KB4014984 doesn't install on Vista (standalone either)

Anonymous
2020-04-03T13:51:17+00:00

Hello there,

once again I have installed my beloved Vista Business (x86), everything goes fine except one of the last updates.

The system finds and suggests me to install the one which is exactly called

"April, 2017 Security and Quality Rollup for NET. Framework 2.0, 3.0, 4.5.2, 4.6 on Windows Vista SP2 and Server 2008 SP2 (KB4014984)".

Installing via Windows Update Center throws out the 800B0109 error.

What I have already tried: I do have NET. Framework 4.6 installed and there is an appropriate (?) update for it (KB4014553) as well as its standalone installer.

After successful file extracting this installer shows the same message with explanation in which it is said that

"A certificate chain processed, but terminated in a root certificate which is not trusted by the trust provider (error 800B0109)".

I also tried to download a standard Microsoft certificate file (found somewhere over the internet) and to import it to MMC (Run/mmc/etc.) - DOES NOT WORK.

But this rollup update (KB4014984) DID work during the last year, what could have happened?

Please help. Appreciated in advance.

Windows for home | Previous Windows versions | Windows update

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments
Answer accepted by question author
Anonymous
2020-04-12T16:01:54+00:00

Hi Great White North, (COMPLETE SOLUTION TO PROBLEM)

Happy Easter.

I tried the method you suggested posted by Greenhillmaniac by downloading his Microsoftrootcertificate2011.cer file and installed it by the command line method he suggested.  Like Mikey said, this method "worked like a charm", and windows update installed the April 2017 rollup perfectly.  The "meticulous scientist" in me (you can probably tell by the way I post) was curious as to why this method worked so much better than the solution I posted yesterday, so I ended up restoring the Windows Vista partition several times and running several trials to answer this question.   It turns out that his certificate file is identical to the one I exported from a Windows 7 computer; however, the "command line" method of installing this certificate is a superior method of installing it that the method I was using, which was to import the certificate into the Trusted Root Certification Authorities tab by using the import button.

To anyone else who may encounter this problem, my recommended solution is outlined below:

Obtain a copy of the Microsoft Root Certificate Authority 2011 certificate either by downloading it (see previous posts in this thread) or exporting it from a more modern up to date computer (I used a Windows 7 computer.)  I would recommend also obtaining the Microsoft Root Certificate Authority 2010 certificate, but for the purposes of this solution the 2011 certificate alone works fine.  Copy this root certificate file (or files) to your C: drive by clicking the My Computer button, then the C: hard drive icon, and move or copy the file(s) to this window (for simplicity, do not put the file inside any folder on the C drive.)  Click the start button, then move the cursor to programs, then the accessories folder, then RIGHT CLICK the command prompt icon and choose "Run as administrator" from the pop up menu that appears.  Type cd\ and hit enter.  Then type certutil -addstore "Root" "c:\XX.cer" and hit enter. Type this command exactly as written including the quotation marks except substitute the name you chose for the certificate file for the XX.  You should get a confirmation message telling you that the command action was successful.  Run this command twice if you are installing both the 2010 and 2011 certificates.   Close the command prompt window and restart the computer.  You should now be able to install the Security and Quality Rollup April 2017 now either by running Windows update (easiest way) or by using the stand alone installers that I discussed yesterday (earlier in this thread.)  You can now delete the Microsoft Root certificates from your C: drive, or move them to a storage folder, or just leave them where they are (they won't hurt anything.)  My thanks to GREAT WHITE NORTH and GREENHILLMANIAC for their contributions to this solution.

Was this answer helpful?

4 people found this answer helpful.
0 comments No comments

56 additional answers

Sort by: Most helpful
  1. Anonymous
    2020-04-18T18:56:22+00:00

    Hi Peter,

    I was initially thinking along the same lines as you with regards to the Rootsupd.exe utility.  Why use a utility designed for another operating system and install a bunch of certificates you don't need when simply installing one or two certificates will fix the problem?  However, it is becoming clear that other problems will be encountered that require the root certificates to be updated.

    Sometimes when you attempt to install software or run software with a root certificate problem, the software will clue you in as to what is going on.  For example, the .net installers (ndp45(etc.) and ndp46(etc.)) told you that they could not run because of a root certificate problem and gave you a clue as to why Windows update was refusing to install the April 2017 .net rollup.  Your GPU-Z and your adobe reader are flagging you about root certificate problems.

    Sometimes software DOES NOT give you a clue as to what is going on, and simply fails to install or run properly.  In early March, my Norton security software simply lost the ability to communicate with the Norton Activation server.  I was convinced that this problem was due to Norton upgrading my subscriptions to Norton 360 (partially correct) and that my old version was not able to communicate with these subscriptions (wrong.)  I thought that a newer version of Norton Security would fix the problem (wrong again.)  I spent the better part of the last two days trying every trick I could think of to install a newer version of the software.  I even managed to obtain a stand alone installer for the latest version; however, this installer failed to run on my computer without any explanation as to why.  Prior to this work with Norton, I tried Bullguard which worked, but kept flagging me about root certificate problems (one of the reasons I did not like it.)  What kind of problems will I encounter in the future if I continue to use this Vista computer?  All of these problems went away when I ran the Rootsupd.exe.  Now the old version of Norton communicates perfectly with the server and the new version installer works perfectly.

    What finally convinced me to try the Rootsupd.exe utility was when I looked at the Trusted Root Certification Authority tab on my other Vista computer.  This computer has never had Rootsupd.exe run on it, but had 38 pages (screens) of installed trusted root certificates (the current computer had 3 pages) just from routine use and updating over the years.  The Rootsupd.exe utility put about 50 pages of certificates on this current machine.  It installed the two Mircrosoft certificates (2010 and 2011) that started this tread.  Like I said, all of the above problems went away after running the utility.  Days of scratching my head suddenly became clear.

    I have about 95% decided that this rootsupd.exe solution is the one I am going to use for this computer.  It has become clear that Microsoft will still give you the updates for Windows Vista up to June of 2017, but they no longer update the Vista root certificates (or Windows Defender, for that matter.)  The utility was originally security software from Microsoft, so I don't think it will install any malware or unsafe certificates on the computer.   Your "shoe" analogy is a good one, but I like to think the utility is fully stocking your library, and this is a good thing.  You may never need a book about the fall of the Roman empire, but it would be nice to have it if you do, especially if not having it can cause unexpected and unexplained problems.  I am going to run a few more speed and stability tests tonight, and if these tests pan out, I think this is the way to go.

    Oh, by the way, I did try the AVG antivirus, but I did not like it.  It did install and run without any obvious root certificate errors, but it slowed my boot time from about 90 seconds to close to five minutes.  Also, it kept trying to sell me other AVG products (even the paid version, which AVG allows you to try for free for 30 days.)  I would run a scan, and it would say "No viruses encountered.  But I did find these other problems.  Would you like me to fix them?"  Say yes and it installs more AVG software and asks you to buy another AVG subscription.  Now that I have gotten it working, I am completely happy with my Norton product.

    Was this answer helpful?

    1 person found this answer helpful.
    0 comments No comments
  2. Anonymous
    2020-04-11T21:49:01+00:00

    Well guys,

    I owe a bottle of wine to each of you :)

    I (too many Ies in my posts, not deliberately) have one more computer that requires Vista much more than my usual lump of wood desktop, it is an HP NX6325 and it's got 1440x1080 screen at least, so -

    after installing Vista I receive 0x800B0109 error again, and what I do then - download the missing certificate from HERE,

    then - Start menu - Run - MMC - Add/Remove Snap-in - Certificates - OK - Certificates - Trusted Root Certificates - More tasks - Import.

    Then we just need to browse the certificate file from where we have saved it and finish the import.

    And...

    Frankly I eventually used the standalone file (because I had it downloaded), it is one of the updates downloaded from Windows Updates Catalog - KB4014559 (from the KB4014984 pack).

    And it works just fine.

    As David Bowie said once, "I think it's a great way to end the day".

    Thank you Frederick and Great White North, and also my thanks to mikey8811 if he reads this thread, if we were there in time (approx. 2006), I'm pretty sure Vista would be a success.

    Was this answer helpful?

    1 person found this answer helpful.
    0 comments No comments
  3. lmacri 2,505 Reputation points
    2020-04-11T21:45:13+00:00

    Hi Peter Starling:

    The link https://mega.nz/file/V0YUDaaB#5pxXFo__HTkkK3suk0qQq2WnyMv1Kaf6FXzxJnNhVfw in greenhillmaniac's 06-Apr-2020 reply <here> in the MSFN forum should open his repository and give you a download link for the same MicrosoftRootCertificateAuthority2011.cer file (see image below), but yes, I'm guessing that rossmcbain's instructions in the MS Answers thread Microsoft Root Certificate 2011.cer look like they would also work.

    If the link to greenhillmaniac's MEGA repository doesn't work let me know if you have a 32-bit or 64-bit OS as well as the name and version of your default browser.  If IE9, go to Help | About Internet Explorer; you should have Updates Versions 9.0.60 / KB4014661 as shown below if your Vista SP2 is patched to end of support on 11-Apr-2017.  I use the Firefox ESR v52.9.0 browser (the legacy version for Win XP/Vista, released 26-Jun-2018) and it supports newer TLS 1.1 and 1.2 protocols (and can be configured to support TLS 1.3) for secure https connections, while IE9 v9.0.60 only supports the less secure TLS 1.0 protocol and doesn't work well with many modern websites.


    32-bit Vista Home Premium SP2 * Firefox ESR v52.9.0 * Norton Security Deluxe v22.15.2.22

    HP Pavilion dv6835ca, Intel Core2Duo T5550 @ 1.83 GHz, 3 GB RAM, NVIDIA GeForce 8400M GS

    Was this answer helpful?

    1 person found this answer helpful.
    0 comments No comments
  4. lmacri 2,505 Reputation points
    2020-04-11T16:30:28+00:00

    ....Anyway, I have a solution worked out for you (us, actually.)  Good job discovering the missing root certificates.  The certificates you need are Microsoft Root Certificate Authority 2010 (expires 06/23/2035) and Microsoft Root Certificate Authority 2011 (expires 03/22/2036.)  The easiest way to obtain these certificates is to export them from a Windows 7 computer (you could probably do it from a Windows 8 or 10 computer, but I do not know how.)  If you need help doing this, write me back and I will send detailed instructions on how do do it with Windows 7....

    Hi Frederick Reisner:

    Thanks for posting your solution.

    Did you ever try the instructions greenhillmaniac posted 06-Apr-2020 in mickey8811's MSFN thread Certifacte Trust Provider Error Installing Updates that I mentioned <here> a few days ago?  Greenhillmaniac's post has instructions on how to add the MicrosoftRootCertificateAuthority2011.cer file (stored in his MEGA repository; a download link is provided) to a Vista SP2 system.  According to mickey8811 that solution "worked like a dream" and allowed installation of KB4014984 (Security and Quality Rollup for .NET Framework 2.0, 3.0, 4.5.2, 4.6 on Windows Vista SP2 and Server 2008 SP2: April 11, 2017) to run to completion.


    32-bit Vista Home Premium SP2 * Firefox ESR v52.9.0 * Norton Security Deluxe v22.15.2.22

    HP Pavilion dv6835ca, Intel Core2Duo T5550 @ 1.83 GHz, 3 GB RAM, NVIDIA GeForce 8400M GS

    Was this answer helpful?

    1 person found this answer helpful.
    0 comments No comments