Determine if You are Affected
Publishing may fail on Server 2012 / 2016 with the following error message in the PatchMyPC.log:
An error occurred while extracting the certificate from WSUS: C:\Usersusername\AppData\Local\Temp\PMP-tempfolderrandomfolder.tmp : Access is denied
Failed to extract the certificate from WSUS Message
This error can be caused by a lack of permissions on the WSUSCertServer Service.
Workaround
- Add the Computer account of the Server that the Patch My PC Publisher is installed to the “WSUS Administrators” Group
- Open Regedit and navigate to “HKEY_CLASSES_ROOT\AppID\{8F5D3447-9CCE-455C-BAEF-55D42420143B}“
- Right Click that key, select Permissions, then click Advanced.
- At the top of the Advanced Permissions window, change the Owner to “WSUS Administrators” and Click OK
- While in this properties window, also ensure that Administrations and SYSTEM have full control of that registry key
- Start dcomcnfg.exe as Administrator
- In the Tree select “Component Services” ->”My Computer” -> “DCOM Config“
- Scroll down and right click on WSusCertServer and click “Properties”, and navigate to the “Security” Tab
- Click “Customize” under “Launch and Activation Permissions” then click “Edit”
- Click “Customize” under “Access Permissions” then click “Edit”
- Click “Customize” under “Configuration Permissions” then click “Edit”
- Restart the WSUSCertServer Service from Services.msc



