Failed to approve some expired updates on WSUS Replica Server (DSS)

SYMPTOMS


You see the following error on WSUS Replica Server (DSS) whilst trying to synchronize with WSUS Upstream Server (USS):


ApplicationException: Failed to approve some updates —>
System.Data.SqlClient.SqlException: Explicit deployments to updates that are
expired are not allowed.
at Microsoft.UpdateServices.ServerSync.CatalogSync
AgentCore.CatalogSyncThreadP­rocessReal(Boolean allowRedirect)


CAUSE


  1. As the error says – Explicit deployments to updates that are expired are not allowed – which means if an update is expired on WSUS Upstream Server (USS) then WSUS Replica Server (DSS) will not be able to synchronize the expired update from the USS and the sync fails.
  2. An update has been expired on WSUS USS during a recent sync with MU and this expired update is still approved on USS for either detection or install. Thus, the DSS is not aware of expired update and tries to download the expired update as it is still approved for either detection or install and eventually it fails.
  3. Also, If you do not choose to automatically approve the revised version, the older version will continue to be approved even if it is expired and synchronization will fail on DSS.
  4. Expired Updates cannot be synchronized to DSS.

WORKAROUND


I am not aware of any way to UN-expire an update from WSUSAdmin Console on USS (Is there any way to cheat SUSDB??.).


So,


  1. You might want to choose to automatically approve the Revised/Updated versions of updates that you have previously approved from Automatic Approval Options.
  2. Then, review the synchronization logs and search for the “Expired” updates on the Master WSUS server that are still deployed (for either Install or Detect Only) and “Decline” it.

NOTE: This issue is supposed to be fixed in WSUS SP1.


To find the Revised updates which are expired, take a look at;


  1. Find New and Changed Windows Updates
  2. Find New and Changed Updates for Microsoft Products Other Than Windows
  3. Archived Updates

Once you decline the expired updates, perform a manual synchronization from DSS and this time it should sync successfully!

Leave a Reply

Your email address will not be published. Required fields are marked *


*

You may use these HTML tags and attributes: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>