question

ValentinBeduhn-8569 avatar image
0 Votes"
ValentinBeduhn-8569 asked learn2skills commented

WSUS not downloading over https from Upstreamserver

Our WSUS Downstreamserver downloads over http and 8530 from the Main WSUS (configured as an SSL WSUS). But I want him to download via https and port 8531. Can someone help me?

windows-server-update-services
· 2
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

To follow-up, Please let us know if you have further query on this.
Please don’t forget to Accept the answer

0 Votes 0 ·

To follow-up, Please let us know if you have further query on this.
Please don’t forget to Accept the answer

0 Votes 0 ·
learn2skills avatar image
0 Votes"
learn2skills answered learn2skills edited

HI @ValentinBeduhn-8569

Configure SSL for downstream WSUS servers
The following instructions configure a downstream server to synchronize to an upstream server that uses SSL.

To synchronize a downstream server to an upstream server that uses SSL
1. Log on to the computer by using a user account that is a member of the local Administrators group or the WSUS Administrators group.
2. Click start, click All Programs, click Administrative Tools, and then click Windows Server Update Service.
3. In the right pane, expand the server name.
4. Click Options, and then click Update Source and Proxy Server.
5. On the Update Source page, select Synchronize from another Windows Server Update Services server.
6. Type the name of the upstream server into the Server name text box. Type the port number that the server uses for SSL connections into the Port number text box.
7. Select the Use SSL when synchronizing update information check box, and then click OK.

Configure SSL on the WSUS server
WSUS requires two ports for SSL: one port that uses HTTPS to send encrypted metadata, and one port that uses HTTP to send updates. When you configure WSUS to use SSL, consider the following:

You cannot configure the whole WSUS website to require SSL because all traffic to the WSUS site would have to be encrypted. WSUS encrypts update metadata only. If a computer attempts to retrieve update files on the HTTPS port, the transfer will fail.

If the Answer is helpful, please click Accept Answer and up-vote, this can be beneficial to other community members.



5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

AllenLiu-MSFT avatar image
0 Votes"
AllenLiu-MSFT answered

@ValentinBeduhn-8569
Thank you for posting in Microsoft Q&A forum.
You may also refer to the article for more details:
How to Configure SSL between WSUS upstream and downstream servers
(Third-party link, just for your reference)


If the response is helpful, please click "Accept Answer" and upvote it.
Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.


5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.