[Solved] WPP remote connection on a downstream server

Topics: Configuration Issue
Jun 13, 2014 at 12:16 PM
Hello,

I use WPP on the upstream server, where I am in administrator group. Everything works.

When I try to use WPP on a downstream server, it works.

If I remove my account from upstream WSUS server administrators group, i can't connect to it with a certificate error.

Is there a way to use WPP on downstream server without administor rights on the upstream server ?

Thanks in advance.

Gregory
Coordinator
Jun 20, 2014 at 8:00 PM
Does the downstream server is a replica ?
Check that the account you are using to run WPP is included in the "Wsus administrators" group on downstream server.
Jun 23, 2014 at 10:03 AM

Yes, the downstream server is a replica.

I am on WSUS administrator group on the replica server and on the upstream server.

If I try to connect to the local server (replica), I can see updates, but I can’t modify or create updates.

On the same server, if I try to connect to the upstream server, I have a certificate error “You don’t have any certificate. You will not be able to publish updates”

If I add my account on the administrators group of upstream server, no problem.

The same certificate set up on the both servers.

How to solve this problem ?

Gregory

De : DCourtel [email removed]
Envoyé : vendredi 20 juin 2014 22:00
À : Seignobosc, Gregory
Objet : Re: WPP remote connection on a downstream server [WsusPackagePublisher:548569]

From: DCourtel

Does the downstream server is a replica ?
Check that the account you are using to run WPP is included in the "Wsus administrators" group on downstream server.

Click here to report this email as spam.



This message has been scanned for malware by Websense. www.websense.com

Coordinator
Jun 24, 2014 at 9:43 AM
If I try to connect to the local server (replica), I can see updates, but I can’t modify or create updates.
That's a normal situation. This is how Replica works. you can't change anything on a replica (except deleting updates). You will never be able to publish directly to the replica or approve directly to the replica. Replica server are manage by the upstream server.
If I add my account on the administrators group of upstream server, no problem.
To manage a Wsus server with WPP, you need to be in the Wsus administrators group.
Jun 24, 2014 at 10:51 AM
Okay for replica.

To manage remotely the WSUS upstream server with WPP, I am on the WSUS administrators group on Upstream and Replica.
If I try to connect remotely to the upstream server in WPP, I got the certificate error.

If I add my account on the administrators group on the upstream server only, it works.

I just want to be able to work on WPP remotely through a replica server, and without to be administrator of the upstream server.

Is it possible ?
Coordinator
Jun 24, 2014 at 5:23 PM
Two points :
  • It is useless to run WPP on the replica server. You will no be able to manage that server. Run WPP directly from your computer (Ensure the Wsus Console is installed).
  • You don't have to be in the Windows Administrators group to manage a Wsus with WPP (or Wsus Console). You just have to use an account that is member of the "Wsus administrators" group, that is, is administrator of the Wsus functionality (not of Windows Server)
Marked as answer by DCourtel on 8/1/2014 at 12:58 AM
Sep 18, 2014 at 10:44 AM
Hello,
I have same kind of setup.
I have installed WPP on up stream server.
But i am not able to detect the clients from WPP.... its giving error when i say "detect"
firewall and settings are fine i have opened the ports which are required.

Any help is most appreciable.

Thanks