System Center Update Publisher 2011 Installation en Configuration


On the 24th of May the System Center Team released System Center Updates Publisher 2011. See the following link to the detailed announcment: Yesterday I installed en configured SCUP in my own lab environment.

See below the steps I did to install and configure. At the end of the page you will find some errors and solutions.

Installation of SCUP 2011

  1. Download the source from here
  2. Start the SCUP installer with administrative rights.
  3. On the welcome screen click Next


  4. Install the Microsoft .Net Framework 4.0
  5. Install the Microsoft WSUS 3.0 SP2 hotfix as suggested on all your WSUS servers in your SCCM environment and the SCUP 2011 server.
  6. Accept the License Agreement and click Next
  7. Select the Installation Location and click Next
  8. Click on Next to start the installation
  9. Click on Finish to end the installation
After the installation some configuration steps needs to be done before you can publish updates to your WSUS/SCCM environment. Follow te steps below to configure SCUP and your clients:
  1. Start the SCUP console from the Start Menu
  2. Click on the blue settings button and click Options
  3. Enable the option “Enable publishing to an update server” and select the correct WSUS Server configuration. Click on “Test Connection” to test the connectivity to your WSUS server
  4. Now we need to select or create a singning certificate. Click on the Create button to create a self-signed certificate
  5. Now we need to export the self-signed certificate from the Certificates store. This can be done through the certificates MMC snapin. The certificate can be found in the Computer account >> WSUS >> Certificates
  6. Right-Click on the WSUS self-signed certificate and select All Tasks >> Export. Follow the wizard an save the certificate with the standard options.
  7. Now import this certificate on your Update Servers and your SCUP server in the following Stores:
    – Trusted Publishers
    – Trusted Root Certification Authorities
  8. After adding the certificate to the servers you also need to place the certificate on the clients. The certificate needs to be placed in the same certificate folders. Beside importing the certificate you also need to enable the group policy option “Allow signed content from intranet Microsoft update service location”. I used a Group Policy to deploy the certificate and to enable te setting. See the Policy below


After adding the above settings SCUP is ready to deploy the updates to your WSUS/SCCM environment. During the above process I got the following error/problems:


Problem: Access Denied errors during the deployment of the updates to the WSUS environment
Solution: Run the SCUP console with administrative permissions


Problem: Unable to install updates on the clients
Solution: I didn’t enabled the “Allow signed content from intranet Microsoft update service location”