locked
Client not updating - Error Code # 0x80244023 and 0x801901f8 RRS feed

  • Question

  • Hello All,

    We have a Windows server (2008) which is not pulling updates from WSUS server. It has two NICs - one is public and another is configured with 172.x.x.x range for Admin use (this is for WSUS communication with no DNS setup).

    See logs below,

    2014-05-07        13:05:50:089     916      1410     Misc      ===========  Logging initialized (build: 7.6.7600.256, tz: +0800)  ===========

    2014-05-07        13:05:50:089     916      1410     Misc        = Process: C:\Windows\system32\svchost.exe

    2014-05-07        13:05:50:089     916      1410     Misc        = Module: c:\windows\system32\wuaueng.dll

    2014-05-07        13:05:50:089     916      1410     Service *************

    2014-05-07        13:05:50:089     916      1410     Service ** START **  Service: Service startup

    2014-05-07        13:05:50:089     916      1410     Service *********

    2014-05-07        13:05:50:091     916      1410     Agent      * WU client version 7.6.7600.256

    2014-05-07        13:05:50:092     916      1410     Agent      * Base directory: C:\Windows\SoftwareDistribution

    2014-05-07        13:05:50:092     916      1410     Agent      * Access type: Named proxy

    2014-05-07        13:05:50:092     916      1410     Agent      * Default proxy: proxy:8083

    2014-05-07        13:05:50:093     916      1410     Agent      * Network state: Connected

    2014-05-07        13:05:50:520     916      1410     DtaStor Default service for AU is {00000000-0000-0000-0000-000000000000}

    2014-05-07        13:05:50:531     916      1410     DtaStor Default service for AU is {9482F4B4-E343-43B6-B170-9A65BC822C77}

    2014-05-07        13:05:50:539     916      1410     Agent    WARNING: Failed to read the service id for re-registration 0x80070002

    2014-05-07        13:05:50:539     916      1410     Agent    WARNING: Missing service entry in the backup data store; cleaning up

    2014-05-07        13:06:01:251     916      1594     Report   CWERReporter::Init succeeded

    2014-05-07        13:06:01:251     916      1594     Agent    ***********  Agent: Initializing Windows Update Agent  ***********

    2014-05-07        13:06:01:253     916      1594     Agent    ***********  Agent: Initializing global settings cache  ***********

    2014-05-07        13:06:01:253     916      1594     Agent      * WSUS server: http://172.16.74.28

    2014-05-07        13:06:01:253     916      1594     Agent      * WSUS status server: http://172.16.74.28

    2014-05-07        13:06:01:253     916      1594     Agent      * Target group: (Unassigned Computers)

    2014-05-07        13:06:01:253     916      1594     Agent      * Windows Update access disabled: No

    2014-05-07        13:06:01:253     916      1410     Report   ***********  Report: Initializing static reporting data  ***********

    2014-05-07        13:06:01:253     916      1410     Report     * OS Version = 6.1.7601.1.0.196626

    2014-05-07        13:06:01:253     916      1594     DnldMgr            Download manager restoring 0 downloads

    2014-05-07        13:06:01:253     916      1410     Report     * OS Product Type = 0x0000000A

    2014-05-07        13:06:01:260     916      1594     AU        ###########  AU: Initializing Automatic Updates  ###########

    2014-05-07        13:06:01:261     916      1594     AU          # WSUS server: http://172.16.74.28

    2014-05-07        13:06:01:261     916      1594     AU          # Detection frequency: 1

    2014-05-07        13:06:01:261     916      1594     AU          # Approval type: Pre-install notify (Policy)

    2014-05-07        13:06:01:261     916      1594     AU          # Auto-install minor updates: Yes (Policy)

    2014-05-07        13:06:01:261     916      1594     AU          # Will interact with non-admins (Non-admins are elevated (Policy))

    2014-05-07        13:06:01:384     916      1410     Report     * Computer Brand = VMware, Inc.

    2014-05-07        13:06:01:384     916      1410     Report     * Computer Model = VMware Virtual Platform

    2014-05-07        13:06:01:390     916      1410     Report     * Bios Revision = 6.00

    2014-05-07        13:06:01:390     916      1410     Report     * Bios Name = PhoenixBIOS 4.0 Release 6.0    

    2014-05-07        13:06:01:390     916      1410     Report     * Bios Release Date = 2012-07-09T00:00:00

    2014-05-07        13:06:01:390     916      1410     Report     * Locale ID = 1033

    2014-05-07        13:06:01:392     916      1594     AU        Successfully wrote event for AU health state:0

    2014-05-07        13:06:01:392     916      1594     AU        Initializing featured updates

    2014-05-07        13:06:01:392     916      1594     AU        Found 0 cached featured updates

    2014-05-07        13:06:01:392     916      1594     AU        Successfully wrote event for AU health state:0

    2014-05-07        13:06:01:395     916      1714     Report   WARNING: Failed to open event cache file at C:\Windows\SoftwareDistribution\EventCache\{1EDE8AC5-7759-45EC-9747-C62989CBAEF4}.bin for reading with hr = 80070002.

    2014-05-07        13:06:01:396     916      1714     Report   WARNING: Failed to open event cache file at C:\Windows\SoftwareDistribution\EventCache\{EEE2278A-AE78-4886-96CF-5C5946BA8699}.bin for reading with hr = 80070002.

    2014-05-07        13:06:01:396     916      1594     AU        Successfully wrote event for AU health state:0

    2014-05-07        13:06:01:396     916      1594     AU        AU finished delayed initialization

    2014-05-07        13:06:01:397     916      1594     AU        Triggering AU detection through DetectNow API

    2014-05-07        13:06:01:397     916      1594     AU        Triggering Online detection (non-interactive)

    2014-05-07        13:06:01:397     916      1410     AU        #############

    2014-05-07        13:06:01:397     916      1410     AU        ## START ##  AU: Search for updates

    2014-05-07        13:06:01:397     916      1410     AU        #########

    2014-05-07        13:06:01:399     916      1410     AU        <<## SUBMITTED ## AU: Search for updates [CallId = {177B400D-42A5-46EB-8588-A6F107FF3C77}]

    2014-05-07        13:06:01:399     916      1714     Agent    *************

    2014-05-07        13:06:01:399     916      1714     Agent    ** START **  Agent: Finding updates [CallerId = AutomaticUpdates]

    2014-05-07        13:06:01:399     916      1714     Agent    *********

    2014-05-07        13:06:01:399     916      1714     Agent      * Online = Yes; Ignore download priority = No

    2014-05-07        13:06:01:399     916      1714     Agent      * Criteria = "IsInstalled=0 and DeploymentAction='Installation' or IsPresent=1 and DeploymentAction='Uninstallation' or IsInstalled=1 and DeploymentAction='Installation' and RebootRequired=1 or IsInstalled=0 and DeploymentAction='Uninstallation' and RebootRequired=1"

    2014-05-07        13:06:01:399     916      1714     Agent      * ServiceID = {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7} Managed

    2014-05-07        13:06:01:399     916      1714     Agent      * Search Scope = {Machine}

    2014-05-07        13:06:01:399     916      1714     Setup    Checking for agent SelfUpdate

    2014-05-07        13:06:01:400     916      1714     Setup    Client version: Core: 7.6.7600.256  Aux: 7.6.7600.256

    2014-05-07        13:07:03:952     916      1714     Misc      WARNING: WinHttp: SendRequestToServerForFileInformation failed with 0x801901f8

    2014-05-07        13:07:03:952     916      1714     Misc      WARNING: WinHttp: ShouldFileBeDownloaded failed with 0x801901f8

    2014-05-07        13:07:22:828     916      1714     Misc      WARNING: WinHttp: SendRequestToServerForFileInformation failed with 0x801901f8

    2014-05-07        13:07:22:828     916      1714     Misc      WARNING: WinHttp: ShouldFileBeDownloaded failed with 0x801901f8

    2014-05-07        13:09:02:845     916      1714     Misc      WARNING: WinHttp: SendRequestToServerForFileInformation failed with 0x801901f8

    2014-05-07        13:09:02:845     916      1714     Misc      WARNING: WinHttp: ShouldFileBeDownloaded failed with 0x801901f8

    2014-05-07        13:10:02:451     916      1714     Misc      WARNING: WinHttp: SendRequestToServerForFileInformation failed with 0x801901f8

    2014-05-07        13:10:02:451     916      1714     Misc      WARNING: WinHttp: ShouldFileBeDownloaded failed with 0x801901f8

    2014-05-07        13:10:02:451     916      1714     Misc      WARNING: DownloadFileInternal failed for http://172.16.74.28/selfupdate/wuident.cab: error 0x801901f8

    2014-05-07        13:10:02:452     916      1714     Setup    WARNING: SelfUpdate check failed to download package information, error = 0x80244023

    2014-05-07        13:10:02:452     916      1714     Setup    FATAL: SelfUpdate check failed, err = 0x80244023

    2014-05-07        13:10:02:452     916      1714     Agent      * WARNING: Skipping scan, self-update check returned 0x80244023

    2014-05-07        13:10:02:452     916      1714     Agent      * WARNING: Exit code = 0x80244023

    2014-05-07        13:10:02:452     916      1714     Agent    *********

    2014-05-07        13:10:02:452     916      1714     Agent    **  END  **  Agent: Finding updates [CallerId = AutomaticUpdates]

    2014-05-07        13:10:02:452     916      1714     Agent    *************

    2014-05-07        13:10:02:452     916      1714     Agent    WARNING: WU client failed Searching for update with error 0x80244023

    2014-05-07        13:10:02:453     916      ae8       AU        >>##  RESUMED  ## AU: Search for updates [CallId = {177B400D-42A5-46EB-8588-A6F107FF3C77}]

    2014-05-07        13:10:02:453     916      ae8       AU          # WARNING: Search callback failed, result = 0x80244023

    2014-05-07        13:10:02:453     916      ae8       AU          # WARNING: Failed to find updates with error code 80244023

    2014-05-07        13:10:02:453     916      ae8       AU        #########

    2014-05-07        13:10:02:454     916      ae8       AU        ##  END  ##  AU: Search for updates [CallId = {177B400D-42A5-46EB-8588-A6F107FF3C77}]

    2014-05-07        13:10:02:454     916      ae8       AU        #############

    2014-05-07        13:10:02:457     916      ae8       AU        Successfully wrote event for AU health state:0

    2014-05-07        13:10:02:457     916      ae8       AU        AU setting next detection timeout to 2014-05-07 06:08:08

    2014-05-07        13:10:02:457     916      ae8       AU        Successfully wrote event for AU health state:0

    2014-05-07        13:10:02:458     916      ae8       AU        Successfully wrote event for AU health state:0

    2014-05-07        13:10:02:463     916      1714     Report   CWERReporter finishing event handling. (00000000)

    2014-05-07        13:10:07:452     916      1714     Report   REPORT EVENT: {E1B169E2-C0FC-4D33-A70B-41F76CB362B9}            2014-05-07 13:10:02:452+0800  1          148       101       {D67661EB-2423-451D-BF5D-13199E37DF28}      1            80244023          SelfUpdate         Failure   Software Synchronization            Windows Update Client failed to detect with error 0x80244023.

    2014-05-07        13:10:07:462     916      1714     Report   CWERReporter::HandleEvents - WER report upload completed with status 0x8

    2014-05-07        13:10:07:463     916      1714     Report   WER Report sent: 7.6.7600.256 0x80244023 D67661EB-2423-451D-BF5D-13199E37DF28 Scan 101 Managed

    2014-05-07        13:10:07:463     916      1714     Report   CWERReporter finishing event handling. (00000000)

    I verified through Nslookup and found WSUS server IP and name does not resolved. However, the download manager window is opening up while accessing - http://172.16.74.28/selfupdate/wuident.cab from server browser.

    Please help.


    Wednesday, May 7, 2014 5:47 AM

Answers

  • 2014-05-07        13:06:01:395     916      1714     Report   WARNING: Failed to open event cache file at C:\Windows\SoftwareDistribution\EventCache\{1EDE8AC5-7759-45EC-9747-C62989CBAEF4}.bin for reading with hr = 80070002.

    This type of error is quite often symptomatic of a corrupted WUA datastore.

    2014-05-07        13:07:03:952     916      1714     Misc      WARNING: WinHttp: SendRequestToServerForFileInformation failed with 0x801901f8

    The 0x801901F8 is an HTTP 504 -- "request timed out waiting on a gateway".

    2014-05-07        13:06:01:253     916      1594     Agent      * Target group: (Unassigned Computers)
    2014-05-07        13:06:01:261     916      1594     AU          # Detection frequency: 1

    When using Server-Side Targeting, this value should be at least 2 hours. Based on the above three observations, I recommend the following response:

    1. Verify that the routing table is correct and that requests for 172.16/16 are actually leaving on the correct NIC.
    2. Change the Detection Frequency to at least 2 hours (until you fix the communication issue it might as well be 22 hours!).
    3. Run wuauclt /resetauthorization /detectnow.

    If the 0x80070002 error persists, do the following:

    1. Stop the Windows Update service.
    2. Rename %windir%\SoftwareDistribution to SoftwareDistribution.OLD.
    3. Start the Windows Update service.
    4. Run wuauclt /resetauthorization /detectnow and observe the results. If the issue is resolved, copy the ReportingEvents.log from SoftwareDistribution.OLD back to the new SoftwareDistribution.

    If the issue is not resolved, post that detection event for further analysis.


    Lawrence Garvin, M.S., MCSA, MCITP:EA, MCDBA
    SolarWinds Head Geek
    Microsoft MVP - Software Packaging, Deployment & Servicing (2005-2014)
    My MVP Profile: http://mvp.microsoft.com/en-us/mvp/Lawrence%20R%20Garvin-32101
    http://www.solarwinds.com/gotmicrosoft
    The views expressed on this post are mine and do not necessarily reflect the views of SolarWinds.

    Wednesday, May 7, 2014 9:30 PM

All replies

  • 2014-05-07        13:06:01:395     916      1714     Report   WARNING: Failed to open event cache file at C:\Windows\SoftwareDistribution\EventCache\{1EDE8AC5-7759-45EC-9747-C62989CBAEF4}.bin for reading with hr = 80070002.

    This type of error is quite often symptomatic of a corrupted WUA datastore.

    2014-05-07        13:07:03:952     916      1714     Misc      WARNING: WinHttp: SendRequestToServerForFileInformation failed with 0x801901f8

    The 0x801901F8 is an HTTP 504 -- "request timed out waiting on a gateway".

    2014-05-07        13:06:01:253     916      1594     Agent      * Target group: (Unassigned Computers)
    2014-05-07        13:06:01:261     916      1594     AU          # Detection frequency: 1

    When using Server-Side Targeting, this value should be at least 2 hours. Based on the above three observations, I recommend the following response:

    1. Verify that the routing table is correct and that requests for 172.16/16 are actually leaving on the correct NIC.
    2. Change the Detection Frequency to at least 2 hours (until you fix the communication issue it might as well be 22 hours!).
    3. Run wuauclt /resetauthorization /detectnow.

    If the 0x80070002 error persists, do the following:

    1. Stop the Windows Update service.
    2. Rename %windir%\SoftwareDistribution to SoftwareDistribution.OLD.
    3. Start the Windows Update service.
    4. Run wuauclt /resetauthorization /detectnow and observe the results. If the issue is resolved, copy the ReportingEvents.log from SoftwareDistribution.OLD back to the new SoftwareDistribution.

    If the issue is not resolved, post that detection event for further analysis.


    Lawrence Garvin, M.S., MCSA, MCITP:EA, MCDBA
    SolarWinds Head Geek
    Microsoft MVP - Software Packaging, Deployment & Servicing (2005-2014)
    My MVP Profile: http://mvp.microsoft.com/en-us/mvp/Lawrence%20R%20Garvin-32101
    http://www.solarwinds.com/gotmicrosoft
    The views expressed on this post are mine and do not necessarily reflect the views of SolarWinds.

    Wednesday, May 7, 2014 9:30 PM
  • Thank you Lawrence.

    I also suspect network related issue, I tried renaming software distribution folder followed by service start - however, it did not help.

    Let me verify the network settings are correct and post which I will be doing steps you suggested above and post my feedback.

    Thanks once again..

    Thursday, May 8, 2014 3:48 AM
  • Thanks Lawrence!

    Issue was with Proxy - we bypass it and it started working...

    Friday, May 9, 2014 9:00 AM
  • Issue was with Proxy - we bypass it and it started working...

    That'll do it every time!... :-)

    Although most interesting that the proxy server did not respond with the appropriate proxy server related error.


    Lawrence Garvin, M.S., MCSA, MCITP:EA, MCDBA
    SolarWinds Head Geek
    Microsoft MVP - Software Packaging, Deployment & Servicing (2005-2014)
    My MVP Profile: http://mvp.microsoft.com/en-us/mvp/Lawrence%20R%20Garvin-32101
    http://www.solarwinds.com/gotmicrosoft
    The views expressed on this post are mine and do not necessarily reflect the views of SolarWinds.

    Saturday, May 10, 2014 12:44 AM