{"id":22091,"date":"2021-11-11T18:53:46","date_gmt":"2021-11-11T17:53:46","guid":{"rendered":"http:\/\/159.69.82.204\/win\/?p=22091"},"modified":"2021-11-15T10:16:59","modified_gmt":"2021-11-15T09:16:59","slug":"november-2021-patchday-probleme-wsus-dc-events","status":"publish","type":"post","link":"https:\/\/borncity.com\/win\/2021\/11\/11\/november-2021-patchday-probleme-wsus-dc-events\/","title":{"rendered":"November 2021 Patchday issues: WSUS, DC, Events"},"content":{"rendered":"<p><img decoding=\"async\" style=\"float: left; margin: 0px 10px 0px 0px; display: inline; border-width: 0px;\" title=\"Update\" src=\"https:\/\/www.borncity.com\/blog\/wp-content\/uploads\/2021\/06\/Update-01.jpg\" alt=\"Update\" align=\"left\" border=\"0\" \/>[<a href=\"https:\/\/www.borncity.com\/blog\/2021\/11\/11\/november-2021-patchday-probleme-wsus-dc-events\/\" target=\"_blank\" rel=\"noopener\">German<\/a>]Microsoft has release various security updates on November 9, 2021 patchday. Beside the already known printing issues caused by previous updates, there are now authentication problems with domain controllers (DCs) in certain Kerberos delegation scenarios. Probably leads to entries in the log files. Some administrators also report that their WSUS cannot pull all updates.<\/p>\n<p><!--more--><\/p>\n<h2>Problems with WSUS update synchronization<\/h2>\n<p><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/vg08.met.vgwort.de\/na\/1741b7f2d37b4712a5952955563948cb\" alt=\"\" width=\"1\" height=\"1\" \/>I don't know if the problem still exists. But as of Nov 11, 2021, several administrators reported that WSUS can't pull all updates. Here's <a href=\"https:\/\/www.borncity.com\/blog\/2021\/11\/10\/microsoft-security-update-summary-9-november-2021\/#comment-116904\" target=\"_blank\" rel=\"noopener\">a German comment<\/a> (translated) from the blog:<\/p>\n<blockquote><p>Our WSUS based on Windows Server 2016, only pulls the November updates of the server versions and the Windows Malicious Software Removal Tool. Multiple times already manually syncronized and rebooted the server, but without the effect of pulling the Windows 10 updates. We have changed absolutely nothing in the server settings and the required Win10 versions are definitely checked off as well.<\/p>\n<p>Can anyone reproduce this as well? Is it possible that Microsoft has pulled the Win10 updates for November???<\/p><\/blockquote>\n<p>The behavior was confirmed by another administrator for Windows Servers 2016 (Windows Server 2019 does not seem to be affected). Anyone else with this problem?<\/p>\n<h2>Authentication issues with domain controllers<\/h2>\n<p>In my German Windows 11 blog post there is the <a href=\"https:\/\/www.borncity.com\/blog\/2021\/11\/10\/patchday-windows-11-updates-9-november-2021\/#comment-116913\" target=\"_blank\" rel=\"noopener\">following comment<\/a> that the security updates should not be installed on domain controllers. Microsoft has since published the support post <a href=\"https:\/\/docs.microsoft.com\/en-ca\/windows\/release-health\/status-windows-10-1809-and-windows-server-2019#2748msgdesc\" target=\"_blank\" rel=\"noopener\">Authentication might fail on DCs with certain Kerberos delegation scenarios<\/a> about this.<\/p>\n<ul>\n<li>After installing the November 9, 2021 security update on domain controllers (DCs), the specified server versions may experience authentication failures on servers related to Kerberos tickets purchased through S4u2self.<\/li>\n<li>The authentication failures are the result of Kerberos tickets acquired through S4u2self and used as proof tickets for protocol transition for delegation to backend services that fail signature validation.<\/li>\n<li>Kerberos authentication fails for Kerberos delegation scenarios where the front-end service retrieves a Kerberos ticket on behalf of a user to access a back-end service.<\/li>\n<\/ul>\n<p>Major Kerberos delegation scenarios, where a Kerberos client provides an evidence ticket to the front-end service, are not affected. Pure Azure Active Directory environments are not affected by this issue.<\/p>\n<p>Microsoft states that end users in your environment may not be able to log in to services or applications that use Single Sign On (SSO) with Active Directory on-premises or in a hybrid Azure Active Directory environment. Updates installed on client Windows devices will not cause or affect this issue, according to Microsoft. Microsoft cites the following server versions as affected &#8211; I've added the updates:<\/p>\n<ul>\n<li>KB5007206: Windows Server 2019<\/li>\n<li>KB5007192: Windows Server 2016<\/li>\n<li>KB5007247: Windows Server 2012 R2<\/li>\n<li>KB5007260:\u00a0 Windows Server 2012<\/li>\n<li>KB5007236: Windows Server 2008 R2 SP1<\/li>\n<li>KB5007263: Windows Server 2008 SP2<\/li>\n<\/ul>\n<p>German blog reader MOM20xx writes <a href=\"https:\/\/www.borncity.com\/blog\/2021\/11\/10\/patchday-windows-11-updates-9-november-2021\/#comment-116931\" target=\"_blank\" rel=\"noopener\">here<\/a>, that the problem does not only affect domain controllers. He had the first authentication problems on patched servers, when the domain controllers were not patched at all. Environments affected by the problems may be using the following features:<\/p>\n<ul>\n<li>Azure Active Directory (AAD) Application Proxy Integrated Windows Authentication (IWA) using Kerberos Constrained Delegation (KCD)<\/li>\n<li>Web Application Proxy (WAP) Integrated Windows Authentication (IWA) Single Sign On (SSO)<\/li>\n<li>Active Directory Federated Services (ADFS)<\/li>\n<li>Microsoft SQL Server<\/li>\n<li>Internet Information Services (IIS) using Integrated Windows Authentication (IWA)<\/li>\n<li>Intermediate devices including Load Balancers performing delegated authentication<\/li>\n<\/ul>\n<p>Then the following errors should occur in the environment in question:<\/p>\n<ul>\n<li><strong>Event Viewer <\/strong>might show <strong>Microsoft-Windows-Kerberos-Key-Distribution-Center<\/strong> <a href=\"https:\/\/docs.microsoft.com\/en-us\/previous-versions\/windows\/it-pro\/windows-server-2008-R2-and-2008\/cc733969(v=ws.10)\" target=\"_blank\" rel=\"noopener\">event 18<\/a> logged in the <strong>System <\/strong>event log<\/li>\n<li>Error 0x8009030c with text <strong>Web Application Proxy encountered an unexpected<\/strong> is logged in the Azure AD Application Proxy event log in Microsoft-AAD Application Proxy Connector event 12027<\/li>\n<li>Network traces contain the following signature similar to the following:\n<ul>\n<li>7281 24:44 (644) 10.11.2.12 &lt;app server hostname&gt;.contoso.com KerberosV5 KerberosV5:TGS Request Realm: CONTOSO.COM Sname: http\/xxxxx-xxx.contoso.com<\/li>\n<li>7282 7290 (0) &lt;hostname&gt;. CONTOSO.COM &lt;IP address of the application server making the TGS request&gt;<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<p>I've noticed a thread about the event entries in System (at least according to my interpretation) today at German site administrator.de within <a href=\"https:\/\/administrator.de\/content\/detail.php?id=1493305028&amp;token=659\" target=\"_blank\" rel=\"noopener\">this post<\/a>. Microsoft is working on a fix.<\/p>\n<p><strong>Addendum:<\/strong> Fixes are out now &#8211; see\u00a0<a href=\"https:\/\/borncity.com\/win\/2021\/11\/15\/windows-10-windows-server-sonderupdates-korrigieren-dc-authentifizierungsfehler-14-11-2021\/\" rel=\"bookmark\">Windows 10\/Windows Server: Out-of-band updates fixes DC authentification error (2021\/11\/14)<\/a>.<\/p>\n<p><strong>Similar articles<br \/>\n<\/strong><a href=\"https:\/\/borncity.com\/win\/2021\/11\/10\/microsoft-security-update-summary-9-november-2021\/\">Microsoft Oktober 2021 Patchday (November 9, 2021)<\/a><br \/>\n<a href=\"https:\/\/borncity.com\/win\/2021\/11\/10\/patchday-windows-10-updates-9-november-2021\/\">Patchday: Windows 10-Updates (November 9, 2021)<\/a><br \/>\n<a href=\"https:\/\/borncity.com\/win\/2021\/11\/10\/patchday-windows-8-1-server-2012-updates-9-november-2021\/\">Patchday: Windows 8.1\/Server 2012 Updates (November 9, 2021)<\/a><br \/>\n<a href=\"https:\/\/borncity.com\/win\/2021\/11\/10\/patchday-updates-fr-windows-7-server-2008-r2-9-november-2021\/\">Patchday: Updates for Windows 7\/Server 2008 R2 (November 9, 2021)<\/a><br \/>\n<a href=\"https:\/\/borncity.com\/win\/2021\/11\/10\/patchday-windows-11-updates-9-november-2021\/\">Patchday: Windows 11 Updates (November 9, 2021)<\/a><br \/>\n<a href=\"https:\/\/borncity.com\/win\/2021\/11\/11\/patchday-microsoft-office-updates-9-november-2021\/\">Patchday Microsoft Office Updates (November 9, 2021)<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>[German]Microsoft has release various security updates on November 9, 2021 patchday. Beside the already known printing issues caused by previous updates, there are now authentication problems with domain controllers (DCs) in certain Kerberos delegation scenarios. Probably leads to entries in &hellip; <a href=\"https:\/\/borncity.com\/win\/2021\/11\/11\/november-2021-patchday-probleme-wsus-dc-events\/\">Continue reading <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[463,580,22,2],"tags":[166,2687,195,194],"class_list":["post-22091","post","type-post","status-publish","format-standard","hentry","category-issue","category-security","category-update","category-windows","tag-issues","tag-patchday-11-2021","tag-update","tag-windows"],"_links":{"self":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts\/22091","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/comments?post=22091"}],"version-history":[{"count":0,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts\/22091\/revisions"}],"wp:attachment":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/media?parent=22091"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/categories?post=22091"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/tags?post=22091"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}