我已经在 Windows server 2012 R2 上安装了 WSUS,并通过组策略配置了工作站和客户端,以从 WSUS 自动安装更新。这些服务器由 WSUS 检测并报告给 WSUS 服务器。在 WSUS 服务器中,我可以看到服务器缺少 53 个更新。我昨天为包含服务器的计算机组批准了这些更新。但是,如果我在服务器上搜索更新,它不会找到任何更新。到目前为止我检查过的内容:
- WSUS 服务器检测到服务器
- 服务器正在联系 WSUS 服务器并向其报告
- 已批准包含服务器的计算机组所需的更新(计算机组的名称:“Prod_01”)
- GPO 应用正确
- 多次尝试这些命令没有任何影响: wuauclt /resetauthorization /detectnow /reportnow
如果我查看 windowsupdate.log 我可以看到以下内容:
2015-01-06 08:34:36:715 12 1508 Setup Checking for agent SelfUpdate
2015-01-06 08:34:36:808 12 1508 Setup Client version: Core: 7.6.7600.320 Aux: 7.6.7600.320
2015-01-06 08:34:36:824 12 1508 Misc Validating signature for C:\Windows\SoftwareDistribution\SelfUpdate\wuident.cab with dwProvFlags 0x00000080:
2015-01-06 08:34:36:840 12 1508 Misc Microsoft signed: NA
2015-01-06 08:34:36:840 12 1508 Misc WARNING: Cab does not contain correct inner CAB file.
2015-01-06 08:34:36:840 12 1508 Misc Validating signature for C:\Windows\SoftwareDistribution\SelfUpdate\wuident.cab with dwProvFlags 0x00000080:
2015-01-06 08:34:36:855 12 1508 Misc Microsoft signed: NA
2015-01-06 08:34:36:855 12 1508 Setup Wuident for the managed service is valid but not quorum-signed. Skipping selfupdate.
2015-01-06 08:34:36:855 12 1508 Setup Skipping SelfUpdate check based on the /SKIP directive in wuident
2015-01-06 08:34:36:855 12 1508 Setup SelfUpdate check completed. SelfUpdate is NOT required.
2015-01-06 08:34:38:462 12 1508 PT +++++++++++ PT: Synchronizing server updates +++++++++++
2015-01-06 08:34:38:462 12 1508 PT + ServiceId = {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}, Server URL = http://wsus.schule.local:8530/ClientWebService/client.asmx
2015-01-06 08:34:38:571 12 1508 PT WARNING: Cached cookie has expired or new PID is available
2015-01-06 08:34:38:571 12 1508 PT Initializing simple targeting cookie, clientId = 0c4aed4f-6c60-46a0-b29b-f2080ea315c1, target group = , DNS name = wsus-server
2015-01-06 08:34:38:571 12 1508 PT Server URL = http://wsus.schule.local:8530/SimpleAuthWebService/SimpleAuth.asmx
2015-01-06 08:34:53:844 12 1508 Agent * Found 0 updates and 76 categories in search; evaluated appl. rules of 699 out of 1392 deployed entities
2015-01-06 08:34:53:844 12 1508 Agent *********
2015-01-06 08:34:53:844 12 1508 Agent ** END ** Agent: Finding updates [CallerId = AutomaticUpdates]
2015-01-06 08:34:53:844 12 1508 Agent *************
2015-01-06 08:34:53:859 12 16b4 AU >>## RESUMED ## AU: Search for updates [CallId = {95840C02-E405-419D-9DA4-260BC14AA845}]
2015-01-06 08:34:53:859 12 16b4 AU # 0 updates detected
2015-01-06 08:34:53:875 12 16b4 AU #########
2015-01-06 08:34:53:875 12 16b4 AU ## END ## AU: Search for updates [CallId = {95840C02-E405-419D-9DA4-260BC14AA845}]
2015-01-06 08:34:53:875 12 16b4 AU #############
2015-01-06 08:34:53:875 12 16b4 AU Successfully wrote event for AU health state:0
2015-01-06 08:34:53:875 12 16b4 AU Featured notifications is disabled.
2015-01-06 08:34:53:875 12 16b4 AU AU setting next detection timeout to 2015-01-06 10:20:45
2015-01-06 08:34:53:875 12 16b4 AU Setting AU scheduled install time to 2015-01-11 01:00:00
2015-01-06 08:34:53:875 12 16b4 AU Successfully wrote event for AU health state:0
2015-01-06 08:34:53:875 12 16b4 AU Successfully wrote event for AU health state:0
2015-01-06 08:34:58:851 12 1508 Report REPORT EVENT: {73BBAB28-58E9-45AC-B910-731F8958C456} 2015-01-06 08:34:53:844+0100 1 147 101 {00000000-0000-0000-0000-000000000000} 0 0 AutomaticUpdates Success Software Synchronization Windows Update Client successfully detected 0 updates.
在第 12 行,我可以看到客户端正在连接到正确的 WSUS 服务器,但在第 14 行,“目标组”是空的,应该是“Prod_01”。那么任何人都可以解释我做错了什么或者为什么目标组现在至少 24 小时没有更新?
当我看到 cookie 警告时,请按照那里的步骤重新同步;http://support.microsoft.com/kb/903262(克隆机?)
引用自知识库;
又过了一天,我能够“解决”这个问题,但老实说,这并不是真正的问题。WSUS 服务器仍在下载更新,如果尚未下载,客户端将无法识别更新。现在一切正常。
无论如何感谢您的贡献。
根据我的经验,WSUS 客户端需要一段时间才能检测到更改,但恕我直言,它应该在 25 小时内检测到它们。
你可以试试:
wuauclt /resetauthorization /detectnow
这应该会说服服务器再次下载其配置,这有望使服务器检测到更新。