WSUS Sync failure

Anonymous
2021-02-07T07:17:51+00:00

SBS2011
WSUS 3.2.7600.226

WSUS sync has started to fail over the last few weeks, initially intermittentl, now I cannot get it to complete at all.
Update source is Microsoft

Console error: Unable to resolve the specified upstream server name.

“WebException: The request failed with HTTP status 404: Not Found.
at System.Web.Services.Protocols.SoapHttpClientProtocol.ReadResponse(SoapClientMessage message, WebResponse response, Stream responseStream, Boolean asyncCall)”
at System.Web.Services.Protocols.SoapHttpClientProtocol.Invoke(String methodName, Object[] parameters)
at Microsoft.UpdateServices.ServerSyncWebServices.ServerSync.ServerSyncProxy.GetAuthConfig()
at Microsoft.UpdateServices.ServerSync.ServerSyncLib.InternetGetServerAuthConfig(ServerSyncProxy proxy, WebServiceCommunicationHelper webServiceHelper)
at Microsoft.UpdateServices.ServerSync.ServerSyncLib.Authenticate(AuthorizationManager authorizationManager, Boolean checkExpiration, ServerSyncProxy proxy, Cookie cookie, WebServiceCommunicationHelper webServiceHelper)
at Microsoft.UpdateServices.ServerSync.CatalogSyncAgentCore.SyncConfigUpdatesFromUSS()
at Microsoft.UpdateServices.ServerSync.CatalogSyncAgentCore.ExecuteSyncProtocol(Boolean allowRedirect)

This seems to be the key bit of the server log

2021-02-06 07:51:26.046 UTC Info w3wp.29 ClientImplementation..ctor Initializing ClientWebService ProcessID = 18412, Process Start Time = 2/6/2021 6:17:59 AM, Product Version = 3.2.7600.325
2021-02-06 07:51:26.065 UTC Info w3wp.29 AuthorizationManager.GetUpstreamServerUriHeader Found config says USS is MU site
2021-02-06 07:51:26.362 UTC Info WsusService.18 SusService.ValidateServerCertificate CheckValidationResult Succeeds: CertOK
2021-02-06 07:51:26.366 UTC Info WsusService.18 ServerCertificateValidator.IsHostAllowedException Requested host: sws1.update.microsoft.com
2021-02-06 07:51:26.367 UTC Info WsusService.18 ServerCertificateValidator.VerifyServerCertificate SSL validation succeeded.
2021-02-06 07:51:26.546 UTC Warning WsusService.18 WebServiceCommunicationHelper.ProcessWebServiceProxyException ProcessWebServiceProxyException found Exception was WebException. Action: Retry. Exception Details: System.Net.WebException: The request failed with HTTP status 404: Not Found.

So it is connecting to sws1.update.microsoft.com, and SSL validation succeeds. It fails after that with some proxy error.

(I realise that this server should be replaced, and work is in hand to migrate to Azure.)

Any help appreciated. Have been unable to fault the installation.

Thanks

Windows for business | Windows Server | User experience | Other

47 answers

Sort by: Most helpful
  1. Sam 71 Reputation points
    2021-02-09T10:58:41.31+00:00

    Hi RitaHu-MSFT.

    I understand that 'Out-of-Support' is an important milestone, and I respect it. Microsoft can't be expected to support old things.
    In common usage, a different milestone is 'End-of-Life' - that one has another meaning altogether.
    Are you saying that because we have reached WSUS/win2008R2/SBS2011 'End-of-Support' that it's OK for WSUS to stop working?

    It looks like a change at sws1.update.microsoft.com has killed the product. It is not End-of-Support, it is End-of-Life.
    Worse still, that EoL breaks security patching for everything behind the WSUS server.

    Was this answer helpful?

    1 person found this answer helpful.
    0 comments No comments

  2. Dale S 6 Reputation points
    2021-02-09T02:28:42.547+00:00

    We're having the same issue since 2021-02-05; our last successful sync was 2021-02-04 10:45:04.327 UTC.

    WSUS Version: 3.2.7600.226
    Windows Server 2008 R2 Standard

    Our failures look like all the others in this thread. Our last successful looks like this:

    2021-02-04 10:45:04.327 UTC Info WsusService.27 ServerCertificateValidator.IsHostAllowedException Requested host: sws1.update.microsoft.com
    2021-02-04 10:45:04.327 UTC Info WsusService.27 ServerCertificateValidator.VerifyServerCertificate SSL validation succeeded.
    2021-02-04 10:45:04.592 UTC Info WsusService.27 CatalogSyncAgentCore.SyncConfigUpdatesFromUSS Category Sync: Filter: <filter SyncAnchor="2021-02-02 18:45:03.336" GetConfig="1"></filter>
    2021-02-04 10:45:05.076 UTC Info WsusService.27 CatalogSyncAgentCore.SyncConfigUpdatesFromUSS Need 182 config updates, 0 are new
    2021-02-04 10:45:05.092 UTC Info WsusService.27 CatalogSyncAgentCore.SyncConfigUpdatesFromUSS Category Sync: New Config Anchor: 2021-02-03 18:45:04.645

    Was this answer helpful?

    1 person found this answer helpful.
    0 comments No comments

  3. Adam J. Marshall 11,031 Reputation points MVP
    2021-02-08T20:22:06.13+00:00

    Was this answer helpful?

    1 person found this answer helpful.

  4. Adam J. Marshall 11,031 Reputation points MVP
    2021-02-08T20:17:35.473+00:00

    Do you have TLS1.0 enabled? If not, make sure you enable TLS1.0 and 1.1. If you recently disabled these to try to harden security on your server, this may be the reason.

    Server 2012+ supports TLS 1.2, but I don't believe Server 2008 or 2008R2 does and you have to keep old TLS ciphers open.

    Was this answer helpful?

    1 person found this answer helpful.

  5. Bob (ISI) 51 Reputation points
    2021-02-08T17:56:59.973+00:00

    When I try un-selecting all products and classifications and press OK the window turns red, not allowing it to save without anything selected. I tried changing things up on both products and classes however it still didn't work with manual sync. One thing to note when trying to step through the configuration wizard method and the Upstream server set to 'Microsoft Update' and Proxy not checked, next step is 'Start Connecting' after a couple of seconds mine comes back with 'Unable to resolve the the upstream server name and if you click on details the below is shown.

    WebException: The request failed with HTTP status 404: Not Found. at System.Web.Services.Protocols.SoapHttpClientProtocol.ReadResponse(SoapClientMessage message, WebResponse response, Stream responseStream, Boolean asyncCall) at System.Web.Services.Protocols.SoapHttpClientProtocol.Invoke(String methodName, Object[] parameters) at Microsoft.UpdateServices.ServerSyncWebServices.ServerSync.ServerSyncProxy.GetAuthConfig() at..

    Was this answer helpful?

    1 person found this answer helpful.
    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.