Sign in with Microsoft
Sign in or create an account.
Hello,
Select a different account.
You have multiple accounts
Choose the account you want to sign in with.

Summary

To align with industry standards, Microsoft is moving away from using SHA-1 signatures for future updates and moving to SHA-2 signatures (see KB4472027 for more details). Without applying this SHA-2 update, beginning July 2019, WSUS 3.0 SP2 (also called WSUS 3.2) will not be able to perform the necessary WSUS update tasks. Starting with WSUS 4.0 on Windows Server 2012, WSUS already supports SHA-2-signed updates, and no customer action is needed for these versions. This update is necessary for those customers still using WSUS 3.0 SP2. We recommend upgrading to the latest version of WSUS, version 10.0.

Note: Adding SHA-2 support will not add support for Windows 10 feature updates on WSUS 3.0 SP2.

 

Prerequisites

  • Windows Monthly Rollup released March 12, 2019 or later, such as

    • KB4489880 or higher rollup for Windows Server 2008 SP2 installed.

    • KB4489878 or higher rollup for Windows Server 2008 R2 SP1 installed.

  • .NET Framework 3.5

Note: We recomend you backup your WSUS database before installation

 

Synchronizing WSUS hierarchy after successful patch installation

We recommend that you synchronize all WSUS servers in your environment after applying this update. If you have a hierarchy of WSUS servers, apply this update and synchronize your servers from the top of the hierarchy.  

To synchronize your servers in this manner, follow the steps below   

  1. Apply update to the WSUS server that synchronizes with Microsoft Update. 

  1. Start the synchronization.

  1. Wait for the synchronization to succeed.

Repeat these steps for each WSUS server that synchronizes to the server that you just updated. 

Known issues

Notes: 

  • This update does not support uninstallation via MSI. Microsoft recommends that validations be performed in a non-production environment.

  • Remote Microsoft SQL Server administrators must download and install the update by using an account that has SQL Server Administrator permissions. WSUS3.0 SP2 installations using a remote SQL Server will always require manual installation of this update.

 

Symptom

Workaround

You may encounter an error message when testing the local publishing feature. In the WSUS log, search and locate the following error message, “PublishPackage(): Operation Failed with Error: Failed to sign package; error was: 2147942527”.

If you find this error in your log, then you have not installed the applicable Windows operating system prerequisite (KB4489880 or KB4489878).  Please install the prerequisite update applicable to your version of Windows and try testing again.

After installing this update, content downloads may fail if WSUS is configured to download express installation files. You may receive the following update in the SoftwareDistribution.log, “Info           WsusService.23      CabUtilities.CheckCertificateSignature                  File cert verification failed for *\WsusContent\*\*.psf with 2148098064.”

To resolve this issue, install the latest version of this update (KB4484071) released September 9, 2019. To verify that you have the latest version installed, go to %windir%\system32\psfsip.dll and verify that it is version 7.6.7600.324.

Now psf files should get downloaded locally when download express installation files is configured on the WSUS server.

 

How to obtain the update

Method 1: Windows Update

This update will be downloaded and installed automatically.

Note: This update is also available through Windows Server Update Services (WSUS).

Method 2: Microsoft Update Catalog

To get the stand-alone package for this update, go to the Microsoft Update Catalog website.

References

Learn about the terminology that Microsoft uses to describe software updates.

Need more help?

Want more options?

Explore subscription benefits, browse training courses, learn how to secure your device, and more.

Communities help you ask and answer questions, give feedback, and hear from experts with rich knowledge.

Was this information helpful?

What affected your experience?
By pressing submit, your feedback will be used to improve Microsoft products and services. Your IT admin will be able to collect this data. Privacy Statement.

Thank you for your feedback!

×