Updates not applying to 2012 servers
Hi guys,
Our ConfigMgr server is 2012R2 with SUP.
I have noticed that our 2012 servers are not applying updates.
Checking in the WindowsUpdate.log for these servers I can see the following:
WARNING: Failed to get Wu Exemption info from NLM, assuming not exempt, error = 0x80240037
Checking online and most are suggesting installing a WSUS update – KB2734608 But our WSUS is v6.2 and I do not believe this update is applicable.
The UpdatesDeployment.log shows this (but no actual errors): No current service window available to run updates assignment with time required = 1 Attempting to install 0 updates
I have confirmed the maintenance windows for the servers via the built in report.
Any help getting these servers patched would be greatly appreciated.
Edit: SCEP updates are being applied ok.
Regards,
Locust12
The errors are spread through the file, I have copied a few repeating ones here and linked the full file via Dropbox.
WARNING: WU client failed Searching for update with error 0x80248014
WARNING: Exit code = 0x00000000, Result code = 0x80248014
COMAPI WARNING: Operation failed due to earlier error, hr=80248014
REPORT EVENT: {32898FA6-A6CE-4B10-ABA0-8D43666E9B3A} 2015-01-11 13:04:34:392+1100 1 148 [AGENT_DETECTION_FAILED] 101 {00000000-0000-0000-0000-000000000000}
0 80248014 System Center Endpoint Protection (DDEFDD14-250E-4DC8-A0B3-9D667EC5D8EB) Failure Software Synchronization Windows Update Client failed to detect with
error 0x80248014.
WARNING: Failed to get service object: 80248014
WARNING: Network Cost is assumed to be not supported as something failed with trying to get handles to wcmapi.dll
WARNING: IsSessionRemote: WinStationQueryInformationW(WTSIsRemoteSession) failed for session 1, GetLastError=2250
https://dl.dropboxusercontent.com/u/32055319/WindowsUpdateEdited.log
Regards,
Locust12
Similar Messages
-
ZCM 11 Group Policies not applying to satellite servers
Hi there
We are running 2 Windows 2012 Primary Servers and a SQL 2012 Database server at our main site, all remote sites have SLES11 SP2/OES11 SP1 as satellite servers. We upgraded all servers last weekend to 11.3.1 and now have an issue with Group Policies applying to the satellites. The satellites are all set up the same with Authentication, Collection, Content and Imaging roles.
Since we upgraded Group Policies are (99% of the time) not applying on satellite sites. I have tried manually replicating content (I assume policies will come from content replication?) to the satellites - I've done this with a zac cdp replicate and zac cvc and everything seems to replicate over however I tried highlighting a satellite server and clicking on Action, Specify Content - select the Policy that is not applying and move it into the selected Content to update column and when I click finish I get the error "The Wizard cannot continue for the following reason(s): Unable to complete your request for the following reason: Error updating content"
On a managed device at the satellite site if you look at the properties of the Zenworks agent and click on Policies it has applied 4 device assigned policies successfully - Remote Management, Power Management, Application Launcher Config and Application Control Policy, also has successfully applied 3 out of the 4 User Assigned Policies - Mandatory Profile, Dynamic Local User, Application Control - but not the Windows Group Policy.
Our PCs are on Windows 8.1 and all policies were applying fine before the weekend upgrade......
Has anyone else had any experience of Group Policies not applying that could point me where to look? I have logged an SR with Novell through our reseller but as yet I am getting no response back at all, not even asking me for more information.
Many thanks
SharonSounds like you have a content replication issue more than a GPO issue.
Especially if the GPO works for locations that point to the Primaries
for Content.
Do you have throttling configured anywhere in any fashion?
You may need to increase the Replication Timeout to make sure content is
getting over to the Sats. Often increasing from 60 to 240 helps, but
watch out for throttling preventing content replication.
It is possible things are backing up.
On 7/31/2014 8:26 AM, shazzypoos wrote:
>
> I should add that when you looked at the "Click for Details" to the
> right of the Effective "Failed" status the message is "Policy
> Enforcement Failed : The action (0) threw an exception. Message (1).
> Exception (2) (grouppolicy, "None of the source locations could be
> found"
>
> Hmmmm! Currently in closest server rules there is only the server for
> the site it's on set - we do not want it to come back to the Primary for
> policies. As I say, this was working before the weekend upgrade. Thanks!
>
>
Craig Wilson - MCNE, MCSE, CCNA
Novell Technical Support Engineer
Novell does not officially monitor these forums.
Suggestions/Opinions/Statements made by me are solely my own.
These thoughts may not be shared by either Novell or any rational human. -
Default Domain Policy Not Applying Settings to Servers or Clients
I have 2008 R2 DC's with a functioning level of 2003. Our domain servers are a mix of 2003, 2008, 2008 R2, and 2012 and our clients are a mix of Windows 7 Pro and Windows 8.1 Pro.
I recently made a change to the Default Domain Policy located at Computer Configuration -> Policies -> Windows Settings -> Security Settings -> Local Policies -> Security Options
For the Security Policy setting called: Network security: Configure encryption types allowed for Kerberos
The change was to enable DES because of a specific need that I have with an application that I work with but enabling DES and leaving the other options such AES unselected caused other applications to not work right. I decided to revert the changes
back to "Not Defined" but those changes did not reflect on the servers even after running the gpupdate /force command.
In order to keep the application working that broke, we enabled all of the encryption levels such as DES, AES, etc. on the server that's running the application via it's Local Security Policy as a temporary fix.
Now, I want to make sure all servers receive the settings from the Default Domain Policy and have their Local Security Policies reflect the "Not Defined" setting but it's not applying. It seems like they worked when I first applied them but
when I try to remove them it does not work.
If I change the setting directly on the Local Security Policy on the server or clients it shows "No minimum" instead of "Not Defined" which I've heard can be fixed by identifying the registry entry for that setting and deleting it...so
help with the location and how to identify that key would also be helpful.
My goal is not to manually have to change servers and clients to revert back to their default settings...I want the Domain policy to apply and override the servers and client's Local Security Policy.
Any help with this would be greatly appreciated and thank you in advance.I have 2008 R2 DC's with a functioning level of 2003. Our domain servers are a mix of 2003, 2008, 2008 R2, and 2012 and our clients are a mix of Windows 7 Pro and Windows 8.1 Pro.
I recently made a change to the Default Domain Policy located at Computer Configuration -> Policies -> Windows Settings -> Security Settings -> Local Policies -> Security Options
For the Security Policy setting called: Network security: Configure encryption types allowed for Kerberos
refer:
http://technet.microsoft.com/en-us/library/jj852180(v=ws.10).aspx
We needed to implement a similar scenario a few years ago (when we introduced Windows7 into our estate).
We had an SAP/NetWeaver implementation which always worked on WinXP, but failed on Win7.
We had to enable the DES ciphers, since those were disabled by default in Win7. We discovered that we also needed to enable all the other ciphers (those which are enabled by default[not configured]).
i.e., when we changed the setting from "Not Configured", enabled DES, and left the RC4/AES stuff untouched by us, the RC4/AES stuff attracted a status of disabled.
So, we had to set the DES ciphers to Enabled, and, also set the RC4/AES ciphers to Enabled - this gave us the "resultant" enablement of the default stuff and the needed change/addition of DES.
When you set a GP setting "back to Not Configured", depending upon the setting *AND* the individual Windows feature itself - one of two things will happen:
a) the feature will "revert" to default behaviour
b) the feature will retain the current configured behaviour but becomes un-managed
In classic Group Policy terms, condition (b) above is often referred to as "tattooing", i.e., the last GP setting remains in effect even though GPMC/RSOP/etc does not reveal that to be the case.
(This is also a really good example of not doing this sort of stuff in the DDP. It could have borked your whole domain :)
What I'd suggest, is that you re-enable your ciphers for KRB settings again - this time, enable all the ciphers that would normally be "default", let that replicate around, and allow time for domain members to action it.
Then, set the setting back to Not Configured. This way, the "last" settings issued by GP will be those you want to remain as the "legacy".
Note: the GP settings reference s/sheet, has this to say:
Network security: Configure encryption types allowed for Kerberos
This policy setting allows you to set the encryption types that Kerberos is allowed to use.
If not selected, the encryption type will not be allowed. This setting may affect compatibility with client computers or services and applications. Multiple selections are permitted.
This policy is supported on at least Windows 7 or Windows Server 2008 R2.
Don
(Please take a moment to "Vote as Helpful" and/or "Mark as Answer", where applicable.
This helps the community, keeps the forums tidy, and recognises useful contributions. Thanks!) -
Updates not getting deployed on servers
Logs from
updatedeployment.log:
created a seprate collection and applied maintenance window to that--no luck
Used deployment option as As Soon As possible but no luck
tried option to install patches outside maintenance window--no luck
For deployment I tried existing software update group as well as new software update group but issue is still the same.
Please help me.
~VSTGuys,
This issue seems to be resolved. Not sure what was the exact issue but I am relating this to a other issue which we were facing on SCCM server. Actually CPU usage for our SCCM server was fluctuating to 100% and due to this everything was working very
slow, we added CPU cores to the server yesterday and when today I checked that all updates were pushed on the servers as I selected to patch them outside maintenance window.
Apart from that for some server the deployment status is changed to waiting for maintenance window which were stuck on
downloading updates earlier.
Can someone please let me know how the CPU usage directly affects software deployment?
Thanks,
VST -
Updating an App-v 5 package in SCCM 2012, update not applying automatically
Hello, just doing some testing of updating an App-v 5 package in SCCM. The application has been deployed and run on a client pc. I've gone back and opened the package in the sequencer and made some changes and saved it as a new package.
In SCCM I've updated the content and pointed it at the new package. That all looks fine. It's showing the new files in the content.
The application deployment settings are set to required and set to install outside maintenance windows. The client has received the update, I can see it in the software center but it's not being applied automatically.
I've waited over 12 hours so the client has also had its maintenance window but it still has not updated. I've also tried launching the application to see if that would bring in the update but still no joy.
Just wondered what experience other people have had with this?Firstly, just because you mentioned saving as a new package, if you select that option it will create a brand new v0.0.0.1 package and users settings will not transfer to the new version, so just use save or save as in most cases.
Have you tried logging the user off and on again? And if the app is published globally, rebooting?
If the application is in use, then the update will be delayed until either of these events occur, depending on how it was published. Also, if the app has certain integration points such as shell extensions or browser plugins, these can create a lock on the
package even though you don't have the application running. You can run a powershell command to stop the package and speed things up if you wish, although this runs the risk of terminating explorer.exe or iexplore.exe:
Get-AppvClientPackage *name* | Stop-AppvClientPackage (and add -global to the end if it was globally published)
Dan Gough - UK App-V MVP
Blog: packageology.com
Twitter: @packageologist
LinkedIn -
Windows 7 x64 SP1 updates not applied to image
I am having a very strange issue. After working correctly for over a year, my build and capture Windows 7 x 64 SP1 task sequence is not working. The first part of the problem is that the image will not capture on a SCVMM 2012 R2 cluster. That problem
has been mentioned in a different post and I have a call into MS.
The second issue is strange. I used my normal install.wim that had updates injected into it via SCCM offline updates. When I built the computer, it showed all updates as being needed including SP1. This same install.wim had worked perfectly
prior 9/15/14. I then did a build using just the install.wim that came with the Windows 7 SP1 iso, I had the same problem. When I go into the computer properties, it shows Windows 7 Service Pack 1 as the OS. However, if I go to Windows Updates,
it shows that SP1 is needed. I apply the update it takes about 3 minutes and it is installed.
Has anyone experienced this issue? The only major changes in the environment was moving the build and capture machine to a SCVMM 2012 R2 infrastructure that is built on Windows 2012 R2 OS. Prior to that we were using SCVMM 2008 R2 on Windows
2008 R2 OS.Hi,
I think you are running same problem as described in the following article:
http://support2.microsoft.com/kb/2894518
Updates trigger multiple boot is caused TS failing. -
Software Updates Not Applied properly
Hello,
I'm facing Software deployment Issue on SCCM 2012 R2 environment, I deployed the Definition patches for Group of 1000 machines, Some of them are failed with below Error
I have started working on the GPO issue,
Request someone to help with the rest of the Errors.I Checked the updatedeployment and handler for Error's.
<![LOG[Progress received for assignment ({0795632a-1adf-49ac-bff4-39cfdfa8b1da})]LOG]!><time="04:01:26.998-330" date="04-16-2014" component="UpdatesDeploymentAgent" context="" type="1" thread="3496" file="updatesassignment.cpp:1988">
<![LOG[Progress received for assignment ({0795632a-1adf-49ac-bff4-39cfdfa8b1da})]LOG]!><time="04:01:27.217-330" date="04-16-2014" component="UpdatesDeploymentAgent" context="" type="1" thread="3016" file="updatesassignment.cpp:1988">
<![LOG[Update (Site_508E7B21-0DA1-4AED-B1FA-03AD7D9A49DD/SUM_e666cd29-ede0-4b24-989c-40d44002f759) Progress: Status = ciStateDownloading, PercentComplete = 24, Result = 0x0]LOG]!><time="04:01:27.217-330" date="04-16-2014" component="UpdatesDeploymentAgent"
context="" type="1" thread="3016" file="updatesassignment.cpp:2031">
<![LOG[Progress received for assignment ({0795632a-1adf-49ac-bff4-39cfdfa8b1da})]LOG]!><time="04:01:31.435-330" date="04-16-2014" component="UpdatesDeploymentAgent" context="" type="1" thread="4080" file="updatesassignment.cpp:1988">
<![LOG[DownloadJob completion received for assignment ({0795632a-1adf-49ac-bff4-39cfdfa8b1da})]LOG]!><time="04:01:31.498-330" date="04-16-2014" component="UpdatesDeploymentAgent" context="" type="1" thread="4080" file="updatesassignment.cpp:2118">
<![LOG[Update (Site_508E7B21-0DA1-4AED-B1FA-03AD7D9A49DD/SUM_e666cd29-ede0-4b24-989c-40d44002f759) Name (Definition Update for Microsoft Endpoint Protection - KB2461484 (Definition 1.169.2676.0)) ArticleID (2461484) added to the targeted list of deployment
({0795632a-1adf-49ac-bff4-39cfdfa8b1da})]LOG]!><time="04:01:31.514-330" date="04-16-2014" component="UpdatesDeploymentAgent" context="" type="1" thread="4080" file="updatesmanager.cpp:420">
<![LOG[Update (Site_508E7B21-0DA1-4AED-B1FA-03AD7D9A49DD/SUM_feb1a592-9666-4a23-bfd1-8d8d971c90d8) Name (Definition Update for Microsoft Endpoint Protection - KB2461484 (Definition 1.169.2706.0)) ArticleID (2461484) added to the targeted list of deployment
({0795632a-1adf-49ac-bff4-39cfdfa8b1da})]LOG]!><time="04:01:31.514-330" date="04-16-2014" component="UpdatesDeploymentAgent" context="" type="1" thread="4080" file="updatesmanager.cpp:420">
<![LOG[CUpdateAssignmentsManager received a SERVICEWINDOWEVENT END Event]LOG]!><time="05:00:00.014-330" date="04-16-2014" component="UpdatesDeploymentAgent" context="" type="1" thread="664" file="assignmentsmanager.cpp:277">
<![LOG[No current service window available to run updates assignment with time required = 1]LOG]!><time="05:00:00.014-330" date="04-16-2014" component="UpdatesDeploymentAgent" context="" type="1" thread="664" file="deploymentutils.cpp:580">
<![LOG[Attempting to cancel any job started at non-business hours.]LOG]!><time="05:00:00.014-330" date="04-16-2014" component="UpdatesDeploymentAgent" context="" type="1" thread="664" file="assignmentsmanager.cpp:527">"
<![LOG[Enabling WUA Managed server policy to use server: http://SCCM.ABC.in:8530]LOG]!><time="09:19:31.182-330" date="04-15-2014" component="WUAHandler" context="" type="1" thread="3728" file="sourcemanager.cpp:948">
<![LOG[Failed to Add Update Source for WUAgent of type (2) and id ({508E7B21-0DA1-4AED-B1FA-03AD7D9A49DD}). Error = 0x80004005.]LOG]!><time="09:19:31.197-330" date="04-15-2014" component="WUAHandler" context="" type="3" thread="3728" file="cwuahandler.cpp:2325">
<![LOG[Its a WSUS Update Source type ({508E7B21-0DA1-4AED-B1FA-03AD7D9A49DD}), adding it.]LOG]!><time="09:29:50.735-330" date="04-15-2014" component="WUAHandler" context="" type="1" thread="2348" file="sourcemanager.cpp:1232">
<![LOG[Unable to read existing resultant WUA policy. Error = 0x80070002.]LOG]!><time="09:29:50.735-330" date="04-15-2014" component="WUAHandler" context="" type="2" thread="2348" file="sourcemanager.cpp:920">
<![LOG[Enabling WUA Managed server policy to use server: http://SCCM.ABC.in:8530]LOG]!><time="09:29:50.735-330" date="04-15-2014" component="WUAHandler" context="" type="1" thread="2348" file="sourcemanager.cpp:948">"
<![LOG[Failed to Add Update Source for WUAgent of type (2) and id ({508E7B21-0DA1-4AED-B1FA-03AD7D9A49DD}). Error = 0x80004005.]LOG]!><time="09:29:50.750-330" date="04-15-2014" component="WUAHandler" context="" type="3" thread="2348" file="cwuahandler.cpp:2325">
<![LOG[CWuaHandler::SetCategoriesForStateReportingExclusion called with E0789628-CE08-4437-BE74-2495B842F43B;E0789628-CE08-4437-BE74-2495B842F43B,A38C835C-2950-4E87-86CC-6911A52C34A3; for leaves and E0789628-CE08-4437-BE74-2495B842F43B,A38C835C-2950-4E87-86CC-6911A52C34A3;
for bundles]LOG]!><time="09:12:34.440-330" date="04-16-2014" component="WUAHandler" context="" type="1" thread="3340" file="cwuahandler.cpp:2527">
<![LOG[Its a WSUS Update Source type ({508E7B21-0DA1-4AED-B1FA-03AD7D9A49DD}), adding it.]LOG]!><time="10:02:54.925-330" date="04-16-2014" component="WUAHandler" context="" type="1" thread="5436" file="sourcemanager.cpp:1232">
<![LOG[Unable to read existing resultant WUA policy. Error = 0x80070002.]LOG]!><time="10:02:54.925-330" date="04-16-2014" component="WUAHandler" context="" type="2" thread="5436" file="sourcemanager.cpp:920">
<![LOG[Enabling WUA Managed server policy to use server: http://SCCM.ABC.in:8530]LOG]!><time="10:02:54.925-330" date="04-16-2014" component="WUAHandler" context="" type="1" thread="5436" file="sourcemanager.cpp:948">
<![LOG[Failed to Add Update Source for WUAgent of type (2) and id ({508E7B21-0DA1-4AED-B1FA-03AD7D9A49DD}). Error = 0x80004005.]LOG]!><time="10:02:54.925-330" date="04-16-2014" component="WUAHandler" context="" type="3" thread="5436" file="cwuahandler.cpp:2325">
<![LOG[Message received: '<?xml version='1.0' ?>
<CIAssignmentMessage MessageType='EnforcementDeadline'>
<AssignmentID>{0795632a-1adf-49ac-bff4-39cfdfa8b1da}</AssignmentID>
</CIAssignmentMessage>']LOG]!><time="10:02:54.643-330" date="04-16-2014" component="UpdatesDeploymentAgent" context="" type="1" thread="4216" file="cdeploymentagent.cpp:189">
<![LOG[Starting forced trigger (TriggerEnforce) for assignment {0795632a-1adf-49ac-bff4-39cfdfa8b1da}]LOG]!><time="10:02:54.643-330" date="04-16-2014" component="UpdatesDeploymentAgent" context="" type="1" thread="4388" file="updatesassignment.cpp:1056">
<![LOG[Detection job ({B58D75C1-787D-443E-86F3-90058B737D0A}) started for assignment ({0795632a-1adf-49ac-bff4-39cfdfa8b1da})]LOG]!><time="10:02:54.675-330" date="04-16-2014" component="UpdatesDeploymentAgent" context="" type="1" thread="4388" file="updatesassignment.cpp:1196">
<![LOG[Deadline received for assignment ({0795632a-1adf-49ac-bff4-39cfdfa8b1da})]LOG]!><time="10:02:54.675-330" date="04-16-2014" component="UpdatesDeploymentAgent" context="" type="1" thread="4216" file="updatesassignment.cpp:923">
<![LOG[Enforcement action already in progress]LOG]!><time="10:02:54.675-330" date="04-16-2014" component="UpdatesDeploymentAgent" context="" type="1" thread="4216" file="updatesassignment.cpp:974">
<![LOG[Job error (0x80004005) received for assignment ({0795632a-1adf-49ac-bff4-39cfdfa8b1da}) action]LOG]!><time="10:02:54.971-330" date="04-16-2014" component="UpdatesDeploymentAgent" context="" type="3" thread="5644" file="updatesassignment.cpp:2214">
<![LOG[Updates will not be made available]LOG]!><time="10:02:54.971-330" date="04-16-2014" component="UpdatesDeploymentAgent" context="" type="2" thread="5644" file="updatesassignment.cpp:2216"> -
System Center Endpoint Protection updates not applying to DirectAccess clients
Hi
I have W2008R2 SP2 with SCCM2012R2 CU3 server.
We started testing DirectAccess. All other updates (Windows, Skype, Adobe) are applying except SCEP.
Initiating policies from laptop did not helped.
DirectAccess subnet is in boundary list.
Computer account is in correct collection. SCEP only updates when laptop is on LAN.
Where to look to resolve this problem?Yes, the boundaries that you put in SCCM which specify your DirectAccess client computers must be the IP addresses they are using, which are the IPv6 addresses given to them via their DA transition technologies (6to4, Teredo, IP-HTTPS). Depending on how
you setup DirectAccess, you may only have some of these available for the clients to utilize. If your DA server is sitting behind a NAT, or if you used the "Getting Started Wizard" to setup DA, then only IP-HTTPS is available to your DA clients and
that is how they are all connecting. In that case you should only need to add the IP-HTTPS IPv6 prefix.
You can use this info to calculate the prefixes, or you can check in the SCCM agent on the client machine, I believe in the section where it shows you the heartbeat it will also show you the current prefix that your client is utilizing:
First Public IPv4=WW.XX.YY.ZZ (address on the DA server)
2001:0:WWXX:YYZZ::/64 (Teredo)
2002:WWXX:YYZZ:8100::/56 (IP-HTTPS)
2002:WWXX:YYZZ:8000::/49 (organizational prefix)
2002:WWXX:YYZZ:8000::/64 (ISATAP)
2002:WWXX:YYZZ:8001::/96 (NAT64/DNS64) -
WSUS updates not applying to Office 2013 Home and Business OEM version
Hi
For some reason I cannot get WSUS updates to automatically install on clients running Office 2013 Home and Business OEM version.
For example
If user opens any of the office 2013 apps e.g. Outlook , word etc, it prompts a message at the top under the ribbon toolbar; UPDATE NOW.
All other updates for OS are downloading and installing just fine from our WSUS server.
What could this be?
I dont have this issue with clients running office 2003First thing you need to do is be absolutely certain which edition of Office you have installed.
There are five editions of "Office 365" and these days, almost anything that is "OEM" is almost certainly Office 365:
Office 365 Home
Office 365 Personal
Office 365 Small Business
Office 365 Small Business Premium
Office 365 Midsize Business
Office 365 ships with an activation code for an online management account, and authorizes the installation of the software on up to five devices. Office 365 is updated via the WEB .. ONLY.
In addition there are three editions of Office 2013:
Office Home & Student
Office Home & Business
Office Professional
If you have one of these three editions, you should also have a DVD and a Product Activation Code for the SINGLE-PC installation which is licensed for these editions provided by the vendor of your computers. Office 2013 can be updated using WSUS.
Since you're getting a prompt IN THE APPLICATION to "Update Now", I believe you're looking at instances of Office 365, not Office 2013. Office 2013 (desktop) does not provide in-product prompts for updates/upgrades.
Lawrence Garvin, M.S., MCSA, MCITP:EA, MCDBA
SolarWinds Head Geek
Microsoft MVP - Software Packaging, Deployment & Servicing (2005-2014)
My MVP Profile: http://mvp.microsoft.com/en-us/mvp/Lawrence%20R%20Garvin-32101
http://www.solarwinds.com/gotmicrosoft
The views expressed on this post are mine and do not necessarily reflect the views of SolarWinds. -
Updates not applying: Scan failed with error = 0x80072efd.
Hi, I'm trying to troubleshoot windows updates which are configured through SCCM2012R2. The WSUS server is installed on server 2012R2, version 6.3.9600.16384. I have it running on the custom website (using ports 8530 and 8531). For
a few weeks, my clients were configured with a conflicting group policy (pointing to the old wsus server). I removed that policy, and now the sccm agent is setting the local group policy to use the proper wusus server. Clients are windows 7 enterprise.
These clients do not have access to the internet.
Now, updates are still failing, with the following events in the wuahandler.log
Its a WSUS Update Source type ({8C51EBC1-265B-4889-8CC4-0B9EF237D704}), adding it.WUAHandler 4/9/2014 4:53:09 PM 4028 (0x0FBC)
Existing WUA Managed server was already set (http://Myserver-12R2-WSUS.mydomain.local:8530), skipping Group Policy registration. WUAHandler 4/9/2014 4:53:09 PM 4028 (0x0FBC)
Added Update Source ({8C51EBC1-265B-4889-8CC4-0B9EF237D704}) of content type: 2 WUAHandler 4/9/2014 4:53:09 PM 4028 (0x0FBC)
Scan results will include superseded updates only when they are superseded by service packs and definition updates. WUAHandler 4/9/2014 4:53:09 PM 4028 (0x0FBC)
Search Criteria is (DeploymentAction=* AND Type='Software') OR (DeploymentAction=* AND Type='Driver') WUAHandler 4/9/2014 4:53:09 PM 4028 (0x0FBC)
Async searching of updates using WUAgent started. WUAHandler 4/9/2014 4:53:09 PM 4028 (0x0FBC)
Async searching completed. WUAHandler 4/9/2014 4:53:12 PM 3452 (0x0D7C)
OnSearchComplete - Failed to end search job. Error = 0x80072efd. WUAHandler 4/9/2014 4:53:12 PM 4028 (0x0FBC)
Scan failed with error = 0x80072efd. WUAHandler 4/9/2014 4:53:12 PM 4028 (0x0FBC)
For troubleshooting so far, I have disabled the client firewall, restarted the wsus server, and confirmed that the clients can get to the default IIS page on the wsus server. I'll try reinstalling the sccm client now, and will report back.
After much searching, none of the answers I have found online were of any help.
Any advice will be greatly appreciated.
Thanks,
KevinI did manage to reinstall the client, and when I look at WUAhandler.log now, I see the following:
Its a WSUS Update Source type ({8C51EBC1-265B-4889-8CC4-0B9EF237D704}), adding it. WUAHandler 4/9/2014 5:42:57 PM 3344 (0x0D10)
Unable to read existing resultant WUA policy. Error = 0x80070002. WUAHandler 4/9/2014 5:42:57 PM 3344 (0x0D10)
Enabling WUA Managed server policy to use server: http://MyServer-12R2-WSUS.Mydomain.local:8530 WUAHandler 4/9/2014 5:42:57 PM 3344 (0x0D10)
Waiting for 2 mins for Group Policy to notify of WUA policy change... WUAHandler 4/9/2014 5:42:57 PM 3344 (0x0D10)
Unable to read existing WUA resultant policy. Error = 0x80070002. WUAHandler 4/9/2014 5:43:01 PM 3344 (0x0D10)
Group policy settings were overwritten by a higher authority (Domain Controller) to: Server and Policy NOT CONFIGURED WUAHandler 4/9/2014 5:43:01 PM 3344 (0x0D10)Failed to Add Update Source for WUAgent of type (2) and id ({8C51EBC1-265B-4889-8CC4-0B9EF237D704}). Error = 0x87d00692.
So that's strange, if it's NOT CONFIGURED (microsoft's caps), you wouldn't think it would be a problem. So, If I generate a group policy results report, I get the following:
Policy:Specify intranet Microsoft update service location
Setting: Enabled
Winning GPO: Local Group Policy
Set the intranet update service for detecting updates: http://Myserver-12R2-WSUS.MyDomain.local:8530
Set the intranet statistics server: http://Myserver-12R2-WSUS.MyDomain.local:8530
Which is exactly what I think the SCCM agent is supposed to do.
Thanks in advance. Hopefully one of the wise souls in this forum can lead me to the light!
Kevin
P.S. I can post the full log if anyone's interested. -
Updates not applying??
I have 2 problems:
1. I have a person I text msg and their name and the history of txt's isn't available from the main text msg screen. I can only see this when they text me and I look at it before swiping the gesture area to go back to the list of texts. When I do that, this person is gone, until they text me again. I've tried to restart and that does seem to help.
2. I use the Updates icon and it returns with my updates, but I have about 5 updates that keep givingme the yellow triangle without updating.
Post relates to: Pre p100eww (Sprint)
Post relates to: Pre p100eww (Sprint)The errors are spread through the file, I have copied a few repeating ones here and linked the full file via Dropbox.
WARNING: WU client failed Searching for update with error 0x80248014
WARNING: Exit code = 0x00000000, Result code = 0x80248014
COMAPI WARNING: Operation failed due to earlier error, hr=80248014
REPORT EVENT: {32898FA6-A6CE-4B10-ABA0-8D43666E9B3A} 2015-01-11 13:04:34:392+1100 1 148 [AGENT_DETECTION_FAILED] 101 {00000000-0000-0000-0000-000000000000}
0 80248014 System Center Endpoint Protection (DDEFDD14-250E-4DC8-A0B3-9D667EC5D8EB) Failure Software Synchronization Windows Update Client failed to detect with
error 0x80248014.
WARNING: Failed to get service object: 80248014
WARNING: Network Cost is assumed to be not supported as something failed with trying to get handles to wcmapi.dll
WARNING: IsSessionRemote: WinStationQueryInformationW(WTSIsRemoteSession) failed for session 1, GetLastError=2250
https://dl.dropboxusercontent.com/u/32055319/WindowsUpdateEdited.log
Regards,
Locust12 -
Not able to install sccm agent in sccm 2012 servers after cu3 update
not able to install sccm agent in sccm 2012 servers after cu3 update
MSI: Setup was unable to register the CCM_Service_HostingConfiguration endpoint
The error code is 80041002 ,below URl specify fix to uninstall Management point ,but in sccm 2012 secondary site canot unintall management point ,please help to install agent in config manager servers
https://blogs.technet.com/b/configurationmgr/archive/2013/11/25/hotfix-quot-error-25150-setup-was-unable-to-register-the-ccm-service-hostingconfiguration-endpoint-quot-when-you-try-to-install-the-client-agent-in-configuration-manager.aspx
ankithExcellent Article!!!!!! Pls check here, Follow the same steps
http://eskonr.com/2013/09/sccm-configmgr-2012-sp1-cu3-installationcollections-upgrade-clients/
This too
http://it.peikkoluola.net/2013/11/18/update-sccm-2012-to-sp1-cu3/
Thanks, Prabha G -
Windows Server 2012 R2 - ALL HF's Failing to install as "Does Not Apply to this computer"
Hi,
A general question about hot fix installs.
I have multiple servers that are all Windows 2012 R2. They do not have internet connections, so I have to install the Hotfixes manually. I download the HF's from the ISO download page (https://support.microsoft.com/en-us/kb/913086) every month. I collect them and install in a bulk install during a release cycle ( a couple times a year). I just realized that NO HF's have installed since JUNE 2014. Every HF that shows up in WindowsServer2012R2 directory fail to install with a message of "The update is not applicable to your computer". Which is fine if that was true, but.... I get this message for every HF from the ISO's since June 2014. NOT one HF thinks it is applicable to my computer. Could that be the case? No HF's apply to my Server 2012 systems since June of 2014?
This is my system info, and below that is the results from attempting to install 95 HF's.
C:\TEMP>systeminfo
Host Name: MYHOST
OS Name: Microsoft Windows Server 2012 R2 Datacenter
OS Version: 6.3.9600 N/A Build 9600
OS Manufacturer: Microsoft Corporation
OS Configuration: Member Server
OS Build Type: Multiprocessor Free
Registered Owner: Windows User
Registered Organization:
Product ID: 00252-80025-36226-AA727
Original Install Date: 6/13/2014, 8:04:39 AM
System Boot Time: 3/16/2015, 2:34:45 PM
System Manufacturer: Dell Inc.
System Model: PowerEdge R720
System Type: x64-based PC
Processor(s): 2 Processor(s) Installed.
[01]: Intel64 Family 6 Model 62 Stepping 4 GenuineInt
el ~2500 Mhz
[02]: Intel64 Family 6 Model 62 Stepping 4 GenuineInt
el ~2500 Mhz
BIOS Version: Dell Inc. 2.2.2, 1/16/2014
Windows Directory: C:\Windows
System Directory: C:\Windows\system32
Boot Device: \Device\HarddiskVolume1
System Locale: en-us;English (United States)
Input Locale: en-us;English (United States)
Time Zone: (UTC-07:00) Mountain Time (US & Canada)
Total Physical Memory: 262,099 MB
Available Physical Memory: 249,337 MB
Virtual Memory: Max Size: 301,011 MB
Virtual Memory: Available: 288,015 MB
Virtual Memory: In Use: 12,996 MB
Page File Location(s): C:\pagefile.sys
Domain: mydomain.sgn
Logon Server: \\MYHOST
Hotfix(s): 25 Hotfix(s) Installed.
[01]: KB2862152
[02]: KB2868626
[03]: KB2876331
[04]: KB2888505
[05]: KB2892074
[06]: KB2893294
[07]: KB2893984
[08]: KB2898785
[09]: KB2898868
[10]: KB2898871
[11]: KB2900986
[12]: KB2901125
[13]: KB2901128
[14]: KB2909210
[15]: KB2909921
[16]: KB2912390
[17]: KB2916036
[18]: KB2919442
[19]: KB2922229
[20]: KB2923392
[21]: KB2925418
[22]: KB2930275
[23]: KB2931358
[24]: KB2931366
[25]: KB2936068
Network Card(s): 6 NIC(s) Installed.
[01]: Broadcom BCM57800 NetXtreme II 10 GigE (NDIS VB
D Client)
Connection Name: ISCSI
DHCP Enabled: No
IP address(es)
[01]: 192.168.1.30
[02]: fe80::38c9:e59c:5ac2:e0a1
[02]: Broadcom BCM57800 NetXtreme II 1 GigE (NDIS VBD
Client)
Connection Name: NIC3
Status: Hardware not present
[03]: Broadcom BCM57800 NetXtreme II 1 GigE (NDIS VBD
Client)
Connection Name: MGMT
DHCP Enabled: No
IP address(es)
[01]: 7.48.64.32
[02]: 7.48.64.30
[03]: fe80::f14e:9339:9326:c7fd
[04]: Broadcom BCM57810 NetXtreme II 10 GigE (NDIS VB
D Client)
Connection Name: SLOT 5 Port 1_swport_VMRepwan
DHCP Enabled: Yes
DHCP Server: N/A
IP address(es)
[05]: Broadcom BCM57800 NetXtreme II 10 GigE (NDIS VB
D Client)
Connection Name: NIC2
Status: Hardware not present
[06]: Broadcom BCM57810 NetXtreme II 10 GigE (NDIS VB
D Client)
Connection Name: SLOT 5 Port 2_swport_VMOpswan
DHCP Enabled: Yes
DHCP Server: N/A
IP address(es)
Hyper-V Requirements: A hypervisor has been detected. Features required for
Hyper-V will not be displayed.
I have a script that runs each HF install.. If I run them manually without the tool I get the same results so it is not the script..
Installing 95 patches
for Microsoft Windows Server 2012 R2 Datacenter x64
Repository path: U:\Patch Repository_4_1\2012_R2_HFs\
1. Windows8.1-KB2894852-v2-x64.msu patch status: DOES NOT APPLY TO THIS COMPUTER
2. Windows8.1-KB2894856-v2-x64.msu patch status: DOES NOT APPLY TO THIS COMPUTER
3. Windows8.1-KB2920189-x64.msu patch status: DOES NOT APPLY TO THIS COMPUTER
4. Windows8.1-KB2926765-x64.msu patch status: DOES NOT APPLY TO THIS COMPUTER
5. Windows8.1-KB2928120-x64.msu patch status: DOES NOT APPLY TO THIS COMPUTER
6. Windows8.1-KB2931358-x64.msu patch status: ALREADY INSTALLED - SKIPPING
7. Windows8.1-KB2931366-x64.msu patch status: ALREADY INSTALLED - SKIPPING
8. Windows8.1-KB2933826-x64.msu patch status: DOES NOT APPLY TO THIS COMPUTER
9. Windows8.1-KB2939576-x64.msu patch status: DOES NOT APPLY TO THIS COMPUTER
10. Windows8.1-KB2953522-x64.msu patch status: DOES NOT APPLY TO THIS COMPUTER
11. Windows8.1-KB2957151-x64.msu patch status: DOES NOT APPLY TO THIS COMPUTER
12. Windows8.1-KB2957189-x64.msu patch status: DOES NOT APPLY TO THIS COMPUTER
13. Windows8.1-KB2957689-x64.msu patch status: DOES NOT APPLY TO THIS COMPUTER
14. Windows8.1-KB2961072-x64.msu patch status: DOES NOT APPLY TO THIS COMPUTER
15. Windows8.1-KB2961887-x64.msu patch status: DOES NOT APPLY TO THIS COMPUTER
16. Windows8.1-KB2962872-x64.msu patch status: DOES NOT APPLY TO THIS COMPUTER
17. Windows8.1-KB2964718-x64.msu patch status: DOES NOT APPLY TO THIS COMPUTER
18. Windows8.1-KB2964736-x64.msu patch status: DOES NOT APPLY TO THIS COMPUTER
19. Windows8.1-KB2965788-x64.msu patch status: DOES NOT APPLY TO THIS COMPUTER
20. Windows8.1-KB2966072-x64.msu patch status: DOES NOT APPLY TO THIS COMPUTER
21. Windows8.1-KB2966826-x64.msu patch status: DOES NOT APPLY TO THIS COMPUTER
22. Windows8.1-KB2966828-x64.msu patch status: DOES NOT APPLY TO THIS COMPUTER
23. Windows8.1-KB2971850-x64.msu patch status: DOES NOT APPLY TO THIS COMPUTER
24. Windows8.1-KB2972213-x64.msu patch status: DOES NOT APPLY TO THIS COMPUTER
25. Windows8.1-KB2972280-x64.msu patch status: DOES NOT APPLY TO THIS COMPUTER
26. Windows8.1-KB2973114-x64.msu patch status: DOES NOT APPLY TO THIS COMPUTER
27. Windows8.1-KB2973201-x64.msu patch status: DOES NOT APPLY TO THIS COMPUTER
28. Windows8.1-KB2973351-x64.msu patch status: DOES NOT APPLY TO THIS COMPUTER
29. Windows8.1-KB2974008-x64.msu patch status: DOES NOT APPLY TO THIS COMPUTER
30. Windows8.1-KB2976627-x64.msu patch status: DOES NOT APPLY TO THIS COMPUTER
31. Windows8.1-KB2976897-x64.msu patch status: DOES NOT APPLY TO THIS COMPUTER
32. Windows8.1-KB2977292-x64.msu patch status: DOES NOT APPLY TO THIS COMPUTER
33. Windows8.1-KB2977629-x64.msu patch status: DOES NOT APPLY TO THIS COMPUTER
34. Windows8.1-KB2978668-x64.msu patch status: DOES NOT APPLY TO THIS COMPUTER
35. Windows8.1-KB2982794-x64.msu patch status: DOES NOT APPLY TO THIS COMPUTER
36. Windows8.1-KB2982998-v2-x64.msu patch status: DOES NOT APPLY TO THIS COMPUTER
37. Windows8.1-KB2987107-x64.msu patch status: DOES NOT APPLY TO THIS COMPUTER
38. Windows8.1-KB2987114-x64.msu patch status: DOES NOT APPLY TO THIS COMPUTER
39. Windows8.1-KB2988948-x64.msu patch status: DOES NOT APPLY TO THIS COMPUTER
40. Windows8.1-KB2992611-x64.msu patch status: DOES NOT APPLY TO THIS COMPUTER
41. Windows8.1-KB2993651-x64.msu patch status: DOES NOT APPLY TO THIS COMPUTER
42. Windows8.1-KB2993958-x64.msu patch status: DOES NOT APPLY TO THIS COMPUTER
43. Windows8.1-KB3000061-x64.msu patch status: DOES NOT APPLY TO THIS COMPUTER
44. Windows8.1-KB3000483-x64.msu patch status: DOES NOT APPLY TO THIS COMPUTER
45. Windows8.1-KB3000869-x64.msu patch status: DOES NOT APPLY TO THIS COMPUTER
46. Windows8.1-KB3001237-x64.msu patch status: DOES NOT APPLY TO THIS COMPUTER
47. Windows8.1-KB3002657-x64.msu patch status: DOES NOT APPLY TO THIS COMPUTER
48. Windows8.1-KB3002885-x64.msu patch status: DOES NOT APPLY TO THIS COMPUTER
49. Windows8.1-KB3003057-x64.msu patch status: DOES NOT APPLY TO THIS COMPUTER
50. Windows8.1-KB3003381-x64.msu patch status: DOES NOT APPLY TO THIS COMPUTER
51. Windows8.1-KB3003743-x64.msu patch status: DOES NOT APPLY TO THIS COMPUTER
52. Windows8.1-KB3004150-x64.msu patch status: DOES NOT APPLY TO THIS COMPUTER
53. Windows8.1-KB3004361-x64.msu patch status: DOES NOT APPLY TO THIS COMPUTER
54. Windows8.1-KB3004365-x64.msu patch status: DOES NOT APPLY TO THIS COMPUTER
55. Windows8.1-KB3005607-x64.msu patch status: DOES NOT APPLY TO THIS COMPUTER
56. Windows8.1-KB3006226-x64.msu patch status: DOES NOT APPLY TO THIS COMPUTER
57. Windows8.1-KB3008923-x64.msu patch status: DOES NOT APPLY TO THIS COMPUTER
58. Windows8.1-KB3008925-x64.msu patch status: DOES NOT APPLY TO THIS COMPUTER
59. Windows8.1-KB3010788-x64.msu patch status: DOES NOT APPLY TO THIS COMPUTER
60. Windows8.1-KB3011780-x64.msu patch status: DOES NOT APPLY TO THIS COMPUTER
61. Windows8.1-KB3013126-x64.msu patch status: DOES NOT APPLY TO THIS COMPUTER
62. Windows8.1-KB3013455-v2-x64.msu patch status: DOES NOT APPLY TO THIS COMPUTER
63. Windows8.1-KB3014029-x64.msu patch status: DOES NOT APPLY TO THIS COMPUTER
64. Windows8.1-KB3018943-x64.msu patch status: DOES NOT APPLY TO THIS COMPUTER
65. Windows8.1-KB3019215-x64.msu patch status: DOES NOT APPLY TO THIS COMPUTER
66. Windows8.1-KB3019978-x64.msu patch status: DOES NOT APPLY TO THIS COMPUTER
67. Windows8.1-KB3020393-x64.msu patch status: DOES NOT APPLY TO THIS COMPUTER
68. Windows8.1-KB3021674-x64.msu patch status: DOES NOT APPLY TO THIS COMPUTER
69. Windows8.1-KB3021952-x64.msu patch status: DOES NOT APPLY TO THIS COMPUTER
70. Windows8.1-KB3023607-x64.msu patch status: DOES NOT APPLY TO THIS COMPUTER
71. Windows8.1-KB3036197-x64.msu patch status: DOES NOT APPLY TO THIS COMPUTER
72. Windows8.1-KB3021953-x64.msu patch status: DOES NOT APPLY TO THIS COMPUTER
73. Windows8.1-KB3022777-x64.msu patch status: DOES NOT APPLY TO THIS COMPUTER
74. Windows8.1-KB3023266-x64.msu patch status: DOES NOT APPLY TO THIS COMPUTER
75. Windows8.1-KB3023562-x64.msu patch status: DOES NOT APPLY TO THIS COMPUTER
76. Windows8.1-KB3024663-x64.msu patch status: DOES NOT APPLY TO THIS COMPUTER
77. Windows8.1-KB3029944-x64.msu patch status: DOES NOT APPLY TO THIS COMPUTER
78. Windows8.1-KB3030377-x64.msu patch status: DOES NOT APPLY TO THIS COMPUTER
79. Windows8.1-KB3031432-x64.msu patch status: DOES NOT APPLY TO THIS COMPUTER
80. Windows8.1-KB3032323-x64.msu patch status: DOES NOT APPLY TO THIS COMPUTER
81. Windows8.1-KB3032359-x64.msu patch status: DOES NOT APPLY TO THIS COMPUTER
82. Windows8.1-KB3040335-x64.msu patch status: DOES NOT APPLY TO THIS COMPUTER
83. Windows8.1-KB3033408-x64.msu patch status: DOES NOT APPLY TO THIS COMPUTER
84. Windows8.1-KB3033889-x64.msu patch status: DOES NOT APPLY TO THIS COMPUTER
85. Windows8.1-KB3034196-x64.msu patch status: DOES NOT APPLY TO THIS COMPUTER
86. Windows8.1-KB3034344-x64.msu patch status: DOES NOT APPLY TO THIS COMPUTER
87. Windows8.1-KB3035017-x64.msu patch status: DOES NOT APPLY TO THIS COMPUTER
88. Windows8.1-KB3035034-x64.msu patch status: DOES NOT APPLY TO THIS COMPUTER
89. Windows8.1-KB3035126-x64.msu patch status: DOES NOT APPLY TO THIS COMPUTER
90. Windows8.1-KB3035131-x64.msu patch status: DOES NOT APPLY TO THIS COMPUTER
91. Windows8.1-KB3035132-x64.msu patch status: DOES NOT APPLY TO THIS COMPUTER
92. Windows8.1-KB3037634-x64.msu patch status: DOES NOT APPLY TO THIS COMPUTER
93. Windows8.1-KB3039066-x64.msu patch status: DOES NOT APPLY TO THIS COMPUTER
94. Windows8.1-KB3044132-x64.msu patch status: DOES NOT APPLY TO THIS COMPUTER
95. Windows8.1-KB3046049-x64.msu patch status: DOES NOT APPLY TO THIS COMPUTER
Thanks,
Dave
Hi Dave,
Would you please check CBS lg file and other relevant event logs if find more clues? On current situation, please refer to following article and check if can help you.
Update is not applicable to your computer- but it is
Best regards,
Justin Gu
Please remember to mark the replies as answers if they help and unmark them if they provide no help. If you have feedback for TechNet Support, contact [email protected] -
Good evening I would please help me, IGood evening I would please help me, I have problems with flash player when update on my computer Flash Player for windows 8, gives me error in the installation that is not apply on my computer. Please help. Thank You
First, confirm that ActiveX Filtering is configured to allow Flash content:
https://forums.adobe.com/thread/867968
Internet Explorer 11 introduces a number of changes both to how the browser identifies itself to remote web servers, and to how it processes JavaScript intended to target behaviors specific to Internet Explorer. Unfortunately, this means that content on some sites will be broken until the content provider changes their site to conform to the new development approach required by modern versions of IE.
You can try to work around these issues by using Compatibility View:
http://windows.microsoft.com/en-us/internet-explorer/use-compatibility-view#ie=ie-11
If that is too inconvenient, using Google Chrome may be a preferable alternative. -
Windows Server 2012 GPO setting are not apply on windows Xp clients
Hi
I am create GPO on windows server 2012. 300 clients on domain are working fine, GPO setting apply on all windows 7, 8 clients. But 200 clients of windows XP are not working. GPO setting are not applies on XP. I am trying to Group Policy
Preference Client Side Extensions for Windows XP (KB943729) on one window XP client, all GPO servers 2012 setting is working fine. But is not solution. I have 200 clients of windows XP, Please provide batter solution on one click command and apply all 200
XP clients.
Thanks.Dear,
I have Windows server 2012 , i have install ADDS with Forest functional level 2008 & Domain functional level 2008 .
I have applied GPO to particular OU, when i login to domain user on Windows 7 PC all GPO working fine but when i login on Windows Xp SP3 PC its not applied on XP.
I am facing issue on windows XP clients it is true. Please see this URL address:
http://blogs.technet.com/b/grouppolicy/archive/2009/03/27/group-policy-preferences-not-applying-on-some-clients-client-side-extension-xmllite.aspx
Please provide batter solution on one click command
Thanks.
Maybe you are looking for
-
How to count number of items present in a data block
hi all, how to count how many items present in a particular data block in oracle forms 10g. whether it is a text_item or display_item or list_item etc is there any method to do this. please reply....
-
How to map when using mail adapter
Hi: I'm doing a test with mail adapter in XI. The scenario is I put an XML representation content based on the outbound interface used by sender mail adapter directly in inbox mail content and send it. At the other side, I want to using receiver file
-
PDF books not exported in XML library
I just migrated from Windows XP to Windows 7. I used my ITunes Library XML, and iTunes Playlist I'd previously saved to move and restore my iTunes music and video library. That worked great,though I did have to re-tag some video files as "TV shows"
-
Cant install flash player. keeps asking for password, and I dont recall it. see no option to reset.
-
Hi all, I did some code like when invalid combinations....then need to raise a request,at that time it showing the error message, but after that error message...when press enter....that work order starts genrating(means start processing).So i need to