Microsoft-Windows CAPI2 failed extract of third-party root list from auto update cab

Anonymous
2009-06-02T10:11:30+00:00

Hi, I get this error in the last few weeks and I am not sure, whether I should do something about it. I went to TechNet, Event ID 11 Automatic Root Certificates Update Configuration, but I would need something simpler that I can follow. Confuseduser P.S. Exact error message is below: -

Log Name:      Application

Source:        Microsoft-Windows-CAPI2

Date:          27/05/2009 8:42:16 PM

Event ID:      11

Task Category: None

Level:         Error

Keywords:      Classic

User:          N/A

Computer:      Helga-PC

Description:

Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab> with error: A required certificate is not within its validity period when verifying against the current system clock or the timestamp in the signed file.

.

Event Xml:

<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">

  <System>

    <Provider Name="Microsoft-Windows-CAPI2" Guid="{5bbca4a8-b209-48dc-a8c7-b23d3e5216fb}" EventSourceName="Microsoft-Windows-CAPI2" />

    <EventID Qualifiers="49154">11</EventID>

    <Version>0</Version>

    <Level>2</Level>

    <Task>0</Task>

    <Opcode>0</Opcode>

    <Keywords>0x80000000000000</Keywords>

    <TimeCreated SystemTime="2009-05-27T10:42:16.000Z" />

    <EventRecordID>32381</EventRecordID>

    <Correlation />

    <Execution ProcessID="0" ThreadID="0" />

    <Channel>Application</Channel>

    <Computer>Helga-PC</Computer>

    <Security />

  </System>

  <EventData>

    <Data>http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab</Data>

    <Data>A required certificate is not within its validity period when verifying against the current system clock or the timestamp in the signed file.

</Data>

  </EventData>

</Event>

Windows for home | Other | Performance and system failures

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments
Answer accepted by question author
Anonymous
2009-10-20T11:32:58+00:00

I don't see any reason the solution above would not work in Vista.  I see the same folder structure and registry entries on Vista. 

If you are not familiar with the registry, here is a very detailed instruction set on how to delete entries:  http://support.microsoft.com/kb/136393

Be sure to use the export option before deleting entries in order to back them up.

Was this answer helpful?

2 people found this answer helpful.
0 comments No comments
Answer accepted by question author
Anonymous
2010-02-26T21:34:07+00:00

This does help.

Now that you've pointed this out I've seen the same behaviour in the CAPI2 Event Viewer log file. My Windows 7 clients have been trying to access two URL's at the domain http://crl.microsoft.com/

None of the posts I had seen on this had mentioned the need for this path.

Thanks,

Michael

hi

Here's a basic definition for CRL in general terms. You can search Google using "Certificate Revocation List" and find a lot more information.

it could also be that direct X is looking for some updated drivers

what happens is that your browser is checking for provoked certificates , is perfectly normal and safe , its to keep you safe

have a nice day

ps for some further info

http://technet.microsoft.com/en-us/library/dd772269.aspx


Scan with OneCare + 50 Windows 7even Tips + Plagued by the Privacy Center? REMOVE IT + Threat Research & Response Blog + Sysinternals Live tools + TRANSLATOR+ Photosynth + Microsoft Security + Microsoft SUPPORT + PIVOT from Live Labs+ Microsoft Live Labs + Office 2010 beta + Get Windows LIVE!

Was this answer helpful?

0 comments No comments

138 additional answers

Sort by: Most helpful
  1. Anonymous
    2009-06-07T17:11:18+00:00

    Hi Confuseduser, Alex_PH, and Baffin,

    Thanks for your responses to the community forum.

    Some issues experienced has been a result of bad cache files in Internet Explorer.

    Try clearing all cache and  resetting Internet Explorer -  if this is IE8

    To clear cache - From IE Click Tools / Internet Options / on the General Tab in Browsing History select Delete. 

    To reset IE - From IE Click Tools / Internet Options / Advanced Tab select Reset.

    At this poinst, follow this knowledge base article.    Microsoft root certificate program members (February 2009)

    Some information in the article is included below. http://support.microsoft.com/kb/931125/en-us

    Update for Root Certificates This item updates the list of root certificates on your computer to the list that is accepted by Microsoft as part of the Microsoft Root Certificate Program.

    The following file is available for download from the Microsoft Download Center:

    Download the rootsupd.exe package now. (http://www.microsoft.com/downloads/details.aspx?FamilyID=f814ec0e-ee7e-435e-99f8-20b44d4531b0)

    Release Date: 2/24/2009

    For more information about how to download Microsoft support files, click the following article number to view the article in the Microsoft Knowledge Base:

    119591  (http://support.microsoft.com/kb/119591/ ) How to obtain Microsoft support files from online services

    Microsoft scanned this file for viruses. Microsoft used the most current virus-detection software that was available on the date that the file was posted. The file is stored on security-enhanced servers that help prevent any unauthorized changes to the file.

    Please let us know if this assists in resolving this issue or if further suggestions are needed involving the issue.

    Regards,


    Debbie

    Microsoft Answers Support Engineer

    Visit our Microsoft Answers Feedback Forumand let us know what you think.

    Was this answer helpful?

    0 comments No comments
  2. Anonymous
    2009-06-06T08:47:31+00:00

    Hi Martin and all the others who might be interested - I found out that CAPI2 now had a reference to a Windows Update file.  I clicked on it and it stated (there is more than I am quoting): Digital Signature Information - the certificate is not valid for the requested usage : -

    Signer information: Microsoft Certificate Trust List Publisher

    Sign time, Saturday 2nd May 2009

    Name of Sign... Email address: timestamp

    Microsoft time not available, Sat. 2nd May.

    When I click on details, I get a long list:

    Certificate Version V3

    Ser.No. 61 02 b4 0c 00 01 00 00

    sign. algorithm sha1 RSA

    Issuer Microsoft Certific Trus...

    Valid Sat 11 Apr 2009

    Valid to Sunday 11 July 2010

    Subj  Microsoft Certiicate

    Public key RSA 12048 bits etc.  I have not found a way of copying it all.  However, it asked me whether I want to install it and I did.  Confuseduser

    Was this answer helpful?

    0 comments No comments
  3. Anonymous
    2009-06-06T08:40:50+00:00

    Martin,

    I just took a look at my Systems32 folder.  My copy of wusa.exe was created and last accessed on 02Jun2, 2009 - the day I installed Vista SP2.  Since the CAPI2 11 errors started on 27May, 2009, I don't think we need to pursue this line of investigation further.

    Alex_PH

    Was this answer helpful?

    0 comments No comments