80244019 : Scan Failure on Workgroup Server Client in DMZ - WSUS Server

Folks

Scenario -   Workgroup Server, 2012 R2.  in DMZ and is the download server for SCCM 2012.  Downloads via Proxy Server.

All functions of SCCM Software Updates work 100%.  

There are other clients in the same DMZ that work 100% all with same subnet 

WSUS server is single NIC - VLAN 2 for all traffic  

The other servers are dual NIC.  VLAN 1 for WWW and VLAN 2 for "internal" 

SCCM Agent functions on this WSUS download server work, EXCEPT this error.

Here are excerpts from the two main logs on the client- IPs and servername removed

WUAHandler.log

OnSearchComplete - Failed to end search job. Error = 0x80244019.           WUAHandler     24/08/2015 07:56:27                8416 (0x20E0)

Scan failed with error = 0x80244019.        WUAHandler     24/08/2015 07:56:27        8416 (0x20E0)

Its a WSUS Update Source type ({90DDADC3-E8CB-4B71-9C3E-CE0F7F1E4646}), adding it.              WUAHandler                24/08/2015 07:56:28        8416 (0x20E0)

Existing WUA Managed server was already set (http://SCCM and SUP server:8530), skipping Group Policy registration.       WUAHandler     24/08/2015 07:56:28        8416 (0x20E0)

Added Update Source ({90DDADC3-E8CB-4B71-9C3E-CE0F7F1E4646}) of content type: 2                WUAHandler                24/08/2015 07:56:28        8416 (0x20E0)

Scan results will include all superseded updates.               WUAHandler     24/08/2015 07:56:28        8416 (0x20E0)

Search Criteria is (DeploymentAction=* AND Type='Software') OR (DeploymentAction=* AND Type='Driver')                WUAHandler     24/08/2015 07:56:28        8416 (0x20E0)

Async searching of updates using WUAgent started.       WUAHandler     24/08/2015 07:56:28        8416 (0x20E0)

Async searching completed.       WUAHandler     24/08/2015 07:56:29        5020 (0x139C)

OnSearchComplete - Failed to end search job. Error = 0x80244019.           WUAHandler     24/08/2015 07:56:29                8416 (0x20E0)

Scan failed with error = 0x80244019.        WUAHandler     24/08/2015 07:56:29        8416 (0x20E0)

WindowsUpdate.Log

2015-08-24          05:56:32:583       856        10a8       WS         WARNING: Nws Failure: errorCode=0x803d000d

2015-08-24          05:56:32:584       856        10a8       WS         WARNING: Error string with resource id '0x6A' is not found for the language id '0x809'.

2015-08-24          05:56:32:584       856        10a8       WS         WARNING: MapToSusHResult mapped Nws error 0x803d000d to 0x80244019

2015-08-24          05:56:32:584       856        10a8       WS         WARNING: Web service call failed with hr = 80244019.

2015-08-24          05:56:32:584       856        10a8       WS         WARNING: Current service auth scheme='None'.

2015-08-24          05:56:32:584       856        10a8       WS         WARNING: Proxy List used: proxy IP removed, Bypass List used: '(null)', Last Proxy used: proxy IP removed, Last auth Schemes used: 'None'.

2015-08-24          05:56:32:584       856        10a8       WS         FATAL: OnCallFailure failed with hr=0X80244019

2015-08-24          05:56:32:584       856        10a8       WS         FATAL: NwsCallWithRetries<Functor>( Functor(_clientId, _targetGroupName, _dnsName, &_result)) failed with hr=0x80244019

2015-08-24          05:56:32:584       856        10a8       IdleTmr WU operation (CAuthorizationCookieWrapper::InitializeSimpleTargetingCookie, operation # 9) stopped; does use network; is at background priority

2015-08-24          05:56:32:584       856        10a8       PT           WARNING: Failed to initialize Simple Targeting Cookie: 0x80244019

2015-08-24          05:56:32:584       856        10a8       PT           WARNING: PopulateAuthCookies failed: 0x80244019

2015-08-24          05:56:32:584       856        10a8       PT           WARNING: RefreshCookie failed: 0x80244019

2015-08-24          05:56:32:584       856        10a8       PT           WARNING: RefreshPTState failed: 0x80244019

and HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate   is the correct SCCM/SUP server

Have re-installed SCCM agent still have problem.

August 24th, 2015 7:48am

Hi,

Please try the following steps.

  1.  Make sure that the "Windows Update" service is stopped
  2.  Rename/delete the folder C:\Windows\SoftwareDistribution
  3.  Check for updates

For more information:http://answers.microsoft.com/en-us/windows/forum/windows8_1-update/httpsfe2updatemicrosoftcomv6simpleauthwebservicesi/2a298c0a-a7c9-456e-a1af-42998699033d?auth=1

Free Windows Admin Tool Kit Click here and download it now
August 25th, 2015 5:48am

Hi Joyce

sorry that has made no difference.

Same errors, exactly

August 25th, 2015 6:50am

Hi,

Have you checked WSUS's IIS logs? Please check if the client request is received by WSUS. If it is not received by WSUS, you may need to capture the network traffic on the client.

Free Windows Admin Tool Kit Click here and download it now
August 27th, 2015 1:45am

80244019 is same as HTTP status 404 ...

Check "HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU\UseWUServer" and see if it set to use WU server....

if it is check to see firewall rule....

August 27th, 2015 10:53am

Hi Joyce,

I assume you mean the IIS logs on the SCCM server ?  

Although this is a WSUS server, it is used only for downloads for  SCCM.  Due to security requirements  it has to be a workgroup server. 

EDIT - UPDATE

OK there are three folders in the ....\inetpub\logs\LogFiles\  ... I can see by the entries that the first two are SCCM due to the IP addres:port no  on each line entry,  and the third folder must be WSUS/SUP - for the same reasons   ie  IP:8530

I can confirm there are NO entries in the third log for the WSUS server  but there are for other servers on the same subnet.

There are entries for the WSUS server in the "SCCM" IIS logs - so the normal agent is working OK as we already thought

I can also confirm that the WSUS server can see the SCCM server on 8530. 

and that WSUS on the SCCM server synchronises with the WSUS download server OK over 8530 

Solutions Architect








Free Windows Admin Tool Kit Click here and download it now
September 2nd, 2015 8:29am

Hi Kanojia

the reg settings are OK as I stated in my original post

Firewalls are OK as there are other clients in the same DMZ all working and all local windows firewall is di

September 2nd, 2015 8:31am

Hi Joyce,

I assume you mean the IIS logs on the SCCM server ?  

Although this is a WSUS server, it is used only for downloads for  SCCM.  Due to security requirements  it has to be a workgroup server. 

EDIT - UPDATE

OK there are three folders in the ....\inetpub\logs\LogFiles\  ... I can see by the entries that the first two are SCCM due to the IP addres:port no  on each line entry,  and the third folder must be WSUS/SUP - for the same reasons   ie  IP:8530

I can confirm there are NO entries in the third log for the WSUS server  but there are for other servers on the same subnet.

There are entries for the WSUS server in the "SCCM" IIS logs - so the normal agent is working OK as we already thought

I can also confirm that the WSUS server can see the SCCM server on 8530. 

and that WSUS on the SCCM server synchronises with the WSUS download server OK over 8530 

Solutions Architect








  • Edited by Nick Bassett Wednesday, September 02, 2015 1:04 PM
Free Windows Admin Tool Kit Click here and download it now
September 2nd, 2015 12:26pm

OK folks - I've fixed it, or at least found the problem.

WINHttp was set to use the proxy when testing some download issues, it hadnt been reset.  

WUA now works, and WSUS is still synchronising with MS Upates

thanks for your time :)

September 3rd, 2015 12:17pm

This topic is archived. No further replies will be accepted.

Other recent topics Other recent topics