Share via

WSUS SSL Setup on Downstream

RSA111 211 Reputation points
2022-07-19T07:36:09.677+00:00

Hello,

I have one WSUS Upstream server setup on Windows Server 2016 and another WSUS Downstream server setup on Windows Server 2016 in DMZ.

The Upstream server WSUS01 is designed to provide an updates to the internal desktop and those desktop doesn't have any Internet connectivity.

The Downstream server WSUS02 is a replica of upstream server and only provides metadata to its client and clients need to download the updates from Microsoft Update server as most of the clients are roaming laptops.

The SSL is configured between server to client and server to server using domain generated certificate and binding and all steps were completed.

The clients are reporting to the Upstream server WSUS01 without any issues.

But for Downstream server WSUS02 and for its any random client, what exactly troubleshooting is needed.

For testing I have taken a workgroup laptop and using gpedit.msc I have configured local GPO with WSUS02 URL, which points it to the WSUS02 server. This laptop is not reaching out to the Downstream server WSUS02. If I check its WindowsUpdate logs I could see WSUS location configured as WSUS02 server.

Please advise.

Windows for business | Windows Server | User experience | Other
0 comments No comments

Answer accepted by question author

PrashantV 81 Reputation points
2022-07-19T09:57:00.553+00:00

Looks like certificate authority root CA is not available on the machine. Please import the certificate and check .

Was this answer helpful?

0 comments No comments

0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.