Showing posts with label SP2. Show all posts
Showing posts with label SP2. Show all posts

Exchange 2010 SP2 Roll Up 4 Does Not Install - Error Code 1603

Tuesday, August 21, 2012
Event 1024 MSiInstaller - Error code 1603

Update: Microsoft is asking customers who are having this issue to open a support case with Microsoft Technical Support.  They see random support calls related to this going back to Exchange 2007, but want to reproduce the issue with customers currently seeing this issue with Exchange 2010 SP2 UR4. 

See
http://support.microsoft.com/kb/319726 for MTS phone numbers in your area. 
I had an interesting problem installing Exchange 2010 SP2 Update Rollup 4 (UR4) on servers that have never had issues installing updates before.  When I tried to install SP2 UR4 on the Edge Transport or typical installation servers it would rollback the installation and log the following error in the application log:
Product: Microsoft Exchange Server - Update 'Update Rollup 4 for Exchange Server 2010 Service Pack 2 (KB2706690) 14.2.318.2' could not be installed. Error code 1603. Windows Installer can create logs to help troubleshoot issues with installing software packages.
Normally this issue us fixed by installing the Update Rollup from an elevated CMD prompt (see http://blog.c7solutions.com/2011/03/exchange-2010-update-rollups-and-error.html), but this time it still wasn't working.

I enabled MSI Installer logging as per http://go.microsoft.com/fwlink/?LinkId=23127 and dived into the setup logs.  I found the following error being logged in the ServiceControl.log:
[19:51:28] [Error] System.Management.Automation.ParseException: At C:\Program Files\Microsoft\Exchange Server\V14\Scripts\ManageScheduledTask.ps1:462 char:5
+                 return $success
+                 ~~~~~~~~~~~~~~~
Control cannot leave a finally block.
 
at System.Management.Automation.Internal.PipelineProcessor.SynchronousExecuteEnumerate(Object input, Hashtable errorResults, Boolean enumerate)
at System.Management.Automation.PipelineOps.InvokePipeline(Object input, Boolean ignoreInput, CommandParameterInternal[][] pipeElements, CommandBaseAst[] pipeElementAsts, CommandRedirection[][] commandRedirections, FunctionContext funcContext)
at System.Management.Automation.Interpreter.ActionCallInstruction`6.Run(InterpretedFrame frame)
at System.Management.Automation.Interpreter.EnterTryCatchFinallyInstruction.Run(InterpretedFrame frame)
at System.Management.Automation.Interpreter.EnterTryCatchFinallyInstruction.Run(InterpretedFrame frame)
I examined the ManagedScheduleTask.ps1 script which apparently disables the 'Database One Copy Alert' scheduled task, but could not determine what the error is.  I also ran the script from EMS, which returned the same error.  Nothing showed up on the Interwebs other than a few references to PowerShell 3.0, which is not installed on these servers.

I finally resolved it by renaming the ManageScheduledTask.ps1 script to ManageScheduledTask.old and creating a new empty ManageScheduledTask.ps1 script.  The script must exist and return a non-error code when executed for the UR4 installer to work.  I renamed the script back when the installer finished.

This may be an esoteric problem, but I wanted to document it in case anyone else has the same problem.  If this does happen in your environment, please leave a comment below.  Thanks.

Follow Up (10/12/2012)
I've found several times so far that this happens to servers that have the Windows Management Framework 3.0 installed.  The RTW version is found at http://www.microsoft.com/en-us/download/details.aspx?id=29939.  The Windows Management Framework 3.0 includes PowerShell 3.0, which is not compatible with Exchange 2010 and explains why the ManageScheduledTask.ps1 script doesn't run properly.

Check the installed updates on the problem server for the Windows Management Framework 3.0 and try uninstalling it to see if it solves the problem.  The Framework allows you to manage servers remotely from the Windows Server 2012 Server Management Console.

Microsoft re-released the following updates to fix a code-signing issue that may affect some customers in the near future:
See the EHLO Blog article, Re-released Exchange 2010 and Exchange 2007 update rollups for more information.  The re-release of the these update rollups has no bearing on the script issue covered in this article, but I do recommend installing the re-released updates on your Exchange servers to prevent future code-signing issues.
Read more ...

New Scripts in Exchange 2010 SP2

Thursday, December 8, 2011
As with most Microsoft Exchange Service Packs and some Update Rollups, Exchange Server SP2 introduces five new scripts that are useful to manage and monitor your Exchange organization. 

All the canned Exchange scripts are located in the %ExchangeInstallPath%\Scripts folder (normally, C:\Program Files\Microsoft\Exchange Server\V14\Scripts).  You can easily change to this folder within the Exchange Management Shell (EMS) using the command cd $exscripts.  It looks dirty, but it's not.  :)

The five new(ish) Exchange Service Pack 2 scripts are:

  • ConvertOABVDir.ps1 - This script will convert the OAB virtual directory to an IIS web application, as well as create a new application pool called MSExchangeOabAppPool. Converting the OAB virtual directory is necessary to support different authentication methods like Kerberos and Certificate authentication.  You need to execute this script on each Client Access Server.  Ross Smith wrote about this script in his article, Recommendation: Enabling Kerberos Authentication for MAPI Clients. 
  • LargeToken-IIS_EWS.ps1 -- This script and the following script, LargeToken-Kerberos.ps1, were actually released in Update Rollup 4 for Exchange Server SP1.  LargeToken-IIS_EWS.ps1 increases the value of the MaxFieldLength and MaxRequestBytes IIS parameters on all CAS servers in the Active Directory site. In addition, it changes the EWS Web.config bindings on Exchange 2010 SP1 and the CAS servers.  See the article, You cannot view the free/busy information of users in a mixed Exchange Server 2007 and Exchange Server 2010 environment for more info.
  • LargeToken-Kerberos.ps1 -- This script sets HKLM\System\CurrentControlSet\Control\Lsa\Kerberos\Parameters values MaxPacketSize to DWORD 1 and MaxTokenSize to DWORD 65535 on all machines in the domain (or on specified machines).  See New resolution for problems with Kerberos authentication when users belong to many groups for more information on these keys.
  • Reenable-AuditLoggingAgent.ps1 -- On Exchange 2010 RTM, if you run "Setup.com /prepareAD" to upgrade to Exchange 2010 SP1, the "Admin Audit Log Agent" gets disabled.  It will not run again until the SP1 installation has completed, meaning that admin auditing will not be captured.  This script fixes that issue by rolling back msExchVersion of the agent in Active Directory.  Note: The issue goes away once SP1 installation is complete.
It's great to see these new scripts make it into mainstream production rollouts.

Read more ...

New Prerequisite for Exchange 2010 SP2

Monday, December 5, 2011

Exchange Server 2010 Service Pack 2 (SP2) was released today without the accompanying release notes.  Until they are released, know that SP2 requires an additional role service for Client Access Servers to support the new Outlook Web App Mini feature: The IIS 6 WMI Compatibility component.

Before you install Exchange 2010 SP2 you need to add this role service using either of the two following methods.

From Windows Server Manager:
  • Open Server Manager and navigate to Roles | Web Server (IIS)
  • Right-click Web Server (IIS) and select Add Role Services
  • Scroll down to IIS 6 Management Compatibility and select IIS 6 WMI Compatibility and click Install
From Windows Powershell:
  • Open Windows Powershell as administrator
  • Enter the following commands:
Import-Module ServerManager
Add-WindowsFeature Web-WMI
Now you can install Exchange 2010 SP2 as planned.
Read more ...

Exchange 2010 Service Pack 2 is Now Available

Friday, December 2, 2011
Today Microsoft released Exchange Server 2010 Service Pack 2 (SP2).  Along with numerous bugfixes, SP2 includes the following new features:
  • Cross-Site Silent Redirection for Outlook Web App (a.k.a. my favorite new feature): With Service Pack 2, you will have the ability to enable silent redirection when CAS must redirect an OWA request to CAS infrastructure located in another Active Directory site. Silent redirection can also provide a single sign-on experience when Forms-Based Authentication is used. Yes!
  • Address Book Policies: Allows organizations to segment their address books into smaller scoped subsets of users providing a more refined user experience than the previous manual configuration approach. The Exchange Team blogged about this new feature recently in GAL Segmentation, Exchange Server 2010 and Address Book Policies.
  • Outlook Web App (OWA) Mini: A browse-only version of OWA designed for low bandwidth and resolution devices. Based on the existing Exchange 2010 SP1 OWA infrastructure, this feature provides a simple text based interface to navigate the user’s mailbox and access to the global address list from a plurality of mobile devices.
  • Hybrid Configuration Wizard: Organizations can choose to deploy a hybrid scenario where some mailboxes are on-premises and some are in Exchange Online with Microsoft Office 365. Hybrid deployments may be needed for migrations taking place over weeks, months or indefinite timeframes. This wizard helps simplify the configuration of Exchange sharing features, like: calendar and free/busy sharing, secure mailflow, mailbox moves, as well as online archive.
All fixes contained within update rollups released prior to Service Pack 2 will also be contained within SP2. Details of the regular Exchange 2010 release rhythm can be found in Exchange 2010 Servicing.

You can download Microsoft Exchange Server Service Pack 2 here.
Read more ...

How to Integrate Lync Server 2010 with Exchange 2010 SP1+ OWA

Thursday, September 30, 2010
Lync Server 2010 can be integrated with Exchange 2010 SP1 or better, so that Exchange Outlook Web App can also act as a Lync web client.  Once integrated, users will automatically log into Lync when they log into OWA.  The OWA interface changes to include the following new features:
  • Sign In and Sign Out - Users can sign in or sign out of instant messaging from OWA.  Once signed in, the user will automatically sign into IM every time they sign into OWA.
  • Presence - User presence information is available for Lync users, showing a colored chiclet indicating their availability.
  • Contact List - The user's Lync IM contact list is made available in the OWA folder pane.  Users can be added and removed, and contact groups can be managed directly from OWA.
  • Instant Messaging - Lync users can chat with other Lync users using instant messaging directly from OWA.
  • Right-Click Functionality - Right-click menus and actions are updated to include new Lync features.  For example, right-click an email address to chat with the user or add them to an IM contact list.
All of these new OWA features can be seen in the screenshot below:


An instant messaging chat session can be started from OWA by double-clicking a contact in the Contact List or right-clicking an email address and choosing Chat.


This article explains how to configure Lync Server 2010 integration with Exchange 2010 SP1 or better.  I will assume that you have functional Lync Server 2010 and Exchange Server 2010 SP1 or SP2 servers already set up.  Let's get started.

Download and install the Microsoft Office Communications Server 2007 R2 Web Service Provider from http://www.microsoft.com/downloads/en/details.aspx?familyid=CA107AB1-63C8-4C6A-816D-17961393D2B8&displaylang=en on your Client Access Server.  This MSI package contains the installation programs to the local hard drive.  Normally it will put them in C:\Web Service Provider Installer Package, but I've also seen it install to a different drive.  Make note of the location it uses during installation.

The package will extract the following files:


Next, download and save the OCS 2007 R2 Web Service Provider Hotfix KB 981256 from http://www.microsoft.com/downloads/en/details.aspx?FamilyID=45C94403-39FA-44D3-BE23-07F25A2D25C7 to the same C:\Web Service Provider Installer Package folder.

Download and save the Unified Communications Managed API 2.0 Redist (64 Bit) Hotfix KB 2400399 from http://www.microsoft.com/downloads/en/details.aspx?FamilyID=1F565A42-71D2-4FBD-8AE0-4B179E8F02AB to the same C:\Web Service Provider Installer Package folder.

If your CAS server is running Exchange 2010 SP1 on Windows Server 2008 R2, you need to download and save the UcmaRedist.msp patch in Microsoft Office Communications Server 2007 R2 Hotfix KB 968802 from http://www.microsoft.com/download/en/details.aspx?displaylang=en&id=19178.  The tricky part here is that the file name (UcmaRedist.msp) is the same as the Communications Managed API 2.0 Redist (64 Bit) Hotfix KB 2400399 you just downloaded.  Just rename this file name to something like UcmaRedist-R2.msp.

Now install the following files as Adminstrator in this order:
  1. vcredist_x64.exe
  2. UcmaRedist.msi
  3. UcmaRedist.msp
  4. UcmaRedist-R2.msp, if your CAS is running on Windows Server 2008 R2
  5. CWAOWASSP.msi
  6. CWAOWASSP.msp
  7. dotnetfx35setup.exe, if the .NET Framework 3.5 is not installed on Windows Server 2008.  For Windows Server 2008 R2, install the .NET Framework 3.5.1 feature from Server Manager.
Note that the MSI and MSP packages have a limited GUI during setup and don't indicate that they've installed successfully.

Next we need to configure the Exchange 2010 SP1 Client Access Server for Lync Server integration.  Run the following two commands from the Exchange Management Shell on the CAS:

$cert = (Get-ExchangeCertificate | Where {$_.Services -ilike "*IIS*"}).Thumbprint
Get-ExchangeServer (hostname)| Get-OWAVirtualDirectory | Set-OWAVirtualDirectory -InstantMessagingType OCS -InstantMessagingEnabled:$true -InstantMessagingCertificateThumbprint $cert -InstantMessagingServerName pool.domain.com
Be sure to change pool.domain.com to the FQDN of your Lync Server FE pool.  (hostname) automatically resolves to the hostname of the server you're running the cmdlet from.

Now we need to configure the Lync 2010 server.  Use the Lync Server Topology Builder to add a new Trusted Application Pool, as follows:
  • Open the existing topology.
  • Expand your Lync Server 2010 > your sitename.
  • Right-click Trusted application servers and select New Trusted Application Pool.
  • Enter your CAS server or CAS array's FQDN in the Pool FQDN field, select Single Computer Pool and click Next.  If you're using a hardware load balancer with separate VIPs for OWA and MAPI connections, use the FQDN for the OWA (HTTPS) connections.
  • Select the Front End Pool for the Trusted Application Pool.
  • Click Finish.
  • Right-click the new Trusted Application Server and select Edit Properties.
  • Clear the check box for Enable replication of configuration data to this pool and click OK.
  • Publish the new topology.  If you used the CAS Array or HTTPS VIP FQDN above, you will get a warning about the computer name not existing in Active Directory.  This is safe to ignore.
The final step is to create a new CsTrustedApplication using the Lync Server Management Shell on the Lync 2010 server.  Run the following command from the management shell:

New-CsTrustedApplication -ApplicationID ExchangeOutlookWebApp -TrustedApplicationPoolFqdn cas.domain.com -Port 9999
Enable-CsTopology
Be sure to change the TrustedApplicationPoolFqdn value in the command above to the FQDN of your CAS server or CAS array.  The Port value can be any unused TCP port.

Now login to Outlook Web App and enjoy the new Lync Server goodness!


Read more ...

Be Aware: Windows Server 2008 SP2 Re-enables Disabled NICs

Wednesday, June 10, 2009

Be aware installing Windows Server 2008 Service Pack 2 (SP2) will re-enable any network adapters that were disabled prior to the update. This will also affect computers updated with Windows Vista Service Pack 2.

[Before installing SP2]

[After installing SP2]

This is important for several reasons. It is best practice on Hyper-V servers to disable the virtual NIC assigned to VM guests, so that a host with a dedicated management NIC does not use the NICs assigned to VM guests. SP2 re-enables all these virtual NICs, as well.

Sometimes disabled NICs should only be enabled for disaster recovery purposes. Enabling these NICs at startup could have dire consequences in these rare situations.

It's important to understand that if you're using the Windows Firewall, the server uses the most secure firewall network profile for all NICs. If your domain joined computer has more than one NIC, but only the NIC that is used to connect to the domain is enabled, the Windows Firewall uses the Domain Network profile. However, after installing SP2 the computer will start up with all NICs enabled. If the previously disabled NICs are not connected, the Windows Firewall will use the Public Network profile, which uses much different firewall policies -- potentially causing service interruptions.

My advice is to document your network connections prior to installing Windows Server 2008 SP2, so you can reconfigure them when your done with the update.

Read more ...

Well, that was fun...

Wednesday, May 27, 2009
Being that Windows Server 2008 Service Pack 2 was released today, you just know I had to load it up on my production machines. So confident in the build quality, I am, I decided to install it on all my physical and virtual servers over an RDP connection.

The installs went perfectly. So good, in fact, that I even ran the CompCln.exe utility that's included in SP2 that deletes all the backup files created during the SP2 installation process. No turning back now, and why would I? Everything installed just fine.

...until I got home to my server and found that the display, keyboard and mouse were unresponsive. I RDP'd into the server and restarted it. Fail. Started in Safe Mode. Fail. Last Known Good. Fail. Fail. Fail.

Not relishing having to rebuild my main Hyper-V server, I gave it one last shot by starting up in Safe Mode Command Prompt Only mode. I suspected it was the VGA driver, so I changed to the Windows\System32\Drivers folder, renamed the ATI video driver (aitkmdag.sys) and restarted. Success! The server started up normally using the Standard VGA Graphics Adapter. Crisis averted.

I can't blame SP2 for this mess. I attibute it to the buggy beta ATI drivers I had installed. In any event, I'm glad I got the server up and running without having to rebuild it all.
Read more ...

Windows Server 2008 and Vista Service Pack 2 Released

Wednesday, May 27, 2009
Today, Microsoft released Service Pack 2 for Windows Server 2008 and Windows Vista.

Service Pack 2 (SP2) for Windows Server 2008 and Windows Vista is an update to Windows Vista and Windows Server 2008. It provides customer and partner feedback-driven fixes into a single service pack, minimizing deployment and testing complexity. In addition to all previously released updates since SP1, SP2 supports new types of hardware, and adds support for several emerging standards.

Details and download links can be found at http://technet.microsoft.com/en-us/windows/dd767623.aspx?ITPID=wtcfeed.

Notable changes in Windows Server 2008 SP2 and Windows Vista SP2 can be viewed from this link.

Along with all the other fixes and rollups that are currently available through hotfixes and rollups, it includes improved power management and new Group Policy settings.
Read more ...