Timestamp Updates

Timestamp Updates

Purpose

This article is to help provide guidance on using the timestamp server options when publishing updates using the Lenovo Patch plugin.

Description

Adding a timestamp to an update during the publishing process will identify when the update was signed. Both timestamping and signing an update, while the certificate is still in its validity period, allows the update to be installed after the certificate expires. When the code signing certificate expires, timestamping will eliminate the need for a Lenovo Patch user to republish relevant updates containing the now expired certificate.  This also eliminates the work associated with removing old content from deployment packages, downloading new copies of the signed content to deployment packages, and updating the content on the distribution point(s).

Solution

To add a timestamp server to the publication process, do the following:

  1. In the Configuration Manager console, navigate to the Software Library workspace.
  2. Navigate to Software Updates > Lenovo Patch > Updates
  3. Click on Settings in the ribbon bar.
  4. In the Lenovo Patch Settings dialog, select the WSUS Server tab.
  5. Navigate to the 'Signing timestamp' section.
  6. Check the box by the 'Use a timestamp server when signing WSUS packages' setting.
  7. In the 'Server:' box, enter the address of the timestamp server to use.
  8. Click the Test button to verify Lenovo Patch can reach and utilize the timestamp server
  9. Click OK.