Microsoft-Windows CAPI2 failed extract of third-party root list from auto update cab

Anonymous
2009-06-02T10:11:30+00:00

Hi, I get this error in the last few weeks and I am not sure, whether I should do something about it. I went to TechNet, Event ID 11 Automatic Root Certificates Update Configuration, but I would need something simpler that I can follow. Confuseduser P.S. Exact error message is below: -

Log Name:      Application

Source:        Microsoft-Windows-CAPI2

Date:          27/05/2009 8:42:16 PM

Event ID:      11

Task Category: None

Level:         Error

Keywords:      Classic

User:          N/A

Computer:      Helga-PC

Description:

Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab> with error: A required certificate is not within its validity period when verifying against the current system clock or the timestamp in the signed file.

.

Event Xml:

<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">

  <System>

    <Provider Name="Microsoft-Windows-CAPI2" Guid="{5bbca4a8-b209-48dc-a8c7-b23d3e5216fb}" EventSourceName="Microsoft-Windows-CAPI2" />

    <EventID Qualifiers="49154">11</EventID>

    <Version>0</Version>

    <Level>2</Level>

    <Task>0</Task>

    <Opcode>0</Opcode>

    <Keywords>0x80000000000000</Keywords>

    <TimeCreated SystemTime="2009-05-27T10:42:16.000Z" />

    <EventRecordID>32381</EventRecordID>

    <Correlation />

    <Execution ProcessID="0" ThreadID="0" />

    <Channel>Application</Channel>

    <Computer>Helga-PC</Computer>

    <Security />

  </System>

  <EventData>

    <Data>http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab</Data>

    <Data>A required certificate is not within its validity period when verifying against the current system clock or the timestamp in the signed file.

</Data>

  </EventData>

</Event>

Windows for home | Other | Performance and system failures

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments
Answer accepted by question author
Anonymous
2009-10-20T11:32:58+00:00

I don't see any reason the solution above would not work in Vista.  I see the same folder structure and registry entries on Vista. 

If you are not familiar with the registry, here is a very detailed instruction set on how to delete entries:  http://support.microsoft.com/kb/136393

Be sure to use the export option before deleting entries in order to back them up.

Was this answer helpful?

2 people found this answer helpful.
0 comments No comments
Answer accepted by question author
Anonymous
2010-02-26T21:34:07+00:00

This does help.

Now that you've pointed this out I've seen the same behaviour in the CAPI2 Event Viewer log file. My Windows 7 clients have been trying to access two URL's at the domain http://crl.microsoft.com/

None of the posts I had seen on this had mentioned the need for this path.

Thanks,

Michael

hi

Here's a basic definition for CRL in general terms. You can search Google using "Certificate Revocation List" and find a lot more information.

it could also be that direct X is looking for some updated drivers

what happens is that your browser is checking for provoked certificates , is perfectly normal and safe , its to keep you safe

have a nice day

ps for some further info

http://technet.microsoft.com/en-us/library/dd772269.aspx


Scan with OneCare + 50 Windows 7even Tips + Plagued by the Privacy Center? REMOVE IT + Threat Research & Response Blog + Sysinternals Live tools + TRANSLATOR+ Photosynth + Microsoft Security + Microsoft SUPPORT + PIVOT from Live Labs+ Microsoft Live Labs + Office 2010 beta + Get Windows LIVE!

Was this answer helpful?

0 comments No comments

138 additional answers

Sort by: Most helpful
  1. Anonymous
    2009-09-12T08:39:39+00:00

    Hi Purdue, further up in the thread, there was a suggestion, that one should inform Microsoft.  Maybe you could do it. The link below is a link to Microsoft.  Maybe somebody (who can cope with all the technical details) could send them the information. Confuseduse

    https://connect.microsoft.com/default.aspx

    Was this answer helpful?

    0 comments No comments
  2. Anonymous
    2009-09-11T15:00:27+00:00

    I agree that no solution seems to have been found.  What some of the above posts suggest is to stop the application or utility that is requesting the "authrootstl.cab" file from getting downloaded. This is not practical in some cases. For use, this "authrootstl.cab" file is being requested via lsass.exe which is part of the normal login process.

    I would like to simplify things by asking the following:

    1) Go to http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab and download this CAB file to your local computer.

    1. Open the CAB file and extract the authroot.stl file to your local computer.
    2. Double-click on the STL file. I'm assuming, near the top, you will see the following: "This certificate trust list is not valid. The certificate that signed the list is not valid."

    All the problems seem to be tied to this STL file (Microsoft's certificate trust list) not being valid.

    Can someone (i.e. Microsoft) explain why this is not valid?  Can it be made valid?   Etc.

    Thanks,

    Was this answer helpful?

    0 comments No comments
  3. Anonymous
    2009-08-31T01:16:04+00:00

    Hi all.

    I hope this thread still have some readers. After all, the solution is not there yet, it seems.

    I run Vista Home Premiun and update everything I can from Wndows. I can see that I have had the error since june 3, so the timing is the same as yours. I have just opgraded to service pack 2  a few days ago. So the error is not related to this update specifically.

    I think that some more attention should be paid to this part of the error message: "A required certificate is not within its validity period when verifying against the current system clock or the timestamp in the signed file."

    I am not a Windows guru, but I have had 11 years as SAP supporter on a fairly high level. And based on this experience I would think that the actual description in the error text should make it possible for a Windows guru to perform a simple test with different date/time settings. In SAP you should never ignore what the system itself tells you are wrong. Perhaps it is also the case with Vista.

    I first really noticed the problem when I resently installed version 9 of IOLO's System Mechanic. Then I started getting erros like "Acces violation at address 1339A131 in module 'IOLOSM~DLL'. Read of address 00000004". I have not (yet!?) seen this error message after I reinstalled the System Mechanic program. But the certificate error persists.

    To me the Microsoft Responces look a lot like the first-level answers you get from SAP too. Very helpfund and friendly supporters  look at all ther existing internal notes and send some of them them to us. But apparrently they have not set up a test environmelt to reproduce the error message. Hopfully they will do that in the end. With such a clear message and with such nice users who are willing to help with all the experiments it should be possible to reproduce the error and then find the solution.

    I got the error message and my Acer laptop (Home Premium) keeps shut down nexpected.  Today I tried to upgrade to Ultimate and it was shut down agian when "Feature and Update".  CAPI2 shows in the event viewers.

    As a Technet Plus users, I'm really disappoint to MS' support.

    Was this answer helpful?

    0 comments No comments