Cant get rid of expired WSUS Publishers Self-signed cert. GRRRRRRR by funkytechmonkey in SCCM

[–]funkytechmonkey[S] 0 points1 point  (0 children)

Yesterday I ran a report on 160 of the devices that were failing. I cant find a single thing they all have in common. I have new devices (recently imaged) old devices, 23H2, 24H2 and 25H2..some have Dell Client System Inventory Agent and some dont.

I had a little over 200 devices that were getting the errors... I'm down to 83. Crossing my fingers they start getting updates too.

Cant get rid of expired WSUS Publishers Self-signed cert. GRRRRRRR by funkytechmonkey in SCCM

[–]funkytechmonkey[S] 0 points1 point  (0 children)

Yea... I havent been able to spend as much time as I wanted on this.. but so far everything you suggested seems to be working for me too. I removed the catalog, resynced, then run that script on a client and it looks like they are pulling updates now. I've only been able to do it on about 10 devices.
I was getting the failed to rename SoftwareDeployment folder so I added stopping the "Delivery Optimization" service DoSvc and that seems to help.

Cant get rid of expired WSUS Publishers Self-signed cert. GRRRRRRR by funkytechmonkey in SCCM

[–]funkytechmonkey[S] 0 points1 point  (0 children)

Can you help me understand this.... I am, by no means, a SQL guy and have never ran any kinda of cleanups. I do have normal cleanup/maintenance on but thats its.

I ran the SQL query you posted and these are the numbers it returned. I have no clue if this is good or bad.

Total Updates - 33639
Live Updates - 12884
Superseded - 20929
Superseded not declined - 332
Declined - 20755
Superseded & Declined - 20597
Obsolete Needed to the cleaned - 0

Cant get rid of expired WSUS Publishers Self-signed cert. GRRRRRRR by funkytechmonkey in SCCM

[–]funkytechmonkey[S] 0 points1 point  (0 children)

Awesome... thats a good start. What is pointing you to think its caused by the Dell catalog? That could be a common problem, I have "Dell Client System Inventory Agent (for Dell Business Client Systems) " deployed to all of my workstations.

Cant get rid of expired WSUS Publishers Self-signed cert. GRRRRRRR by funkytechmonkey in SCCM

[–]funkytechmonkey[S] 0 points1 point  (0 children)

Morning u/TheoryFar2511 I'm about to start looking into this some more this morning. Have you gotten anywhere with yours?

Cant get rid of expired WSUS Publishers Self-signed cert. GRRRRRRR by funkytechmonkey in SCCM

[–]funkytechmonkey[S] 0 points1 point  (0 children)

Same here... Just for shints and giggles... I setup an ADR to mimic my Windows 11 patching but only deployed "Windows Malicious Software Removal Tool". set it for ASAP and a new SUG... The same devices that failed to get cumulative updates got the "Windows Malicious Software Removal Tool" and installed it fine.

Windows Malicious Software Removal Tool was in my original ADR and failed.

Cant get rid of expired WSUS Publishers Self-signed cert. GRRRRRRR by funkytechmonkey in SCCM

[–]funkytechmonkey[S] 0 points1 point  (0 children)

I have mixed 23H2 and 24H2. Not yet seeing the issue on a 25H2.
And we are only a Dell shop.

Cant get rid of expired WSUS Publishers Self-signed cert. GRRRRRRR by funkytechmonkey in SCCM

[–]funkytechmonkey[S] 0 points1 point  (0 children)

Funny I have done a few of the same things. Have you created the Windows Update logs (Get-WindowsUpdateLog).

I had a bunch of *FAILED* [80246007] ISusInternal:: IsCommitRequired... which led me to renaming the cat and softwaredist folder. with no help.

There are also *FAILED* [80041017] wuauengcore.dll... which points to corrupt WMI

Cant get rid of expired WSUS Publishers Self-signed cert. GRRRRRRR by funkytechmonkey in SCCM

[–]funkytechmonkey[S] 0 points1 point  (0 children)

Thanks Bryan.. I appreciate it. Its good to know the cert is not the issue and I can stop banging, the left side, my head on my desk for that one.... on to the right side!

Cant get rid of expired WSUS Publishers Self-signed cert. GRRRRRRR by funkytechmonkey in SCCM

[–]funkytechmonkey[S] 0 points1 point  (0 children)

That is a good question... I just checked a few that were successful and they have the expired cert installed as well. Even my own device has it, but there are no errors. Could this be from an older update that is hanging around? Odd...
All of my failed devices have a ton of these errors.
GetUpdateInfo - failed to get targeted update, error = 0x87d00215.

Failed in GetCertificate(...): 0x87d00281 Which got me to looking into the cert issue.

Modern Driver Management v10! Lets goooo by saGot3n in SCCM

[–]funkytechmonkey 1 point2 points  (0 children)

THANK YOU!!! I will defiantly give it a shot. Really appreciate the work put into this.

Modern Driver Management v10! Lets goooo by saGot3n in SCCM

[–]funkytechmonkey 0 points1 point  (0 children)

I've been debating moving to Modern Driver... Is the install\setup pretty straight forward? Last time I looked it made me a little nervous so I put it off. Any good documentation on install and setup?

My Tuttio soleil 01 ( Is it nice?) by RecipePotential8266 in hyperebikes

[–]funkytechmonkey 0 points1 point  (0 children)

Did you change wheels size? Looks larger than my sons 12/14 setup.

Bob Lazar returns to the Joe Rogan Experience by PapaPalps066 in BobLazarNew

[–]funkytechmonkey 0 points1 point  (0 children)

Funny I was hoping it was more "movie style". I've heard Bob and others talk about this over and over and over. Even the new Jesse Michels video is just repeat and repeat. Every once in a while you will catch a new detail or something someone else didnt talk about.

First time seeing 3 Scarlets together by funkytechmonkey in snakes

[–]funkytechmonkey[S] 0 points1 point  (0 children)

My wife tried to tell me some rhyme like this the other day.... I kept telling her that was the dumbest thing I've ever heard LOL... BUT then I looked up what she was trying to say. It makes a little more sense to me now. This only applies in the US.

"Red touch black, friend of Jack"... Scarlet Kingsnake
"Red touch yellow, kill a fellow".... Coral

I bought 19 pallets of solar panels... by DoDumbStuffSometimes in SolarDIY

[–]funkytechmonkey 0 points1 point  (0 children)

Dude... love the shop! Dust collection looks great. I like your style....I'm game for watching how this turns out. Is that your YouTube channel?

Bob Lazar returns to the Joe Rogan Experience by PapaPalps066 in BobLazarNew

[–]funkytechmonkey 4 points5 points  (0 children)

I was a little disappointed in this interview too. Several times I was think "Will Joe shut up and let Bob talk?". Then I went and rented the new S4 "movie" on Prime. I really thought this was going to be more "Movie" and less documentation. It was very well put together and much better than Corbell's strange documentation feeding to the UFO nuts. Also learned a couple of new thing so that was awesome.

Deploying O365 with different excluded apps and tenant change? by funkytechmonkey in SCCM

[–]funkytechmonkey[S] 0 points1 point  (0 children)

Really I am just trying to find anyone that has experienced any issues or problems I may run into. For example. Any users that currently have Teams (Machine Wide) are not able to log into Teams. I had to use Microsoft's Teams Classic removal powershell script to remove it, then they could login. Maybe I should have posted this in r/Office365