Welcome to Tech Support Forum home to more then 136,000 problems solved. Issues have included: Spyware, Malware, Virus Issues, Windows, Microsoft, Linux, Networking, Security, Hardware, and Gaming Getting your problem solved is as easy as:
1. Registering for a free account
2. Asking your question
3. Receiving an answer

Registered members:
* Get free support
* Communicate privately with other members (PM).
* Removal of this message
* See fewer ads.
* And much more..

 



Want to know how to post a question? click here Having problems with spyware and pop-ups? First Steps
Go Back   Tech Support Forum > Microsoft Support > Windows NT/2000/2003 Server/2008 Server
User Name
Password
Site Map Register Donate Rules Blogs Mark Forums Read


Windows NT/2000/2003 Server/2008 Server Find support for Windows NT/2000/2003 Server/2008 Server editions.

Reply
 
LinkBack Thread Tools
Old 09-09-2006, 11:08 AM   #1 (permalink)
Member, Networking Team
 
Join Date: Jan 2005
Location: Ohio
Posts: 1,040
OS: Windows Server 2003


WSUS SSL Client Configuration

I set the clients to access the https://192.168.10.101 address which is of my WSUS server. I am using the deafult port for SSL (431) so I should not have to include that but my clients still will not check in. I think this is my problem. Can anyone help me.

Quote:
Configuring SSL on client computers
There are two important caveats when configuring client computers:

• You must include a URL for a secure port that the WSUS server is listening on. Because you cannot require SSL on the server, the only way to ensure that client computers use a secure channel is to make sure they use a URL that specifies HTTPS. If you are using any port other than 443 for SSL, you must include that port in the URL, too.

For example, you might use https://ssl-servername:3051 to point clients to a WSUS server that is using a custom SSL port of 3051.

Likewise, you might use https://ssl-servername for a WSUS server that is using port 443 for HTTPS.

For more information about how to point client computers to the WSUS server, see "Specify intranet Microsoft Update service location" in Configure Automatic Updates by Using Group Policy later in this guide.

• The certificate on client computers has to be imported into either the Local Computer's Trusted Root CA store or Automatic Update Service's Trusted Root CA store. If the certificate is only imported to the Local User's Trusted Root CA store Automatic Updates will fail server authentication.

• Your client computers must trust the certificate you bind to the WSUS server in IIS. Depending upon the type of certificate you are using, you may have to set up a service to enable the clients to trust the certificate bound to the WSUS server. For more information, see "Further Reading" later in this section.
__________________
Because you can read this thank a teacher, because it's English thank a soldier.
newhouse1390 is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Reply With Quote
Important Information
Join the #1 Tech Support Forum Today - It's Totally Free!

TechSupportForum.com is a leading support website for your computer needs. We offer free, friendly and personalized computer support. Why pay to have your computer fixed when you can do it for free.

Join TechSupportforum.com Today - Click Here

Old 09-09-2006, 02:44 PM   #2 (permalink)
Registered User
 
Join Date: Jun 2006
Location: Cincinnati, Ohio
Posts: 617
OS: Windows XP

My System

Send a message via AIM to whardman Send a message via MSN to whardman
The default port for https is 443 not 431. You need to change the port to 443 or change the address to https://192.168.10.101:431.
whardman is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Reply With Quote
Old 09-10-2006, 08:05 AM   #3 (permalink)
Member, Networking Team
 
Join Date: Jan 2005
Location: Ohio
Posts: 1,040
OS: Windows Server 2003


I think I just misspoke. I did not change the default port used, and I am under the understanding that if that doesn't change their is no reason to include the port number in the URL. I will try putting the port number in. I still believe this issue is along the line of certificates not being trusted.
__________________
Because you can read this thank a teacher, because it's English thank a soldier.
newhouse1390 is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Reply With Quote
Old 09-10-2006, 12:31 PM   #4 (permalink)
Moderator Networking Team
 
Cellus's Avatar
 
Join Date: Aug 2006
Location: Canada
Posts: 2,664
OS: Windows Vista Business SP1, Windows XP Professional SP3

My System

Untrusted certificates are a common problem when you create a custom CA and forget to have the new CA trusted.
__________________
TSF Networking Team

Virus/Trojan/Spyware Removal Help
Donate!
Cellus is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Reply With Quote
Old 09-10-2006, 09:07 PM   #5 (permalink)
Member, Networking Team
 
Join Date: Jan 2005
Location: Ohio
Posts: 1,040
OS: Windows Server 2003


Can you tell me how I can get my Certificate trusted by my client computers?
__________________
Because you can read this thank a teacher, because it's English thank a soldier.
newhouse1390 is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Reply With Quote
Old 09-11-2006, 06:47 AM   #6 (permalink)
Registered User
 
crazijoe's Avatar
 
Join Date: Oct 2004
Location: Omaha, The Center of the Universe
Posts: 7,632
OS: WinXP, Win2K3

My System

You will need to install the certificate on the users computers.
crazijoe is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Reply With Quote
Old 09-13-2006, 11:01 AM   #7 (permalink)
Member, Networking Team
 
Join Date: Jan 2005
Location: Ohio
Posts: 1,040
OS: Windows Server 2003


Will installing the cert that is presented when you access the webpage good enough to install. Or do I need to go to the cert services intranet site? How would you reccommend getting that done?
__________________
Because you can read this thank a teacher, because it's English thank a soldier.
newhouse1390 is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Reply With Quote
Old 09-13-2006, 11:05 AM   #8 (permalink)
Registered User
 
crazijoe's Avatar
 
Join Date: Oct 2004
Location: Omaha, The Center of the Universe
Posts: 7,632
OS: WinXP, Win2K3

My System

Quote:
Originally Posted by newhouse1390 View Post
Will installing the cert that is presented when you access the webpage good enough to install.
We tried it that way and it didn't work. I know this sounds crazy but this was the only way we could get it to work. What we did it was we imported it off the server and installed it onto each machine that needed it.
crazijoe is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Reply With Quote
Old 09-21-2006, 03:30 PM   #9 (permalink)
Member, Networking Team
 
Join Date: Jan 2005
Location: Ohio
Posts: 1,040
OS: Windows Server 2003


This link has the fix, I have been able to come up with a new error message . I think I just need to know where to get the cert off of the server and where / how to input it on the clients.

http://www.security-forums.com/viewt...fa88a97da921ed
__________________
Because you can read this thank a teacher, because it's English thank a soldier.
newhouse1390 is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Reply With Quote
Old 09-25-2006, 07:09 AM   #10 (permalink)
Member, Networking Team
 
Join Date: Jan 2005
Location: Ohio
Posts: 1,040
OS: Windows Server 2003


This issue was resolved. There was a conflict with the SSL configuration on the default page and that change did not take affect on the child websites.
__________________
Because you can read this thank a teacher, because it's English thank a soldier.
newhouse1390 is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Reply With Quote
Reply


Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off




All times are GMT -7. The time now is 07:55 AM.



Copyright 2001 - 2009, Tech Support Forum
Home Tips Plus | Outdoor Basecamp | Automotive Support Forum

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85