Microsoft-Windows CAPI2 failed extract of third-party root list from auto update cab

Anonymous
2009-06-02T10:11:30+00:00

Hi, I get this error in the last few weeks and I am not sure, whether I should do something about it. I went to TechNet, Event ID 11 Automatic Root Certificates Update Configuration, but I would need something simpler that I can follow. Confuseduser P.S. Exact error message is below: -

Log Name:      Application

Source:        Microsoft-Windows-CAPI2

Date:          27/05/2009 8:42:16 PM

Event ID:      11

Task Category: None

Level:         Error

Keywords:      Classic

User:          N/A

Computer:      Helga-PC

Description:

Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab> with error: A required certificate is not within its validity period when verifying against the current system clock or the timestamp in the signed file.

.

Event Xml:

<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">

  <System>

    <Provider Name="Microsoft-Windows-CAPI2" Guid="{5bbca4a8-b209-48dc-a8c7-b23d3e5216fb}" EventSourceName="Microsoft-Windows-CAPI2" />

    <EventID Qualifiers="49154">11</EventID>

    <Version>0</Version>

    <Level>2</Level>

    <Task>0</Task>

    <Opcode>0</Opcode>

    <Keywords>0x80000000000000</Keywords>

    <TimeCreated SystemTime="2009-05-27T10:42:16.000Z" />

    <EventRecordID>32381</EventRecordID>

    <Correlation />

    <Execution ProcessID="0" ThreadID="0" />

    <Channel>Application</Channel>

    <Computer>Helga-PC</Computer>

    <Security />

  </System>

  <EventData>

    <Data>http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab</Data>

    <Data>A required certificate is not within its validity period when verifying against the current system clock or the timestamp in the signed file.

</Data>

  </EventData>

</Event>

Windows for home | Other | Performance and system failures

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments
Answer accepted by question author
Anonymous
2009-10-20T11:32:58+00:00

I don't see any reason the solution above would not work in Vista.  I see the same folder structure and registry entries on Vista. 

If you are not familiar with the registry, here is a very detailed instruction set on how to delete entries:  http://support.microsoft.com/kb/136393

Be sure to use the export option before deleting entries in order to back them up.

Was this answer helpful?

2 people found this answer helpful.
0 comments No comments
Answer accepted by question author
Anonymous
2010-02-26T21:34:07+00:00

This does help.

Now that you've pointed this out I've seen the same behaviour in the CAPI2 Event Viewer log file. My Windows 7 clients have been trying to access two URL's at the domain http://crl.microsoft.com/

None of the posts I had seen on this had mentioned the need for this path.

Thanks,

Michael

hi

Here's a basic definition for CRL in general terms. You can search Google using "Certificate Revocation List" and find a lot more information.

it could also be that direct X is looking for some updated drivers

what happens is that your browser is checking for provoked certificates , is perfectly normal and safe , its to keep you safe

have a nice day

ps for some further info

http://technet.microsoft.com/en-us/library/dd772269.aspx


Scan with OneCare + 50 Windows 7even Tips + Plagued by the Privacy Center? REMOVE IT + Threat Research & Response Blog + Sysinternals Live tools + TRANSLATOR+ Photosynth + Microsoft Security + Microsoft SUPPORT + PIVOT from Live Labs+ Microsoft Live Labs + Office 2010 beta + Get Windows LIVE!

Was this answer helpful?

0 comments No comments

138 additional answers

Sort by: Most helpful
  1. Anonymous
    2009-10-21T15:48:38+00:00

    I think all the other solutions I've found ... except the one I posted about cleaning the root files and registry entries .... treat the symptoms, not the problem.  Turning off ISA restrictions, virus scans, etc, all create their own problems.  In fact, I had turned off McAfee for a short time to test the problem myself.  But that's not a realistic solution because it doesn't treat the root problem of bad certificate authority lists and creates real security threats.

    I'm thinking that the root authority file itself may contain a corruption of some sort that MS definitely should fix.  My guess is that since it is not causing critical problems for folks and they are unlikely to remedy it.

    If you are uncomfortable messing with the registry, you can probably ignore the error and move on.  This is probably no issue for home users of Vista.  If you like your machine logs to look nice and clean, the registry and file deletion may be the only remedy that you ever see.  Just make sure you do backups before you go down that road.  I don't have a lot of faith that MS is going to do anything about it since its been so long since the problem started.

    I have a 2008 domain controller that is having this error and I'm hesitating to apply this remedy.  I will probably demote it from its role before attempting it, just to be safe.  It does not have any of the major FSMO roles, so I can do that.  But I don't want to see that error in reports for the next few years that server is running.

    Was this answer helpful?

    0 comments No comments
  2. Anonymous
    2009-10-21T11:27:45+00:00

    I think a lot of the confusion surrounding this problem is becuase many of us are solving our individual cases of why/when the authrootstl.cab file is getting called. In have seen enough scenarios in this thread and others on the web to make me think that this authrootstl.cab file gets called/referenced many different times for different reasons. Therefore, many of the posted "solutions" that involve doing something on the client do not usually work for other users who are in a different situation. I still believe that there is a fundamental problem with the authrootstl.cab file itself (http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab). If you manually download this file, extract the contained authroot.stl file, double-click on it to view it, then you will see that it is "invalid".

    I'm probably wrong, but it seems that if we (i.e. Microsoft) could fix this underlying issue, then maybe all of our individual problems would go away.

    Thanks,

    P.S . Here are the steps to download, extract, and view the file in question.

    1) Go to http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab and download this CAB file to your local computer.

    1. Open the CAB file and extract the authroot.stl file to your local computer.
    2. Double-click on the STL file. I'm assuming, near the top, you will see the following: "This certificate trust list is not valid. The certificate that signed the list is not valid."

    Was this answer helpful?

    0 comments No comments
  3. Anonymous
    2009-10-21T05:55:43+00:00

    Hi Jon, I actually asked, whether a home user needs to go to all that trouble.  I have tracked it down to the fact that it probably has something to do with AVG (in one of the emails above, this was suggested).  I also have Vista.  However, meanwhile I have come to the conclusion that the error does not seem to affect anything (although in the Event Viewer under Security it also appears as a problem).  I really do not want to make so many changes in the registry, especially as I am not really sure whether it will work or not.  Confuseduser

    Was this answer helpful?

    0 comments No comments