Guest Guest Posted December 9, 2020 Posted December 9, 2020 Looks like your getting error 80244022, apparently remove your wsus settings and reconfiguring should sort it
kennysarmy Posted December 9, 2020 Author Posted December 9, 2020 On checking the Server Event Logs for Windows Server Update Service Back in October! Self-update is not working. The Reporting Web Service is not working. The API Remoting Web Service is not working. The Server Synchronization Web Service is not working. The Client Web Service is not working. The SimpleAuth Web Service is not working. The DSS Authentication Web Service is not working. The WSUS content directory is not accessible. System.Net.WebException: The remote server returned an error: (503) Server Unavailable. at System.Net.HttpWebRequest.GetResponse() at Microsoft.UpdateServices.Internal.HealthMonitoring.HmtWebServices.CheckContentDirWebAccess(EventLoggingType type, HealthEventLogger logger) Things seemed to have gone downhill since that point!
computer_expert Posted December 9, 2020 Posted December 9, 2020 (edited) I see you are using a proxy - there were some changes in september with HTTP based WSUS servers and proxies. https://techcommunity.microsoft.com/t5/windows-it-pro-blog/changes-to-improve-security-for-windows-devices-scanning-wsus/ba-p/1645547 If WSUS is too far gone then rebuild it. I find it's easier to rebuild from scratch than fix WSUS. My tips for rebuilding: Use SQL express rather than the internal database as I've found it to run better. Only tick the products and categories you need forget the driver category - it causes lots of issues Read this Newer windows server revisions default to port 8530 (8531 HTTPS) rather than 80 (443 HTTPS). Edited December 9, 2020 by computer_expert 1
kennysarmy Posted December 10, 2020 Author Posted December 10, 2020 I see you are using a proxy - there were some changes in september with HTTP based WSUS servers and proxies. https://techcommunity.microsoft.com/t5/windows-it-pro-blog/changes-to-improve-security-for-windows-devices-scanning-wsus/ba-p/1645547 If WSUS is too far gone then rebuild it. I find it's easier to rebuild from scratch than fix WSUS. My tips for rebuilding: Use SQL express rather than the internal database as I've found it to run better. Only tick the products and categories you need forget the driver category - it causes lots of issues Read this Newer windows server revisions default to port 8530 (8531 HTTPS) rather than 80 (443 HTTPS). Thanks for the heads up. Do you mean if the PC's are using a proxy to contact the WSUS server? OR just using a proxy in general for Internet access - we have a smoothwall filtering device so all web traffic goes through that. The PC's don't need a proxy to access the WSUS server however as it's just one of our on-prem servers.
kennysarmy Posted December 10, 2020 Author Posted December 10, 2020 I'll turn SSL on anyway - nothing to lose
kennysarmy Posted December 10, 2020 Author Posted December 10, 2020 SSL seems to be working - but errors still remain in the Clients WindowsUpdateLog 2020/12/10 08:55:05.6559266 8232 11312 Agent *FAILED* [8024043D] GetIsInventoryRequired 2020/12/10 08:55:06.3298123 8232 11312 Misc Got WSUS Client/Server URL: https://10.107.93.9:8531/ClientWebService/client.asmx"" 2020/12/10 08:55:06.3367767 8232 11312 Driver Skipping printer driver 8 due to incomplete info or mismatched environment - HWID[(null)] Provider[Adobe] MfgName[Adobe] Name[Adobe PDF Converter] pEnvironment[Windows x64] LocalPrintServerEnv[Windows x64] 2020/12/10 08:55:06.3367811 8232 11312 Driver Skipping printer driver 9 due to incomplete info or mismatched environment - HWID[microsoftmicrosoft_musd] Provider[Microsoft] MfgName[Microsoft] Name[Microsoft enhanced Point and Print compatibility driver] pEnvironment[Windows NT x86] LocalPrintServerEnv[Windows x64] 2020/12/10 08:55:06.5878658 8232 11312 ProtocolTalker ServiceId = {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}, Server URL = [url]https://10.107.93.9:8531/ClientWebService/client.asmx[/url] 2020/12/10 08:55:06.5886273 8232 11312 ProtocolTalker PT: Calling GetConfig on server 2020/12/10 08:55:06.5886406 8232 11312 IdleTimer WU operation (CAgentProtocolTalker::GetConfig_WithRecovery) started; operation # 7; does use network; is at background priority 2020/12/10 08:55:06.5886791 8232 11312 WebServices Auto proxy settings for this web service call. 2020/12/10 08:55:06.6969981 8232 11312 WebServices WS error: Error string with resource id '0xB7' is not found for the language id '0x809'. 2020/12/10 08:55:06.6969993 8232 11312 WebServices WS error: Error string with resource id '0x800B010F' is not found for the language id '0x809'. 2020/12/10 08:55:06.6973378 8232 11312 WebServices *FAILED* [800B010F] Web service call 2020/12/10 08:55:06.6973391 8232 11312 WebServices Current service auth scheme=0. 2020/12/10 08:55:06.6973399 8232 11312 WebServices Current Proxy auth scheme=0. 2020/12/10 08:55:06.6973456 8232 11312 IdleTimer WU operation (CAgentProtocolTalker::GetConfig_WithRecovery, operation # 7) stopped; does use network; is at background priority 2020/12/10 08:55:06.6973540 8232 11312 ProtocolTalker *FAILED* [800B010F] GetConfig_WithRecovery failed 2020/12/10 08:55:06.6973580 8232 11312 ProtocolTalker *FAILED* [800B010F] RefreshConfig failed 2020/12/10 08:55:06.6973594 8232 11312 ProtocolTalker *FAILED* [800B010F] RefreshPTState failed 2020/12/10 08:55:06.6973780 8232 11312 ProtocolTalker SyncUpdates round trips: 0 2020/12/10 08:55:06.6973789 8232 11312 ProtocolTalker *FAILED* [800B010F] Sync of Updates 2020/12/10 08:55:06.6973859 8232 11312 ProtocolTalker *FAILED* [800B010F] SyncServerUpdatesInternal failed 2020/12/10 08:55:06.7045731 8232 11312 Agent *FAILED* [800B010F] Synchronize 2020/12/10 08:55:06.7249656 8232 11312 Agent * END * Finding updates CallerId = <>: PowerShell_ISE.exe, Id = 2, Exit code = 0x800B010F (cV = 0W8Tanbdsk+WBpUX.1.0.0.2) 2020/12/10 08:55:06.7275641 8232 11312 IdleTimer WU operation (CSearchCall::Init ID 2, operation # 6) stopped; does use network; is not at background priority 2020/12/10 08:55:06.7311060 8804 6776 ComApi *RESUMED* Search ClientId = <>: PowerShell_ISE.exe, ServiceId = 3DA21691-E39D-4DA6-8A4B-B43877BCB1B7 (cV = 0W8Tanbdsk+WBpUX.1.0.0) 2020/12/10 08:55:06.7347599 8804 6776 ComApi Exit code = 0x00000000, Result code = 0x800B010F (cV = 0W8Tanbdsk+WBpUX.1.0.0) 2020/12/10 08:55:06.7347634 8804 6776 ComApi * END * Search ClientId = <>: PowerShell_ISE.exe, Updates found = 0, ServiceId = 3DA21691-E39D-4DA6-8A4B-B43877BCB1B7 (cV = 0W8Tanbdsk+WBpUX.1.0.0) 2020/12/10 08:55:06.7350129 8804 12744 ComApi * END * All federated searches have completed. Jobs = 1, Succeeded = 0, ClientId = <>: PowerShell_ISE.exe (cV = 0W8Tanbdsk+WBpUX.1.1) 2020/12/10 08:55:54.3681666 8232 2040 Shared UninitializeSUS 2020/12/10 08:55:54.3681718 8232 2040 Misc CSusClientGlobal::DoServicePreShutdown 2020/12/10 08:55:54.3681730 8232 2040 IdleTimer Idle timer disabled in preparation for service shutdown 2020/12/10 08:55:54.3681779 8232 2040 Misc WUTaskManager uninit 2020/12/10 08:55:54.3681804 8232 2040 Agent Earliest future timer found: 2020/12/10 08:55:54.3681872 8232 2040 Agent Timer: 29A863E7-8609-4D1E-B7CD-5668F857F1DB, Expires 2020-12-10 14:50:20, not idle-only, not network-only 2020/12/10 08:55:54.3808141 8232 2040 Misc CreateSessionStateChangeTrigger, TYPE:2, Enable:No 2020/12/10 08:55:54.3808251 8232 2040 Misc CreateSessionStateChangeTrigger, TYPE:4, Enable:No 2020/12/10 08:55:54.3844995 8232 2040 Misc Agent uninit 2020/12/10 08:55:54.3856173 8232 2040 Misc Reporter uninit 2020/12/10 08:55:54.3877106 8232 2040 Misc network cost manager uninit 2020/12/10 08:55:54.3877289 8232 2040 Misc Eventer uninit 2020/12/10 08:55:54.3915140 8232 2040 Misc ServiceManager uninit 2020/12/10 08:55:54.3915295 8232 2040 Misc PersistentTimeoutScheduler uninit 2020/12/10 08:55:54.3915314 8232 2040 Misc datastore uninit 2020/12/10 08:55:54.4419945 8232 2040 Misc setting cache uninit 2020/12/10 08:55:54.4419969 8232 2040 Misc security checker uninit 2020/12/10 08:55:54.4420008 8232 2040 Misc Test Hook uninit 2020/12/10 08:55:54.4420015 8232 2040 Misc IdleTimer uninit 2020/12/10 08:55:54.4433696 8232 2040 Shared * END * Service exit Exit code = 0x240001
kennysarmy Posted December 10, 2020 Author Posted December 10, 2020 Unsure what should be ticked in the red area?
kennysarmy Posted December 10, 2020 Author Posted December 10, 2020 [ATTACH=CONFIG]60134[/ATTACH] Unsure what should be ticked in the red area? If I tick the Require option then the WSUS Server Node won't open at all
kennysarmy Posted December 10, 2020 Author Posted December 10, 2020 My original GPO to set the "Specify intranet Microsoft update service location" was using the IP address of the WSUS server. Now I'm using SSL I had to change it to the FQDN.
kennysarmy Posted December 10, 2020 Author Posted December 10, 2020 PC's are starting to appear in WSUS !!!!!!!!!!!!!!!!!! 1
computer_expert Posted December 10, 2020 Posted December 10, 2020 Thanks for the heads up. Do you mean if the PC's are using a proxy to contact the WSUS server? OR just using a proxy in general for Internet access - we have a smoothwall filtering device so all web traffic goes through that. The PC's don't need a proxy to access the WSUS server however as it's just one of our on-prem servers. Good to see you've got it going now. My best guess was that as you don't have proxy excusions defined for local servers/WSUS, they are getting routed though the proxy (possibly blocked?), then the september updates were causing issues with the upgraded requirements. 1
kennysarmy Posted December 11, 2020 Author Posted December 11, 2020 Good to see you've got it going now. My best guess was that as you don't have proxy excusions defined for local servers/WSUS, they are getting routed though the proxy (possibly blocked?), then the september updates were causing issues with the upgraded requirements. Definitely the Sept. updates played a part - so was good to force us I guess to use SSL for WSUS - not sure the proxy was at play. If I check the system proxy on some servers it's "Direct" and others it's the IE imported ones - both variants now seem to be updating. But I also have still got a couple of servers giving errors when they check for updates. 80072EF3 errors and 0x80244022 If I just get those sorted I'm happy! I've copied the SSL certificate to the servers and checked the new group policy has taken to point the updates to the FQDN of the WSUS server. Also tried these commands: net stop bits net stop wuauserv reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate" /v AccountDomainSid /f reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate" /v PingID /f reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate" /v SusClientId /f reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate" /v SusClientIDValidation /f rd /s /q "C:\WINDOWS\SoftwareDistribution" net start bits net start wuauserv wuauclt /resetauthorization /detectnow PowerShell.exe (New-Object -ComObject Microsoft.Update.AutoUpdate).DetectNow()
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now