KB4014984 doesn't install on Vista (standalone either)

Anonymous
2020-04-03T13:51:17+00:00

Hello there,

once again I have installed my beloved Vista Business (x86), everything goes fine except one of the last updates.

The system finds and suggests me to install the one which is exactly called

"April, 2017 Security and Quality Rollup for NET. Framework 2.0, 3.0, 4.5.2, 4.6 on Windows Vista SP2 and Server 2008 SP2 (KB4014984)".

Installing via Windows Update Center throws out the 800B0109 error.

What I have already tried: I do have NET. Framework 4.6 installed and there is an appropriate (?) update for it (KB4014553) as well as its standalone installer.

After successful file extracting this installer shows the same message with explanation in which it is said that

"A certificate chain processed, but terminated in a root certificate which is not trusted by the trust provider (error 800B0109)".

I also tried to download a standard Microsoft certificate file (found somewhere over the internet) and to import it to MMC (Run/mmc/etc.) - DOES NOT WORK.

But this rollup update (KB4014984) DID work during the last year, what could have happened?

Please help. Appreciated in advance.

Windows for home | Previous Windows versions | Windows update

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments
Answer accepted by question author
Anonymous
2020-04-12T16:01:54+00:00

Hi Great White North, (COMPLETE SOLUTION TO PROBLEM)

Happy Easter.

I tried the method you suggested posted by Greenhillmaniac by downloading his Microsoftrootcertificate2011.cer file and installed it by the command line method he suggested.  Like Mikey said, this method "worked like a charm", and windows update installed the April 2017 rollup perfectly.  The "meticulous scientist" in me (you can probably tell by the way I post) was curious as to why this method worked so much better than the solution I posted yesterday, so I ended up restoring the Windows Vista partition several times and running several trials to answer this question.   It turns out that his certificate file is identical to the one I exported from a Windows 7 computer; however, the "command line" method of installing this certificate is a superior method of installing it that the method I was using, which was to import the certificate into the Trusted Root Certification Authorities tab by using the import button.

To anyone else who may encounter this problem, my recommended solution is outlined below:

Obtain a copy of the Microsoft Root Certificate Authority 2011 certificate either by downloading it (see previous posts in this thread) or exporting it from a more modern up to date computer (I used a Windows 7 computer.)  I would recommend also obtaining the Microsoft Root Certificate Authority 2010 certificate, but for the purposes of this solution the 2011 certificate alone works fine.  Copy this root certificate file (or files) to your C: drive by clicking the My Computer button, then the C: hard drive icon, and move or copy the file(s) to this window (for simplicity, do not put the file inside any folder on the C drive.)  Click the start button, then move the cursor to programs, then the accessories folder, then RIGHT CLICK the command prompt icon and choose "Run as administrator" from the pop up menu that appears.  Type cd\ and hit enter.  Then type certutil -addstore "Root" "c:\XX.cer" and hit enter. Type this command exactly as written including the quotation marks except substitute the name you chose for the certificate file for the XX.  You should get a confirmation message telling you that the command action was successful.  Run this command twice if you are installing both the 2010 and 2011 certificates.   Close the command prompt window and restart the computer.  You should now be able to install the Security and Quality Rollup April 2017 now either by running Windows update (easiest way) or by using the stand alone installers that I discussed yesterday (earlier in this thread.)  You can now delete the Microsoft Root certificates from your C: drive, or move them to a storage folder, or just leave them where they are (they won't hurt anything.)  My thanks to GREAT WHITE NORTH and GREENHILLMANIAC for their contributions to this solution.

Was this answer helpful?

4 people found this answer helpful.
0 comments No comments

56 additional answers

Sort by: Most helpful
  1. lmacri 2,505 Reputation points
    2020-05-06T02:00:08+00:00

    ...To answer your question as best I can, the instructions you post in*Updates not working,* instructions, I think the instructions you have are very good, but I would suggest recommending that people check for the Microsoft 2011 trusted root certificate and install it with the certutil.exe utility if not present....

    Hi Peter Starling / Frederick Risener:

    Just wanted you to know I've encountered another user who performed a clean reinstall of their Vista SP2 OS and had Windows Update throw an error 800B0109 ("A certificate chain processed, but terminated in a root certificate which is not trusted by the trust provider") while trying to install KB4014984 (Security and Quality Rollup for NET. Framework 2.0, 3.0, 4.5.2, 4.6 on Windows Vista SP2 and Server 2008 SP2: April 11, 2017).  See Only2's post today in the VistaForums thread Problem After Installing Updates Agent 7.6.7600.256 where I post as user lmacri.

    This looks like it's going to be an ongoing issue so I've added a footnote to my instructions in m#l's thread Updates not working, it has been searching for updates for hours that directs users to greenhillmaniac's fix for adding the MicrosoftRootCertificateAuthority2011.cer file.

    Thanks to both of you for your valuable input and feedback.


    32-bit Vista Home Premium SP2 * Firefox ESR v52.9.0 * Norton Security Deluxe v22.15.2.22

    Was this answer helpful?

    0 comments No comments
  2. Anonymous
    2020-04-21T07:23:11+00:00

    ....Sometimes when you attempt to install software or run software with a root certificate problem, the software will clue you in as to what is going on.  For example, the .net installers (ndp45(etc.) and ndp46(etc.)) told you that they could not run because of a root certificate problem and gave you a clue as to why Windows update was refusing to install the April 2017 .net rollup.  Your GPU-Z and your adobe reader are flagging you about root certificate problems....

    ...I have about 95% decided that this rootsupd.exe solution is the one I am going to use for this computer.  It has become clear that Microsoft will still give you the updates for Windows Vista up to June of 2017, but they no longer update the Vista root certificates (or Windows Defender, for that matter.) ...

    Hi Frederick Risener:

    It's quite likely your observation about the Windows Defender definition updates for Vista SP2 is relevant to your problems installing KB4014984 (the April 2017 .NET Framework security update) and it might even have something to do with your problems with your recent Norton Security product updates.

    Vista SP2 users who were fully patched to the end of extended support on 11-Apr-2017 (i.e., who were not affected by the Windows Update "Checking for updates..." hangs) noticed that Windows Update stopped delivering new virus definitions for their Windows Defender anti-malware scanner in July 2019.  After July 2019 Vista SP2 users were able to manually install newer virus definitions by downloading the latest definition update package (mpas-fe.exe) from https://www.microsoft.com/en-us/wdsi/defenderupdates and then right-clicking and choosing "Run as Administrator", but that workaround stopped working for Vista SP2 on 21-Oct-2019.

    The Microsoft's Security Intelligence Updates for Windows Defender Antivirus and Other Microsoft Antimalware download page at https://www.microsoft.com/en-us/wdsi/defenderupdates now states ...

        "Note: Starting on Monday October 21, 2019, the Security intelligence update packageswill be SHA2 signed.  Please make sure you have the necessary update installed to support SHA2 signing, see2019 SHA-2 Code Signing Support requirement for Windows and WSUS."

    ...and the rollout schedule in the MS support article 2019 SHA-2 Code Signing Support requirement for Windows and WSUS notes that as of 28-Jan-2020 "Signatures on the Certificate Trust Lists (CTLs) for the Microsoft Trusted Root Program changed from dual-signed (SHA-1/SHA-2) to SHA-2 only**"** for new security updates for Win 7 SP1 and higher.

    Vista SP2 operating systems patched to the end of extended support on 11-Apr-2017 do not have the required security updates to support installation of newer Windows Defender update packages that are now signed exclusively with SHA-2 digital signatures (see the two images I posted on 29-Oct-2019 in the VistaForums thread Windows Defender Definition Updates as user lmacri).  I wanted to check if the latest installer for Norton Security v22.15.3.20 is dual-signed with SHA-1 / SHA-2 digital certificates, but according to Norton employee Gayathri_R's 15-Apr-2020 post <here> a downloadable v22.15.3.20 installer will only be available "in the coming weeks".  In the mean time that v22.15.3.20 product update can only be pushed out via a Norton LiveUpdate.


    32-bit Vista Home Premium SP2 * Firefox ESR v52.9.0 * Norton Security Deluxe v22.15.2.22

    HP Pavilion dv6835ca, Intel Core2Duo T5550 @ 1.83 GHz, 3 GB RAM, NVIDIA GeForce 8400M GS

    Hi Great White North,

    To answer your question about the Norton Security,  as far as I can tell the installers for 22.15.2.37 and 22.15.3.20 are not exclusively signed to SHA256.  At least they both installed fine on this 32 bit Vista computer (after the Root certificates were updated.)

    As far as SHA-2 goes, it was my understanding that Vista computers were supposed to be compatible with SHA-2 as long as the KB2763674 patch was installed.  However, I have noticed that Windows Defender Definition updates no longer install on this computer, even with  the manual updater.  I don't really need Windows Defender to work since I use Norton, but I thought this subject was interesting.  Any thoughts?

    Thanks

    Was this answer helpful?

    0 comments No comments
  3. Anonymous
    2020-04-19T18:59:09+00:00

    Hi Great White North,

    Did Microsoft Email you the post with my Email that I deleted?

    If not, let me know and I will repost it.  Thanks.

    Was this answer helpful?

    0 comments No comments
  4. Anonymous
    2020-04-19T18:58:05+00:00

    Hi Great White North,

    To answer your question as best I can, the instructions you post in   Updates not working, instructions, I think the instructions you have are very good, but I would suggest recommending that people check for the Microsoft 2011 trusted root certificate and install it with the certutil.exe utility if not present.  Then everything as far as Windows Update should work fine.  As far as Windows update is concerned, using the Rootsupd.exe utility is optional, but may help with future problems down the line. 

    To further answer your question, when I reinstalled Windows Vista, I personally did not go all the way back to the Vista DVD and start from there.  I am a big fan of r-tt tools R drive image, which I have used since the days of Windows 95.  Unfortunately, the last clean image that I had for this computer was from May of 2010.  This image was fully up to date with all Windows updates installed up to May of 2010.  After restoring this update, I had 215 Windows updates (including updates for Microsoft office) to install.  All of the updates worked except for the April rollup that started this thread.  I do not know if other root certificate errors will occur if you do a clean install from the Vista DVD.  I made a new image after installing all Windows updates except IE9, the April rollup, and a couple of other updates (so I could test whether Windows Update worked after installing IE9 then the "speedup" update for IE9) so it was easy for me to roll back to this point and try different install methods for the Root updates and the Norton software.

    Hope this helps.  Thanks.

    Was this answer helpful?

    0 comments No comments