Security Compliance

Publishing packages error: Verification of Signature failed for file in Patch Manager

This article addresses an an error that occurs when you publish third-party updates to your WSUS server. Error: Verification of Signature failed for file

First published date

11/16/2018 12:43 AM

Last published date

11/16/2018 12:43 AM

Overview

When you publish third-party updates to your WSUS server, the following error displays: 

Verification of Signature failed for file:

This error is also seen in scenarios where you have multiple WSUS servers and you are trying to publish a package to different WSUS servers without re-signing during the publishing wizard.

Product section

Patch Manager

Cause

  • Publishing the same package that was published to a different WSUS server without re-signing the package during the publishing wizard.
  • The package was signed with an expired or invalid certificate. 
  • Unknown in some cases

Resolution

Solution 1: Run the Provision WSUS Server for Publishing Wizard 

This procedure creates or distributes the certificate needed for publishing.

  1. Log in to the Patch Manager Administrator Console as an administrator.
  2. Expand Administration and Reporting and select Software Publishing.
  3. In the Actions pane, click Server Publishing Setup Wizard.
  4. In the wizard, click the WSUS Server drop-down menu and select your WSUS server.
  5. Complete the remaining fields, and click Next.
  6. Complete the wizard. 

Verification

Run Microsoft MMC and add the snap-in for certificates for the computer account on the WSUS and the Patch Manager servers.
The certificates should be in the following:

  • Trusted Publishers store
  • Trusted Root store

On the WSUS server, the certificates should be in the WSUS certificate store.

Solution 2:

If the steps in Solution 1 do not help:

  1. Back up the existing WSUS cert from the MMC snapin.
  2. Delete the WSUS cert from Trusted Root and Trusted Publishers store(s).
  3. Follow steps in Solution 1  and then verify the result .
  4. Make sure there are no duplicate or old certificates in the Trusted Publishers and Trusted Root and WSUS store.
Solution 3:
- If this is error is generated when you publish select third party update, while you can publish majority of them successfully, then please make sure you have upgraded your patch manager version to the latest release. Because this helped one customer who was on 2020.2.6