WSUS [A certificate chain processed, but terminated in a root certificate which is not trusted by the trust provider (hr = 0x800b0109), Message: Unable to search for updates]

chirag patel 1 Reputation point
2022-10-17T15:19:42.97+00:00

Windows clients failed to autheticate with WSUS server and get above subjected error. The CA certificate is invalid in windows update log file.

When i look at the client machine and try to reach WSUS server, I get bad server certificate or invalid server certificate.

FYI - Certificate on server looks good and root certificate on client also good and valid but still some clients wont get the updates because of this certificate error.

I tried below to troubleshoot but did not work.

deleted the softwaredistribution folder.
Clear SSL state in internet explorer.
browser history deleted.
Date and time also correct.

Could you please help me with this issue. Please let me know if you need addiditonal information.

Windows for business | Windows Server | User experience | Other
Windows for business | Windows Client for IT Pros | User experience | Other
{count} votes

2 answers

Sort by: Most helpful
  1. Adam J. Marshall 10,356 Reputation points MVP
    2022-10-17T15:49:02.877+00:00

    If there's a certificate error, WSUS Clients will not talk to WSUS. You must fix the underlying certificate error. 9 times out of 10, if the certificate has not expired, the issue is that the certificate has not been installed on the client's Trusted Root Certificate Authorities store.

    https://www.ajtek.ca/wsus/how-to-setup-manage-and-maintain-wsus-part-7-ssl-setup-for-wsus-and-why-you-should-care/

    Either via GPO or by a manual import process.


  2. CherryZhang-MSFT 6,496 Reputation points
    2022-10-24T09:34:19.95+00:00

    Hi @chirag patel ,

    1, Please help confirm that GPO " Allow signed content from intranet Microsoft update service location " is enabled

    Navigate to Computer configuration > Policies > Administrative Templates > Windows Components > Windows Update. Select "Allow signed content from intranet Microsoft update service location" and click Edit policy settings.
    253531-1.png

    2, We can see the published certificate exists in the client's Trusted Root Certification Authorities, right?
    253458-2.png

    3, If the problem is still can’t be solved. Please upload a full windowsupdate.log for us to discuss together.

    Thanks for your time and patience!

    Best regards,
    Cherry

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.