Go Premium for a chance to win a PS4. Enter to Win

x
?
Solved

WSUS 3.0 Clients not reported

Posted on 2009-05-05
27
Medium Priority
?
1,346 Views
Last Modified: 2012-06-21
Installed WSUS 3.0 SP1 on a Server 2003 R2 server (DC).  Installation worked fine and is synchronizing ok.  Unfortunately no computers are shown.

Have read numerous articles with no luck.  wuauclt /detectnow from client did not work.  Have deleted the "SusClientID" reg entry.

Typing http://wsusserver/selfupdate/wuident.cab from client and comes up with file as it should do.  Have checked client logs and found that Update Client failed to detect with error 0x800710dd.

http://wsusserver:80 comes up with page under construction.

Any ideas?
0
Comment
Question by:buddles
  • 15
  • 10
26 Comments
 
LVL 21

Expert Comment

by:JBlond
ID: 24304408
0
 
LVL 47

Expert Comment

by:Donald Stewart
ID: 24306337
Check the your default permissions and user rights for IIS 6.0
 
http://support.microsoft.com/kb/812614/ 
0
 
LVL 47

Expert Comment

by:Donald Stewart
ID: 24306379
It could be as simple as checking in the IIS Manager to see what type of authentication is enabled on the directories that are part of the WSUS Server. Windows Integrated Authentication needs to be enabled on the "SimpleAuthWebService", "Content", "ClientWebService", "ReportingWebService" and the "SelfUpdate" folders.
0
VIDEO: THE CONCERTO CLOUD FOR HEALTHCARE

Modern healthcare requires a modern cloud. View this brief video to understand how the Concerto Cloud for Healthcare can help your organization.

 

Author Comment

by:buddles
ID: 24306434
Thanks Guys.  Still going through some of the items listed however I can confirm that Windows Authentication is enabled on these items.  They were not, soI enabled them last week and performed a iisreset.  I have noticed though that Enable Anonymous access is enabled on a couple of these.
0
 
LVL 47

Expert Comment

by:Donald Stewart
ID: 24306520
0
 
LVL 47

Expert Comment

by:Donald Stewart
ID: 24306543
In case there's something missed
Verifying WSUS Server Settings
0
 

Author Comment

by:buddles
ID: 24315239
Have looked all links provided but the only thing that was different was that Anonymous and windows authentication were both configured on some sites.  Any other ideas?
0
 

Author Comment

by:buddles
ID: 24315347
When I enabled Anonymous access and disabled Windows authentication, and tried to reach the wsus server through IE, I got:

You are not authorized to view this page
You do not have permission to view this directory or page using the credentials that you supplied.
--------------------------------------------------------------------------------

Please try the following:

Contact the Web site administrator if you believe you should be able to view this directory or page.
Click the Refresh button to try again with different credentials.
HTTP Error 401.1 - Unauthorized: Access is denied due to invalid credentials.
Internet Information Services (IIS)

Should Windows authentication really be turned off?
0
 
LVL 47

Expert Comment

by:Donald Stewart
ID: 24315847
"Should Windows authentication really be turned off?"
Yes.
 
WSUS 3.0 does not use a webpage to administer anymore, you need to use the MMC.
Start>>>Administrative tools>>>Microsoft Windows Update Services 3.0
0
 

Author Comment

by:buddles
ID: 24315912
I understand that however I have read in numerous articles that you should be able to reach the wsusserver by typing in the URL to a browser in 3.0 as part of the troubleshooting.
0
 

Author Comment

by:buddles
ID: 24327719
Client log details:
2009-05-07	17:07:34:933	1132	14b0	Misc	WARNING: SendRequest failed with hr = 800710dd. Proxy List used: <(null)> Bypass List used : <(null)> Auth Schemes used : <>
2009-05-07	17:07:34:933	1132	14b0	PT	  + Last proxy send request failed with hr = 0x800710DD, HTTP status code = 401
2009-05-07	17:07:34:933	1132	14b0	PT	  + Caller provided credentials = No
2009-05-07	17:07:34:933	1132	14b0	PT	  + Impersonate flags = 2
2009-05-07	17:07:34:933	1132	14b0	PT	  + Possible authorization schemes used = 
2009-05-07	17:07:34:933	1132	14b0	PT	WARNING: GetConfig failure, error = 0x800710DD, soap client error = 5, soap error code = 0, HTTP status code = 200
2009-05-07	17:07:34:933	1132	14b0	PT	WARNING: PTError: 0x800710dd
2009-05-07	17:07:34:933	1132	14b0	PT	WARNING: GetConfig_WithRecovery failed: 0x800710dd
2009-05-07	17:07:34:933	1132	14b0	PT	WARNING: RefreshConfig failed: 0x800710dd
2009-05-07	17:07:34:933	1132	14b0	PT	WARNING: RefreshPTState failed: 0x800710dd
2009-05-07	17:07:34:933	1132	14b0	PT	WARNING: PTError: 0x800710dd
2009-05-07	17:07:34:933	1132	14b0	Report	WARNING: Reporter failed to upload events with hr = 800710dd.
2009-05-07	17:13:31:716	1132	14b0	Misc	WARNING: SendRequest failed with hr = 800710dd. Proxy List used: <(null)> Bypass List used : <(null)> Auth Schemes used : <>
2009-05-07	17:13:31:716	1132	14b0	PT	  + Last proxy send request failed with hr = 0x800710DD, HTTP status code = 401
2009-05-07	17:13:31:716	1132	14b0	PT	  + Caller provided credentials = No
2009-05-07	17:13:31:716	1132	14b0	PT	  + Impersonate flags = 2
2009-05-07	17:13:31:716	1132	14b0	PT	  + Possible authorization schemes used = 
2009-05-07	17:13:31:716	1132	14b0	PT	WARNING: GetConfig failure, error = 0x800710DD, soap client error = 5, soap error code = 0, HTTP status code = 200
2009-05-07	17:13:31:716	1132	14b0	PT	WARNING: PTError: 0x800710dd
2009-05-07	17:13:31:716	1132	14b0	PT	WARNING: GetConfig_WithRecovery failed: 0x800710dd
2009-05-07	17:13:31:716	1132	14b0	PT	WARNING: RefreshConfig failed: 0x800710dd
2009-05-07	17:13:31:716	1132	14b0	PT	WARNING: RefreshPTState failed: 0x800710dd
2009-05-07	17:13:31:716	1132	14b0	PT	WARNING: PTError: 0x800710dd
2009-05-07	17:13:31:716	1132	14b0	Report	WARNING: Reporter failed to upload events with hr = 800710dd.

Open in new window

0
 
LVL 47

Expert Comment

by:Donald Stewart
ID: 24327917
0
 

Author Comment

by:buddles
ID: 24334266
Having now rebooted the server, WSUS now does not open.  Advising of Error:  Connection Error.   Very frustrating!
0
 

Author Comment

by:buddles
ID: 24364764
Have reinstalled WSUS 3.0 and now back to how things were 1st day with no computers being reported.
0
 
LVL 47

Expert Comment

by:Donald Stewart
ID: 24364980
0
 

Author Comment

by:buddles
ID: 24365130
Run on a client machine:
WSUS Client Diagnostics Tool

Checking Machine State
        Checking for admin rights to run tool . . . . . . . . . PASS
        Automatic Updates Service is running. . . . . . . . . . PASS
        Background Intelligent Transfer Service is running. . . PASS
        Wuaueng.dll version 7.2.6001.788. . . . . . . . . . . . PASS
                This version is WSUS 2.0

Checking AU Settings
        AU Option is 2 : Notify Prior to Download . . . . . . . PASS
                Option is from Policy settings

Checking Proxy Configuration
        Checking for winhttp local machine Proxy settings . . . PASS
                Winhttp local machine access type
                        <Direct Connection>
                Winhttp local machine Proxy. . . . . . . . . .  NONE
                Winhttp local machine ProxyBypass. . . . . . .  NONE
        Checking User IE Proxy settings . . . . . . . . . . . . PASS
                User IE Proxy. . . . . . . . . . . . . . . . .  NONE
                User IE ProxyByPass. . . . . . . . . . . . . .  NONE
                User IE AutoConfig URL Proxy . . . . . . . . .  NONE
                User IE AutoDetect
                AutoDetect not in use

Checking Connection to WSUS/SUS Server
                WUServer = http://wsusserver
                WUStatusServer = http://wsusserver
        UseWuServer is enabled. . . . . . . . . . . . . . . . . PASS

VerifyWUServerURL() failed with hr=0x800710dd

The operation identifier is not valid.


Press Enter to Complete
0
 
LVL 47

Accepted Solution

by:
Donald Stewart earned 2000 total points
ID: 24365231
0
 

Author Comment

by:buddles
ID: 24366269
Thanks again.  Believe it or not I have read all these articles before.  Very confusing as nobody seems to be able to advise if Anonymous access or Windows integrated is required.  Most knowledge docs contradict each other.  

I have though changed the specific IIS permissions back to Windows integrated following your link to 'What are the correct IIS and NTFS permissions for WSUS?' and clientdiag now completes... weird as I have changed this back and forth many times.

Now reads:
WSUS Client Diagnostics Tool

Checking Machine State
        Checking for admin rights to run tool . . . . . . . . . PASS
        Automatic Updates Service is running. . . . . . . . . . PASS
        Background Intelligent Transfer Service is running. . . PASS
        Wuaueng.dll version 7.2.6001.788. . . . . . . . . . . . PASS
                This version is WSUS 2.0

Checking AU Settings
        AU Option is 2 : Notify Prior to Download . . . . . . . PASS
                Option is from Policy settings

Checking Proxy Configuration
        Checking for winhttp local machine Proxy settings . . . PASS
                Winhttp local machine access type
                        <Direct Connection>
                Winhttp local machine Proxy. . . . . . . . . .  NONE
                Winhttp local machine ProxyBypass. . . . . . .  NONE
        Checking User IE Proxy settings . . . . . . . . . . . . PASS
                User IE Proxy. . . . . . . . . . . . . . . . .  NONE
                User IE ProxyByPass. . . . . . . . . . . . . .  NONE
                User IE AutoConfig URL Proxy . . . . . . . . .  NONE
                User IE AutoDetect
                AutoDetect not in use

Checking Connection to WSUS/SUS Server
                WUServer = http://WSUSServer
                WUStatusServer = http://WSUSServer
        UseWuServer is enabled. . . . . . . . . . . . . . . . . PASS
        Connection to server. . . . . . . . . . . . . . . . . . PASS
        SelfUpdate folder is present. . . . . . . . . . . . . . PASS

Press Enter to Complete

Will now wait to see if client computers are added.
0
 
LVL 47

Expert Comment

by:Donald Stewart
ID: 24366350
Run these commands on client and they should appear right away
 
wuauclt.exe /resetauthorization
wuauclt.exe /detectnow
wuauclt.exe /reportnow
0
 

Author Comment

by:buddles
ID: 24366668
Thanks ds.  Have done that but still nothing appearing.  Should you be able to run clientdiag on the server?  Also, should the group policy apply to the server OU as well as the computers?
0
 

Author Comment

by:buddles
ID: 24372843
I am able to download/view files from:
http://servername//iuident.cab
http://servername/selfupdate/iuident.cab
http://servername/clientwebservice/wusserverversion.xml
http://servername/simpleauthwebservice/simpleauth.asmx

and via the corresponding 80 port.

When I run wuauclt /detectnow I get:

2009-05-13	10:17:56:360	1108	4d8	AU	Triggering AU detection through DetectNow API
2009-05-13	10:17:56:360	1108	4d8	AU	Triggering Online detection (non-interactive)
2009-05-13	10:17:56:360	1108	1cc	AU	#############
2009-05-13	10:17:56:360	1108	1cc	AU	## START ##  AU: Search for updates
2009-05-13	10:17:56:360	1108	1cc	AU	#########
2009-05-13	10:17:56:360	1108	1cc	AU	<<## SUBMITTED ## AU: Search for updates [CallId = {A8AD32D5-4A73-4646-B10E-0F3C577836FC}]
2009-05-13	10:17:56:360	1108	ac0	Agent	*************
2009-05-13	10:17:56:360	1108	ac0	Agent	** START **  Agent: Finding updates [CallerId = AutomaticUpdates]
2009-05-13	10:17:56:360	1108	ac0	Agent	*********
2009-05-13	10:17:56:360	1108	ac0	Agent	  * Online = Yes; Ignore download priority = No
2009-05-13	10:17:56:360	1108	ac0	Agent	  * Criteria = "IsHidden=0 and IsInstalled=0 and DeploymentAction='Installation' and IsAssigned=1 or IsHidden=0 and IsPresent=1 and DeploymentAction='Uninstallation' and IsAssigned=1 or IsHidden=0 and IsInstalled=1 and DeploymentAction='Installation' and IsAssigned=1 and RebootRequired=1 or IsHidden=0 and IsInstalled=0 and DeploymentAction='Uninstallation' and IsAssigned=1 and RebootRequired=1"
2009-05-13	10:17:56:360	1108	ac0	Agent	  * ServiceID = {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
2009-05-13	10:17:56:360	1108	ac0	Agent	  * Search Scope = {Machine}
2009-05-13	10:17:56:360	1108	ac0	Misc	Validating signature for C:\WINDOWS\SoftwareDistribution\SelfUpdate\Default\wuident.cab:
2009-05-13	10:17:56:376	1108	ac0	Misc	 Microsoft signed: Yes
2009-05-13	10:17:56:392	1108	ac0	Misc	WARNING: WinHttp: SendRequestToServerForFileInformation failed with 0x80190191
2009-05-13	10:17:56:392	1108	ac0	Misc	WARNING: WinHttp: ShouldFileBeDownloaded failed with 0x80190191
2009-05-13	10:17:56:392	1108	ac0	Misc	WARNING: WinHttp: SendRequestToServerForFileInformation failed with 0x80190191
2009-05-13	10:17:56:392	1108	ac0	Misc	WARNING: WinHttp: ShouldFileBeDownloaded failed with 0x80190191
2009-05-13	10:17:56:407	1108	ac0	Misc	WARNING: WinHttp: SendRequestToServerForFileInformation failed with 0x80190191
2009-05-13	10:17:56:407	1108	ac0	Misc	WARNING: WinHttp: ShouldFileBeDownloaded failed with 0x80190191
2009-05-13	10:17:56:407	1108	ac0	Misc	WARNING: WinHttp: SendRequestToServerForFileInformation failed with 0x80190191
2009-05-13	10:17:56:407	1108	ac0	Misc	WARNING: WinHttp: ShouldFileBeDownloaded failed with 0x80190191
2009-05-13	10:17:56:407	1108	ac0	Misc	WARNING: DownloadFileInternal failed for http://wsusserver/selfupdate/wuident.cab: error 0x80190191
2009-05-13	10:17:56:407	1108	ac0	Setup	FATAL: IsUpdateRequired failed with error 0x80244017
2009-05-13	10:17:56:407	1108	ac0	Setup	WARNING: SelfUpdate: Default Service: IsUpdateRequired failed: 0x80244017
2009-05-13	10:17:56:407	1108	ac0	Setup	WARNING: SelfUpdate: Default Service: IsUpdateRequired failed, error = 0x80244017
2009-05-13	10:17:56:407	1108	ac0	Agent	  * WARNING: Skipping scan, self-update check returned 0x80244017
2009-05-13	10:17:56:407	1108	ac0	Agent	  * WARNING: Exit code = 0x80244017
2009-05-13	10:17:56:407	1108	ac0	Agent	*********
2009-05-13	10:17:56:407	1108	ac0	Agent	**  END  **  Agent: Finding updates [CallerId = AutomaticUpdates]
2009-05-13	10:17:56:407	1108	ac0	Agent	*************
2009-05-13	10:17:56:407	1108	ac0	Agent	WARNING: WU client failed Searching for update with error 0x80244017
2009-05-13	10:17:56:407	1108	9a0	AU	>>##  RESUMED  ## AU: Search for updates [CallId = {A8AD32D5-4A73-4646-B10E-0F3C577836FC}]
2009-05-13	10:17:56:407	1108	9a0	AU	  # WARNING: Search callback failed, result = 0x80244017
2009-05-13	10:17:56:407	1108	9a0	AU	  # WARNING: Failed to find updates with error code 80244017
2009-05-13	10:17:56:407	1108	9a0	AU	#########
2009-05-13	10:17:56:407	1108	9a0	AU	##  END  ##  AU: Search for updates [CallId = {A8AD32D5-4A73-4646-B10E-0F3C577836FC}]
2009-05-13	10:17:56:407	1108	9a0	AU	#############
2009-05-13	10:17:56:407	1108	9a0	AU	AU setting next detection timeout to 2009-05-13 12:43:18

Open in new window

0
 

Author Comment

by:buddles
ID: 24372986
I do not understand where the problem is, for example

2006-05-02 13:23:04 1080 998 Misc WARNING: DownloadFileInternal failed for http://wsusserver/selfupdate/wuident.cab: error 0x80190191 and yet I can download that file from the browser.

Under IIS default web site I have:
ClientWebservice - anonymous access and integrated windows auth
Content - anonymous access and integrated windows auth
Reporting Webservice - anonymous access and integrated windows auth
SelfUpdate - anonymous access and integrated windows auth
SimpleAuthWebService - anonymous access and integrated windows auth

Does anyone have any ideas?
0
 
LVL 47

Expert Comment

by:Donald Stewart
ID: 24375341
Again from here
http://wsusinfo.onsitechsolutions.com/articles/016.htm 
The permissions on all of the virtual directories should only have anonymous access enabled, except 'WSUSAdmin', which should only have Integrated Authentication enabled, and 'selfupdate', which for some reason has anonymous and Integrated Authentication enabled.

also did you verify your application pool and execute permissions ?
 
http://technet.microsoft.com/en-us/library/cc708545.aspx
 here's my working setup

selfupdate.bmp
simpleauth.bmp
reportingweb.bmp
content.bmp
clientweb.bmp
wsusadmin.bmp
0
 

Author Comment

by:buddles
ID: 24451654
Have checked all settings and they are as they should be.  No clients showing up still.
0
 

Author Comment

by:buddles
ID: 24555586
Problem solved...
Reinstalled WSUS again.
Originally could not browse to http://wsusserv/ClientWebService/client.asmx and was getting 80244019 errors in the client windowsupdate.log

Installed Update for Windows Server Update Services (WSUS) 3 Service Pack 1 (KB954960) which can be found at http://www.microsoft.com/downloads/details.aspx?familyid=6AA8A49D-170C-4077-8B9B-61F7BF5A1281&displaylang=en
This brought up new evnt id 1309 Source: ASP.NET 2.0.50727.0 in Application log.  Made sure the network service permission was on default WSUS folder.

Make sure you check your GPO WSUS path and correct port is specified if default is not used.

Thanks for all your help dstewartjr
0
 

Author Closing Comment

by:buddles
ID: 31578003
Thanks for all your help with this.  Not sure why did not work the first time I tried.
0

Featured Post

Veeam Disaster Recovery in Microsoft Azure

Veeam PN for Microsoft Azure is a FREE solution designed to simplify and automate the setup of a DR site in Microsoft Azure using lightweight software-defined networking. It reduces the complexity of VPN deployments and is designed for businesses of ALL sizes.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Numerous times I have been asked this questions that what is it that makes my machine log on so slow, there have been cases where computers took 23 minute exactly after taking password and getting to the desktop. Interesting thing was the fact th…
Many of us need to configure DHCP server(s) in their environment. We can do that simply via DHCP console on server or using MMC snap-in on each computer with Administrative Tools installed in a network. But what if we have to configure many DHCP ser…
This video shows how to quickly and easily deploy an email signature for all users in Office 365 and prevent it from being added to replies and forwards. (the resulting signature is applied on the server level in Exchange Online) The email signat…
Loops Section Overview

824 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question