Secunia CSI Setup Guide | University of Oregon: Information Security
Information Security Information Services home

CSI Console Setup Guide

This guide walks you through the process of installing the CSI Console, connecting to your Windows Server Update Service server, creating a GPO and deploying the CSI Agent.

The following has been modified from the Secunia CSI Technical Manual.

For technical support please create a ticket with and "CC"

IS Security Requirements

  • AD Domain participation
  • Hosted WSUS server
  • Available departmental technical support

CSI GUI/Console Requirements

  • Download the CSI 5.0 Console
  • Windows XP SP3, Vista, 7, Server 2003 or Server 2008
  • Microsoft IE 7 or higher
  • CSI Console must be launched by a user with Domain Admin privileges
  • Add ( to the IE trusted sites
  • Open SSL 443/TCP outbound to
  • Minimum 1200 * 768 screen resolution

CSI with Patching Capability Requirements

The following must also be present with installing Secunia CSI:


  1. Request a CSI account from
  2. Download and install the CSI Console
  3. Run the CSI Console as administrator
  4. Log in with CSI account credentials
  5. First login will require a change of password

WSUS Integration

Follow the WSUS Integration Guide to connect the Secunia CSI Console to your WSUS server.

GPO Requirements

If you wish to create your own GPO, the following policies must be met:

  • Enable: Configure Automatic Updates
  • Enable: Specify intranet Microsoft update service location
  • Enable: Allow signed updates from an intranet Microsoft update service location
  • The WSUS Self-Signed Certificate must be placed in "Trusted Publishers" and "Trusted Root Certification Authorities"

Agent Requirements for Target Hosts (Windows)

  • Administrative privileges (to install the CSI Agent)
  • Microsoft Windows XP, Vista, 7, Server 2003 or 2008
  • Open SSL 443/TCP to
  • Windows Update Agent 2.0 or later

Agent Requirements for Target Hosts (Mac OS X)

The following requirements should be met before installing the Single Host Agent:

  • Supported Systems: Mac OS X 10.4, Mac OS X 10.5, Mac OS X 10.6, Mac OS X 10.7
  • Root privileges for the system
  • Open SSL 443/TCP to

Agent-less Requirements for Target Hosts (Windows)

  • Microsoft Windows XP, Vista, 7, Server 2003 or 2008
  • Open: ports 139/TCP and 445/TCP (Inbound Only)
  • Enable: File sharing
  • Disable: Easy/simple file sharing
  • Windows Update Agent 2.0 or later
  • Set the following Windows Services to automatic:
    • Workstation
    • Server Service
    • Remote Registry (by default is disabled on 7/Vista)
    • COM+ System Application

Agent Deployment

Follow the CSI Agent Deployment Guide to deploy agents to the remote clients on the AD domain.