tomsimon
Member
- Messages
- 6
- Solutions
- 1
- Reaction score
- 0
- Points
- 1
I have been unsuccessful for days trying to get my SCCM server, with a WSUS install on the same machine, downloading updates from an upstream WSUS server.
QUESTION #1: Why are there no files in the WsusContent folder?
Errors in SoftwareDistribution.log:
ERROR: Service is not healthy. Error status: TrustFailure, Error message: The underlying connection was closed: Could not establish trust relationship for the SSL/TLS secure channel.
(I don't know if this message is relevant to this issue. We are running as HTTP, not HTTPS/PKI. I have double-checked the SUP, MP and DP)
Error WsusService.41 ContentSyncAgent.JobError Download error: http://SERVERNAME:8530/Content/FB/134501186F4C81089054E4EC3376E74EEC895EFB.exe failed in download: (-2145844844) HTTP status 404: The requested URL does not exist on the server.
(This error is also present for one more file, and neither of these files are on the upstream server either)
There are no errors in wsyncmgr.log, WCM.log or WSUSCtrl.log.
SUMMARY OF SUCCESSFUL MESSAGES
SoftwareDistribution.log (these statements show every cycle):
Found 0 telemetry queries to run
Found 0 telemetry counts to run
Successfully run 0 Telemetry queries
TaskManager: 0 task(s) running, 0 task(s) waiting to start
wsyncmgr.log:
Read SUPs from SCF for SERVERNAME
Found 1 SUPs
Found active SUP SERVERNAME from SCF File
Synchronizing WSUS, default server is SERVERNAME
sync: WSUS synchronizing categories, processed 11 out of 11 items (100%)
sync: WSUS synchronizing updates, processed 13 out of 5580 items (0%) ...
sync: WSUS synchronizing updates, processed 5580 out of 5580 items (100%) ... [2 hours later]
Set content version of update source XXXXXXXXXXXXXXXXXXXXX for site XXX to 3
Resetting MaxInstall RunTime for Cumulative updates
Synchronizing SMS database with WSUS, default server is SERVERNAME
:
Syncing all updates
Requested categories Product=Office2016, Product=Windows Server 2016, Product=Microsoft Edge, Product=Windows 10, UpdateClassification=Security Updates, UpdateClassification=Update Rollups, ... UpdateClassification=Critical Updates
sync: SMS synchronizing categories, processed 375 out of 375 items (100%)
sync: WSUS synchronizing updates
syncBatchCount not set, using default 1
Collecting existing updates ...
sync: SMS synchronizing updates, processed 0 out of 524 items (0%)
Skipped update xxxxxxxxxxxxxxxxx - Security Update for Microsoft Office 2016 (KB3085538) 64-Bit Edition because it is up to date
:
Skipped update xxxxxxxxxxxxxxxxx - XXXXXXXXXXXXXXXXXXXXXXXXXXXXXX because it is was superseded
:
Synchronizing update f00da434-23d9-429f-ad31-1bbc6e7b076d - Security Update for Windows 10 Version 1809 for x64-based Systems (KB4535680)
[Also lists the versions for Windows 10 Version 1803 and 1607]
[Also lists more updates that were synchronized]
sync: SMS synchronizing updates, processed 524 out of 524 items (100%)
sync: SMS performing cleanup
Removed 21623 unreferenced updates
Done synchronizing SMS with WSUS Server SERVERNAME
Set content version of update source XXXXXXXXXXXXXXXX for site XXX to 4
:
sync: Starting SMS database synchronization
Syncing updates arrived after 02/10/2021 05:47:07
:
Done indexing SUSDB. Custom indexes were created if they didn't exist previously. SERVERNAME
Cleanup processed 531 total updates and declined 83
Starting Deletion of ObsoleteUpdates
0 update(s) were deleted from SUSDB in Server xxxxxxxx
Deletion Completed
:
Sync succeeded. Setting sync alert to canceled state on site XXX
Updated 21737 items in SMS database, new update source content version is 4
WSUSCtrl.log
Successfully connected to local WSUS server
There are no unhealthy WSUS Server components on WSUS Server SERVERNAME
Successfully checked database connection on WSUS server SERVERNAME
WCM.log
No changes - WSUS Server settings are correctly configured and Upstream Server is set to IPADDRESS
Refreshing categories from WSUS server
Successfully connected to local WSUS server
QUESTION #2: Should an upstream WSUS server have any products and classifications specified, or should that be left blank or fully populated? Since the Configuration Manager SUP role is controlling the updates, what does the upstream WSUS server have listed for products and classifications?
QUESTION #1: Why are there no files in the WsusContent folder?
Errors in SoftwareDistribution.log:
ERROR: Service is not healthy. Error status: TrustFailure, Error message: The underlying connection was closed: Could not establish trust relationship for the SSL/TLS secure channel.
(I don't know if this message is relevant to this issue. We are running as HTTP, not HTTPS/PKI. I have double-checked the SUP, MP and DP)
Error WsusService.41 ContentSyncAgent.JobError Download error: http://SERVERNAME:8530/Content/FB/134501186F4C81089054E4EC3376E74EEC895EFB.exe failed in download: (-2145844844) HTTP status 404: The requested URL does not exist on the server.
(This error is also present for one more file, and neither of these files are on the upstream server either)
There are no errors in wsyncmgr.log, WCM.log or WSUSCtrl.log.
SUMMARY OF SUCCESSFUL MESSAGES
SoftwareDistribution.log (these statements show every cycle):
Found 0 telemetry queries to run
Found 0 telemetry counts to run
Successfully run 0 Telemetry queries
TaskManager: 0 task(s) running, 0 task(s) waiting to start
wsyncmgr.log:
Read SUPs from SCF for SERVERNAME
Found 1 SUPs
Found active SUP SERVERNAME from SCF File
Synchronizing WSUS, default server is SERVERNAME
sync: WSUS synchronizing categories, processed 11 out of 11 items (100%)
sync: WSUS synchronizing updates, processed 13 out of 5580 items (0%) ...
sync: WSUS synchronizing updates, processed 5580 out of 5580 items (100%) ... [2 hours later]
Set content version of update source XXXXXXXXXXXXXXXXXXXXX for site XXX to 3
Resetting MaxInstall RunTime for Cumulative updates
Synchronizing SMS database with WSUS, default server is SERVERNAME
:
Syncing all updates
Requested categories Product=Office2016, Product=Windows Server 2016, Product=Microsoft Edge, Product=Windows 10, UpdateClassification=Security Updates, UpdateClassification=Update Rollups, ... UpdateClassification=Critical Updates
sync: SMS synchronizing categories, processed 375 out of 375 items (100%)
sync: WSUS synchronizing updates
syncBatchCount not set, using default 1
Collecting existing updates ...
sync: SMS synchronizing updates, processed 0 out of 524 items (0%)
Skipped update xxxxxxxxxxxxxxxxx - Security Update for Microsoft Office 2016 (KB3085538) 64-Bit Edition because it is up to date
:
Skipped update xxxxxxxxxxxxxxxxx - XXXXXXXXXXXXXXXXXXXXXXXXXXXXXX because it is was superseded
:
Synchronizing update f00da434-23d9-429f-ad31-1bbc6e7b076d - Security Update for Windows 10 Version 1809 for x64-based Systems (KB4535680)
[Also lists the versions for Windows 10 Version 1803 and 1607]
[Also lists more updates that were synchronized]
sync: SMS synchronizing updates, processed 524 out of 524 items (100%)
sync: SMS performing cleanup
Removed 21623 unreferenced updates
Done synchronizing SMS with WSUS Server SERVERNAME
Set content version of update source XXXXXXXXXXXXXXXX for site XXX to 4
:
sync: Starting SMS database synchronization
Syncing updates arrived after 02/10/2021 05:47:07
:
Done indexing SUSDB. Custom indexes were created if they didn't exist previously. SERVERNAME
Cleanup processed 531 total updates and declined 83
Starting Deletion of ObsoleteUpdates
0 update(s) were deleted from SUSDB in Server xxxxxxxx
Deletion Completed
:
Sync succeeded. Setting sync alert to canceled state on site XXX
Updated 21737 items in SMS database, new update source content version is 4
WSUSCtrl.log
Successfully connected to local WSUS server
There are no unhealthy WSUS Server components on WSUS Server SERVERNAME
Successfully checked database connection on WSUS server SERVERNAME
WCM.log
No changes - WSUS Server settings are correctly configured and Upstream Server is set to IPADDRESS
Refreshing categories from WSUS server
Successfully connected to local WSUS server
QUESTION #2: Should an upstream WSUS server have any products and classifications specified, or should that be left blank or fully populated? Since the Configuration Manager SUP role is controlling the updates, what does the upstream WSUS server have listed for products and classifications?