Microsoft-Windows CAPI2 failed extract of third-party root list from auto update cab

Anonymous
2009-06-02T10:11:30+00:00

Hi, I get this error in the last few weeks and I am not sure, whether I should do something about it. I went to TechNet, Event ID 11 Automatic Root Certificates Update Configuration, but I would need something simpler that I can follow. Confuseduser P.S. Exact error message is below: -

Log Name:      Application

Source:        Microsoft-Windows-CAPI2

Date:          27/05/2009 8:42:16 PM

Event ID:      11

Task Category: None

Level:         Error

Keywords:      Classic

User:          N/A

Computer:      Helga-PC

Description:

Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab> with error: A required certificate is not within its validity period when verifying against the current system clock or the timestamp in the signed file.

.

Event Xml:

<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">

  <System>

    <Provider Name="Microsoft-Windows-CAPI2" Guid="{5bbca4a8-b209-48dc-a8c7-b23d3e5216fb}" EventSourceName="Microsoft-Windows-CAPI2" />

    <EventID Qualifiers="49154">11</EventID>

    <Version>0</Version>

    <Level>2</Level>

    <Task>0</Task>

    <Opcode>0</Opcode>

    <Keywords>0x80000000000000</Keywords>

    <TimeCreated SystemTime="2009-05-27T10:42:16.000Z" />

    <EventRecordID>32381</EventRecordID>

    <Correlation />

    <Execution ProcessID="0" ThreadID="0" />

    <Channel>Application</Channel>

    <Computer>Helga-PC</Computer>

    <Security />

  </System>

  <EventData>

    <Data>http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab</Data>

    <Data>A required certificate is not within its validity period when verifying against the current system clock or the timestamp in the signed file.

</Data>

  </EventData>

</Event>

Windows for home | Other | Performance and system failures

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments
Answer accepted by question author
Anonymous
2009-10-20T11:32:58+00:00

I don't see any reason the solution above would not work in Vista.  I see the same folder structure and registry entries on Vista. 

If you are not familiar with the registry, here is a very detailed instruction set on how to delete entries:  http://support.microsoft.com/kb/136393

Be sure to use the export option before deleting entries in order to back them up.

Was this answer helpful?

2 people found this answer helpful.
0 comments No comments
Answer accepted by question author
Anonymous
2010-02-26T21:34:07+00:00

This does help.

Now that you've pointed this out I've seen the same behaviour in the CAPI2 Event Viewer log file. My Windows 7 clients have been trying to access two URL's at the domain http://crl.microsoft.com/

None of the posts I had seen on this had mentioned the need for this path.

Thanks,

Michael

hi

Here's a basic definition for CRL in general terms. You can search Google using "Certificate Revocation List" and find a lot more information.

it could also be that direct X is looking for some updated drivers

what happens is that your browser is checking for provoked certificates , is perfectly normal and safe , its to keep you safe

have a nice day

ps for some further info

http://technet.microsoft.com/en-us/library/dd772269.aspx


Scan with OneCare + 50 Windows 7even Tips + Plagued by the Privacy Center? REMOVE IT + Threat Research & Response Blog + Sysinternals Live tools + TRANSLATOR+ Photosynth + Microsoft Security + Microsoft SUPPORT + PIVOT from Live Labs+ Microsoft Live Labs + Office 2010 beta + Get Windows LIVE!

Was this answer helpful?

0 comments No comments

138 additional answers

Sort by: Most helpful
  1. Anonymous
    2009-06-21T08:41:52+00:00

    Hi Philippe, you might be right, but I really think that Microsoft should have taken some action by now.  As far as I am concerned the issue is not yet resolved. Confuseduser

    Was this answer helpful?

    0 comments No comments
  2. Anonymous
    2009-06-21T08:33:08+00:00

    I have the feeling that there is nothing wrong in our computers but thatit happened on Microsoft server sites, where a published list of certificate is not valid.

    I went to <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab> manually, and tool the "authroot.stl" certificate file inside: when you double click on it to view the certificate, it indicates "Cette liste de certificat de confiance n'est pas valide. Le certificat qui a signé la liste n'est pas valide." (which I can translate in EN as "This list of trusted certificates is invalid. The certificate that did sign the lsit is not valid."

    And indeed, looking at the certificate that signed the list, it appears that it is a certificate is still not in the validity period but is not declared as valid for performing such an action (signing a list of root certificates).

    I believe the problem will be resolved when Microsoft will realize about the glitch and will fixed the certificate located at this URL (and in that sense, OUR POSTS MIGHT HELP).

    Until then, I am afraid that we should live without trying to have 100% error-free VISTA event managers. I noticed no side effect in the way applications behave, except the error message.

    Philippe

    Was this answer helpful?

    0 comments No comments
  3. Anonymous
    2009-06-21T08:19:48+00:00

    Hi Rainer Meier,

    Thanks for using the Answers Forum.

    It looks like you might want to check your motherboard manufactuer for a firmware/BIOS update or patch.

    You may also want to investigate the CMOS battery to see if it needs replacing.

    Hope this helps.


    Chris

    Microsoft Answers Support Engineer

    Visit our Microsoft Answers Feedback Forum and let us know what you think.

    This is almost getting funny...

    Please add me to the list of paying customers that have been waiting for a solution to this problem. Might I suggest Microsoft push this to the level 2 support guys (and girls)?

    Was this answer helpful?

    0 comments No comments