paulmac110
asked on
WSUS can't connect to clients
Having trouble with WSUS and the fact that it is showing no Computers in the console. Have looked in the windows logs and here's the information that seems to be behiond the problem.
Can anyone help?
Server URL = http://10.0.0.211:8530/SimpleAuthWebService/SimpleAuth.asmx
2013-02-22 12:36:04:061 1128 1c58 PT WARNING: GetAuthorizationCookie failure, error = 0x8024400E, soap client error = 7, soap error code = 400, HTTP status code = 200
2013-02-22 12:36:04:061 1128 1c58 PT WARNING: SOAP Fault: 0x000190
2013-02-22 12:36:04:061 1128 1c58 PT WARNING: faultstring:Fault occurred
2013-02-22 12:36:04:061 1128 1c58 PT WARNING: ErrorCode:InternalServerEr ror(5)
2013-02-22 12:36:04:061 1128 1c58 PT WARNING: Message:(null)
2013-02-22 12:36:04:061 1128 1c58 PT WARNING: Method:"http://www.microsoft.com/SoftwareDistribution/Server/SimpleAuthWebService/GetAuthorizationCookie"
2013-02-22 12:36:04:061 1128 1c58 PT WARNING: ID:d3717cf0-1c6e-4609-ae77 -364dc8012 3b4
2013-02-22 12:36:04:061 1128 1c58 PT WARNING: Failed to initialize Simple Targeting Cookie: 0x8024400e
2013-02-22 12:36:04:061 1128 1c58 PT WARNING: PopulateAuthCookies failed: 0x8024400e
2013-02-22 12:36:04:061 1128 1c58 PT WARNING: RefreshCookie failed: 0x8024400e
2013-02-22 12:36:04:061 1128 1c58 PT WARNING: RefreshPTState failed: 0x8024400e
2013-02-22 12:36:04:061 1128 1c58 PT WARNING: PTError: 0x8024400e
2013-02-22 12:36:04:061 1128 1c58 Report WARNING: Reporter failed to upload events with hr = 8024400e.
2013-02-22 12:49:03:215 1128 1c58 PT WARNING: Cached cookie has expired or new PID is available
2013-02-22 12:49:03:215 1128 1c58 PT Initializing simple targeting cookie, clientId = ba1a8f88-a401-4244-8af4-17 1826be7772 , target group = http://10.0.0.211:8530, DNS name = control-2.noeas.local
2013-02-22 12:49:03:215 1128 1c58 PT Server URL = http://10.0.0.211:8530/SimpleAuthWebService/SimpleAuth.asmx
Can anyone help?
Server URL = http://10.0.0.211:8530/SimpleAuthWebService/SimpleAuth.asmx
2013-02-22 12:36:04:061 1128 1c58 PT WARNING: GetAuthorizationCookie failure, error = 0x8024400E, soap client error = 7, soap error code = 400, HTTP status code = 200
2013-02-22 12:36:04:061 1128 1c58 PT WARNING: SOAP Fault: 0x000190
2013-02-22 12:36:04:061 1128 1c58 PT WARNING: faultstring:Fault occurred
2013-02-22 12:36:04:061 1128 1c58 PT WARNING: ErrorCode:InternalServerEr
2013-02-22 12:36:04:061 1128 1c58 PT WARNING: Message:(null)
2013-02-22 12:36:04:061 1128 1c58 PT WARNING: Method:"http://www.microsoft.com/SoftwareDistribution/Server/SimpleAuthWebService/GetAuthorizationCookie"
2013-02-22 12:36:04:061 1128 1c58 PT WARNING: ID:d3717cf0-1c6e-4609-ae77
2013-02-22 12:36:04:061 1128 1c58 PT WARNING: Failed to initialize Simple Targeting Cookie: 0x8024400e
2013-02-22 12:36:04:061 1128 1c58 PT WARNING: PopulateAuthCookies failed: 0x8024400e
2013-02-22 12:36:04:061 1128 1c58 PT WARNING: RefreshCookie failed: 0x8024400e
2013-02-22 12:36:04:061 1128 1c58 PT WARNING: RefreshPTState failed: 0x8024400e
2013-02-22 12:36:04:061 1128 1c58 PT WARNING: PTError: 0x8024400e
2013-02-22 12:36:04:061 1128 1c58 Report WARNING: Reporter failed to upload events with hr = 8024400e.
2013-02-22 12:49:03:215 1128 1c58 PT WARNING: Cached cookie has expired or new PID is available
2013-02-22 12:49:03:215 1128 1c58 PT Initializing simple targeting cookie, clientId = ba1a8f88-a401-4244-8af4-17
2013-02-22 12:49:03:215 1128 1c58 PT Server URL = http://10.0.0.211:8530/SimpleAuthWebService/SimpleAuth.asmx
Correct your target group in group policy. It looks like you have it specified as your server instead of a group name
"target group = http://10.0.0.211:8530,"
"target group = http://10.0.0.211:8530,"
ASKER
In the GPO editor, under "Specify Intranet Microsoft update service location" I have changed both fields to "http://10.0.0.211:8530/iuident.cab"
10.0.0.211 being the WSUS server.
I had previously tried it like this "http://10.0.0.211:8530"
I have also changed the target group to the domain name.
Any suggestions?
10.0.0.211 being the WSUS server.
I had previously tried it like this "http://10.0.0.211:8530"
I have also changed the target group to the domain name.
Any suggestions?
Paul
Did you try what I posted?
Did you try what I posted?
Nobody said to change the specify intranet location, you had it correct. It was your target groups policy that is wrong. You must change the specify intranet back and correct your target groups
ASKER
Ok, sorry about changing the Intranet location but had to try it to see if it made any difference. So now changed back to:- "http://10.0.0.211:8530"
Our domain is called NOEAS so I have entered that in the group policy object field for "Target Groups". Do I need to specify NOEAS.local? in that field? Or is it okay as NOEAS?
Our domain is called NOEAS so I have entered that in the group policy object field for "Target Groups". Do I need to specify NOEAS.local? in that field? Or is it okay as NOEAS?
Typically you use group names like " servers" or "workstations"
Also since you are using group policy to configure target groups, you need to select that option in your wsus console.
Also since you are using group policy to configure target groups, you need to select that option in your wsus console.
ASKER
OK, so the client are still not reporting.
I have changed client-side targetting to include these groups "CONTROL;BOARD;IT;WORKSHOP "
In the WSUS console I have created all these groups.
Have run a wuauclt /reauthorization /detectnow on some of the clients. Waiting so see what appears on the WSUS console now.
I have changed client-side targetting to include these groups "CONTROL;BOARD;IT;WORKSHOP
In the WSUS console I have created all these groups.
Have run a wuauclt /reauthorization /detectnow on some of the clients. Waiting so see what appears on the WSUS console now.
You can also schedule in the gpo how often the clients try to report
change it to like every 3 hours so you do not have to wait so long
Also is the Server showing up in the WSUS console ?
run wsusutil checkhealth on the server post results
change it to like every 3 hours so you do not have to wait so long
Also is the Server showing up in the WSUS console ?
run wsusutil checkhealth on the server post results
Did you create a separate policy for each target group?
On a client that is not reporting, what results do get from the CMD prompt ???
Reg query HKLM\SOFTWARE\Policies\Mic rosoft\Win dows\Windo wsUpdate /s
Reg query HKLM\SOFTWARE\Policies\Mic
ASKER
dstewartjr - No, I haven't created a separate policy for each group. I need to do this too?
Here's the result of the reg query:
HKEY_LOCAL_MACHINE\SOFTWAR E\Policies \Microsoft \Windows\W indowsUpda te
ElevateNonAdmins REG_DWORD 0x1
WUServer REG_SZ http://10.0.0.211:8530
WUStatusServer REG_SZ http://10.0.0.211:8530
TargetGroupEnabled REG_DWORD 0x1
TargetGroup REG_SZ Clients
AcceptTrustedPublisherCert s REG_DWORD 0x1
HKEY_LOCAL_MACHINE\SOFTWAR E\Policies \Microsoft \Windows\W indowsUpda te\AU
NoAutoUpdate REG_DWORD 0x0
AUOptions REG_DWORD 0x3
ScheduledInstallDay REG_DWORD 0x0
ScheduledInstallTime REG_DWORD 0x17
AUPowerManagement REG_DWORD 0x1
DetectionFrequencyEnabled REG_DWORD 0x1
DetectionFrequency REG_DWORD 0x16
AutoInstallMinorUpdates REG_DWORD 0x1
IncludeRecommendedUpdates REG_DWORD 0x1
NoAutoRebootWithLoggedOnUs ers REG_DWORD 0x1
RebootRelaunchTimeoutEnabl ed REG_DWORD 0x1
RebootRelaunchTimeout REG_DWORD 0xa
UseWUServer REG_DWORD 0x1
Here's the result of the reg query:
HKEY_LOCAL_MACHINE\SOFTWAR
ElevateNonAdmins REG_DWORD 0x1
WUServer REG_SZ http://10.0.0.211:8530
WUStatusServer REG_SZ http://10.0.0.211:8530
TargetGroupEnabled REG_DWORD 0x1
TargetGroup REG_SZ Clients
AcceptTrustedPublisherCert
HKEY_LOCAL_MACHINE\SOFTWAR
NoAutoUpdate REG_DWORD 0x0
AUOptions REG_DWORD 0x3
ScheduledInstallDay REG_DWORD 0x0
ScheduledInstallTime REG_DWORD 0x17
AUPowerManagement REG_DWORD 0x1
DetectionFrequencyEnabled REG_DWORD 0x1
DetectionFrequency REG_DWORD 0x16
AutoInstallMinorUpdates REG_DWORD 0x1
IncludeRecommendedUpdates REG_DWORD 0x1
NoAutoRebootWithLoggedOnUs
RebootRelaunchTimeoutEnabl
RebootRelaunchTimeout REG_DWORD 0xa
UseWUServer REG_DWORD 0x1
could you please browse to the client C:\Windows and here windowsupdate log file
here you will find the latest task details
please read it carefully
here you will find the latest task details
please read it carefully
ASKER CERTIFIED SOLUTION
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
run wuauclt /reauthorization /detectnow on the computers
wait about 10 15 mins see if they report
also does the wsus server itslef show up in the console?