This project has moved and is read-only. For the latest updates, please go here.

[Solved] Error while trying to deploy updates

Topics: Configuration Issue
May 28, 2014 at 2:34 PM
I have followed all guides setup software deployments etc. & everything seems good until i start to deploy any updates to the client machines. I get an error 'Failed to copy this file'. I can confirm the windows Firewall service is disabled on both the target machine and server and there is no corporate firewall between the machine and the server.
May 28, 2014 at 2:58 PM
Pls tell us step by step what you are doing.

Did you got the error if you are click on publish the update or before or after or on the client?
May 28, 2014 at 3:17 PM
The updates as far as i can tell are published successfully and seemed to be approved ok when i carried out the action to approve to the relevant machine groups.
I noticed that the updates were showing as failed when checking the report even though the clients were online and scheduled to get the updates today.

The operation that reports the error is as follows:
Under updates for flash i navigate to the relevant update for Flash Plugin, in right hand window I select the status tab, find a machine that is online (a colleague next to me) the status shows as failed. I right click the machine and select install this update, the wizard appears and at that point i get Failed to copy this file error. If required i can provide screenshots etc. thanks
May 28, 2014 at 5:07 PM
Mewes wrote:
The updates as far as i can tell are published successfully and seemed to be approved ok when i carried out the action to approve to the relevant machine groups.
I noticed that the updates were showing as failed when checking the report even though the clients were online and scheduled to get the updates today.
Try on a machine to run windows update and try to install the published update. If it fail, look in %windir%\WindowsUpdate.log for error messages.
The operation that reports the error is as follows:
Under updates for flash i navigate to the relevant update for Flash Plugin, in right hand window I select the status tab, find a machine that is online (a colleague next > to me) the status shows as failed. I right click the machine and select install this update, the wizard appears and at that point i get Failed to copy this file error. If > required i can provide screenshots etc. thanks
Did you use the MSI from the flash player from adobe or are you using the exe?
May 28, 2014 at 8:04 PM
Hi, there is two problems here :
  • First, updates didn't install on clients computers. This can be due to certificate issue. Please, on a client computer that didin't install updates, go to C:\Windows\ and open the file WindowsUpdate.log. Look for error message (or copy/paste the last update session here)
  • Second, you can't use the option "install this update". The error message can mean that you don't have administrative privileges on remote computer. Which credential are you using to run WPP ? Do you have specified credentials in the Tools - >Settings -> Authentifiaction settings ?
May 29, 2014 at 9:36 AM
To answer the questions posted.

I used the Catalog function to get updates from Adobe then imported them into the Publishing Software, to be honest i am not quite sure how this pulls in the install files best guess would be it uses the MSI although i cannot be sure, i will check and get back to you.

I didnt use the certificate funtion as our domain doesn't completely use these at present although we are planning to lock everything down to certificates using the CA very soon as part of a major overhaul.

following is the update log from a failed client.

2014-05-29 08:43:48:206 1080 11e0 DnldMgr ** START ** DnldMgr: Downloading updates [CallerId = AutomaticUpdates]
2014-05-29 08:43:48:206 1080 11e0 DnldMgr *********
2014-05-29 08:43:48:206 1080 11e0 DnldMgr * Call ID = {9FC73A8B-9516-4FF9-A807-25E952C5FF32}
2014-05-29 08:43:48:206 1080 11e0 DnldMgr * Priority = 2, Interactive = 0, Owner is system = 1, Explicit proxy = 0, Proxy session id = -1, ServiceId = {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
2014-05-29 08:43:48:206 1080 11e0 DnldMgr * Updates to download = 1
2014-05-29 08:43:48:206 1080 11e0 Agent * Title = Adobe Flash Player 32-bit/64-bit ActiveX 13.0.0.214
2014-05-29 08:43:48:206 1080 11e0 Agent * UpdateId = {F2A02435-7F3A-4C84-A399-80CC4603CBBD}.1
2014-05-29 08:43:48:206 1080 11e0 DnldMgr *********** DnldMgr: New download job [UpdateId = {F2A02435-7F3A-4C84-A399-80CC4603CBBD}.1] ***********
2014-05-29 08:43:48:206 1080 11e0 DnldMgr * Queueing update for download handler request generation.
2014-05-29 08:43:48:206 1080 11e0 DnldMgr Generating download request for update {F2A02435-7F3A-4C84-A399-80CC4603CBBD}.1
2014-05-29 08:43:48:268 1080 11e0 DnldMgr *********** DnldMgr: New download job [UpdateId = {F2A02435-7F3A-4C84-A399-80CC4603CBBD}.1] ***********
2014-05-29 08:43:48:362 1080 11e0 DnldMgr * BITS job initialized, JobId = {A66AE67E-BCCD-426C-944A-15D8E1A2C73B}
2014-05-29 08:43:48:518 1080 11e0 DnldMgr * Downloading from http://xxxxxxxxxx.xxxxx.xxxxxxxxx.xxx.xx/Content/D8/C5D1D3E245C7358B811E0A515044496F22A891D8.cab to C:\Windows\SoftwareDistribution\Download\70901396e80ca9466a79b3ec2033eb1d\80d68140-00e9-4e71-bf93-6bab756a8aad_1.cab (full file).
2014-05-29 08:43:48:642 1080 11e0 Agent *********
2014-05-29 08:43:48:642 1080 11e0 Agent ** END ** Agent: Downloading updates [CallerId = AutomaticUpdates]
2014-05-29 08:43:48:642 1080 11e0 Agent *************
2014-05-29 08:43:52:388 1080 11e0 Report REPORT EVENT: {8FBB38EC-D604-47EA-BC88-7FCF3F5970BB} 2014-05-29 08:43:47:379+0100 1 147 101 {00000000-0000-0000-0000-000000000000} 0 0 AutomaticUpdates Success Software Synchronization Windows Update Client successfully detected 1 updates.
2014-05-29 08:43:52:388 1080 11e0 Report REPORT EVENT: {422E64A5-853F-4B65-8F77-F73B4CF2335C} 2014-05-29 08:43:47:379+0100 1 156 101 {00000000-0000-0000-0000-000000000000} 0 0 AutomaticUpdates Success Pre-Deployment Check Reporting client status.
2014-05-29 08:43:52:388 1080 11e0 Report CWERReporter finishing event handling. (00000000)
2014-05-29 08:44:02:482 1080 16e0 AU Windows Update is disabled by policy for user
2014-05-29 08:44:02:482 1080 16e0 AU WARNING: AU found no suitable session to launch client in
2014-05-29 08:44:05:961 1080 1308 DnldMgr BITS job {A66AE67E-BCCD-426C-944A-15D8E1A2C73B} completed successfully
2014-05-29 08:44:06:086 1080 1308 Misc Validating signature for C:\Windows\SoftwareDistribution\Download\70901396e80ca9466a79b3ec2033eb1d\80d68140-00e9-4e71-bf93-6bab756a8aad_1.cab:
2014-05-29 08:44:06:164 1080 1308 Misc WARNING: Error: 0x800b0109 when verifying trust for C:\Windows\SoftwareDistribution\Download\70901396e80ca9466a79b3ec2033eb1d\80d68140-00e9-4e71-bf93-6bab756a8aad_1.cab
2014-05-29 08:44:06:164 1080 1308 Misc WARNING: Digital Signatures on file C:\Windows\SoftwareDistribution\Download\70901396e80ca9466a79b3ec2033eb1d\80d68140-00e9-4e71-bf93-6bab756a8aad_1.cab are not trusted: Error 0x800b0109
2014-05-29 08:44:06:164 1080 1308 DnldMgr WARNING: File failed postprocessing, error = 800b0109
2014-05-29 08:44:06:164 1080 1308 DnldMgr Failed file: URL = 'http://xxxxxxxxxx.xxxxx.xxxxxxxxx.xxx.xx/Content/D8/C5D1D3E245C7358B811E0A515044496F22A891D8.cab', Local path = 'C:\Windows\SoftwareDistribution\Download\70901396e80ca9466a79b3ec2033eb1d\80d68140-00e9-4e71-bf93-6bab756a8aad_1.cab'
2014-05-29 08:44:06:164 1080 1308 DnldMgr Error 0x800b0109 occurred while downloading update; notifying dependent calls.
2014-05-29 08:44:06:288 1080 1524 AU >>## RESUMED ## AU: Download update [UpdateId = {F2A02435-7F3A-4C84-A399-80CC4603CBBD}]
2014-05-29 08:44:06:288 1080 1524 AU # WARNING: Download failed, error = 0x800B0109
2014-05-29 08:44:06:288 1080 1524 AU #########
2014-05-29 08:44:06:288 1080 1524 AU ## END ## AU: Download updates
2014-05-29 08:44:06:288 1080 1524 AU #############
May 29, 2014 at 10:16 AM
You have to create a certificate and publish the certificate to all clients/Servers. Without certificate = no 3rd Party Updates publishing to clients/servers.


WARNING: Digital Signatures on file C:\Windows\SoftwareDistribution\Download\70901396e80ca9466a79b3ec2033eb1d\80d68140-00e9-4e71-bf93-6bab756a8aad_1.cab are not trusted: Error 0x800b0109
May 29, 2014 at 10:48 AM
Ok. As this is a domain based machine should i generate a Code Signing Certificate from the software? I can confirm that we have no Code Signing Certificate on the domain at present.

If this is the case i will follow the instructions for generation of the Code Signing Certificate, restart the WSUS server, add it to the MMC Certificates area then publish it via GPO to the client machines, i will test again tomorrow once the GPOs are fully deployed and then advise of the results.

Thanks for the help.
May 29, 2014 at 1:32 PM
Hi, as Adobe Flash Player has been successfuly publish into your Wsus server, this mean that there is already a code signin certificate on the Wsus server.
The certificate of the root authority has to be distribute to client computers. Client computers has to be enable to trust 3rd party Publisher :
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AcceptTrustedPublisherCerts should be set to 1
There is a GPO for this.
Marked as answer by DCourtel on 5/29/2014 at 8:53 AM
May 29, 2014 at 2:25 PM
Thanks for all the help. I have regenerated the cert, added it to the mmc on the wsus box, amended all the relevant GPOs (Certificate & 3rd party parts) for WSUS as required per guide, i can now see the update in windows update on my client machine for Adboe Reader and from the sub menu on the software for pending updates (flash player is already up to date on my machine) When i try to install the update it would appear to download it ok but it fails on my client machine at this point.

We have WSUS set for scheduled updates via GPOs at specific times for specific machine OUs etc and mine is one of those that are fixed for a Wednesday only. Would this be problem? The log would show that the update is set to install on the 4th June (Wednesday next week) I have included the log below from the latest attempt at the install.

2014-05-29 14:14:23:765 1284 ab0 AU #############
2014-05-29 14:14:23:765 1284 ab0 AU ## START ## AU: Search for updates
2014-05-29 14:14:23:765 1284 ab0 AU #########
2014-05-29 14:14:23:765 1284 ab0 AU <<## SUBMITTED ## AU: Search for updates [CallId = {8CA12A9B-D7D7-4A38-B01C-9C076983CD62}]
2014-05-29 14:14:23:765 1284 122c Agent *************
2014-05-29 14:14:23:765 1284 122c Agent ** START ** Agent: Finding updates [CallerId = AutomaticUpdates]
2014-05-29 14:14:23:765 1284 122c Agent *********
2014-05-29 14:14:23:765 1284 122c Agent * Online = No; Ignore download priority = No
2014-05-29 14:14:23:765 1284 122c Agent * Criteria = "IsInstalled=0 and DeploymentAction='Installation' or IsPresent=1 and DeploymentAction='Uninstallation' or IsInstalled=1 and DeploymentAction='Installation' and RebootRequired=1 or IsInstalled=0 and DeploymentAction='Uninstallation' and RebootRequired=1"
2014-05-29 14:14:23:765 1284 122c Agent * ServiceID = {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7} Managed
2014-05-29 14:14:23:765 1284 122c Agent * Search Scope = {Machine}
2014-05-29 14:14:26:682 1284 122c Agent * Added update {C011BB2D-536F-40CF-92EA-EF51C754B8C5}.1 to search result
2014-05-29 14:14:26:682 1284 122c Agent * Found 1 updates and 82 categories in search; evaluated appl. rules of 512 out of 1605 deployed entities
2014-05-29 14:14:26:682 1284 122c Agent *********
2014-05-29 14:14:26:682 1284 122c Agent ** END ** Agent: Finding updates [CallerId = AutomaticUpdates]
2014-05-29 14:14:26:682 1284 122c Agent *************
2014-05-29 14:14:26:698 1284 1b08 AU >>## RESUMED ## AU: Search for updates [CallId = {8CA12A9B-D7D7-4A38-B01C-9C076983CD62}]
2014-05-29 14:14:26:698 1284 1b08 AU # 1 updates detected
2014-05-29 14:14:26:698 1284 1b08 AU #########
2014-05-29 14:14:26:698 1284 1b08 AU ## END ## AU: Search for updates [CallId = {8CA12A9B-D7D7-4A38-B01C-9C076983CD62}]
2014-05-29 14:14:26:698 1284 1b08 AU #############
2014-05-29 14:14:26:698 1284 1b08 AU Featured notifications is disabled.
2014-05-29 14:14:26:698 1284 1b08 AU Setting AU scheduled install time to 2014-06-04 09:00:00
2014-05-29 14:14:26:698 1284 1b08 AU Successfully wrote event for AU health state:0
2014-05-29 14:14:26:698 1284 122c Report REPORT EVENT: {EDB048EC-7AAD-42FF-A106-7192BB692E25} 2014-05-29 14:14:21:737+0100 1 161 101 {C011BB2D-536F-40CF-92EA-EF51C754B8C5} 1 800b0109 AutomaticUpdatesWuApp Failure Content Download Error: Download failed.
2014-05-29 14:14:26:698 1284 1b08 AU Successfully wrote event for AU health state:0
2014-05-29 14:14:26:698 1284 c1c AU Getting featured update notifications. fIncludeDismissed = true
2014-05-29 14:14:26:698 1284 c1c AU No featured updates available.
2014-05-29 14:14:26:714 1284 122c Report CWERReporter::HandleEvents - WER report upload completed with status 0x8
2014-05-29 14:14:26:714 1284 122c Report WER Report sent: 7.6.7600.256 0x800b0109 C011BB2D-536F-40CF-92EA-EF51C754B8C5 Download 101 Managed
2014-05-29 14:14:26:714 1284 122c Report CWERReporter finishing event handling. (00000000)
2014-05-29 14:14:31:706 1284 122c Report CWERReporter finishing event handling. (00000000)
May 29, 2014 at 3:06 PM
Did you sign the package with the current certificate?

Is the current certificate on the client in the two certificates stores? Did you set the registry key which David was posted?
May 29, 2014 at 3:32 PM
The relevant entries are all set via a GPOs and after an gpupdate / force the reg entry is now at 1 & the certificates are showing in the correct certificate stores on the client machine i.e. Public Key Policies/Trusted Root Certification Authorities & Public Key Policies/Trusted Publishers Certificates

I have rebooted client machine since just to be on safe side.

The packages to distribute were setup before i re-generated the certificate on the WSUS server using the software, so this sounds like it will be the problem. Do i have to remove all the Adobe updates and set them up again to sign the package? Or is there another of doing this?
May 29, 2014 at 3:51 PM
Edited May 29, 2014 at 3:52 PM
I have used the resign function on all updates and they are distributing to the client machine. Thank you very much for all your help with this it has been very helpful and very much appreciated.
May 29, 2014 at 4:53 PM
Each time you change the certificate, you need to resign already published package.