Page 1 of 1

Dynamische Root-Zertifikate

PostPosted: 05.05.2019, 17:56
by aker
:arrow: Ref: viewtopic.php?f=6&t=9186
rbronca wrote:[...]

I have also manually added the Microsoft root certificate and disallowed certs using this guide:
http://woshub.com/updating-trusted-root ... indows-10/ "The List of Root Certificates in STL Format"

[...]

Re: Dynamische Root-Zertifikate

PostPosted: 06.05.2019, 02:08
by rbronca
The root certificate issues is something Microsoft should have addressed, but hasn't.
For non internet connected devices there isn't a simple way to update these.
They should be a standard part of the patches that require them.

These missing certs are a patch blocker for recent .Net patches.

The latest stacking updates do update these on at least some operating systems, I believe.

wsusoffline is the best weapon for non internet connected device patching, so can the deployment of these certificates be a standard step?

I have temporarily addressed this by using the initialization hook, but had to manually download and extract the files.

regards

Robert

Re: Dynamische Root-Zertifikate

PostPosted: 06.05.2019, 02:33
by Dalai
I already made a suggestion a couple of weeks ago: viewtopic.php?f=5&t=9039

Regards
Dalai

Re: Dynamische Root-Zertifikate

PostPosted: 10.05.2019, 21:22
by WSUSUpdateAdmin
Sorry, missed this topic/thread and will work on it, hopefully next week.