Microsoft-Windows CAPI2 failed extract of third-party root list from auto update cab

Anonymous
2009-06-02T10:11:30+00:00

Hi, I get this error in the last few weeks and I am not sure, whether I should do something about it. I went to TechNet, Event ID 11 Automatic Root Certificates Update Configuration, but I would need something simpler that I can follow. Confuseduser P.S. Exact error message is below: -

Log Name:      Application

Source:        Microsoft-Windows-CAPI2

Date:          27/05/2009 8:42:16 PM

Event ID:      11

Task Category: None

Level:         Error

Keywords:      Classic

User:          N/A

Computer:      Helga-PC

Description:

Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab> with error: A required certificate is not within its validity period when verifying against the current system clock or the timestamp in the signed file.

.

Event Xml:

<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">

  <System>

    <Provider Name="Microsoft-Windows-CAPI2" Guid="{5bbca4a8-b209-48dc-a8c7-b23d3e5216fb}" EventSourceName="Microsoft-Windows-CAPI2" />

    <EventID Qualifiers="49154">11</EventID>

    <Version>0</Version>

    <Level>2</Level>

    <Task>0</Task>

    <Opcode>0</Opcode>

    <Keywords>0x80000000000000</Keywords>

    <TimeCreated SystemTime="2009-05-27T10:42:16.000Z" />

    <EventRecordID>32381</EventRecordID>

    <Correlation />

    <Execution ProcessID="0" ThreadID="0" />

    <Channel>Application</Channel>

    <Computer>Helga-PC</Computer>

    <Security />

  </System>

  <EventData>

    <Data>http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab</Data>

    <Data>A required certificate is not within its validity period when verifying against the current system clock or the timestamp in the signed file.

</Data>

  </EventData>

</Event>

Windows for home | Other | Performance and system failures

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments
Answer accepted by question author
Anonymous
2009-10-20T11:32:58+00:00

I don't see any reason the solution above would not work in Vista.  I see the same folder structure and registry entries on Vista. 

If you are not familiar with the registry, here is a very detailed instruction set on how to delete entries:  http://support.microsoft.com/kb/136393

Be sure to use the export option before deleting entries in order to back them up.

Was this answer helpful?

2 people found this answer helpful.
0 comments No comments
Answer accepted by question author
Anonymous
2010-02-26T21:34:07+00:00

This does help.

Now that you've pointed this out I've seen the same behaviour in the CAPI2 Event Viewer log file. My Windows 7 clients have been trying to access two URL's at the domain http://crl.microsoft.com/

None of the posts I had seen on this had mentioned the need for this path.

Thanks,

Michael

hi

Here's a basic definition for CRL in general terms. You can search Google using "Certificate Revocation List" and find a lot more information.

it could also be that direct X is looking for some updated drivers

what happens is that your browser is checking for provoked certificates , is perfectly normal and safe , its to keep you safe

have a nice day

ps for some further info

http://technet.microsoft.com/en-us/library/dd772269.aspx


Scan with OneCare + 50 Windows 7even Tips + Plagued by the Privacy Center? REMOVE IT + Threat Research & Response Blog + Sysinternals Live tools + TRANSLATOR+ Photosynth + Microsoft Security + Microsoft SUPPORT + PIVOT from Live Labs+ Microsoft Live Labs + Office 2010 beta + Get Windows LIVE!

Was this answer helpful?

0 comments No comments

138 additional answers

Sort by: Oldest
  1. Anonymous
    2009-06-22T03:34:03+00:00

    Tabagaras, you face another issue I am afraid.

    The lack of update of root certificates should imho not have immediate impact: this will be gradual and the ones that will be complaining the most to MS will be e-governement, merchands, etc. For the end user, it would require at the worst manual installation of root certificate authorities.

    What puzzle me is the fact that the error message happens at each boot time, prior to opening a network connection (WIFI in case of notebooks), which seems to indicate that an automatic update has downloaded and cached <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>

    Still the online file itself is indeed not fixed at this stage by Microsoft.

    Philippe

    Was this answer helpful?

    0 comments No comments
  2. Anonymous
    2009-06-22T07:56:02+00:00

    I have the feeling that there is nothing wrong in our computers but thatit happened on Microsoft server sites, where a published list of certificate is not valid.

    I think you are completely right here. When I open the Certificiate Trust List it immediately presents a warning/error:

    Certificate Trust List Information

    This certificate trust list is not valid. The certificate that signed the list is not valid.

    Then click on "View Signature" and you will get another error displayed:

    Digital Signature Information

    The certificate is not valid for the requested usage.

    Clicking on "View Certificate" reveals the following:

    Certificate Information

    This certificate is not valid for the selected purpose.

    In the "Details" tab under "Key Usage" it reads "Digital Signature (80)" and the icon has a yellow exclamation mark.

    Going to the "Certification Path" tab shows the following path:

    Microsoft Root Certificate Authority

        Microsoft Certificate Trust List PCA

            Microsoft Certificate Trust List Publisher

    The last one seems to be the guilty one (see above properties).

    Going one step down to the "Microsoft Certificate Trust List PCA" certificate it shows the following in the "Key Usage" field: "Digital Signature, Certificate Signing, Off-line CRL Signing, CRL Signing (86)" and it has a green arrow within the icon (compared to the yellow exclamation mark of the Microsoft Certificate Trust List Publisher certificate).

    I've verified this on two Vista machines - one of them does not show the CAPI2 error.

    So it seems that the "Microsoft Certificate Trust List Publisher" certificate is broken and contains wrong key usage flags.

    Was this answer helpful?

    0 comments No comments
  3. Anonymous
    2009-06-22T21:25:46+00:00

    Rainer,

    I am a bit scared about your statement than only one of your VISTA machines demonstrated this. For sure, we are quite a few in this thread to experience the problem at the last days of May 2009. I hope it remains a pure MS server issue (invalid certificate), and that our local "root of the root certificate or so" (if any) has not been broken by 'mistake' during a MS update.

    Fyi, I have opened yesterday a ticket to MS, associating this to the free-support "Windows Update" topic that relates to it. Unfortunately, my suggestion was not considered as  the reply was "please follow the following instruction in order to pay for a ticket that we will (only then)  process" :(

    Quite disappointing for a 17-years professional experience master in IT engineering that spent time reporting an issue! Moreover, this let me think that if I pay I wil have to fight again for the issue to be taken seriously (ie with no reply à la "reinstall from scratch or so")

    Ph.

    Was this answer helpful?

    0 comments No comments