Jump to content


  • 0
rodrigo848

Third-Party Updates with SCCM

Question

Hi everybody,

 

First of all I would like to thanks everybody for the great installations guides of SCCM, there's just a little point missing and it's how to deploy third-party updates with SCCM. I've done some research and I found out that I need SCUP and obviously WSUS but once I configure both of them I don't know what else to do !?!? How do I create/import updates ? Do I have to create a packages as I do with MS updates ? And what about the custom catalogs that are provided by intel, adobe, etc ? Can someone explain me how all this works :blink: ?

 

Thanx !

Share this post


Link to post
Share on other sites

7 answers to this question

Recommended Posts

  • 0

Hello,

 

i tried to install the newest flash updates with sccm2007 and scup2011. I´ve done it with the guide "The-complete-guide-to-System-Center-Updates-Publisher-2011-V1.01"

After sync i can see the updates in sccm2007 and i deployed them to my testclient. the package is downloaded to C:\Windows\System32\CCM\Cache but the installation failed.

In the cache folder there is a .cab file and inside the .cab there is the file install_flash_player_11_plugin.msi.

 

error message in the report States 7 - Error status messages for a computer:

Updates failures occured during enforcement for assignment {D5B2E801-1C7D-4F20-810F-A96B21B9794E}. The operating system reported error -2146762487: A certificate chain processed, but terminated in a root certificate which is not trusted by the trust provider.

 

I created the certificate in scup and added it with the command certutil to my testcomputer. when i open mmc and certificates i can see the imported wsus certificates.

 

Any ideas ? Do you need other logfiles ?

 

THX

Share this post


Link to post
Share on other sites

  • 0

Yes the certificates were succesfully installed on my client with certutil.exe -addstore Root wsus2011.cer and certutil.exe -addstore TrustedPublisher wsus2011.cer.

Our admin said he applied the GPO setting. i checked it and found this one for my testclient. Is this right ?

 

 

http://www.pic-upload.de/view-16916640/Unbenannt.png.html

Share this post


Link to post
Share on other sites

  • 0

The same error.

But i´ve found the problem. It was the second time i tried to install the updates. I found this hint in the internet:

A software update (the binary) can only be published once to WSUS. If you change the signing certificate, you will then also want to resign that binary by publishing it with the resign option (in Advanced settings).

 

So i published the updates in SCUP2011 again but i activated the option "Sign all software updates with a new publishing certificate when published software updates have not changed but their certificate has changed."

After running synchronization for the update repository in SCCM 2007 it works fine.

 

Thank you !!

Share this post


Link to post
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Answer this question...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

Loading...


×
×
  • Create New...

Important Information

We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.