Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

WSUS RODC Server 2012


  • Please log in to reply
5 replies to this topic

#1 computerguy101

computerguy101

  • Members
  • 4 posts
  • OFFLINE
  •  
  • Local time:12:09 PM

Posted 13 February 2015 - 03:53 PM

Trying To setup WSUS on my RODC server and its giving me errors.  I found many people that said you needed to create security groups. 

 

 

1.      SQLServer2005MSFTEUser$Servername$Microsoft##SSEE

2.      SQLServer2005MSSQLUser$Servername$Microsoft##SSEE

Note: Servername= RODC server name

 

 

However This only fixed half of the issues. It gets passed created group WSUS Administrators now, but is still getting stuck on WSUS Reporters. Have tried several other fixes but to no avail. Any help would be great! Thanks!


Edited by computerguy101, 13 February 2015 - 04:01 PM.


BC AdBot (Login to Remove)

 


#2 sflatechguy

sflatechguy

  • BC Advisor
  • 2,233 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:01:09 PM

Posted 14 February 2015 - 07:10 PM

Was the primary WSUS installed on a read/write domain controller? If not, the WSUS Administrators and WSUS Reporters will be local groups on that WSUS server. These two groups need to be domain groups in order to work with the RODC, and once created, you then force the replication to the RODC. Because it's an RODC, there is no security account manager and the RODC can't create the groups.



#3 computerguy101

computerguy101
  • Topic Starter

  • Members
  • 4 posts
  • OFFLINE
  •  
  • Local time:12:09 PM

Posted 16 February 2015 - 12:47 PM

Was the primary WSUS installed on a read/write domain controller? If not, the WSUS Administrators and WSUS Reporters will be local groups on that WSUS server. These two groups need to be domain groups in order to work with the RODC, and once created, you then force the replication to the RODC. Because it's an RODC, there is no security account manager and the RODC can't create the groups.

 

Yes, I saw this on another forum somewhere and also added those two as a domain security group. However that still resulted in the same error when trying to run the WSUS setup. It finds and configures the first group - WSUS Administrators, yet fails to find the WSUS Reporters.

Edit: Actually I just tried it again today and it got even further now.  Now it gets to configuring the database and fails to start the service MSSQL$MICROSOFT##WID on computer '.' - Have yet to look into this yet but will do so today and post my findings. 


Edited by computerguy101, 16 February 2015 - 01:23 PM.


#4 sflatechguy

sflatechguy

  • BC Advisor
  • 2,233 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:01:09 PM

Posted 16 February 2015 - 07:49 PM

You'll need to troubleshoot why the Windows Internal Databse is not starting. Check the services snap-in to see how the service is set to start. Also, make sure the accounts for WSUS haven't been locked out and that they have the proper logon type -- that is, logon as a service.

#5 computerguy101

computerguy101
  • Topic Starter

  • Members
  • 4 posts
  • OFFLINE
  •  
  • Local time:12:09 PM

Posted 17 February 2015 - 11:42 AM

Correct! I had to go into my Default Domain Controller Policy under - Computer Configuration - Windows Settings - Security Settings - Local Policy - User Rights Assignment and add NT SERVICE/ALL SERVICES to the logon as service policy and it worked great!

 

Thanks for your help on this sflatechguy!



#6 sflatechguy

sflatechguy

  • BC Advisor
  • 2,233 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:01:09 PM

Posted 17 February 2015 - 01:05 PM

Glad you got that resolved. :thumbup2:






0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users