Security Compliance

Error codes and patches for WSUS servers

This article describes the error codes and patches that apply to WSUS servers.

First published date

10/30/2018 2:15 PM

Last published date

10/30/2018 2:15 PM

Overview

This article describes the error codes and patches that apply to WSUS servers.

Product section

Patch Manager

Resolution

Patches and KBs 

KB     TARGET VERSION     DESCRIPTION

WSUS 3.0 Service Pack 2
(KB2734608)

3.0 SP2 

An update for Windows Server Update Services 3.0 Service Pack 2 is available (KB2734608) 
(© 2017 Microsoft, available at https://support.microsoft.com/, obtained on January 24, 2016.)

This update allows servers running Windows Server Update Services (WSUS) 3.0 SP2 to provide updates to Windows 8 and Windows Server 2012 computers.

 

KB2734608 updates the hashing algorithm and calculations of the content hashes stored in the update metadata. The 0x80246003 error displayed in Windows 8 and Windows Server 2012 server systems is caused by the WUAgent not being able to validate the newer hashing algorithm because the update only has the older hashes.

 

When a WSUS 6 server synchronizes from a WSUS 3 server without KB2734608, the WSUS 3 server doesn’t have the new hash calculations. As a result, the WSUS 6 server cannot get them from the synchronized metadata. Updating a Windows 8 or Windows Server 2012 client from the WSUS 6 server will fail, just as it would from the unpatched WSUS 3 server.

WSUS 3.0 Service Pack 2

 3.0 SP2An update for Windows Server Update Services 3.0 Service Pack 2 is available. (© 2017 Microsoft, available at https://support.microsoft.com/, obtained on January 24, 2016.)

This update improves the WSUS communication channels (just 1024bit+ certs can be used) . This includes trusting only files that are issued by the Microsoft Update certification authority.

 

Error codes