When publishing updates, the AutoPublish.log and Lenovo Patch.log file will show the following:
Error on check 'The WSUS signing certificate is not expired.' : Valid from 2019-01-01 to 2020-01-01 Error on check 'WSUS signing certificate is in Root store on WSUS01.THELAB.LOCAL.' : Certificate not found in the certificate store. Error on check 'An update can be successfully published as user 'THELAB\LPPublisher'.' : Failed to sign package; error was: 2148204810
The error code resolves to 'A certificate chain could not be built to a trusted root authority.' This error usually means the code signing certificate imported into Lenovo Patch has expired. It is no longer allowed or valid to sign newly published updates. Import a valid code signing certificate in the .PFX format with the private key included.