Hi,
Yesterday I read the article below and it says a certificate for wsus web site is also required for ssl communication. I haven’t created this wsus web site certificate yet, because I am still not sure if I have to create this certificate or not. Maybe the problems I mentioned below are because I havent created the wsus certificate.
http://jackstromberg.com/2013/11/enabling-ssl-on-windows-server-update-services-wsus/
In my environment, I have 1 Site Server that has SUP role installed and 1 database server that has wsus database. All communication was done via http then I changed sccm communication from HTTP to HTTPS. Clients and server can communicate without any problems over SSL.
However if I try to open WSUS admin console, it gives error: ”Error Connection, Click Reset Server Node to try to connect”.
I see following error logs in wsyncmgr.log:
Sync failed: WSUS server not configured. Please refer to WCM.log for configuration error details.. Source: CWSyncMgr::DoSync
STATMSG: ID=6703 SEV=E LEV=M SOURCE="SMS Server" COMP="SMS_WSUS_SYNC_MANAGER" SYS=srvsccm2012.sehir.edu.local SITE=ISU PID=916 TID=4120 GMTDATE=Wed Oct 08 12:25:33.212 2014 ISTR0="CWSyncMgr::DoSync" ISTR1="WSUS server not configured. Please refer to WCM.log for configuration error details." ISTR2="" ISTR3="" ISTR4="" ISTR5="" ISTR6="" ISTR7="" ISTR8="" ISTR9="" NUMATTRS=0
And I see the following error logs in WCM.log:
System.Net.WebException: The underlying connection was closed: An unexpected error occurred on a send. ---> System.IO.IOException: Unable to read data from the transport connection: An existing connection was forcibly closed by the remote host. ---
Remote configuration failed on WSUS Server.
I did the required changes for WSUS for SSL Communication:
- APIRemoting30,ClientWebService,DSSAuthWebService,ServerSyncWebService, andSimpleAuthWebService virtual directories that reside under the WSUS Web site are configured and I ran the commandWSUSUtil.exe configuresslMySiteserver.local
- My WSUS web site is a secondary web site (not default)
- I configured SUP properties to use SSL on port 8531
- No proxy server is involved
- Both servers’ firewalls are disabled
Yavuz Selim Atmaca