Microsoft-Windows CAPI2 failed extract of third-party root list from auto update cab

Anonymous
2009-06-02T10:11:30+00:00

Hi, I get this error in the last few weeks and I am not sure, whether I should do something about it. I went to TechNet, Event ID 11 Automatic Root Certificates Update Configuration, but I would need something simpler that I can follow. Confuseduser P.S. Exact error message is below: -

Log Name:      Application

Source:        Microsoft-Windows-CAPI2

Date:          27/05/2009 8:42:16 PM

Event ID:      11

Task Category: None

Level:         Error

Keywords:      Classic

User:          N/A

Computer:      Helga-PC

Description:

Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab> with error: A required certificate is not within its validity period when verifying against the current system clock or the timestamp in the signed file.

.

Event Xml:

<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">

  <System>

    <Provider Name="Microsoft-Windows-CAPI2" Guid="{5bbca4a8-b209-48dc-a8c7-b23d3e5216fb}" EventSourceName="Microsoft-Windows-CAPI2" />

    <EventID Qualifiers="49154">11</EventID>

    <Version>0</Version>

    <Level>2</Level>

    <Task>0</Task>

    <Opcode>0</Opcode>

    <Keywords>0x80000000000000</Keywords>

    <TimeCreated SystemTime="2009-05-27T10:42:16.000Z" />

    <EventRecordID>32381</EventRecordID>

    <Correlation />

    <Execution ProcessID="0" ThreadID="0" />

    <Channel>Application</Channel>

    <Computer>Helga-PC</Computer>

    <Security />

  </System>

  <EventData>

    <Data>http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab</Data>

    <Data>A required certificate is not within its validity period when verifying against the current system clock or the timestamp in the signed file.

</Data>

  </EventData>

</Event>

Windows for home | Other | Performance and system failures

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments
Answer accepted by question author
Anonymous
2009-10-20T11:32:58+00:00

I don't see any reason the solution above would not work in Vista.  I see the same folder structure and registry entries on Vista. 

If you are not familiar with the registry, here is a very detailed instruction set on how to delete entries:  http://support.microsoft.com/kb/136393

Be sure to use the export option before deleting entries in order to back them up.

Was this answer helpful?

2 people found this answer helpful.
0 comments No comments
Answer accepted by question author
Anonymous
2010-02-26T21:34:07+00:00

This does help.

Now that you've pointed this out I've seen the same behaviour in the CAPI2 Event Viewer log file. My Windows 7 clients have been trying to access two URL's at the domain http://crl.microsoft.com/

None of the posts I had seen on this had mentioned the need for this path.

Thanks,

Michael

hi

Here's a basic definition for CRL in general terms. You can search Google using "Certificate Revocation List" and find a lot more information.

it could also be that direct X is looking for some updated drivers

what happens is that your browser is checking for provoked certificates , is perfectly normal and safe , its to keep you safe

have a nice day

ps for some further info

http://technet.microsoft.com/en-us/library/dd772269.aspx


Scan with OneCare + 50 Windows 7even Tips + Plagued by the Privacy Center? REMOVE IT + Threat Research & Response Blog + Sysinternals Live tools + TRANSLATOR+ Photosynth + Microsoft Security + Microsoft SUPPORT + PIVOT from Live Labs+ Microsoft Live Labs + Office 2010 beta + Get Windows LIVE!

Was this answer helpful?

0 comments No comments

138 additional answers

Sort by: Newest
  1. Anonymous
    2009-06-03T15:22:35+00:00

    Martin:

    I ran sfc and it executed with no errors ("Windows Resource Protection did not find any integrity violations").

    Then I used msconfig.exe to disable all non-Microsoft services, as you directed, and did a restart -- no improvement -- the system behaved the same, pausing on an empty blue screen.

    Here's more info that might be helpful:  During boot, the usual things happen up to the display of the Welcome message.   During the display of the Welcome message, the disk rattles as usual but then slows down to just a few flickers.  After a few sectonds of this, the screen changes to empty blue.  After a few more seconds, the disk starts rattling at 'normal' intensity and the blue screen clears (though on one occasion, as I described above, it stayed on the blue screen).

    Maybe during the pause in disk activity during the Welcome display the system is tring to access the internet?  And getting the root cert problem?   While waiting maybe the Welcome times out and blue screen comes?  Then the internet reply causes the resumption of the usual boot sequence?  (and if no reply, no resumption?)

    Anyway, it looks like a Microsoft problem, since the problem seems to occur even with just MS services enabled on a 'clean' boot.  Has anyone checked that the certificate it wants is still valid?  That looks like the obvious thing to check.

    Looking forward to your reply, and thanks for your help.

    Addendum:  When I went to resture the normal boot (using msconfig.exe) I found TrueVector was enabled, which is ZoneAlarm's firewall, in case that's useful info.  Also, my hardware is a Dell Inspiron 531 in an off-the-shelf config.

    Was this answer helpful?

    0 comments No comments
  2. Anonymous
    2009-06-03T10:05:07+00:00

    Hi again Martin, I just found the following on another Forum:

    "Event Log Online Help offers absolutely no help other than to identify the problematic cab download as the "Automatic Root Certificates Update component designed to automatically check the list of trusted authorities on the Microsoft Windows Update Web site."

    My system clock is correctly synched to Microsoft time and as owner/administrator I have full permissions to extract the file. But the properties for authroot.stl indicate "The certificate is not valid for the requested usage." It was signed by Microsoft on December 19, 2007.

    Bottom line, this Microsoft-created Certificate Trust List is out of date or faulty, yet Microsoft refuses to issue a current certificate and has yet to reply to dozens of online posts seeking answers, yet another known Vista issue Microsoft ignores. Can Microsoft please explain why? Moreover, will Microsoft please update its Trust List for its own Windows Update site? "

    This covers my error, so what should I do now.  Confuseduser

    Was this answer helpful?

    0 comments No comments
  3. Anonymous
    2009-06-03T09:54:49+00:00

    Hi Martin, I just ran scannow.  The verification phase was 100 percent complete and stated "Windows Resource Protection did not find any integrity violations".  After that scannow stopped. I have no problems with the Startup (like the other user above), therefore, I am wondering whether I need to follow your suggestions.  However, I now realize that my message turns up after 4 pm (and at 4 pm every day I run the Windows Automatic Update).  The error message led me to Microsoft TechNet, Event ID 11 Automatic Root Certificates Update Configuration. Under Resolve, I was asked to ensure that the user account is logged on with full Control permission.  I checked and it is logged on as System.  However, I cannot follow "Verify" because I do not know how to find a Web browser that requires the Automatic Root Certificates.  All of the above is definitely caused by the last Vista Service Pack 2 and I assume that my computer is trying every day to find whatever is wrong.  Confuseduser

    Was this answer helpful?

    0 comments No comments