Security Compliance
Create or replace a WSUS publishing certificate for third-party publishing
Once you have Patch Manager up and running, you need to create your publishing certificate. This article provides guidelines to create or replace an existing certificate for third-party publishing.
First published date
Last published date
Overview
Product section
Resolution
- Log in to the Patch Manager Administrator Console as an administrator.
- In the navigation pane, expand Administration and Reporting and select Software Publishing.
- Click Server Publishing Setup Wizard in the Actions pane.
- Click the WSUS Server drop-down menu and select the upstream WSUS Server..
- Select Create self-signed certificate to create or replace the existing certificate.
- Click Next.
- Select the Patch Manager servers, upstream servers, and downstream WSUS servers that require the publishing certificate, and then click Next.
- Click Finish.
After you create the certificate, see Using Group Policy to Configure Managed Clients in the Patch Manager Administrator Guide for details about importing the certificate to your Group Policy (GPO).
Key local stores that require the certificate on client servers and the SCCM server include Trusted Root Certification Authorities and Trusted Publishers stores.