I have the feeling that there is nothing wrong in our computers but thatit happened on Microsoft server sites, where a published list of certificate is not valid.
I think you are completely right here. When I open the Certificiate Trust List it immediately presents a warning/error:
Certificate Trust List Information
This certificate trust list is not valid. The certificate that signed the list is not valid.
Then click on "View Signature" and you will get another error displayed:
Digital Signature Information
The certificate is not valid for the requested usage.
Clicking on "View Certificate" reveals the following:
Certificate Information
This certificate is not valid for the selected purpose.
In the "Details" tab under "Key Usage" it reads "Digital Signature (80)" and the icon has a yellow exclamation mark.
Going to the "Certification Path" tab shows the following path:
Microsoft Root Certificate Authority
Microsoft Certificate Trust List PCA
Microsoft Certificate Trust List Publisher
The last one seems to be the guilty one (see above properties).
Going one step down to the "Microsoft Certificate Trust List PCA" certificate it shows the following in the "Key Usage" field: "Digital Signature, Certificate Signing, Off-line CRL Signing, CRL Signing (86)" and it has a green arrow within the icon (compared
to the yellow exclamation mark of the Microsoft Certificate Trust List Publisher certificate).
I've verified this on two Vista machines - one of them does not show the CAPI2 error.
So it seems that the "Microsoft Certificate Trust List Publisher" certificate is broken and contains wrong key usage flags.