fe5, target group = , DNS name = PC110.domain.org

2016-09-30 08:51:17:795 1004 dac PT Server URL = http://susserver/SimpleAuthWebService/SimpleAuth.asmx

2016-09-30 08:52:15:635 1004 dac Report Uploading 2 events using cached cookie, reporting URL = http://susserver/ReportingWebService/ReportingWebService.asmx

2016-09-30 08:52:16:146 1004 dac Report Reporter successfully uploaded 2 events.

 

I've run the usual WSUS reset tools etc on this PC

Posted

Have you run SURT on a client?

https://support.microsoft.com/en-us/kb/947821

 

Almost all the hits for that error refer to an update (Office 2K3 SP1) being in an inconsistent approval state. Supposedly fixed by a WSUS 3 Service pack, but won't hurt anything to check that it's either absent or declined for all WSUS groups (KB842532) Ancient, unlikely, and you've probably already covered it.

 

Revisiting the error, it suggests a bad XML file for an update causing the server to not be able to respond with a valid update list - if neither of the two comments above are productive, my next thought would be to run a wsusutil /reset (when you're ready to leave for the day, it would be like watching a lake freeze) and try again in the morning.

Posted
Have you run SURT on a client?

https://support.microsoft.com/en-us/kb/947821

 

Almost all the hits for that error refer to an update (Office 2K3 SP1) being in an inconsistent approval state. Supposedly fixed by a WSUS 3 Service pack, but won't hurt anything to check that it's either absent or declined for all WSUS groups (KB842532) Ancient, unlikely, and you've probably already covered it.

 

Revisiting the error, it suggests a bad XML file for an update causing the server to not be able to respond with a valid update list - if neither of the two comments above are productive, my next thought would be to run a wsusutil /reset (when you're ready to leave for the day, it would be like watching a lake freeze) and try again in the morning.

 

We haven't run Office 2003 updates since we had Win 7 so that should be OK - the inconsistent nature of this is very odd as a room full of identically images PCs on the same hardware get different results.

 

I guess I'll have to remove wsus and let the client pull down critical updates themselves, although the way MS is going there will barely be any for W7 anymore!

Posted (edited)

Nowhere in the discussion has malware been mentioned - have you run Malwarebytes or SuperAnti on any of the clients that dont update?

 

If you havent already, the System Update readiness tool I mentioned upthread would also be a good idea as it tends to root out corruption in the stack.

Edited by KevinH

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...