Microsoft-Windows CAPI2 failed extract of third-party root list from auto update cab

Anonymous
2009-06-02T10:11:30+00:00

Hi, I get this error in the last few weeks and I am not sure, whether I should do something about it. I went to TechNet, Event ID 11 Automatic Root Certificates Update Configuration, but I would need something simpler that I can follow. Confuseduser P.S. Exact error message is below: -

Log Name:      Application

Source:        Microsoft-Windows-CAPI2

Date:          27/05/2009 8:42:16 PM

Event ID:      11

Task Category: None

Level:         Error

Keywords:      Classic

User:          N/A

Computer:      Helga-PC

Description:

Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab> with error: A required certificate is not within its validity period when verifying against the current system clock or the timestamp in the signed file.

.

Event Xml:

<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">

  <System>

    <Provider Name="Microsoft-Windows-CAPI2" Guid="{5bbca4a8-b209-48dc-a8c7-b23d3e5216fb}" EventSourceName="Microsoft-Windows-CAPI2" />

    <EventID Qualifiers="49154">11</EventID>

    <Version>0</Version>

    <Level>2</Level>

    <Task>0</Task>

    <Opcode>0</Opcode>

    <Keywords>0x80000000000000</Keywords>

    <TimeCreated SystemTime="2009-05-27T10:42:16.000Z" />

    <EventRecordID>32381</EventRecordID>

    <Correlation />

    <Execution ProcessID="0" ThreadID="0" />

    <Channel>Application</Channel>

    <Computer>Helga-PC</Computer>

    <Security />

  </System>

  <EventData>

    <Data>http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab</Data>

    <Data>A required certificate is not within its validity period when verifying against the current system clock or the timestamp in the signed file.

</Data>

  </EventData>

</Event>

Windows for home | Other | Performance and system failures

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments
Answer accepted by question author
Anonymous
2009-10-20T11:32:58+00:00

I don't see any reason the solution above would not work in Vista.  I see the same folder structure and registry entries on Vista. 

If you are not familiar with the registry, here is a very detailed instruction set on how to delete entries:  http://support.microsoft.com/kb/136393

Be sure to use the export option before deleting entries in order to back them up.

Was this answer helpful?

2 people found this answer helpful.
0 comments No comments
Answer accepted by question author
Anonymous
2010-02-26T21:34:07+00:00

This does help.

Now that you've pointed this out I've seen the same behaviour in the CAPI2 Event Viewer log file. My Windows 7 clients have been trying to access two URL's at the domain http://crl.microsoft.com/

None of the posts I had seen on this had mentioned the need for this path.

Thanks,

Michael

hi

Here's a basic definition for CRL in general terms. You can search Google using "Certificate Revocation List" and find a lot more information.

it could also be that direct X is looking for some updated drivers

what happens is that your browser is checking for provoked certificates , is perfectly normal and safe , its to keep you safe

have a nice day

ps for some further info

http://technet.microsoft.com/en-us/library/dd772269.aspx


Scan with OneCare + 50 Windows 7even Tips + Plagued by the Privacy Center? REMOVE IT + Threat Research & Response Blog + Sysinternals Live tools + TRANSLATOR+ Photosynth + Microsoft Security + Microsoft SUPPORT + PIVOT from Live Labs+ Microsoft Live Labs + Office 2010 beta + Get Windows LIVE!

Was this answer helpful?

0 comments No comments

138 additional answers

Sort by: Oldest
  1. Anonymous
    2009-06-23T04:07:22+00:00

    I'm having the CAPI2 Event 11 issue on two Small Business Server 2008 servers I administrator.  No luck finding a solution either.

    Pete

    Was this answer helpful?

    0 comments No comments
  2. Anonymous
    2009-06-23T07:11:55+00:00

    I am a bit scared about your statement than only one of your VISTA machines demonstrated this. For sure, we are quite a few in this thread to experience the problem at the last days of May 2009. I hope it remains a pure MS server issue (invalid certificate), and that our local "root of the root certificate or so" (if any) has not been broken by 'mistake' during a MS update.

    Fyi, I have opened yesterday a ticket to MS, associating this to the free-support "Windows Update" topic that relates to it. Unfortunately, my suggestion was not considered as  the reply was "please follow the following instruction in order to pay for a ticket that we will (only then)  process" :(

    Quite disappointing for a 17-years professional experience master in IT engineering that spent time reporting an issue! Moreover, this let me think that if I pay I wil have to fight again for the issue to be taken seriously (ie with no reply à la "reinstall from scratch or so")

    As I stated the CAPI2 error only appears on one of the machines I have (my Laptop, Vista Business 64). On my desktop at home (Vista Business 64) and on my office machine (Vista Enterprise 32) the CAPI2 message does not appear. But this does not really irritate me. I assume that the certificate trust list is not updated very frequently. It might have happened that our machines showing the problem just started to update the certificate trust list in the wrong moment. Maybe the machines which still work (because they do not try yet to upgrade the trust list) keep an old list but they might enter the same mode any time (maybe if you visit an SSL/HTTPS page which uses a certificate signed by unknown CA?).

    Probably somebody knows how to manually issue a certificate trust list update or how to disable this automatic update. Personally I am not aware what I did to trigger it on my Laptop.

    In addition I can confirm again, that the trust list it tries to download shows an invalid signature on ALL the machines (even the ones which do not log the CAPI2 error yet).

    Unfortunately I get the same feeling that Microsoft does not care too much about issues like this and I don't feel like paying just to report an issue for a product I already paid licenses for. Especially because it seems to be obvious that at least the certificate trust list it tries to download is broken on Microsoft servers. There must be quite some downloads of this file every day but it does not look like it reaches a limit where Microsoft notices that something is wrong. At least my machine is downloading and discarding it 2-5 times a day.

    By the way, there is a thread on technet about the same topic too:

    http://social.technet.microsoft.com/Forums/en-US/itprovistasecurity/thread/fdf97ac2-21b7-49af-9fc5-d8b2dc3e8d83

    It seems to affect w2k8 servers (technical base identical to Vista) but it's probably even worse there - one user reported that the error is logged every minute.

    br,

    Rainer

    Was this answer helpful?

    0 comments No comments
  3. Anonymous
    2009-06-23T08:05:22+00:00

    It seems to affect w2k8 servers (technical base identical to Vista) but it's probably even worse there - one user reported that the error is logged every minute.

    Helo,

    I can confirm that on our Exchange Win2008 standard 64bit servers there is the same problem since last days of May 2009 and these events are reported every minute . On our domain controllers we don't have these problems...


    Mac

    Was this answer helpful?

    0 comments No comments