WSUS Public CA SSL

Matthew Tipler 21 Reputation points
2021-10-04T17:18:31.8+00:00

Hey guys,

I've a downstream DMZ based WSUS server WSUS.CONTOSO.LOCAL deployed to service internet based clients.

I have a public CA created SSL certificate (WSUS.CONTOSO.COM) to apply to the WSUS site (8531) to make WSUS accessible to internet based clients over SSL / HTTPS.

However, if i run WsusUtil.exe configuressl WSUS.CONTOSO.COM it breaks access to the WSUS console which requires the server hostname in order to function WSUS.CONTOSO.LOCAL.

Any idea what the solution is here? I'm a little stumped.

Regards.

Windows Server
Windows Server
A family of Microsoft server operating systems that support enterprise-level management, data storage, applications, and communications.
12,058 questions
Windows Server Infrastructure
Windows Server Infrastructure
Windows Server: A family of Microsoft server operating systems that support enterprise-level management, data storage, applications, and communications.Infrastructure: A Microsoft solution area focused on providing organizations with a cloud solution that supports their real-world needs and meets evolving regulatory requirements.
509 questions
0 comments No comments
{count} votes

2 answers

Sort by: Most helpful
  1. Adam J. Marshall 8,541 Reputation points MVP
    2021-10-06T00:00:26.73+00:00

    Remove the "Server" from the WSUS MMC Console, then right click and Add Server, fill out wsus.contoso.com, put a checkmark in SSL, and click Add

    It should then work.


  2. Limitless Technology 39,331 Reputation points
    2021-10-06T14:36:34.447+00:00

    Hello,

    Thank you for your question.

    You must import the certificate to all computers that will communicate with the WSUS server. This includes all client computers, downstream servers, and computers that run the WSUS Administration Console. The certificate should be imported into the local computer Trusted Root CA store or into the Windows Server Update Service Trusted Root CA store.

    Please have a look on below Microsoft article mentioning how to secure WSUS with SSL.

    https://learn.microsoft.com/en-us/previous-versions/windows/it-pro/windows-server-2008-R2-and-2008/dd939849(v=ws.10)#secure-wsus-with-the-secure-sockets-layer-protocol

    https://social.technet.microsoft.com/Forums/lync/en-US/1c89036e-3a06-49ee-bfbe-dfee8104c7ab/externally-facing-wsus-server-best-practice?forum=winserverwsus

    ----------------------------------------------------------------------------------------------------------------------

    --If the reply is helpful, please Upvote and Accept as answer--

    0 comments No comments