Jump to content

Recommended Posts

Posted

I am really surprised that for as much as Adobe plugins are forced upon up, how little is offered by Adobe in way of network administration tools.

 

 

I am looking for ways to updating the typical browser plugs Flash / Shockwave / Reader.

 

 

Searching Adobe's site I see that AUSST is part of the Creative Cloud Packager installer suite for Creative Suite and Creative Cloud applications, looks like for Adobe Enterprise application users.

 

 

I found some information on System Center Updates Publisher (SCUP) on Adobe's website, but like AUSST, the documentation is based on the assumption you are a user of Adobe Enterprise products, not just browser plugins.

 

 

 

 

In researching I found Wsus Package Publisher Free Tool for Publishing Third-Party Updates or Applications to Wsus

https://wsuspackagepublisher.codeplex.com/

 

 

I see a few older conversations on Wsus Package Publisher, but nothing recent.

 

 

I added to this information to this thread, hoping to stir up some new conversation, hopefully by anyone using Wsus Package Publisher for product such as Flash / Shockwave / Reader.

 

 

Issues? Problems? Success stories?

Posted

Thanks for the feedback. I'll have to revisit SCUP. The documentation I found on it did not look at that quick and easy.

 

I tried using Wsus Package Publisher to push down Flash and Reader, followed what looked like quick and easy instructions on the website, but updates are giving errors. I should know that the first rule of tech is that nothing is ever as easy as it looks. :(

Posted

Hey @Guru42

 

I suspect wsus package publisher uses a similar method to scup in which it will need a signing cert which your clients trust. I got errors until I cracked this.

 

You are right. Nothing is as easy as it seems

Posted

We're using WPP for .msi, .msp and .exe* deployment. As noted above, you do have to sign the packages you deploy. The PDF guide on the codeplex site will get you started: https://www.codeplex.com/Download?ProjectName=WsusPackagePublisher&DownloadId=499803

 

The short version is:

 

  • Configure WSUS for SSL if you haven't already
  • Obtain a code signing certificate via internal CA
  • Unpack WPP, run elevated from an admin PC and point at the WSUS server's FQDN
  • Check that WSUS versions match on Admin PC and WSUS server
  • Set a proxy for WPP if it hasn't autodetected via IE (so it can download SCUP catalogue updates)
  • Ensure WSUS is using the code signing certificate
  • Create a test package, only deploy to HereBeDragons** until you're sure it works properly (and ideally, you test installing over an older version and installing from scratch). Then push to TestGroup. Then to other groups.
  • Subscribe to the publicly available SCUP catalogues from Dell, HP & Adobe.

 

*caveat, requires sane developers - YMMV.

**our initial test group for patches.

  • Thanks 1
Posted (edited)

I use WPP and it works very well for me pushing out adobe updates (flash/reader) from their scup catalogue. If you use the WPP generated self signed certificate, you'll need to export the certificate from WPP (Tools > certificate > save button) and add it to the needed certificate stores (trusted publisher and trusted root certification authorities) on the clients, then set the allow signed updates from wsus (The exact name escapes me now) via GPO.

 

edit - @pete 's method is the way I do it but I had trouble where it didn't like my internal CAs certificate (despite working fine previously) so switched back to self signed instead.

Edited by computer_expert
  • Thanks 1
Posted

Thanks to everyone who contributed here. I went through all the info, still having issues with both methods.

 

When I use SCUP I get --> Error connecting to Configuration Manager Server

 

 

When I use WPP --> Looks like updates deployed and applied, but fail to install on workstation

 

 

I "inherited" this installation of WSUS, it was already installed by my predecessor. So I am re-thinking things, wondering if I should just re-install WSUS from scratch.

 

 

I opened a new thread on WSUS installed with other server services. I wanted to keep it separate from the topic of just WSUS.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...