Windows 7 Forums


Reply
Thread Tools

Windows Update error - 0x80072f8f

 
 
mrbill mrbill is offline
New Member
Join Date: Aug 2010
Location: Southern MD
Posts: 6
Thanked: 0
 
      08-05-2010
Hey guys, I figured it was finally time to register with this forum...

I get this error while trying to update a copy of windows7 professional. My time IS correct, syncronized to the windows time server.

I work as a navy contractor. I hardened this machine per DISA's hardening requirements. This means some things get disabled, like "automatic updates" Lots of netowork protocol stuff gets edited in the secuirty policy also. I should (i think) still be able to update the machine by clicking the windows update button though. "BITS" works, and the "windows update" service is up, but no worky.

Second thing it may be... The install is not-yet activated. We have a number of identical machines here and I'm trying to make a depolyable image. After I deploy the image, I can activate each with a seperate license. Would the system NOT being activated be an issue? I'm trying to eliminate this variable as we speak by re-imaging the origional install from before I hardened it.

Third thing - As we do work for the governmnet, there is no "internet" here. We have government networks that require a number of accreditations to allow them to be put on the network. So I have this computer accessing the internet through a shared connection on my laptop's Verizon 3g air card. My boss is doing a YUM update on his linux test computer right now, so I know it physically WORKS. Internet works on this computer also.

Any ideas? Please tell me you have ideas.

Edit: Just finished loading the pre-hardened image and it seems to be working, so there's a setting SOMEWHERE

Last edited by mrbill; 08-05-2010 at 04:28 PM..
 
Reply With Quote
 
 
 
 
TrainableMan TrainableMan is offline
^ The World's First ^
TrainableMan's Avatar
Join Date: May 2010
Location: PA, USA
Posts: 4,656
Thanked: 887
 
      08-05-2010
The date / time on your computer is too different from the date / time of the SSL (Secure Sockets Layer) certificates used by the Windows Update site.

Check you have the correct time and date and time zone.

How do you get updates if you don't have internet access?

If this is fed via satellite etc then maybe wherever this link is coming from should be the date time you use (and whether the daylight savings time flag is checked or not).
 
Reply With Quote
 
mrbill mrbill is offline
New Member
Join Date: Aug 2010
Location: Southern MD
Posts: 6
Thanked: 0
 
      08-05-2010
It's not a clock issue. Maybe it's an SSL issue on the computer, but as I just said, the time is syncronized with the microsoft time server.
Also, when I loaded a base install of windows7 (not hardened) windows update works fine.

We get updates via the air card I have in the laptop. It's a verizon 3g card with internet connection sharing on. It's shared to the ethernet port, which goes to a switch, which goes to the computer.
 
Reply With Quote
 
TrainableMan TrainableMan is offline
^ The World's First ^
TrainableMan's Avatar
Join Date: May 2010
Location: PA, USA
Posts: 4,656
Thanked: 887
 
      08-05-2010
Also some sites suggest registering your DLLs ...

Register Softpub.dll, Wintrust.dll, Initpki.dll, and Mssip32.dl Files

Open Start menu, select Run, and then run this for each of the four DLLs: regsvr32 filename where filename is the dll


(I haven't tried this so I don't know if you need the DLLs full path or just the short filename so if you get an error I suppose you would try it with the full path)
 
Reply With Quote
 
mrbill mrbill is offline
New Member
Join Date: Aug 2010
Location: Southern MD
Posts: 6
Thanked: 0
 
      08-05-2010
Okay so maybe I'm getting somewhere.

The first and fourth dlls registered without issue.
wintrust.dll and Initpki.dll both had errors.
wintrust failed with error 0x80070005
Initpki.dll says "make sure the binary is sotred at the specified path or debug it to check for plobles with the binary or dependant .dll files"

edit: looks like wintrust was a permissions issue, ran as admin and it worked

Last edited by mrbill; 08-05-2010 at 05:51 PM..
 
Reply With Quote
 
mrbill mrbill is offline
New Member
Join Date: Aug 2010
Location: Southern MD
Posts: 6
Thanked: 0
 
      08-05-2010
So I rebooted and it still doesn't work ;-(
 
Reply With Quote
 
TrainableMan TrainableMan is offline
^ The World's First ^
TrainableMan's Avatar
Join Date: May 2010
Location: PA, USA
Posts: 4,656
Thanked: 887
 
      08-05-2010
Only things I saw said it has to do with your clocks being too far out of sync with what the windows update site SSL certificates timestamps are. As I said, I don't understand how you can get to the updates server w/o internet connection anyway.
 
Reply With Quote
 
mrbill mrbill is offline
New Member
Join Date: Aug 2010
Location: Southern MD
Posts: 6
Thanked: 0
 
      08-05-2010
Quote:
Originally Posted by TrainableMan View Post
Only things I saw said it has to do with your clocks being too far out of sync with what the windows update site SSL certificates timestamps are. As I said, I don't understand how you can get to the updates server w/o internet connection anyway.
we have the internet. Like I said twice, we have a verizon broadband card on a laptop with a shared ethernet connection.

The computer needs to be updated, scanned with the network vulnerabilty scanner (eEye retina) and DISA's gold-disk.

So a recent development, if I put in the department of defense's WSUS server in gpedit... it works. Clearly the DoD's WSUS lacks some security protocol that Microsoft's has and is disabled/limited by my procedures.
 
Reply With Quote
 
TrainableMan TrainableMan is offline
^ The World's First ^
TrainableMan's Avatar
Join Date: May 2010
Location: PA, USA
Posts: 4,656
Thanked: 887
 
      08-05-2010
So is it solved, can you leave the DOD server in there?
 
Reply With Quote
 
mrbill mrbill is offline
New Member
Join Date: Aug 2010
Location: Southern MD
Posts: 6
Thanked: 0
 
      08-05-2010
I dunno if I'd call it solved... I got it working, but regular WSUS still doesn't work
 
Reply With Quote
 
 
 
Reply

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
How to Install Windows 7 davehc Software 0 08-16-2010 02:50 PM
Windows 7 Annoyances Nibiru2012 General Discussion 6 03-17-2010 06:17 PM
Clean Install Windows 7 with Upgrade Media Nibiru2012 Installation, Setup and Updates 0 12-22-2009 07:03 PM
Clean Install Windows 7 with Upgrade Media Nibiru2012 Installation, Setup and Updates 2 12-04-2009 06:30 PM
Important Issues in This Release Candidate of Windows 7 Ian News 0 05-05-2009 03:25 PM


All times are GMT +1. The time now is 01:38 PM.
W7Forums is an independent website and is not affiliated with Microsoft Corporation.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33