Microsoft-Windows CAPI2 failed extract of third-party root list from auto update cab

Anonymous
2009-06-02T10:11:30+00:00

Hi, I get this error in the last few weeks and I am not sure, whether I should do something about it. I went to TechNet, Event ID 11 Automatic Root Certificates Update Configuration, but I would need something simpler that I can follow. Confuseduser P.S. Exact error message is below: -

Log Name:      Application

Source:        Microsoft-Windows-CAPI2

Date:          27/05/2009 8:42:16 PM

Event ID:      11

Task Category: None

Level:         Error

Keywords:      Classic

User:          N/A

Computer:      Helga-PC

Description:

Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab> with error: A required certificate is not within its validity period when verifying against the current system clock or the timestamp in the signed file.

.

Event Xml:

<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">

  <System>

    <Provider Name="Microsoft-Windows-CAPI2" Guid="{5bbca4a8-b209-48dc-a8c7-b23d3e5216fb}" EventSourceName="Microsoft-Windows-CAPI2" />

    <EventID Qualifiers="49154">11</EventID>

    <Version>0</Version>

    <Level>2</Level>

    <Task>0</Task>

    <Opcode>0</Opcode>

    <Keywords>0x80000000000000</Keywords>

    <TimeCreated SystemTime="2009-05-27T10:42:16.000Z" />

    <EventRecordID>32381</EventRecordID>

    <Correlation />

    <Execution ProcessID="0" ThreadID="0" />

    <Channel>Application</Channel>

    <Computer>Helga-PC</Computer>

    <Security />

  </System>

  <EventData>

    <Data>http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab</Data>

    <Data>A required certificate is not within its validity period when verifying against the current system clock or the timestamp in the signed file.

</Data>

  </EventData>

</Event>

Windows for home | Other | Performance and system failures

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments
Answer accepted by question author
Anonymous
2009-10-20T11:32:58+00:00

I don't see any reason the solution above would not work in Vista.  I see the same folder structure and registry entries on Vista. 

If you are not familiar with the registry, here is a very detailed instruction set on how to delete entries:  http://support.microsoft.com/kb/136393

Be sure to use the export option before deleting entries in order to back them up.

Was this answer helpful?

2 people found this answer helpful.
0 comments No comments
Answer accepted by question author
Anonymous
2010-02-26T21:34:07+00:00

This does help.

Now that you've pointed this out I've seen the same behaviour in the CAPI2 Event Viewer log file. My Windows 7 clients have been trying to access two URL's at the domain http://crl.microsoft.com/

None of the posts I had seen on this had mentioned the need for this path.

Thanks,

Michael

hi

Here's a basic definition for CRL in general terms. You can search Google using "Certificate Revocation List" and find a lot more information.

it could also be that direct X is looking for some updated drivers

what happens is that your browser is checking for provoked certificates , is perfectly normal and safe , its to keep you safe

have a nice day

ps for some further info

http://technet.microsoft.com/en-us/library/dd772269.aspx


Scan with OneCare + 50 Windows 7even Tips + Plagued by the Privacy Center? REMOVE IT + Threat Research & Response Blog + Sysinternals Live tools + TRANSLATOR+ Photosynth + Microsoft Security + Microsoft SUPPORT + PIVOT from Live Labs+ Microsoft Live Labs + Office 2010 beta + Get Windows LIVE!

Was this answer helpful?

0 comments No comments

138 additional answers

Sort by: Oldest
  1. Anonymous
    2009-06-04T07:49:53+00:00

    Hi Martin, I am wondering whetheryou noticed my above email that a 

    " Microsoft-created Certificate Trust List is out of date or faulty, yet Microsoft refuses to issue a current certificate and has yet to reply to dozens of online posts seeking answers, yet another known Vista issue Microsoft ignores. Can Microsoft please explain why? Moreover, will Microsoft please update its Trust List for its own Windows Update site? "  (I found this on another Forum through Google). Will above fix this problem or not?  I do not have any problem with Microsoft Updates and when I go to Windows Updates in the Control Panel everything seems to be uptodate.  I only noticed that the above problem seems to occur, when Windows checks for Updates.

    My problem clearly refers to a Certificate that is invalid. Confuseduser P.S. I have the Microsoft Updates in my trusted sites.   P.S. I also found Microsoft TechNet Even ll and I followed some of it, however, I do not know how to handle a web browser that requires an Automatic Root Certificate.   Confuseduser

    Was this answer helpful?

    0 comments No comments
  2. Anonymous
    2009-06-04T10:08:04+00:00

    Hi Martin, I found out the following: Every  day after 4 pm the Certificate Services Client starts, afterwards the Security Centre starts and then I get the error with the CAPI2 as above.  I have now gone back to the Windows Security log.  I found even 5038 audit failure, System Integrity (it happened at the same time as the CAPI2 message).  I get error message: Device/HarddiskVolume1\Windows\System32\drivers\mchInjDrv.sys is the cause.

    I looked around on the Internet and it could be a Rootkit and it could be Malware.  What do I do now.  I really don't even know, what it all means. However, I think that it is all linked.  Confuseduser

    Was this answer helpful?

    0 comments No comments
  3. Anonymous
    2009-06-04T14:48:59+00:00

    04 June, 2009

    Hello Everyone,

    I too started experiencing CAPI2 11 errors on 27May2009 - the day Windows Vista SP2 appeared on my Windows Update list.  At that time however, I only set Windows Update to 'hide' Vista SP2 for the meantime to allow it time to go through the usual debugging process for newly issued software. 

    But after noticing the CAPI2 11 errors a few days later, I decided to install Vista SP2 immediately to see if the CAPI2 11 errors will go away.  So now with deep foreboding I am using Vista SP2 and the CAPI2 11 errors still haven't gone away.

    What I noticed though is that:

    (a) The CAPI2 11 errors occur only during pc start-up and only when my internet connection is enabled prior to pc start-up - my usual pradtice ever since;

    (b) I have tried disabling my internet connection is disabled prior to start-up - by disabling the on-board LAN prior to shutdown - and discovered that no CAPI2 11 error occurs during the next pc start up.

    Aside from Windows Vista, the only other software I have that has automatic update enabled is Norton 360 v2.  By experimentation, I have determined that the CAPI2 11 errors still occur during pc start up when the on-board LAN is enabled, whether N360 v2 automatic update is enabled or disabled.

    To Martin:  I do not think the problem is Vista SP2.  I think it was Windows Update on 27May2009 - all CAPI2 11 errors started occuring on that date!  The last time something like this happened to me with automatic Windows Update, I lost access to my Security Center.  Back then, I was also directed to run SFC and to check my start-up programs one by one - to no avail.  I have forgotten the prescribed solution for that problem, but it I think it involved fixing a corrupted configuration file(?) that could not be detected by SFC.

    Alex_PH

    Was this answer helpful?

    0 comments No comments