Jump to content

Recommended Posts

Posted (edited)

Been regularly doing the MS updates manually on our Servers recently as, well it just seems easier.

 

But on checking WSUS I've noticed that only a few of my Servers are showing on the console.

 

In comparing a Server which is working as expected with one that is n't I'm seeing errors in the "WindowsUpdate.log" file on the server.

 

working :

 

2017-05-16 12:33:47:882 740 10b4 EP Got WSUS SimpleTargeting URL: "http://xxx:8530"

2017-05-16 12:33:47:882 740 10b4 IdleTmr WU operation (CAuthorizationCookieWrapper::InitializeSimpleTargetingCookie) started; operation # 8; does use network; is at background priority

2017-05-16 12:33:47:897 740 10b4 PT Initializing simple targeting cookie, clientId = 99e38e4d-d573-4830-a57a-82f5f27f5e7f, target group = Servers, DNS name = fp4.curriculum.local

2017-05-16 12:33:47:897 740 10b4 PT Server URL = http://xxx:8530/SimpleAuthWebService/SimpleAuth.asmx

2017-05-16 12:33:48:038 740 10b4 IdleTmr WU operation (CAuthorizationCookieWrapper::InitializeSimpleTargetingCookie, operation # 8) stopped; does use network; is at background priority

2017-05-16 12:33:48:038 740 10b4 IdleTmr WU operation (CAgentProtocolTalker::GetCookie_WithRecovery) started; operation # 9; does use network; is at background priority

2017-05-16 12:33:48:054 740 10b4 IdleTmr WU operation (CAgentProtocolTalker::GetCookie_WithRecovery, operation # 9) stopped; does use network; is at background priority

2017-05-16 12:33:48:085 740 10b4 Agent Reading cached app categories using lifetime 604800 seconds

2017-05-16 12:33:48:085 740 10b4 Agent Read 0 cached app categories

2017-05-16 12:33:48:085 740 10b4 Agent SyncUpdates adding 0 visited app categories

2017-05-16 12:33:49:835 740 10b4 IdleTmr WU operation (CAgentProtocolTalker::SyncUpdates_WithRecover) started; operation # 10; does use network; is at background priority

2017-05-16 12:33:49:835 740 10b4 IdleTmr WU operation (CAgentProtocolTalker::SyncUpdates_WithRecover, operation # 10) stopped; does use network; is at background priority

2017-05-16 12:33:49:851 740 10b4 Agent Reading cached app categories using lifetime 604800 seconds

2017-05-16 12:33:49:851 740 10b4 Agent Read 0 cached app categories

2017-05-16 12:33:49:851 740 10b4 Agent SyncUpdates adding 0 visited app categories

2017-05-16 12:33:49:866 740 10b4 IdleTmr WU operation (CAgentProtocolTalker::SyncUpdates_WithRecover) started; operation # 11; does use network; is at background priority

2017-05-16 12:33:49:897 740 10b4 IdleTmr WU operation (CAgentProtocolTalker::SyncUpdates_WithRecover, operation # 11) stopped; does use network; is at background priority

2017-05-16 12:33:49:913 740 10b4 PT + SyncUpdates round trips: 2

2017-05-16 12:33:52:288 740 10b4 PT +++++++++++ PT: Synchronizing extended update info +++++++++++

2017-05-16 12:33:52:288 740 10b4 PT + ServiceId = {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}, Server URL = http://xxx:8530/ClientWebService/client.asmx

2017-05-16 12:33:52:304 740 10b4 IdleTmr WU operation (CAgentProtocolTalker::GetExtendedUpdateInfo_WithRecovery) started; operation # 12; does use network; is at background priority

2017-05-16 12:33:52:304 740 10b4 IdleTmr WU operation (CAgentProtocolTalker::GetExtendedUpdateInfo_WithRecovery, operation # 12) stopped; does use network; is at background priority

2017-05-16 12:33:52:616 740 10b4 Agent WARNING: Fail to download eula file http://xxx:8530/Content/13/33D8A4B8183134CA79120BB436C18DDAB713E713.txt with error 0x80246003

2017-05-16 12:33:52:694 740 10b4 Agent * Found 0 updates and 88 categories in search; evaluated appl. rules of 821 out of 1517 deployed entities

2017-05-16 12:33:52:757 740 10b4 Agent Reporting status event with 1 installable, 159 installed, 0 installed pending, 0 failed and 0 downloaded updates

2017-05-16 12:33:52:757 740 10b4 Agent *********

2017-05-16 12:33:52:757 740 10b4 Agent ** END ** Agent: Finding updates [CallerId = AutomaticUpdates Id = 1]

2017-05-16 12:33:52:772 740 10b4 Agent *************

2017-05-16 12:33:52:772 740 10b4 IdleTmr WU operation (CSearchCall::Init ID 1, operation # 7) stopped; does use network; is at background priority

2017-05-16 12:33:52:772 740 a98 AU >>## RESUMED ## AU: Search for updates [CallId = {73538518-F042-4651-9B80-FDE2060C7D30} ServiceId = {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}]

2017-05-16 12:33:52:772 740 a98 AU # 0 updates detected

 

 

not working:

2017-05-16 13:04:15:680 776 f90 EP Got WSUS SimpleTargeting URL: "http://xxx:8530"

2017-05-16 13:04:15:680 776 f90 IdleTmr WU operation (CAuthorizationCookieWrapper::InitializeSimpleTargetingCookie) started; operation # 374; does use network; is at background priority

2017-05-16 13:04:15:680 776 f90 PT Initializing simple targeting cookie, clientId = 99e38e4d-d573-4830-a57a-82f5f27f5e7f, target group = Servers, DNS name = fp5.curriculum.local

2017-05-16 13:04:15:680 776 f90 PT Server URL = http://xxx:8530/SimpleAuthWebService/SimpleAuth.asmx

2017-05-16 13:04:15:696 776 f90 WS WARNING: Nws Failure: errorCode=0x803d001a

2017-05-16 13:04:15:696 776 f90 WS WARNING: There was an error communicating with the endpoint at 'http://xxx:8530/SimpleAuthWebService/SimpleAuth.asmx'.

2017-05-16 13:04:15:696 776 f90 WS WARNING: The server returned HTTP status code '407 (0x197)' with text 'Proxy Authentication Required'.

2017-05-16 13:04:15:696 776 f90 WS WARNING: The proxy requires HTTP authentication scheme 'NTLM'.

2017-05-16 13:04:16:743 776 f90 WS WARNING: Nws Failure: errorCode=0x803d0000

2017-05-16 13:04:16:743 776 f90 WS WARNING: There was an error communicating with the endpoint at 'http://xxx:8530/SimpleAuthWebService/SimpleAuth.asmx'.

2017-05-16 13:04:16:743 776 f90 WS WARNING: The content type 'text/html' did not match the expected value 'text/xml'.

2017-05-16 13:04:16:743 776 f90 WS WARNING: MapToSusHResult mapped Nws error 0x803d0000 to 0x80240439

2017-05-16 13:04:16:743 776 f90 WS WARNING: Web service call failed with hr = 80240439.

2017-05-16 13:04:16:743 776 f90 WS WARNING: Current service auth scheme='None'.

2017-05-16 13:04:16:743 776 f90 WS WARNING: Proxy List used: 'xxx:800', Bypass List used: '', Last Proxy used: 'xxx:800', Last auth Schemes used: 'Negotiate (NTLM or Kerberos);'.

2017-05-16 13:04:16:743 776 f90 WS FATAL: OnCallFailure failed with hr=0X80240439

2017-05-16 13:04:16:743 776 f90 WS FATAL: NwsCallWithRetries( Functor(_clientId, _targetGroupName, _dnsName, &_result)) failed with hr=0x80240439

2017-05-16 13:04:16:743 776 f90 IdleTmr WU operation (CAuthorizationCookieWrapper::InitializeSimpleTargetingCookie, operation # 374) stopped; does use network; is at background priority

2017-05-16 13:04:16:743 776 f90 PT WARNING: Failed to initialize Simple Targeting Cookie: 0x80240439

2017-05-16 13:04:16:743 776 f90 PT WARNING: PopulateAuthCookies failed: 0x80240439

2017-05-16 13:04:16:743 776 f90 PT WARNING: RefreshCookie failed: 0x80240439

2017-05-16 13:04:16:743 776 f90 PT WARNING: RefreshPTState failed: 0x80240439

2017-05-16 13:04:16:743 776 f90 PT WARNING: PTError: 0x80240439

2017-05-16 13:04:16:743 776 f90 Report WARNING: Reporter failed to upload events with hr = 80240439.

2017-05-16 13:04:16:743 776 f90 Report WARNING: CSerializationHelper:: InitSerialize failed : 0x80070002

2017-05-16 13:05:44:071 776 e5c AU Currently AUX is enabled - so not show any WU Upgrade notifications.

2017-05-16 13:05:44:102 776 e5c AU WARNING: Failed to get Network Cost info from NLM, assuming network is NOT metered, error = 0x80240037

2017-05-16 13:05:44:164 776 e5c AU WARNING: Failed to get Network Cost info from NLM, assuming network is NOT metered, error = 0x80240037

 

 

Anyone any ideas?

Edited by kennysarmy
Posted
EULA didn't download

 

WARNING: Fail to download eula file http://xxx:8530/Content/13/33D8A4B81...DAB713E713.txt with error 0x80246003

 

No EULA clicky no update.

 

I wonder if something on our Smoothwall could be blocking access....not sure.

 

All the Windows 7 clients are working fine.

 

If I go to a server which is not on WSUS and check for updates I get an error : 80244022

 

If I then add 10.* to the IE proxy exceptions it then reports all but 3 important updates are available.

 

Do I need to use the tool Proxycfg.exe to configure a proxy server?

Posted

I've two domain controllers but with exactly the same settings in IE proxy and both the same results from netsh winhttp show proxy : Direct access (no proxy server).

 

One DC is showing in WSUS and one is n't....

 

:(

Posted (edited)

Proxy server set using netsh winhttp? Or a proxy server set for the user running Windows Update which doesn't have a bypass exception?

 

2017-05-16 13:04:15:696 776 f90 WS WARNING: There was an error communicating with the endpoint at 'http://xxx:8530/SimpleAuthWebService/SimpleAuth.asmx'.

2017-05-16 13:04:15:696 776 f90 WS WARNING: The server returned HTTP status code '407 (0x197)' with text 'Proxy Authentication Required'.

2017-05-16 13:04:15:696 776 f90 WS WARNING: The proxy requires HTTP authentication scheme 'NTLM'.

2017-05-16 13:04:16:743 776 f90 WS WARNING: Nws Failure: errorCode=0x803d0000

 

Edit: Just seen your reply above.

 

I'd maybe try old faithful of renaming the softwaredistribution folder, does seem like a proxy server issue, as it's trying to access it over port 800? Failing that, the Windows Update troubleshooter. Just going off this extra line, it hasn't got any bypass options set other than local. Or run Windows Update as administrator after restarting the service with the IE proxy disabled.

 

2017-05-16 13:04:16:743 776 f90 WS WARNING: Proxy List used: 'xxx:800', Bypass List used: '', Last Proxy used: 'xxx:800', Last auth Schemes used: 'Negotiate (NTLM or Kerberos);'.

Edited by Cache
Posted
Proxy server set using netsh winhttp? Or a proxy server set for the user running Windows Update which doesn't have a bypass exception?

 

2017-05-16 13:04:15:696 776 f90 WS WARNING: There was an error communicating with the endpoint at 'http://xxx:8530/SimpleAuthWebService/SimpleAuth.asmx'.

2017-05-16 13:04:15:696 776 f90 WS WARNING: The server returned HTTP status code '407 (0x197)' with text 'Proxy Authentication Required'.

2017-05-16 13:04:15:696 776 f90 WS WARNING: The proxy requires HTTP authentication scheme 'NTLM'.

2017-05-16 13:04:16:743 776 f90 WS WARNING: Nws Failure: errorCode=0x803d0000

 

Edit: Just seen your reply above.

 

I'd maybe try old faithful of renaming the softwaredistribution folder, does seem like a proxy server issue, as it's trying to access it over port 800? Failing that, the Windows Update troubleshooter. Just going off this extra line, it hasn't got any bypass options set other than local. Or run Windows Update as administrator after restarting the service with the IE proxy disabled.

 

2017-05-16 13:04:16:743 776 f90 WS WARNING: Proxy List used: 'xxx:800', Bypass List used: '', Last Proxy used: 'xxx:800', Last auth Schemes used: 'Negotiate (NTLM or Kerberos);'.

 

The command netsh winhttp show proxy shows the same results for the two DC's - Direct access (no proxy server).

 

Both have the same IE proxy settings in IE - though I'm not sure this is relevant...

 

We have a Smoothwall filtering device on site so the :800 port is referring to that....

Posted
Proxy server set using netsh winhttp? Or a proxy server set for the user running Windows Update which doesn't have a bypass exception?

 

2017-05-16 13:04:15:696 776 f90 WS WARNING: There was an error communicating with the endpoint at 'http://xxx:8530/SimpleAuthWebService/SimpleAuth.asmx'.

2017-05-16 13:04:15:696 776 f90 WS WARNING: The server returned HTTP status code '407 (0x197)' with text 'Proxy Authentication Required'.

2017-05-16 13:04:15:696 776 f90 WS WARNING: The proxy requires HTTP authentication scheme 'NTLM'.

2017-05-16 13:04:16:743 776 f90 WS WARNING: Nws Failure: errorCode=0x803d0000

 

Edit: Just seen your reply above.

 

I'd maybe try old faithful of renaming the softwaredistribution folder, does seem like a proxy server issue, as it's trying to access it over port 800? Failing that, the Windows Update troubleshooter. Just going off this extra line, it hasn't got any bypass options set other than local. Or run Windows Update as administrator after restarting the service with the IE proxy disabled.

 

2017-05-16 13:04:16:743 776 f90 WS WARNING: Proxy List used: 'xxx:800', Bypass List used: '', Last Proxy used: 'xxx:800', Last auth Schemes used: 'Negotiate (NTLM or Kerberos);'.

 

Following the Windows Update Troublshooted I get to step 6!

 

Make sure the WSUS server is reachable from the client!

 

So I attempt to browse to : http://ServerIP:8350/iuident.cab and I get This page can’t be displayed - BUT - I am getting this on every single client on the domain - even all the Windows 7 PC's who are working fine in WSUS...so should I be too worried about this?

Posted
Hmmm. Windows Firewall enabled or blocking that port on that server (maybe a GPO differs between them?)

 

Windows firewall disabled on both and they are both in the same OU and I've checked the WSUS policy is applying!

 

I'm starting to believe this is not a client issue....and something is up with the WSUS Server preventing it from logging the requests & information from certain Servers...

Posted

So I attempt to browse to : http://ServerIP:8350/iuident.cab and I get This page can’t be displayed - BUT - I am getting this on every single client on the domain - even all the Windows 7 PC's who are working fine in WSUS...so should I be too worried about this?

 

Tried on ours and it tries to download the cab file, you might have mixed the port number up though - it should be 8530.

 

Might also be worth trying wuauclt /resetauthorization /detectnow

Posted
Tried on ours and it tries to download the cab file, you might have mixed the port number up though - it should be 8530.

 

Might also be worth trying wuauclt /resetauthorization /detectnow

 

404.jpg

 

:(

Posted
I wonder if it's worth spinning up another VM and setting up a new WSUS Server initially just for my Servers, changing the group policies to point the Servers at this new WSUS and see if I get the same issues...
Posted

# Solarwinds® Diagnostic Tool for the WSUS Agent

# 18/05/2017

Machine state

User rights: User has administrator rights

Update service status: Running

Background Intelligent Transfer service status: Running

OS Version: Windows 7 Professional Service Pack 1

Windows update agent version: 7.6.7601.23735 (WU Agent is OK)

Windows Update Agent configuration settings

Automatic Update: Enabled

Options: Scheduled (Every day at 3:00 AM)

Use WSUS Server: Enabled

Windows Update Server: http://10.107.93.9:8530

Windows Update Status Server: http://10.107.93.9:8530

WSUS URLs are identical: Identical

WSUS URL is valid: Valid URL

WSUS Server Connectivity

clientwebservice/client.asmx: OK

simpleauthwebservice/simpleauth.asmx: OK

content: Error: Forbidden (Incorrect proxy client configuration - use settings tab to test proxy configuration settings; may also be caused by misconfigured SSL implementation or access rights on WSUS server)

selfupdate/iuident.cab: OK

iuident.cab: Error: NotFound (Omitting required port suffix on URL to access WSUS installed to port 8530 or resource is unreachable)

 

 

 

This was from a PC which is showing in WSUS OK

 

 

And below from a Server NOT showing in WSUS

# Solarwinds® Diagnostic Tool for the WSUS Agent

# 18/05/2017

Machine state

User rights: User has administrator rights

Update service status: Running

Background Intelligent Transfer service status: Running

OS Version: Windows Server 2012 R2 Standard

Windows update agent version: 7.9.9600.18628 (WU Agent is OK)

Windows Update Agent configuration settings

Automatic Update: Enabled

Options: Automatically download and notify of installation

Use WSUS Server: Enabled

Windows Update Server: http://10.107.93.9:8530

Windows Update Status Server: http://10.107.93.9:8530

WSUS URLs are identical: Identical

WSUS URL is valid: Valid URL

WSUS Server Connectivity

clientwebservice/client.asmx: OK

simpleauthwebservice/simpleauth.asmx: OK

content: Error: Forbidden (Incorrect proxy client configuration - use settings tab to test proxy configuration settings; may also be caused by misconfigured SSL implementation or access rights on WSUS server)

selfupdate/iuident.cab: OK

iuident.cab: Error: NotFound (Omitting required port suffix on URL to access WSUS installed to port 8530 or resource is unreachable)

Posted
I wonder if it's worth spinning up another VM and setting up a new WSUS Server initially just for my Servers, changing the group policies to point the Servers at this new WSUS and see if I get the same issues...

 

So I took a physical server (our ex vRanger Server) that was turned off a few weeks ago after an upgrade to VEEAM and I installed WSUS!

 

I left yesterday thinking even that was n't working as I put "itself" in a new WSUSTEST OU (set a new group policy to point it at the new WSUS) and even that was n't appearing on the WSUS console - WELL - I've come in this morning and it's appeared in the new group and has reported in and all looks fine.

 

I'm going to APPROVE a few more updates and check they get seen and install OK.

 

Maybe next week I will move over one of the "live" servers and point it at this new WSUS and see if it also appears!

  • 3 years later...
Posted
2017-05-16 13:04:15:680 776 f90 PT Server URL = http://xxx:8530/SimpleAuthWebService/SimpleAuth.asmx

2017-05-16 13:04:15:696 776 f90 WS WARNING: Nws Failure: errorCode=0x803d001a

2017-05-16 13:04:15:696 776 f90 WS WARNING: There was an error communicating with the endpoint at 'http://xxx:8530/SimpleAuthWebService/SimpleAuth.asmx'.

2017-05-16 13:04:15:696 776 f90 WS WARNING: The server returned HTTP status code '407 (0x197)' with text 'Proxy Authentication Required'.

2017-05-16 13:04:15:696 776 f90 WS WARNING: The proxy requires HTTP authentication scheme 'NTLM'.

2017-05-16 13:04:16:743 776 f90 WS WARNING: Nws Failure: errorCode=0x803d0000

2017-05-16 13:04:16:743 776 f90 WS WARNING: There was an error communicating with the endpoint at 'http://xxx:8530/SimpleAuthWebService/SimpleAuth.asmx'.

2017-05-16 13:04:16:743 776 f90 WS WARNING: The content type 'text/html' did not match the expected value 'text/xml'.

 

 

is the WSUS server ip in the Guardian > Exceptions > destination exceptions on the smoothwall. the 407 sounds like the smoothwall is trying to get authentication from it? assuming this isnt wsus trying to authenticate.

 

if you replace the ip with fqdn does it work? check your smoothwalls live log and see if you can spot the browsing to the base IIS directory in the logs, AFAIK the smoothwall wont serve pages from ports unless explicitly told to (80/443 by default) - ideally you would make the smoothwall not serve the internal content though

  • Thanks 1

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...