Quantcast
Channel: Configuration Manager 2007 Software Updates Management forum
Viewing all 700 articles
Browse latest View live

Updates not installing

$
0
0

We have a collection of clients that the latest patches have been targeted against using a deployment template.  The collection contains the clients that we would like to get patched.  All patches have been downloaded into a package and distributed to the required DP's.  The date and time that the updates are made available and the required deadline have already passed. The clients do not have any other maintenance windows against them from any collections.

On most clients, the individual folders are created in the cache folder, but not all have the updates inside the folders.  The log files show the updates as already being downloaded and available, but the updates are not actually installed on the clients, even though the deadline has already passed.  There is no notification in the task bar as this is hidden in our environment and normally the updates just get installed.

This process has worked month on month for over a year, but for the first time now has stopped working as far as we can tell.  Is there anything that can be done to resolve this?


SCUP installation

$
0
0

Hi,

I have a primary sccm sp2 server (w2k3 r2 x64) and a remote sup (w2k3 r2 x64), and I now want to setup SCUP 4.5.

My first question is:

1. Is there just one download for 32 and 64bit servers? I can only see one so I guess it must be?

2. Can I just install SCUP on the primary sccm server where the WSUS database is (i.e. I guess I don't have to install it on the remote SUP server)?

3. Do I just create the self signed certificates on the primary sccm server and the clients, and I don't have to add them to the SUP server as well (i.e. I don't need to alter the SUP server config at all)?

Thanks


Jaz

SCCM WSUS SCAN FAILING (unable to read existing resultant WUA policy).

$
0
0

We're getting the following errors in the WUAHandler.log on about 3/70K machines:

-------------------------------------------------------------

- Its a WSUS Update Source type ({F5DD8FAF-442E-4309-A536-190FF99E644A}), adding it. WUAHandler 5/17/2013 1:03:56 PM 9832 (0x2668)
- Unable to read existing resultant WUA policy. Error = 0x800703fa. WUAHandler 5/17/2013 1:03:56 PM 9832 (0x2668)
- Enabling WUA Managed server policy to use server: http://USFLTPA-WAP01.ADS.AEXP.COM:8530 WUAHandler 5/17/2013 1:03:56 PM 9832 (0x2668)
- Waiting for 2 mins for Group Policy to notify of WUA policy change... WUAHandler 5/17/2013 1:03:56 PM 9832 (0x2668)
- Unable to read existing WUA resultant policy. Error = 0x800703fa. WUAHandler 5/17/2013 1:04:30 PM 9832 (0x2668)
- Group policy settings were overwritten by a higher authority (Domain Controller) to: Server  and Policy NOT CONFIGURED WUAHandler 5/17/2013 1:04:30 PM 9832 (0x2668)
- Failed to Add Update Source for WUAgent of type (2) and id ({F5DD8FAF-442E-4309-A536-190FF99E644A}). Error = 0x80040692. WUAHandler 5/17/2013 1:04:30 PM 9832 (0x2668)

-------------------------------------------------------------

From what I've found this generally refers to a GPO that's pointing the machines to an invalid server...............but in my case we do not have any GPOs in place that's changing WUA settings. I've been tracking the machines that this affects and have seen a machine successfully scan at 7:50am and then start to fail at 11:50am the same day.

Since I don't believe we have a GPO corrupting these settings I'm focusing on "Unable to read existing WUA resultant policy" and what would cause that.

Please advise.......

Jason Steeves


Jason

SCCM Patch Size - In A Report

$
0
0

I want to build a report that lists the Patch [bulletin id / article id / description  / size]. I can get all the fields except for the patch size……………………Does anyone know how to get the size of a patch via a query / report?

Thanks,


JASON STEEVES


Jason

Unable to modify Update List

$
0
0

Hi Folks,

I have SCCM 2007 implemented in our environment. There are several update lists used by us. Few update lists have 700+ updates. but suddenly for past few days, when i tried add or delete updates, it crashes the MMC and throws error. I have even tried by adding\deleting single update, though the result is same. Have anyone faced this issue.

If so can anyone help me in resolving this issue.

SCCM Server

$
0
0
In my SCCM Server 2007 the four updates are runing good like, All updates,Critical updates, Security updates, Service packs and two other updates has been stop such as like, WSUS Updates and MFEP 2010 updates. I cant distribute a package/softwear to client pc and also even the MFEP is not Deploying to client pc. please help me to solve this problem???

Reboot machines after Software Update in SCCM 2007

$
0
0

I came across a situation that i need to build different reboot settings for 2 different Collections after automatically deploying Software Updates. Here i am talking about one root and one Sub collection.

For one collection the Reboot is mandatory according to our defined timelines. For other one Software Updates need to apply but reboot need to be supressed. I know we can do this by creating 2 different Deployment Management and Deployment Packages. But i want to achieve this using single Deployment Management and single Deployment Package.

In my current environment i have one sinlge Production package and 2 collections sayA and B. A is root and B is sub collection inA. I targeted my Deployment Management to Collection A and its member collection. In the Deployment Management i made sure to supress reboot to Servers and not for Clients. Now as i target this deployment to CollectionA and its sub, it is rebooting the machines after said time for both collections..

I want collection A to be rebooted automatically but CollectionB to be supressed using sinlgle Deployment Management and Deployment Package. I know it is possible via Maintenance mode but i dont want to use that as user needs to install packages 24/7.

Is there any other way i can acheive?? Please share.

Reagards

Pratap


pmm

Detection State Unknown - Possible Cause

$
0
0
I have around 1000 machines i our environment in which i am facing the issue of detection state unknown .  

1. Inventory logs of these are good - as these are reporting to the database.

2. they are reporting to their MP and then to the Central Site.

3. even updates are getting sync in WUAHandler.log as getting the below logs.

Async searching of updates using WUAgent started. WUAHandler5/20/2013 10:47:21 AM4924 (0x133C)

Async searching completed.WUAHandler5/20/2013 10:49:28 AM4388 (0x1124)

Successfully completed scan.WUAHandler5/20/2013 10:49:29 AM4920 (0x1338)

Its a WSUS Update Source type ({5561D5BD-67C8-467D-A16D-0583DE9263ED}), adding it.WUAHandler5/20/2013 10:49:32 AM4920 (0x1338)

Existing WUA Managed server was already set (http://XXXXXXXXXXXXXXXXX:8530), skipping Group Policy registration.WUAHandler5/20/2013 10:49:32 AM4920 (0x1338)

Added Update Source ({5561D5BD-67C8-467D-A16D-0583DE9263ED}) of content type: 2WUAHandler5/20/2013 10:49:33 AM4920 (0x1338)

Async searching of updates using WUAgent started. WUAHandler5/20/2013 10:49:33 AM4920 (0x1338)

Async searching completed.WUAHandler5/20/2013 10:49:47 AM3568 (0x0DF0)

Successfully completed scan.WUAHandler5/20/2013 10:49:48 AM4920 (0x1338)

Async searching of updates using WUAgent started. WUAHandler5/20/2013 10:57:41 AM2212 (0x08A4)

Async searching completed.WUAHandler5/20/2013 10:58:01 AM3428 (0x0D64)

Successfully completed scan.WUAHandler5/20/2013 10:58:01 AM2212 (0x08A4)

Its a WSUS Update Source type ({5561D5BD-67C8-467D-A16D-0583DE9263ED}), adding it.WUAHandler5/21/2013 10:48:49 AM2456 (0x0998)

Existing WUA Managed server was already set (http://XXXXXXXXXXXX:8530), skipping Group Policy registration.WUAHandler5/21/2013 10:48:49 AM2456 (0x0998)

Added Update Source ({5561D5BD-67C8-467D-A16D-0583DE9263ED}) of content type: 2WUAHandler5/21/2013 10:48:49 AM2456 (0x0998)

Async searching of updates using WUAgent started. WUAHandler5/21/2013 10:48:50 AM2456 (0x0998)

Async searching completed.WUAHandler5/21/2013 10:49:32 AM2796 (0x0AEC)

Successfully completed scan.WUAHandler5/21/2013 10:49:33 AM2456 (0x0998).



I have tried below steps but with no luck.



1. Upgraded the Windows Update Agent on all the machines -  But nothing changes issue remains the same.
2. Checked all the status and client on MP for communication from client to MP machine is reporting to MP.
3. Checked the "windowsupdate.log"  for all machine everything looks good.
4. Followed below steps as found on Technet - 
                  1. Stop the Automatic Updates service and BITS service.
                         net stop wuauserv
                         net stop bits
                  2. Delete “%windir%\softwaredistribution” directory.
                  3. Start the Automatic Updates service and BITS service. When these two services 
                      have been started, they will auto-create “softwaredistribution” and its subfolder 
                     at system directory.
                                net start wuauserv
                               net start bits
                 4. After the “%windir%\softwaredistribution” directory has been generated, please 
                     let the client contact the WSUS server immediately.

                                wuauclt.exe /resetauthorization /detectnow
                 5. After 15 minutes, please check the client to confirm whether it detects needed 
                     updates. 

After following these steps also nothing changes and issue remains the same.

5. Run the blow script in order to update the status message - but nothing changes and issue remains the same.
     
     Option Explicit
       On Error Resume Next

        Call RefreshServerComplianceState

        ' WScript.Echo "Finished"

      Sub RefreshServerComplianceState()

              ' Initialize the UpdatesStore variable.
                dim newCCMUpdatesStore
   
    ' Create the COM object.
               set newCCMUpdatesStore = CreateObject ("Microsoft.CCM.UpdatesStore")

    ' Refresh the server compliance state by running the RefreshServerComplianceState method.
                newCCMUpdatesStore.RefreshServerComplianceState
   
    ' Output success message.
              '    wscript.echo "Ran RefreshServerComplianceState."

End Sub


 >>after this i came to a conclusion their can be an issue in the report also mentioned below.



          
              declare @DeploymentLocalID int
              select @DeploymentLocalID = AssignmentID from v_CIAssignment where Assignment_UniqueID = @DEPLOYMENTID
              declare @COLLCOUNT as int
              select @COLLCOUNT=count(*) from v_CIAssignmentTargetedMachines where AssignmentID=@DeploymentLocalID
              declare @LOCALUPDATEID int
              select @LOCALUPDATEID=CI_ID from v_UpdateCIs where CI_UniqueID=@UPDATEID

              select
              sn.StateName as Status,
              count(*) as NumberOfComputers,
              PComputers=convert(numeric(5,2), (isnull(count(*), 0)* 100.00 / isnull(nullif(@COLLCOUNT, 0), 1))),
              @DEPLOYMENTID as DeploymentID,
              @UPDATEID as UniqueUpdateID,
              sn.TopicType*10000 + sn.StateID as DeploymentStateID
              from v_UpdateState_Combined uc
              join v_StateNames sn
              on uc.StateType = sn.TopicType and sn.StateID=isnull(uc.StateID,0)
              join v_CIAssignmentTargetedMachines atm
              on uc.ResourceID = atm.ResourceID
              join v_CIAssignmentToCI aci on aci.CI_ID = @LOCALUPDATEID and aci.AssignmentID = @DeploymentLocalID
              where atm.AssignmentID=@DeploymentLocalID and uc.CI_ID=@LOCALUPDATEID
              group by sn.StateName, sn.TopicType, sn.StateID
              order by sn.StateName
            

]
            

But i am unable to get an idea that how and by which constraint and rule this query is taking the status (E.g by last states sent by the machine or any other)

4. I have created the below report in order to check the status of the machine state.

 Select US.ResourceID, vrs.Netbios_Name0,  sn.StateName , sn.StateDescription , us.StateTime, ws.LastHWScan, ws.TimeStamp from v_R_System vrs
            join v_UpdateState_Combined as us on vrs.ResourceID = us.ResourceID
            join v_StateNames as sn on us.StateID = sn.StateID
            Join v_GS_WORKSTATION_STATUS ws on ws.ResourceID = vrs.ResourceID
           where vrs.Netbios_Name0 = 'XXXXXX'

by this we are able to get the different status of the machine.






Server 2003 R2 client not installing updates

$
0
0

I am trying to patch a Windows Server 2003 R2 box using SCCM and I am not having luck getting the updates to install.   I have added it to the correct group and I can see in the SCCM reports that updates are required.

I have checked WindowsUpdate.Log and the Update logs in SCCM and nothing immediately stands out as being wrong.

Any ideas what I can do next to troubleshoot?

Regards

Mark

single software update deployment management for office and OS patches

$
0
0

Hi All ,

I have one query regarding software update management , usually office updates and OS (windows 7)  updates are not clubbed together, like there must be a separate update list for both and separate  packages and like wise . and i guess these are also best practices to keep them segregated . Now my question is that  my management wants to create a separate pkgs for both(office and win 7 updates) but to keep single update list for  them and a single deployment management . But  as per my knowledge , this is not the best practise also it may involve some complex operations during monitoring .

So please help me out in this by providing your valuable advise  and if I go with single DM option will it make moitoring easy.

Thanks in advance

Display Notifications and Available Software Updates not in System Tray

$
0
0

I am deploying patches to Windows 2000/2003 servers and usually I suppress display messages and set a deadline to make the updates mandatory.  That works fine.  In some cases on special servers we want the software update deployment to be manual so that an admin can login to the server and manually run the deployment from the systray when they are ready.  Problem is, the icon is not showing in the systray at all.  I can see that the machines got policy and they have downloaded updates and they show a status of downloaded updates so all appears healthy there.  Cannot figure out why I don't see the icon in the systray.  I am allowing display notifications on clients in the deployment.  I checked and I do not have the site wide setting to hide display notifications set on the SUP client agent.  Even if I did, from what I have read, I would still see the icon but not the balloon popups.  I don't really care about the balloon popups whether they appear or not, I just want the systray icon so the patches can be launched manually.  Any ideas?  I am logging into the servers via remote desktop.  Not sure if that plays a role. I remeber in the past certain items not displaying when connected through terminal services so not sure if that is going on.  Without the icon is there any other way to manually launch the deployment (ie. an exe).

Trigger software updates synchronization from command line

$
0
0

Hi all,

I am trying to automate as much as possible of the import of updates to an isolated network running ConfigMgr 2007 and WSUS. To save time and work, I have built a powershell script that copies the WSUS content and runs wsusutil.exe for the import of metadata.

As a next step, I would like to be able to trigger the SCCM SUP Synchronization as soon as the metadata import is finished. Have traversed this forum and other good sources, but have not found anything I could use. Would it be possible using WMI?


Morten

All SUS logs say installed but Microsoft Update indicates still needed

$
0
0
I am installing 25 Office patches through WSUS in COnfig Mgr 2007. I watch the WUAHandler.log and it indicates that most patches are installed. The execmgr.log gives a 0 error code, but I reboot the system and then run Microsoft update and the same kb patches that say installed in the WUAHandler.log are still showing as required by Microsoft Update. Also there is no .log file for these updates in c:\windows???

SCCM Server logs date and time stamp is off. It says 1/1/1601? Is this normal?

$
0
0
SCCM Server logs date and time stamp is off.  It says 1/1/1601? Is this normal?

Software Updated - Expired

$
0
0

 

I have a problem where all my software updates shown as expired (they are all grey). I have waited couple of days to see if they turn green again, but nothing happened.

If I try and download them by right clicking on to the update and selecting 'Download Software Update', I get an error telling me 'All software updates in this selection are expired or metadata-only. The deployment cannot be created.'

This causes SCCM console to freeze and I am unable to do anything but kill the console from the task manager and start again.

I would love to know what metadata is and what might be the reason behind this. I've spent most of the time searching for answers, but had no luck so far.

Hopefully somone out there can help.

 

Thanks.


Unable to Push Updates out VIA SCCM 2007, please help!

$
0
0

I have been having some issues getting Patches to push to clients, I download the updates and deploy them to the clients but the updates never show up to install it just sits there no matter the deadline I put and I am getting really frustrated.  I thought I figured it out when I realized GPO was blocking SCCM after I got that resolved  the WUA handler logs look great syncing everything is successful but I did find these errors in the UpdatesDeployment.logs on a lot of the clients which i think it is the problem and i cant figure out with the life of me how to fix it.

Here is the following errors from the Updatesdeployment.log



<![LOG[Service startup system task]LOG]!><time="13:16:02.756+420" date="05-22-2013" component="UpdatesDeploymentAgent" context="" type="1" thread="2676" file="systemtasks.cpp:30">
<![LOG[Software Updates client configuration policy has not been received.]LOG]!><time="13:16:02.771+420" date="05-22-2013" component="UpdatesDeploymentAgent" context="" type="1" thread="2676" file="updatesconfig.cpp:229">
<![LOG[Software updates functionality will not be enabled until the configuration policy has been received. If this issue persists please check client/server policy communication.]LOG]!><time="13:16:02.771+420" date="05-22-2013" component="UpdatesDeploymentAgent" context="" type="1" thread="2676" file="updatesconfig.cpp:230">
<![LOG[Software Updates feature is disabled]LOG]!><time="13:16:02.771+420" date="05-22-2013" component="UpdatesDeploymentAgent" context="" type="1" thread="2676" file="cdeploymentagent.cpp:59">
<![LOG[Software Updates client configuration policy has not been received.]LOG]!><time="13:16:02.771+420" date="05-22-2013" component="UpdatesDeploymentAgent" context="" type="1" thread="2676" file="updatesconfig.cpp:229">
<![LOG[Software updates functionality will not be enabled until the configuration policy has been received. If this issue persists please check client/server policy communication.]LOG]!><time="13:16:02.771+420" date="05-22-2013" component="UpdatesDeploymentAgent" context="" type="1" thread="2676" file="updatesconfig.cpp:230">
<![LOG[No user is logged on]LOG]!><time="13:16:04.287+420" date="05-22-2013" component="UpdatesDeploymentAgent" context="" type="1" thread="2676" file="updatesdeployment.cpp:118">

"Suppress Restart" settings effect after sccm server shutdown

"Suppress Restart" settings after SCCM server shutdown

$
0
0

Hi Guys,

There is a disaster recovery implementation planned in our organization and the SCCM Primary site server is set to shut down for two weeks. My concern is like we had a "Restart suppress" settings in effect for software update we deployed earlier to some critical servers and are pending reboot. I'm confused and suspect that they may be triggered to auto reboot as the server goes down (policies also). Please suggest your inputs.

Thank You.

"Suppress Restart" settings after SCCM server shutdown

$
0
0

Hi Guys,

There is a disaster recovery implementation planned in our organization and the SCCM Primary site server is set to shut down for two weeks. My concern is like we had a "Restart suppress" settings in effect for software update we deployed earlier to some critical servers and are pending reboot. I'm confused and suspect that they may be triggered to auto reboot as the server goes down (policies also). Please suggest your inputs.

Thank You.

Deploying Software updates in SCCM 2007 Best Practices

$
0
0
Hi Everyone,

I'm beginning the process of using the Software Updates in SCCM 2007 and I'm looking for some guidance from the guru's on the best way to start rolling. 

I understand how to roll out updates, so that's not really the issue, rather, it is how to roll out the first set of updates to get my network "current" on updates.

Basically, all of the updates from 2008 have NOT been performed.  Yes, I know YIKES, however I just recently realized that if you have a Software Update Point in your network but are not deploying updates, Windows update doesn't work... rookie mistake.

Question: As for rolling out all of the 2008 and part of 2009 updates, do you reccomend pulling the updates by month or just making it one large software update?

Thanks in advance for your input.

Sean
Viewing all 700 articles
Browse latest View live


<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>