@Steve Y
For some reason, I left it last night and the computer finally registered - with no changes made. It shouldn't take weeks to register a device when on the same switch, with no firewalling, routing, or anything to prevent it, right?
We should wait for a while and the clients will registered to the WSUS server, about a day if there is no error occurred.
I've enabled SSL this morning, and its failing to connect again, but I suspect its just going to take a long time before reporting in again.
Perhaps you didn't enabled the SSL correctly.
According to the log you provided, the clients did try to connect to the WSUS server under 8531 not 8530. But I didn't find any error information. Perhaps the log is too short to review.
Refer to the below step to check the connection between the WSUS server and the clients:
We could open the IE on the client and connect to the WSUS server as the below URL:
https://WSUS server's FQDN:8531/selfupdate/iuident.cab
If the connection is OK, a file will be downloaded from the WSUS server to the client.
Please refer to the below link to configure the SSL on the WSUS Server:
https://learn.microsoft.com/en-us/windows-server/administration/windows-server-update-services/deploy/2-configure-wsus#25-secure-wsus-with-the-secure-sockets-layer-protocol
Note that we have to import the certificate to all the clients which registered to the WSUS server to enable the SSL.
Hope the above will be helpful.
Rita
If the response is helpful, please click "Accept Answer" and upvote it.
Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.