KB4014984 doesn't install on Vista (standalone either)

Anonymous
2020-04-03T13:51:17+00:00

Hello there,

once again I have installed my beloved Vista Business (x86), everything goes fine except one of the last updates.

The system finds and suggests me to install the one which is exactly called

"April, 2017 Security and Quality Rollup for NET. Framework 2.0, 3.0, 4.5.2, 4.6 on Windows Vista SP2 and Server 2008 SP2 (KB4014984)".

Installing via Windows Update Center throws out the 800B0109 error.

What I have already tried: I do have NET. Framework 4.6 installed and there is an appropriate (?) update for it (KB4014553) as well as its standalone installer.

After successful file extracting this installer shows the same message with explanation in which it is said that

"A certificate chain processed, but terminated in a root certificate which is not trusted by the trust provider (error 800B0109)".

I also tried to download a standard Microsoft certificate file (found somewhere over the internet) and to import it to MMC (Run/mmc/etc.) - DOES NOT WORK.

But this rollup update (KB4014984) DID work during the last year, what could have happened?

Please help. Appreciated in advance.

Windows for home | Previous Windows versions | Windows update

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments
Answer accepted by question author
Anonymous
2020-04-12T16:01:54+00:00

Hi Great White North, (COMPLETE SOLUTION TO PROBLEM)

Happy Easter.

I tried the method you suggested posted by Greenhillmaniac by downloading his Microsoftrootcertificate2011.cer file and installed it by the command line method he suggested.  Like Mikey said, this method "worked like a charm", and windows update installed the April 2017 rollup perfectly.  The "meticulous scientist" in me (you can probably tell by the way I post) was curious as to why this method worked so much better than the solution I posted yesterday, so I ended up restoring the Windows Vista partition several times and running several trials to answer this question.   It turns out that his certificate file is identical to the one I exported from a Windows 7 computer; however, the "command line" method of installing this certificate is a superior method of installing it that the method I was using, which was to import the certificate into the Trusted Root Certification Authorities tab by using the import button.

To anyone else who may encounter this problem, my recommended solution is outlined below:

Obtain a copy of the Microsoft Root Certificate Authority 2011 certificate either by downloading it (see previous posts in this thread) or exporting it from a more modern up to date computer (I used a Windows 7 computer.)  I would recommend also obtaining the Microsoft Root Certificate Authority 2010 certificate, but for the purposes of this solution the 2011 certificate alone works fine.  Copy this root certificate file (or files) to your C: drive by clicking the My Computer button, then the C: hard drive icon, and move or copy the file(s) to this window (for simplicity, do not put the file inside any folder on the C drive.)  Click the start button, then move the cursor to programs, then the accessories folder, then RIGHT CLICK the command prompt icon and choose "Run as administrator" from the pop up menu that appears.  Type cd\ and hit enter.  Then type certutil -addstore "Root" "c:\XX.cer" and hit enter. Type this command exactly as written including the quotation marks except substitute the name you chose for the certificate file for the XX.  You should get a confirmation message telling you that the command action was successful.  Run this command twice if you are installing both the 2010 and 2011 certificates.   Close the command prompt window and restart the computer.  You should now be able to install the Security and Quality Rollup April 2017 now either by running Windows update (easiest way) or by using the stand alone installers that I discussed yesterday (earlier in this thread.)  You can now delete the Microsoft Root certificates from your C: drive, or move them to a storage folder, or just leave them where they are (they won't hurt anything.)  My thanks to GREAT WHITE NORTH and GREENHILLMANIAC for their contributions to this solution.

Was this answer helpful?

4 people found this answer helpful.
0 comments No comments

56 additional answers

Sort by: Most helpful
  1. Anonymous
    2020-04-19T10:43:19+00:00

    Great White North,

    I doubt I can answer your question keeping the same (as yours) level of precision,

    but maybe if I remind you the very order of encountering problems and what happened then, it gets clear.

    First, I never tried to install .NET 4.6 before 4.5.2 - ONLY one after another (4.5.2 and then 4.6).

    Then, I noticed that if I ignore the Windows Update Center's suggestion to install .NET 4.5.2 (as a recommended update), I anyway receive April, 17 Rollup.

    Due to absence of .NET 4.5.2 (which I had ignored) in my Windows this Rollup perfectly installs via Windows Update Center - just the way it is to.

    Why so?

    The only explanation I can see is that the April, 17 Rollup is compiled of 4 updates, which apply depending on those .NET's one has installed.

    And that also means (I'm fairly shure) that in this case the success message reflects that some files (of that 4-component KB4014984 update) have been used within installation, and some haven't.

    I think you know the details better than me, so please correct me if I'm wrong - KB4014561 file out of that bunch is a critical update for .NET Framework 2.0, and it seems to have been used (in this case, no 4.5.2).

    KB4014553 and KB4014559 have nothing to do with current state of things (I beg your pardon, but find it necessary to remind - no 4.5.2 yet).

    The KB3078601 (4th from the April, 17*...*) update is a blind-spot for me, but I have found out that it is just a critical security update for Vista, and may be used or not depending on its presence or absence in the system by the moment.

    Then things went as following - I refreshed the Update search and received .NET 4.5.2suggestion again.

    The very .NET 4.5.2 installed fine via Update Center.

    After having detected this version of .NET Framework the Update Center suggested to install April, 17...(KB4014984) again, meaning this time its particular component - KB4014559.

    This file (actually no matter which way to be installed) requires that missing root certificate which you, mikey8811, Frederick Risener and one more guy from another MS Community thread have successfully found after all.

    I know it is a pretty boring post to read (and my thoroughness may be pointless) but trying to answer your question I have also to add that -

    then I downloaded the NDP46 installer, which worked out fine.

    And then the time had come for KB4014553 update (as a a part of April 17 Rollup), which reacted the certificate problem just the same, as well as its solution.

    Was this answer helpful?

    0 comments No comments
  2. Anonymous
    2020-04-18T22:37:48+00:00

    Hi Great White North,

    Does Microsoft Email you when I reply to your post?

    Was this answer helpful?

    0 comments No comments
  3. lmacri 2,505 Reputation points
    2020-04-18T22:11:42+00:00

    ....Sometimes when you attempt to install software or run software with a root certificate problem, the software will clue you in as to what is going on.  For example, the .net installers (ndp45(etc.) and ndp46(etc.)) told you that they could not run because of a root certificate problem and gave you a clue as to why Windows update was refusing to install the April 2017 .net rollup.  Your GPU-Z and your adobe reader are flagging you about root certificate problems....

    ...I have about 95% decided that this rootsupd.exe solution is the one I am going to use for this computer.  It has become clear that Microsoft will still give you the updates for Windows Vista up to June of 2017, but they no longer update the Vista root certificates (or Windows Defender, for that matter.) ...

    Hi Frederick Risener:

    It's quite likely your observation about the Windows Defender definition updates for Vista SP2 is relevant to your problems installing KB4014984 (the April 2017 .NET Framework security update) and it might even have something to do with your problems with your recent Norton Security product updates.

    Vista SP2 users who were fully patched to the end of extended support on 11-Apr-2017 (i.e., who were not affected by the Windows Update "Checking for updates..." hangs) noticed that Windows Update stopped delivering new virus definitions for their Windows Defender anti-malware scanner in July 2019.  After July 2019 Vista SP2 users were able to manually install newer virus definitions by downloading the latest definition update package (mpas-fe.exe) from https://www.microsoft.com/en-us/wdsi/defenderupdates and then right-clicking and choosing "Run as Administrator", but that workaround stopped working for Vista SP2 on 21-Oct-2019.

    The Microsoft's Security Intelligence Updates for Windows Defender Antivirus and Other Microsoft Antimalware download page at https://www.microsoft.com/en-us/wdsi/defenderupdates now states ...

        "Note: Starting on Monday October 21, 2019, the Security intelligence update packageswill be SHA2 signed.  Please make sure you have the necessary update installed to support SHA2 signing, see2019 SHA-2 Code Signing Support requirement for Windows and WSUS."

    ...and the rollout schedule in the MS support article 2019 SHA-2 Code Signing Support requirement for Windows and WSUS notes that as of 28-Jan-2020 "Signatures on the Certificate Trust Lists (CTLs) for the Microsoft Trusted Root Program changed from dual-signed (SHA-1/SHA-2) to SHA-2 only**"** for new security updates for Win 7 SP1 and higher.

    Vista SP2 operating systems patched to the end of extended support on 11-Apr-2017 do not have the required security updates to support installation of newer Windows Defender update packages that are now signed exclusively with SHA-2 digital signatures (see the two images I posted on 29-Oct-2019 in the VistaForums thread Windows Defender Definition Updates as user lmacri).  I wanted to check if the latest installer for Norton Security v22.15.3.20 is dual-signed with SHA-1 / SHA-2 digital certificates, but according to Norton employee Gayathri_R's 15-Apr-2020 post <here> a downloadable v22.15.3.20 installer will only be available "in the coming weeks".  In the mean time that v22.15.3.20 product update can only be pushed out via a Norton LiveUpdate.


    32-bit Vista Home Premium SP2 * Firefox ESR v52.9.0 * Norton Security Deluxe v22.15.2.22

    HP Pavilion dv6835ca, Intel Core2Duo T5550 @ 1.83 GHz, 3 GB RAM, NVIDIA GeForce 8400M GS

    Was this answer helpful?

    0 comments No comments
  4. Anonymous
    2020-04-18T16:37:17+00:00

    Hi Great White North,

    The problem that both Peter and I were having with the Windows update and the .net April 2017 Security and Quality rollup absolutely was the missing Microsoft Root Certificate Authority 2011 root certificate.  Once this certificate was properly installed, BOTH the Windows update installation and the use of the manual updates above worked fine.  As I discussed in an earlier post on this thread, the "command line" installation method for this certificate worked a lot better than simply importing the certificate into the Trusted Root Certification Authorities tab in the control panel.  When the command line procedure was used to install the root certificate, both Windows update and the stand alone installers could update the .net framework with the April 2017 rollup.  When the "import certifcate" button was used to bring this certificate into the Trusted Root Certification Authorities tab, the stand alone installers worked but Windows update did not.

    As you probably know, .net framework 4.6 is an update for .net framework 4.5.2.  The last version of .net 4 for Windows Vista available through Windows update is .net 4.5.2.  The .net 4.6 is available for Windows Vista, but must be manually downloaded from the Windows Update catalog and installed.  With regards to the 4 stand alone updates above for the April 2017 rollup, all 4 are not needed.  The Windows6.0-kb4014561-x86 update is an update for .net framework 2.0 and needs to be installed.  As far as the ndp installers,  these update .net 4 and only one is needed depending on the version of .net 4 installed.  The ndp45 file is for .net 4.5.2 and will not work if .net 4.6 is installed, and vice-versa for the ndp46 updater.  I am not sure what the last file, Windows6.0-kb3078601-x86(etc.) does, except that it is an update from 2015.  When I tried to install it, I got a message indicating that it was already installed (presumably by Windows update.)  I did not see any point in investigating it further.  By the way, the Window6.0-kb4014561 installed fine prior to installing the 2011 Microsoft Root Certificate, but the ndp installers would not run without it.

    As far as your final thoughts about Norton's recent Norton Security 22.15.3.20 release, you may well be on to something.  ALL of the problems that I was having with Norton Security went away after I ran the rootsupd.exe utility.  This is a microsoft utility for XP that "works" on Windows Vista as well.  I was able to install version 22.15.0.88 and update it to 22.15.3.20 and I was able to run a stand alone version of 22.15.3.20 which did not work on my computer prior to running the rootsupd.exe utility.  This utility also installed both of the missing Microsoft certificates (2010 and 2011) and allowed both Windows update and the stand alone installers above to work perfectly.    As I am about to write to Peter, this is the solution I have pretty much (95%) decided to use on this computer.  I am going to run some more tests for system stability and speed tonight.  If I were using WindowsXP, I would absolutely run this utility before updating Norton, since we know that XP does not update its own certificates.

    Was this answer helpful?

    0 comments No comments