Maybe my problem is related to the problem lots of folks are having with Chrome?
What do you think?
This browser is no longer supported.
Upgrade to Microsoft Edge to take advantage of the latest features, security updates, and technical support.
Immediately after every reboot of Win 10 Pro 64-bit version 1803, in Event Viewer, there are between two and four Audit Failures for something related to Cryptography. So my Win 10 machine is insecure? I have run sfc /scannow and Dism /Online /Cleanup-Image /RestoreHealth many times, with no luck. And I hardly even use my Win 10 machine - there are almost no apps on it yet. My actual Win 10 build is 17134.706
Here are the latest five Cryptography-related Audit Failures, from two reboots:
LATEST OF FIVE:
Log Name: Security
Source: Microsoft-Windows-Security-Auditing
Date: 4/28/2019 12:27:52 PM
Event ID: 5061
Task Category: System Integrity
Level: Information
Keywords: Audit Failure
User: N/A
Computer: DESKTOP-3#####N
Description:
Cryptographic operation.
Subject:
Security ID: DESKTOP-3#####N[My user name]
Account Name: [My user name]
Account Domain: DESKTOP-3#####N
Logon ID: 0x3EC24
Cryptographic Parameters:
Provider Name: Microsoft Software Key Storage Provider
Algorithm Name: UNKNOWN
Key Name: Microsoft Connected Devices Platform device certificate
Key Type: User key.
Cryptographic Operation:
Operation: Open Key.
Return Code: 0x80090016
Event Xml:
<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
<System>
<Provider Name="Microsoft-Windows-Security-Auditing" Guid="{54849625-5478-4994-A5BA-3E3B0328C30D}" />
<EventID>5061</EventID>
<Version>0</Version>
<Level>0</Level>
<Task>12290</Task>
<Opcode>0</Opcode>
<Keywords>0x8010000000000000</Keywords>
<TimeCreated SystemTime="2019-04-28T16:27:52.339705400Z" />
<EventRecordID>19582</EventRecordID>
<Correlation />
<Execution ProcessID="880" ThreadID="948" />
<Channel>Security</Channel>
<Computer>DESKTOP-3#####N</Computer>
<Security />
</System>
<EventData>
<Data Name="SubjectUserSid">S-1-5-21-[My Identifier 10-9-10 digits]-1001</Data>
<Data Name="SubjectUserName">[My user name]</Data>
<Data Name="SubjectDomainName">DESKTOP-3#####N</Data>
<Data Name="SubjectLogonId">0x3ec24</Data>
<Data Name="ProviderName">Microsoft Software Key Storage Provider</Data>
<Data Name="AlgorithmName">UNKNOWN</Data>
<Data Name="KeyName">Microsoft Connected Devices Platform device certificate</Data>
<Data Name="KeyType">%%2500</Data>
<Data Name="Operation">%%2480</Data>
<Data Name="ReturnCode">0x80090016</Data>
</EventData>
</Event>
FOURTH OF FIVE:
Log Name: Security
Source: Microsoft-Windows-Security-Auditing
Date: 4/28/2019 12:26:51 PM
Event ID: 5061
Task Category: System Integrity
Level: Information
Keywords: Audit Failure
User: N/A
Computer: DESKTOP-3#####N
Description:
Cryptographic operation.
Subject:
Security ID: LOCAL SERVICE
Account Name: LOCAL SERVICE
Account Domain: NT AUTHORITY
Logon ID: 0x3E5
Cryptographic Parameters:
Provider Name: Microsoft Software Key Storage Provider
Algorithm Name: UNKNOWN
Key Name: [Hex number]
Key Type: User key.
Cryptographic Operation:
Operation: Open Key.
Return Code: 0x80090016
Event Xml:
<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
<System>
<Provider Name="Microsoft-Windows-Security-Auditing" Guid="{54849625-5478-4994-A5BA-3E3B0328C30D}" />
<EventID>5061</EventID>
<Version>0</Version>
<Level>0</Level>
<Task>12290</Task>
<Opcode>0</Opcode>
<Keywords>0x8010000000000000</Keywords>
<TimeCreated SystemTime="2019-04-28T16:26:51.704606400Z" />
<EventRecordID>19552</EventRecordID>
<Correlation />
<Execution ProcessID="880" ThreadID="1004" />
<Channel>Security</Channel>
<Computer>DESKTOP-3#####N</Computer>
<Security />
</System>
<EventData>
<Data Name="SubjectUserSid">S-1-5-19</Data>
<Data Name="SubjectUserName">LOCAL SERVICE</Data>
<Data Name="SubjectDomainName">NT AUTHORITY</Data>
<Data Name="SubjectLogonId">0x3e5</Data>
<Data Name="ProviderName">Microsoft Software Key Storage Provider</Data>
<Data Name="AlgorithmName">UNKNOWN</Data>
<Data Name="KeyName">[Hex number]</Data>
<Data Name="KeyType">%%2500</Data>
<Data Name="Operation">%%2480</Data>
<Data Name="ReturnCode">0x80090016</Data>
</EventData>
</Event>
THIRD OF FIVE:
Log Name: Security
Source: Microsoft-Windows-Security-Auditing
Date: 4/28/2019 11:29:28 AM
Event ID: 5061
Task Category: System Integrity
Level: Information
Keywords: Audit Failure
User: N/A
Computer: DESKTOP-3#####N
Description:
Cryptographic operation.
Subject:
Security ID: DESKTOP-3#####N[My user name]
Account Name: [My user name]
Account Domain: DESKTOP-3#####N
Logon ID: 0x3EF94
Cryptographic Parameters:
Provider Name: Microsoft Software Key Storage Provider
Algorithm Name: UNKNOWN
Key Name: Microsoft Connected Devices Platform device certificate
Key Type: User key.
Cryptographic Operation:
Operation: Open Key.
Return Code: 0x80090016
Event Xml:
<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
<System>
<Provider Name="Microsoft-Windows-Security-Auditing" Guid="{54849625-5478-4994-A5BA-3E3B0328C30D}" />
<EventID>5061</EventID>
<Version>0</Version>
<Level>0</Level>
<Task>12290</Task>
<Opcode>0</Opcode>
<Keywords>0x8010000000000000</Keywords>
<TimeCreated SystemTime="2019-04-28T15:29:28.196237300Z" />
<EventRecordID>19387</EventRecordID>
<Correlation />
<Execution ProcessID="884" ThreadID="928" />
<Channel>Security</Channel>
<Computer>DESKTOP-3#####N</Computer>
<Security />
</System>
<EventData>
<Data Name="SubjectUserSid">S-1-5-21-[My Identifier 10-9-10 digits]-1001</Data>
<Data Name="SubjectUserName">[My user name]</Data>
<Data Name="SubjectDomainName">DESKTOP-3#####N</Data>
<Data Name="SubjectLogonId">0x3ef94</Data>
<Data Name="ProviderName">Microsoft Software Key Storage Provider</Data>
<Data Name="AlgorithmName">UNKNOWN</Data>
<Data Name="KeyName">Microsoft Connected Devices Platform device certificate</Data>
<Data Name="KeyType">%%2500</Data>
<Data Name="Operation">%%2480</Data>
<Data Name="ReturnCode">0x80090016</Data>
</EventData>
</Event>
SECOND OF FIVE:
Log Name: Security
Source: Microsoft-Windows-Security-Auditing
Date: 4/28/2019 11:28:27 AM
Event ID: 5061
Task Category: System Integrity
Level: Information
Keywords: Audit Failure
User: N/A
Computer: DESKTOP-3#####N
Description:
Cryptographic operation.
Subject:
Security ID: LOCAL SERVICE
Account Name: LOCAL SERVICE
Account Domain: NT AUTHORITY
Logon ID: 0x3E5
Cryptographic Parameters:
Provider Name: Microsoft Software Key Storage Provider
Algorithm Name: UNKNOWN
Key Name: [Hex number]
Key Type: User key.
Cryptographic Operation:
Operation: Open Key.
Return Code: 0x80090016
Event Xml:
<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
<System>
<Provider Name="Microsoft-Windows-Security-Auditing" Guid="{54849625-5478-4994-A5BA-3E3B0328C30D}" />
<EventID>5061</EventID>
<Version>0</Version>
<Level>0</Level>
<Task>12290</Task>
<Opcode>0</Opcode>
<Keywords>0x8010000000000000</Keywords>
<TimeCreated SystemTime="2019-04-28T15:28:27.709849300Z" />
<EventRecordID>19363</EventRecordID>
<Correlation />
<Execution ProcessID="884" ThreadID="992" />
<Channel>Security</Channel>
<Computer>DESKTOP-3#####N</Computer>
<Security />
</System>
<EventData>
<Data Name="SubjectUserSid">S-1-5-19</Data>
<Data Name="SubjectUserName">LOCAL SERVICE</Data>
<Data Name="SubjectDomainName">NT AUTHORITY</Data>
<Data Name="SubjectLogonId">0x3e5</Data>
<Data Name="ProviderName">Microsoft Software Key Storage Provider</Data>
<Data Name="AlgorithmName">UNKNOWN</Data>
<Data Name="KeyName">[Hex number]</Data>
<Data Name="KeyType">%%2500</Data>
<Data Name="Operation">%%2480</Data>
<Data Name="ReturnCode">0x80090016</Data>
</EventData>
</Event>
FIRST OF FIVE:
Log Name: Security
Source: Microsoft-Windows-Security-Auditing
Date: 4/28/2019 11:28:27 AM
Event ID: 5061
Task Category: System Integrity
Level: Information
Keywords: Audit Failure
User: N/A
Computer: DESKTOP-3#####N
Description:
Cryptographic operation.
Subject:
Security ID: LOCAL SERVICE
Account Name: LOCAL SERVICE
Account Domain: NT AUTHORITY
Logon ID: 0x3E5
Cryptographic Parameters:
Provider Name: Microsoft Software Key Storage Provider
Algorithm Name: UNKNOWN
Key Name: [Hex number]
Key Type: User key.
Cryptographic Operation:
Operation: Open Key.
Return Code: 0x80090016
Event Xml:
<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
<System>
<Provider Name="Microsoft-Windows-Security-Auditing" Guid="{54849625-5478-4994-A5BA-3E3B0328C30D}" />
<EventID>5061</EventID>
<Version>0</Version>
<Level>0</Level>
<Task>12290</Task>
<Opcode>0</Opcode>
<Keywords>0x8010000000000000</Keywords>
<TimeCreated SystemTime="2019-04-28T15:28:27.709849300Z" />
<EventRecordID>19363</EventRecordID>
<Correlation />
<Execution ProcessID="884" ThreadID="992" />
<Channel>Security</Channel>
<Computer>DESKTOP-3#####N</Computer>
<Security />
</System>
<EventData>
<Data Name="SubjectUserSid">S-1-5-19</Data>
<Data Name="SubjectUserName">LOCAL SERVICE</Data>
<Data Name="SubjectDomainName">NT AUTHORITY</Data>
<Data Name="SubjectLogonId">0x3e5</Data>
<Data Name="ProviderName">Microsoft Software Key Storage Provider</Data>
<Data Name="AlgorithmName">UNKNOWN</Data>
<Data Name="KeyName">[Hex number]</Data>
<Data Name="KeyType">%%2500</Data>
<Data Name="Operation">%%2480</Data>
<Data Name="ReturnCode">0x80090016</Data>
</EventData>
</Event>
So, what the *** are these, and how do we fix? No guesses - just the real fix.
glnzglnz
☺ In the office, Dell Optiplex 7040 with 8GB RAM, Win 7 Pro 64-bit and Office 2010
☻ At home, Dell Optiplex 7010 with 16GB RAM dual-booting Win 7 Pro 64-bit (now with Office 365 Home) and Win 10 Pro 64-bit
♥ Also still have Dell Optiplex 755 with 4GB RAM with Win XP Pro SP3 (which still gets updates with the POS hack) and Office 2003
Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.
Maybe my problem is related to the problem lots of folks are having with Chrome?
What do you think?
Glnz: Thanks for the May 9 cross post to the
April 2018 (1803) Update broke Chrome thread
Since you don't run Chrome and I'm blind on how Chrome might work on your PC, it's hard to say if this is the same problem.
The Chrome CryptSvc problem did begin with 1803 and shows up after a feature update (like your 1709->1803) update (like yours), or when reinstalling windows.
The only reliable fix is the registry User...Certificates>Root cleanup described in the April 1803 Chrome thread (more details in the Chrome help thread here). The registry cleanup is safe, particularly if you use the automated script from the Chrome help thread. If this fixes the event 5061 warning, it's the same problem. Using the automated script also catches some logs that might help me see if your problem is related to the Chrome failure. I'm curious to see if the registry cleanup helps.
The Chrome problem is related to access to the user installed certificates, and can be avoided by disabling this user service (see Chrome thread for details). Disabling the user service might confirm that your 5061 failures are the same problem. The dependency on user certs might also explain the early 2018 NVidia problems mentioned in the Win10 Forums Event ID 5016 thread cited 4/28 by Andre.
The 5 failures you noted at the top of the thread appear to come from 2 boot sequences. #1,2,3 are from 4/28 16:26++, #4,5 are from 4/28 15:28++.
Each sequence begins with a Local Service warning and ends with a User Acct warning, for the same ProcessID and ThreadID of each boot.
The user SID is the same for both boots, but the user Login ID varies(0x3EF94, 0x3EC24).
The connection to One-Drive is interesting, but I have not seen this mentioned before.
Re: Is safe for personal banking? Info level warnings generally reflect 'annoyances'. If the service impact was significant, the warning level would be higher. In general, the keys computed and exchanged during secure connections are trustworthy. If there are problems, the session will fail.
Larry - thanks very much for your detailed post above.
[Edit - I found the button that shows ten more replies. But is there any way to see ALL the 455 replies at once?]
I'll work on this over the weekend.
[Edit - I found the Protected Roots in HKCU - was in wrong place - shall work on this weekend.]
Glnz: I have an 5/10 email from this thread with the following, but don't see it above - I assume you edited your 5/10 post, which now reads as above
==original content, before edit==
Larry - Unfortunately, on my Win 10 machine, in
HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\Root\
there is no "ProtectedRoots", and both Root and its subfolders Certificates, CRLs and CTLs are empty.
However, if I use Run to go to certmgr.msc, I certainly have many certificates in Trusted Root Certification Authorities and other folders.
Thoughts?
==end orig content
In a nutshell - the effective set of root certs comes from 3 areas:
system - aka Windows built in
local machine - mostly more Windows certs, can also be extended from
local apps, software, etc.
user - certs only for your login
HKCU (HKEY_CURRENT_USER)...SystemCerts\Root only contains the user certs, is often empty, but still needs the correct access permissions, even when empty. View the permissions from regedit with Root right click> Permissions should be: read by all, update only by CryptSvc. Deleting and auto-rebuild of Root refreshes with the correct permissions. The Chrome CryptSvc problem stems from the HKCU permissions. You need to watch the permissions as well as the content.
certmgr.msc Trusted Root Certs>Certs displays the composite of all 3 areas.
certlm.msc Trusted Root Certs>Certs displays the composite w/o user certs;
If 0 user certs (from HKCU...SysCerts\Root\Certs) the 2 lists will be same, but still long (100+).
In regedit, if you right click HKCU...SysCerts\Root, you'll see a link to the Local Machine certs (aka HKLM). This is the local machine storage area mentioned above. The list is usually short (~10) and not related to the Chrome CryptSvc problem.