A new Flexera Community experience is coming on November 25th. Click here for more information.
A full guide on how to create a GPO to distribute WSUS certificate and Windows update settings.
This short guide describes how to create a Group Policy Object (GPO) for CSI-WSUS by using the Group Policy Management console. Once the GPO is created and linked to the correct Organizational Unit (OUs), the computers in that OU will download the WSUS publisher's self-signed certificate and Windows settings so that third-party updates can be downloaded correctly.
Login to your Software Vulnerability Manager account.
Navigate to Patching > Configuration > WSUS / System Center > Configure Upstream Server.
Connect to the WSUS server and then click Next.
On Step 2, click "Export Signing Certificate" which will be saved to your documents folder.
Computers will download the Policy after the next policy refresh interval or reboot. You can force the policy to apply by running the command:
gpupdate /force
Sometimes it may take several hours for the policy to actually propagate. You can verify that the GPO is being applied to the machine by checking to see if the certs have been added to the appropriate cert stores on any given machine.
If the GPO has not been applied yet, or it is not being applied to the machine in question, then you will receive an error (0x800b0109) when deploying third-party updates.
on Nov 16, 2018 04:45 PM - edited on Sep 16, 2019 03:29 PM by RDanailov