Skip to content

TechDirectArchive

Hands-on IT, Cloud, Security & DevOps Insights

  • Home
  • About
  • Advertise With US
  • Reviews
  • Contact
  • Toggle search form
Home » Windows Server » Configure SSL connection for WSUS Upstream and Downstream Servers
  • fix IP addressed blocked Synology
    IP Address blocked on Synology NAS due to forgotten Password Storage
  • pst
    How to Import PST file into Exchange Server 2016 Network | Monitoring
  • Disable automatic updates
    Turn off Automatic Updates in Windows via Windows Registry and Group Policy Windows
  • MicrosoftOneDrive32
    Microsoft OneDrive Setup: Files On-Demand & Key Features Backup
  • Remove Bing Chat Button from Edge Sidebar
    How to Remove Bing Chat Button from Edge Sidebar Windows
  • screenshot 2020 04 22 at 23.28.23
    Remove saved RDP connections in Windows Windows
  • Norton iOS Calender
    Scan Apple Calendar: Prevent Norton from scanning your Apple Calendar on iOS Anti-Virus Solution
  • increaseEmailsize
    Email Size Limits: Boost for High Profile Users in Exchange 2010 Network | Monitoring

Configure SSL connection for WSUS Upstream and Downstream Servers

Posted on 10/03/201816/03/2024 Christian By Christian No Comments on Configure SSL connection for WSUS Upstream and Downstream Servers
Secure communication

In this article, we will learn how to Configure SSL connection for WSUS Upstream and Downstream Servers. SSL stands for Secure Sockets Layer, a vital security technology. See the following guides for some related articles I have written. Configuring WSUS Email Notification to Work With Office365, How to setup and configure Windows server update services (WSUS), important Areas to Master on WSUS (Installed and not applicable, Install 1/4, and Installed / Not applicable 100).

SSL and its successor, Transport Layer Security (TLS) are protocols that establish authenticated and encrypted links between networked computers.

Before we proceed with these steps, please take a look at the articles below. – Targeting WSUS Client with the Registry keys: How to configure WSUS Clients to get Updates from the WSUS server using Registry settings and how to apply Windows Updates from WSUS to the server using AWS RunCommand and some very handy WSUS Commands “Windows Server Update Services Commands, WAUACLT, PowerShell and USOClient “.

Configure Server Certificate

From the Server Manager, click Tools and open IIS. Click on the IIS Server Node, and double click on the Server Certificate

SSL setup

Click on Import (and import the SSL certificate in .pfx format and enter the password)

WSUS servers

Note: Nonetheless, to ensure secure communication, it’s crucial to learn how to configure SSL. Import the CA certificate into the Trusted Root CA store on downstream WSUS servers or the local computer.

If the certificate is only imported to the Local User Trusted Root CA store, the downstream WSUS server will not be authenticated on the upstream server.

Note: Moreover, You must import the certificate to all computers that will communicate with the WSUS server. Therefore, this includes all client computers, downstream servers, and computers that run the WSUS Administration Console.

The certificate should be imported into the local computer Trusted Root CA store or into the Windows Server Update Service Trusted Root CA store. See how to configure WSUS.

Bind the SSL certificate

We have to bind the SSL certificate. Expand your server, expand Sites, and select WSUS Administration

Under Actions, click on Bindings

The binding windows opens, click on Edit and enter the host names (Select the cert for HTTPS)

SSL configuration

Enforce SSL Encryption

Now enforce the SSL encryption on the following virtual roots listed below. Ensure to repeat all steps for each directory listed below

  • ApiRemoting30
  • ClientWebService
  • DSSAuthWebService
  • ServerSyncWebService
  • SimpleAuthWebService
Secure communication

Select the directory (virtual root) e.g  ClientWebService and double click on SSL Settings

Check the require SSL  and under Actions click on Apply

Let’s instruct WSUS to make use of SSL, and this can be done via the command line.

Navigate to the WSUS installation path C:Program FilesUpdate ServicesTools as shown below on your Server

Run the WsusUtil.exe as shown above followed by configuressl and the FQDN as shown below

The result would be this

Finally, restart the WSUS server to make sure all changes take effect.  This should enable access to the  WSUS management console if everything is okay.

See the following guide for some related WSUS contents “how to Start, Stop and Restart Windows Server Update Services (WSUS) via PowerShell and CMD, Windows Server Update Services: Windows 2016 Servers does not show up on the WSUS console, and WSUS clients appear and disappear from the WSUS Update Services console“.

Note: However, You can witness some weird issues after configuring SSL, simply use these link

  • wsusutil usecustomwebsite false
  • wsusutil usecustomwebsite true
C:Program FilesUpdate ServicesToolsWSUSutil usecustomwebsite false

And rerun

C:Program FilesUpdate ServicesToolsWSUSutil usecustomwebsite True

To establish secure communication for downstream servers connecting to the upstream server via port 8531. Ensure proper rules are in place for this setup. And you can additionally reconfigure using the configure SSL from this path.

C:Program FilesUpdate ServicesToolsWSUSutil

Note: However, You can set up your own CA: (Enterprise root CA). I hope you found this article useful on how to Configure SSL connection for WSUS Upstream and Downstream Servers. Please feel free to leave a comment below.

Rate this post

Thank you for reading this post. Kindly share it with others.

  • Click to share on X (Opens in new window) X
  • Click to share on Reddit (Opens in new window) Reddit
  • Click to share on LinkedIn (Opens in new window) LinkedIn
  • Click to share on Facebook (Opens in new window) Facebook
  • Click to share on Pinterest (Opens in new window) Pinterest
  • Click to share on Tumblr (Opens in new window) Tumblr
  • Click to share on Telegram (Opens in new window) Telegram
  • Click to share on WhatsApp (Opens in new window) WhatsApp
  • Click to share on Pocket (Opens in new window) Pocket
  • Click to share on Mastodon (Opens in new window) Mastodon
  • Click to share on Bluesky (Opens in new window) Bluesky
  • Click to share on Threads (Opens in new window) Threads
  • Click to share on Nextdoor (Opens in new window) Nextdoor
Windows Server Tags:Certificates, HTTPS, SSL

Post navigation

Previous Post: How to target WSUS clients with the registry keys
Next Post: Configure WSUS Email Notification for Office365

Related Posts

  • Error 0x800f0823 The specified package cannot be added to this Windows Image
    Error 0x800f0823: Wizard.hta Screen stuck during WDS Deployment Windows Server
  • fgbv
    Export and Import Scheduled Tasks in Windows Windows Server
  • sadx
    Error 0x80070002: When trying to mount an image file Windows Server
  • WindowsTerminalServerRDS
    Remove a Remote Desktop Service collection Windows Server
  • 1 kajkbmlyehn0inifwrh 8w
    How to install Kerberos packages with Cygwin on Windows Windows Server
  • BdeHdCfg
    Fix System Partition not available or large enough on Microsoft BitLocker Administration and Monitoring [Part 1] Windows Server

More Related Articles

Error 0x800f0823 The specified package cannot be added to this Windows Image Error 0x800f0823: Wizard.hta Screen stuck during WDS Deployment Windows Server
fgbv Export and Import Scheduled Tasks in Windows Windows Server
sadx Error 0x80070002: When trying to mount an image file Windows Server
WindowsTerminalServerRDS Remove a Remote Desktop Service collection Windows Server
1 kajkbmlyehn0inifwrh 8w How to install Kerberos packages with Cygwin on Windows Windows Server
BdeHdCfg Fix System Partition not available or large enough on Microsoft BitLocker Administration and Monitoring [Part 1] Windows Server

Leave a Reply Cancel reply

You must be logged in to post a comment.

Microsoft MVP

VEEAMLEGEND

vexpert-badge-stars-5

Virtual Background

GoogleNews

Categories

veeaam100

sysadmin top30a

  • fix IP addressed blocked Synology
    IP Address blocked on Synology NAS due to forgotten Password Storage
  • pst
    How to Import PST file into Exchange Server 2016 Network | Monitoring
  • Disable automatic updates
    Turn off Automatic Updates in Windows via Windows Registry and Group Policy Windows
  • MicrosoftOneDrive32
    Microsoft OneDrive Setup: Files On-Demand & Key Features Backup
  • Remove Bing Chat Button from Edge Sidebar
    How to Remove Bing Chat Button from Edge Sidebar Windows
  • screenshot 2020 04 22 at 23.28.23
    Remove saved RDP connections in Windows Windows
  • Norton iOS Calender
    Scan Apple Calendar: Prevent Norton from scanning your Apple Calendar on iOS Anti-Virus Solution
  • increaseEmailsize
    Email Size Limits: Boost for High Profile Users in Exchange 2010 Network | Monitoring

Subscribe to Blog via Email

Enter your email address to subscribe to this blog and receive notifications of new posts by email.

Join 1,839 other subscribers
  • RSS - Posts
  • RSS - Comments
  • About
  • Authors
  • Write for us
  • Advertise with us
  • General Terms and Conditions
  • Privacy policy
  • Feedly
  • Telegram
  • Youtube
  • Facebook
  • Instagram
  • LinkedIn
  • Tumblr
  • Pinterest
  • Twitter
  • mastodon

Tags

AWS Azure Bitlocker Microsoft Windows PowerShell WDS Windows 10 Windows 11 Windows Deployment Services Windows Server 2016

Copyright © 2025 TechDirectArchive

 

Loading Comments...
 

You must be logged in to post a comment.