Wsus Package Publisher: Installation Guide: Check Pre-Requisites
Wsus Package Publisher: Installation Guide: Check Pre-Requisites
I.
II.
III.
Check pre-requisites :
a. Microsoft .NET 4.0 must be installed on the local machine.
b. You must be Administrator of the local machine.
c. The Wsus server must be at release 3.0 SP2 or greater.
d. You can run Wsus Package Publisher on the Wsus server, or on a workstation. If so,
Wsus Administration Console must be installed first (or RSAT for Windows 8). And
the account use to run Wsus Package Publisher must be part of the Wsus
Administrators group of the Wsus server.
e. To run on Windows 8, first install RSAT (Remote Server Administration Tools).
f. Wsus Server and Wsus Console must be at the same level of release.
Download binaries :
a. Go to : http://wsuspackagepublisher.codeplex.com/releases
b. Get the latest release.
Connecting to the Wsus Server :
a. Start : Wsus Package Publisher.exe. If WPP runs on the Wsus server, it will detect the
Wsus Role, and therefore will automatically add the local server to the servers list.
b. Go to : Tools then Settings
1 : Display the list of defined Wsus Servers.
c.
d.
e.
f.
j.
IV.
b. If you dont have a Code Signing Certificate, click on Generate the certificate . If
Wsus run on Windows Server 2012R2 or beyond, then you have to run WPP locally
on the server to generate this Self-Signed Certificate. With previous version of
Windows Server, you can run WPP on a remote machine or locally on the Wsus
Server.
c. Once the certificate have been generate, click on the Save the certificate button
to record the file onto the disk. (You will need it in the next step). Don't forget to
restart the Wsus Server.
d. If you already own a Code Signing Certificate, then enter the Certificate password
into the password field and click on the Load a certificate button. To be able
to load a certificate, you must run WPP on the Wsus server or remotely through a
SSL connection. (You will have to provide a .pfx file). Don't forget to restart the Wsus
Server.
V.
VI.
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AcceptTrustedPu
blisherCerts = 1
b. In Active Directory:
In the GPO you use to set your computers, set the option Allow signed content from intranet
Microsoft update service location to yes.
Your Certificate
authority
Certificate
Code Signing
Code Signing
Root Authority
Wsus Server
Client Machine
Wsus Store
Trusted
Publisher Store
Trusted
Publisher Store
Trusted Root
Certification
Trusted Root
Authorities
Certification
Authorities
Wsus Store
Trusted
Publisher Store
Trusted
Publisher Store
Trusted Root
Trusted Root
Certification
Certification
Authorities
Authorities
The Wsus Store is create by Wsus when calling the API SetSigningCertificate()