Microsoft-Windows CAPI2 failed extract of third-party root list from auto update cab

Anonymous
2009-06-02T10:11:30+00:00

Hi, I get this error in the last few weeks and I am not sure, whether I should do something about it. I went to TechNet, Event ID 11 Automatic Root Certificates Update Configuration, but I would need something simpler that I can follow. Confuseduser P.S. Exact error message is below: -

Log Name:      Application

Source:        Microsoft-Windows-CAPI2

Date:          27/05/2009 8:42:16 PM

Event ID:      11

Task Category: None

Level:         Error

Keywords:      Classic

User:          N/A

Computer:      Helga-PC

Description:

Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab> with error: A required certificate is not within its validity period when verifying against the current system clock or the timestamp in the signed file.

.

Event Xml:

<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">

  <System>

    <Provider Name="Microsoft-Windows-CAPI2" Guid="{5bbca4a8-b209-48dc-a8c7-b23d3e5216fb}" EventSourceName="Microsoft-Windows-CAPI2" />

    <EventID Qualifiers="49154">11</EventID>

    <Version>0</Version>

    <Level>2</Level>

    <Task>0</Task>

    <Opcode>0</Opcode>

    <Keywords>0x80000000000000</Keywords>

    <TimeCreated SystemTime="2009-05-27T10:42:16.000Z" />

    <EventRecordID>32381</EventRecordID>

    <Correlation />

    <Execution ProcessID="0" ThreadID="0" />

    <Channel>Application</Channel>

    <Computer>Helga-PC</Computer>

    <Security />

  </System>

  <EventData>

    <Data>http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab</Data>

    <Data>A required certificate is not within its validity period when verifying against the current system clock or the timestamp in the signed file.

</Data>

  </EventData>

</Event>

Windows for home | Other | Performance and system failures

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments
Answer accepted by question author
Anonymous
2009-10-20T11:32:58+00:00

I don't see any reason the solution above would not work in Vista.  I see the same folder structure and registry entries on Vista. 

If you are not familiar with the registry, here is a very detailed instruction set on how to delete entries:  http://support.microsoft.com/kb/136393

Be sure to use the export option before deleting entries in order to back them up.

Was this answer helpful?

2 people found this answer helpful.
0 comments No comments
Answer accepted by question author
Anonymous
2010-02-26T21:34:07+00:00

This does help.

Now that you've pointed this out I've seen the same behaviour in the CAPI2 Event Viewer log file. My Windows 7 clients have been trying to access two URL's at the domain http://crl.microsoft.com/

None of the posts I had seen on this had mentioned the need for this path.

Thanks,

Michael

hi

Here's a basic definition for CRL in general terms. You can search Google using "Certificate Revocation List" and find a lot more information.

it could also be that direct X is looking for some updated drivers

what happens is that your browser is checking for provoked certificates , is perfectly normal and safe , its to keep you safe

have a nice day

ps for some further info

http://technet.microsoft.com/en-us/library/dd772269.aspx


Scan with OneCare + 50 Windows 7even Tips + Plagued by the Privacy Center? REMOVE IT + Threat Research & Response Blog + Sysinternals Live tools + TRANSLATOR+ Photosynth + Microsoft Security + Microsoft SUPPORT + PIVOT from Live Labs+ Microsoft Live Labs + Office 2010 beta + Get Windows LIVE!

Was this answer helpful?

0 comments No comments

138 additional answers

Sort by: Oldest
  1. Anonymous
    2010-10-01T03:52:36+00:00

    Finally addressed here-

    http://support.microsoft.com/kb/2328240

    I tried the workaround recommended in that MSKB article, and after that my Win2008 server will not boot. Be very,very careful if you plan to try the workarounds from that MSKB article on production servers...

    Was this answer helpful?

    0 comments No comments
  2. Anonymous
    2010-10-07T11:10:52+00:00

    October 6, 2010  OS: Vista x64 Ultimate

    On my system, The earliest entry in Event Viewer for CAPI2 Event ID 11 errors is July 11, 2010. Since that date Event Viewer shows 725 instances of that particular error.

    Following many days of research I tried the solution recommended in Microsoft KB2328240 (http://support.microsoft.com/kb/2328240).

    NOTE: KB2328240 leaves out something very important. I believe you need to right click on Command Prompt and select "run as administrator".

    KB2328240: To resolve the problem, follow these steps: Open a command prompt. To do this, click Start, click All Programs, click Accessories, and then click Command Prompt*(should be right click Command Prompt and select run as administrator)* . At the command prompt, type the following command, and then press ENTER: certutil -urlcache * delete

    For clarification:  certutil (space) -urlcache (space) * (space) delete

    Afterward, I saw this as the last line in the command prompt window:  CertUtil: -URLCache command completed successfully

    After reboot, Event Viewer showed that the CAPI2 Event ID 11 error still occurred. I noted the time I logged into my account and the error event time stamp showed the event had taken place before my logon. My conclusion at that point was that the error must be related to a System account and not my user account.

    I checked the file locations specified in KB2328240 and all of the folders still had nothing in them (empty folders).

    The next solution I tried was Kevin Zhao's that is posted here:

    http://social.answers.microsoft.com/Forums/en-US/vistawu/thread/685e65f6-72a7-4986-b02c-f17e8be78926

    Abbreviated version of Kevin Zhao's solution:

    Based on my research, the issue can be caused by corrupted certificate data on the server. I suggest you try the following steps to test the issue:

    1. Backup and delete the contents of the following folders:

    C:\Windows\System32\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content

    C:\Windows\System32\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData

    1. Backup and delete the certificates listed under "Certificates" key:

    HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\AuthRoot\Certificates

    Then, restart the server to check the result.

    Since I had already deleted the contents of the two folders he referenced , I opened registry editor and exported a backup of all the subkeys under \AuthRoot\Certificates. Then, I deleted all of the subkeys as per his instructions.  After I rebooted the system, Event Viewer showed that the CAPI2 Event ID 11 error still occurred, again before I logged on.

    I was tempted to give up at that point but decided to try again one last time. I checked the folder locations specified in KB2328240 and they were still empty so I opened registry editor again to HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\AuthRoot\Certificates. There were three certificates listed as subkeys which I deleted (Oops, should have read KB293781 first).  

    I didn't reboot the system this time. Instead I ran the following executable, again after right clicking on it and selecting run as administrator:

    Update for Root Certificates Aug 2010 KB931125

    rootsupd.exe (331 KB)

    Version: 931125, Date Published: Aug 23, 2010

    http://www.microsoft.com/downloads/en/details.aspx?FamilyID=f5eff286-5412-4d7f-81b2-3a1418a4f8b9

    Next, I synced the system clock and then rebooted. After logon, I let the computer run until the drive activity light went out. When I checked Event Viewer there were no CAPI2 Event ID 11 errors listed in the time period after I restarted the system. I expanded the Windows Logs section and selected Application. Upon scrolling down, I saw an Information level entry for CAPI2 with the following result:

    Successful auto update of third-party root certificate:: Subject: <CN=UTN-USERFirst-Object, OU=http://www.usertrust.com, O=The USERTRUST Network, L=Salt Lake City, S=UT, C=US> Sha1 thumbprint: <E12DFB4B41D7D9C32B30514BAC1D81D8385E2D46>.

    Final Thoughts:  Everything about the CAPI2 errors seems to point to an invalid root certificate.  As I'm sure everyone knows by now, Event Viewer shows the following for CAPI2 Error ID 11:

    Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab> with error: A required certificate is not within its validity period when verifying against the current system clock or the timestamp in the signed file.

    I clicked on the link and downloaded the authrootstl.cab file. Extracting authroot.stl from the cab file and opening it gives the following:

    Certificate Trust List - General Tab

    Certificate Trust List Information

    This certificate trust list is not valid. The certificate that signed the list is not valid.

    Subject usage  Root List Signer

    Effective date  Monday, July 19, 2010 4:15:54 pm.

    When I click on View Signature I see the following:

    Digital Signature Information

    The certificate is not valid for the requested usage

    Name: Microsoft Certificate Trust List Publisher

    Click on View Certificate in that dialog box, then select the Details Tab.  It shows that the certificate is Validfrom Thursday, April 08, 2010 and Validto Friday, July 08, 2010.

    The certificate trust list is not valid because it expired on July 08, 2010.  Many of the forum posts I looked at regarding CAPI2 error events reference a date shortly after July 8,2010 as when their CAPI2 errors began.  In my case, the earliest date I had CAPI2 errors was July 11, 2010. What puzzles me is why the cert wasn't updated after so many people reported CAPI2 errors. Perhaps it's because it didn't really cause any problems outside of an error event showing up in Event Viewer.  

    In my case, after eliminating this error, my system now loads in half the time it did before. Previously it took Vista over 3 minutes to load. Now it loads in 1:30. Considering I spent about 500 minutes solving this problem, it will take quite awhile before I make up that time. Of course, there is also the possibility that the CAPI2 events had no bearing on my system load times. Oh well.

    Was this answer helpful?

    0 comments No comments
  3. Anonymous
    2010-10-11T15:40:39+00:00

    fix posted here at Microsoft here is link works 100% http://support.microsoft.com/default.aspx?scid=kb;en-us;2328240

    Was this answer helpful?

    0 comments No comments