Microsoft-Windows CAPI2 failed extract of third-party root list from auto update cab

Anonymous
2009-06-02T10:11:30+00:00

Hi, I get this error in the last few weeks and I am not sure, whether I should do something about it. I went to TechNet, Event ID 11 Automatic Root Certificates Update Configuration, but I would need something simpler that I can follow. Confuseduser P.S. Exact error message is below: -

Log Name:      Application

Source:        Microsoft-Windows-CAPI2

Date:          27/05/2009 8:42:16 PM

Event ID:      11

Task Category: None

Level:         Error

Keywords:      Classic

User:          N/A

Computer:      Helga-PC

Description:

Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab> with error: A required certificate is not within its validity period when verifying against the current system clock or the timestamp in the signed file.

.

Event Xml:

<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">

  <System>

    <Provider Name="Microsoft-Windows-CAPI2" Guid="{5bbca4a8-b209-48dc-a8c7-b23d3e5216fb}" EventSourceName="Microsoft-Windows-CAPI2" />

    <EventID Qualifiers="49154">11</EventID>

    <Version>0</Version>

    <Level>2</Level>

    <Task>0</Task>

    <Opcode>0</Opcode>

    <Keywords>0x80000000000000</Keywords>

    <TimeCreated SystemTime="2009-05-27T10:42:16.000Z" />

    <EventRecordID>32381</EventRecordID>

    <Correlation />

    <Execution ProcessID="0" ThreadID="0" />

    <Channel>Application</Channel>

    <Computer>Helga-PC</Computer>

    <Security />

  </System>

  <EventData>

    <Data>http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab</Data>

    <Data>A required certificate is not within its validity period when verifying against the current system clock or the timestamp in the signed file.

</Data>

  </EventData>

</Event>

Windows for home | Other | Performance and system failures

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments
Answer accepted by question author
Anonymous
2009-10-20T11:32:58+00:00

I don't see any reason the solution above would not work in Vista.  I see the same folder structure and registry entries on Vista. 

If you are not familiar with the registry, here is a very detailed instruction set on how to delete entries:  http://support.microsoft.com/kb/136393

Be sure to use the export option before deleting entries in order to back them up.

Was this answer helpful?

2 people found this answer helpful.
0 comments No comments
Answer accepted by question author
Anonymous
2010-02-26T21:34:07+00:00

This does help.

Now that you've pointed this out I've seen the same behaviour in the CAPI2 Event Viewer log file. My Windows 7 clients have been trying to access two URL's at the domain http://crl.microsoft.com/

None of the posts I had seen on this had mentioned the need for this path.

Thanks,

Michael

hi

Here's a basic definition for CRL in general terms. You can search Google using "Certificate Revocation List" and find a lot more information.

it could also be that direct X is looking for some updated drivers

what happens is that your browser is checking for provoked certificates , is perfectly normal and safe , its to keep you safe

have a nice day

ps for some further info

http://technet.microsoft.com/en-us/library/dd772269.aspx


Scan with OneCare + 50 Windows 7even Tips + Plagued by the Privacy Center? REMOVE IT + Threat Research & Response Blog + Sysinternals Live tools + TRANSLATOR+ Photosynth + Microsoft Security + Microsoft SUPPORT + PIVOT from Live Labs+ Microsoft Live Labs + Office 2010 beta + Get Windows LIVE!

Was this answer helpful?

0 comments No comments

138 additional answers

Sort by: Most helpful
  1. Anonymous
    2009-07-23T21:17:44+00:00

    Hi, I followed your method and logged CAPI2 error. It was determined to be vsmon.exe which happens to be ZoneAlarm Free.

    Since removal of ZoneAlarm Free, I had not seen this error anymore on my Vista Ultimate and WXP SP3.

    Well this issue seems to be clearly related to the crypto API (CAPI2) of Windows. So the error can be triggered by basically any application using the crypto API. Obviously it's related to certificate verification which triggers an updated of the certificate trust list (CTL).

    As a result anybody experiencing this problem might have a different source for the problem. While on one of my machines it was the media sharing it might be an anti-virus in another case (using HTTPS connection for signature update probably) or anything else. Most probably CAPI2 is updating the CTL only once when it's first invoked - so uninstalling antivirus might prevent the error on Windows boot but it might show up later during Windows operation when another application first uses the API. Obviously not a lot of applications are using the crypto API (e.g. Firefox was not using it properly until version 3.5.1 to acquire random numbers/entropy).

    By the way I have been at a customer today which showed exactly the same error on Windows XP SP3 when running Windows Update. So it's not limited to Vista. The CTL is definitely broken. Please Microsoft, fix it!

    Was this answer helpful?

    0 comments No comments
  2. Anonymous
    2009-07-20T13:39:31+00:00

    I have found the source of my error on Server 2008.  It ended up being McAfee.

    To determine the cause of the CAPI2 error, I enabled CAPI2 logging in the event log.

    You can do this by go to **** Applications and Services Logs\Microsoft\Windows\CAPI2\Operational in the event viewer.  Choose operational and enable logging.

    I noticed my error occurred every time I rebooted, so rebooted the server and checked that event log by nativating to Applications and Services Logs\Microsoft\Windows\CAPI2\Operational.  One of the log items indicated an error and mentioned a mcafee exe.

    I removed McAfee and rebooted.  The error is gone.

    I know this won't solve everyone's issue, but you could use the same methodology to determine the root cause of your own CAPI2 errors.

    Hi, I followed your method and logged CAPI2 error. It was determined to be vsmon.exe which happens to be ZoneAlarm Free.

    Since removal of ZoneAlarm Free, I had not seen this error anymore on my Vista Ultimate and WXP SP3.

    Was this answer helpful?

    0 comments No comments
  3. Anonymous
    2009-07-19T12:25:55+00:00

    Hello,

    we have at 4 different customers and at our own office with SBS2008-SP2 exactly the same problem since 27.05.2009. The certificate-trust-list (authroot.stl)  show the same error like at the diskussion above (the certicate that sign this list is not correct). I search allready for the solution, but i am sure, that MS make something wrong. The rtc onboard the server are syncronized at ntp server here in germany and the timezone is correct. Hardware wasn´t changed. The MS-sites are included the trusted sites and are not running over any proxy, this mistake is known too... Deactivated the Trendmicro virusscanner at our office: no result. Only SBS and Trendmicro are running at the SBS2008, nothing more. No addons. All is functionaly (at moment) only this error is all time at the event-log.

    Let´s look, if after one MS-update, or a new trust list with correct sign,  next time the error are away ;)

    Was this answer helpful?

    0 comments No comments