Skip to content

Commit 84a32cc

Browse files
committed
2111-certpinningcmg-12590425
1 parent ba2f33c commit 84a32cc

1 file changed

Lines changed: 3 additions & 2 deletions

File tree

memdocs/configmgr/sum/get-started/software-update-point-ssl.md

Lines changed: 3 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -289,10 +289,11 @@ Starting in Configuration Manager 2103, you can further increase the security of
289289
- Configuration Manager version 2103
290290
- Ensure your WSUS servers and software update points are configured to use TLS/SSL
291291
- Add the certificates for your WSUS servers to the new `WindowsServerUpdateServices` certificate store on your clients
292+
- When using certificate pinning with a cloud management gateway (CMG), the `WindowsServerUpdateServices` store needs the CMG certificate. If clients switch from internet to VPN both the CMG and WSUS server certificates are needed in the `WindowsServerUpdateServices` store. <!--12590425-->
292293

293294
> [!Note]
294-
> - Software update scans for devices will continue to run successfully using the default value of **Yes** for the **Enforce TLS certificate pinning for Windows Update client for detecting updates** client setting. This includes scans over both HTTP and HTTPS. The certificate pinning doesn't take effect until a certificate is in the client's `WindowsServerUpdateServices` store and the WSUS server is configured to use TLS/SSL.
295-
> - When using certificate pinning with a cloud management gateway (CMG), the `WindowsServerUpdateServices` store needs the CMG certificate. If clients switch from internet to VPN both the CMG and WSUS server certificates are needed in the `WindowsServerUpdateServices` store. <!--12590425-->
295+
> Software update scans for devices will continue to run successfully using the default value of **Yes** for the **Enforce TLS certificate pinning for Windows Update client for detecting updates** client setting. This includes scans over both HTTP and HTTPS. The certificate pinning doesn't take effect until a certificate is in the client's `WindowsServerUpdateServices` store and the WSUS server is configured to use TLS/SSL.
296+
296297

297298

298299
### Enable or disable TLS certificate pinning for devices scanning HTTPS-configured WSUS servers

0 commit comments

Comments
 (0)