KB4014984 doesn't install on Vista (standalone either)

Anonymous
2020-04-03T13:51:17+00:00

Hello there,

once again I have installed my beloved Vista Business (x86), everything goes fine except one of the last updates.

The system finds and suggests me to install the one which is exactly called

"April, 2017 Security and Quality Rollup for NET. Framework 2.0, 3.0, 4.5.2, 4.6 on Windows Vista SP2 and Server 2008 SP2 (KB4014984)".

Installing via Windows Update Center throws out the 800B0109 error.

What I have already tried: I do have NET. Framework 4.6 installed and there is an appropriate (?) update for it (KB4014553) as well as its standalone installer.

After successful file extracting this installer shows the same message with explanation in which it is said that

"A certificate chain processed, but terminated in a root certificate which is not trusted by the trust provider (error 800B0109)".

I also tried to download a standard Microsoft certificate file (found somewhere over the internet) and to import it to MMC (Run/mmc/etc.) - DOES NOT WORK.

But this rollup update (KB4014984) DID work during the last year, what could have happened?

Please help. Appreciated in advance.

Windows for home | Previous Windows versions | Windows update

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments
Answer accepted by question author
Anonymous
2020-04-12T16:01:54+00:00

Hi Great White North, (COMPLETE SOLUTION TO PROBLEM)

Happy Easter.

I tried the method you suggested posted by Greenhillmaniac by downloading his Microsoftrootcertificate2011.cer file and installed it by the command line method he suggested.  Like Mikey said, this method "worked like a charm", and windows update installed the April 2017 rollup perfectly.  The "meticulous scientist" in me (you can probably tell by the way I post) was curious as to why this method worked so much better than the solution I posted yesterday, so I ended up restoring the Windows Vista partition several times and running several trials to answer this question.   It turns out that his certificate file is identical to the one I exported from a Windows 7 computer; however, the "command line" method of installing this certificate is a superior method of installing it that the method I was using, which was to import the certificate into the Trusted Root Certification Authorities tab by using the import button.

To anyone else who may encounter this problem, my recommended solution is outlined below:

Obtain a copy of the Microsoft Root Certificate Authority 2011 certificate either by downloading it (see previous posts in this thread) or exporting it from a more modern up to date computer (I used a Windows 7 computer.)  I would recommend also obtaining the Microsoft Root Certificate Authority 2010 certificate, but for the purposes of this solution the 2011 certificate alone works fine.  Copy this root certificate file (or files) to your C: drive by clicking the My Computer button, then the C: hard drive icon, and move or copy the file(s) to this window (for simplicity, do not put the file inside any folder on the C drive.)  Click the start button, then move the cursor to programs, then the accessories folder, then RIGHT CLICK the command prompt icon and choose "Run as administrator" from the pop up menu that appears.  Type cd\ and hit enter.  Then type certutil -addstore "Root" "c:\XX.cer" and hit enter. Type this command exactly as written including the quotation marks except substitute the name you chose for the certificate file for the XX.  You should get a confirmation message telling you that the command action was successful.  Run this command twice if you are installing both the 2010 and 2011 certificates.   Close the command prompt window and restart the computer.  You should now be able to install the Security and Quality Rollup April 2017 now either by running Windows update (easiest way) or by using the stand alone installers that I discussed yesterday (earlier in this thread.)  You can now delete the Microsoft Root certificates from your C: drive, or move them to a storage folder, or just leave them where they are (they won't hurt anything.)  My thanks to GREAT WHITE NORTH and GREENHILLMANIAC for their contributions to this solution.

Was this answer helpful?

4 people found this answer helpful.
0 comments No comments

56 additional answers

Sort by: Newest
  1. Anonymous
    2020-04-18T16:37:17+00:00

    Hi Great White North,

    The problem that both Peter and I were having with the Windows update and the .net April 2017 Security and Quality rollup absolutely was the missing Microsoft Root Certificate Authority 2011 root certificate.  Once this certificate was properly installed, BOTH the Windows update installation and the use of the manual updates above worked fine.  As I discussed in an earlier post on this thread, the "command line" installation method for this certificate worked a lot better than simply importing the certificate into the Trusted Root Certification Authorities tab in the control panel.  When the command line procedure was used to install the root certificate, both Windows update and the stand alone installers could update the .net framework with the April 2017 rollup.  When the "import certifcate" button was used to bring this certificate into the Trusted Root Certification Authorities tab, the stand alone installers worked but Windows update did not.

    As you probably know, .net framework 4.6 is an update for .net framework 4.5.2.  The last version of .net 4 for Windows Vista available through Windows update is .net 4.5.2.  The .net 4.6 is available for Windows Vista, but must be manually downloaded from the Windows Update catalog and installed.  With regards to the 4 stand alone updates above for the April 2017 rollup, all 4 are not needed.  The Windows6.0-kb4014561-x86 update is an update for .net framework 2.0 and needs to be installed.  As far as the ndp installers,  these update .net 4 and only one is needed depending on the version of .net 4 installed.  The ndp45 file is for .net 4.5.2 and will not work if .net 4.6 is installed, and vice-versa for the ndp46 updater.  I am not sure what the last file, Windows6.0-kb3078601-x86(etc.) does, except that it is an update from 2015.  When I tried to install it, I got a message indicating that it was already installed (presumably by Windows update.)  I did not see any point in investigating it further.  By the way, the Window6.0-kb4014561 installed fine prior to installing the 2011 Microsoft Root Certificate, but the ndp installers would not run without it.

    As far as your final thoughts about Norton's recent Norton Security 22.15.3.20 release, you may well be on to something.  ALL of the problems that I was having with Norton Security went away after I ran the rootsupd.exe utility.  This is a microsoft utility for XP that "works" on Windows Vista as well.  I was able to install version 22.15.0.88 and update it to 22.15.3.20 and I was able to run a stand alone version of 22.15.3.20 which did not work on my computer prior to running the rootsupd.exe utility.  This utility also installed both of the missing Microsoft certificates (2010 and 2011) and allowed both Windows update and the stand alone installers above to work perfectly.    As I am about to write to Peter, this is the solution I have pretty much (95%) decided to use on this computer.  I am going to run some more tests for system stability and speed tonight.  If I were using WindowsXP, I would absolutely run this utility before updating Norton, since we know that XP does not update its own certificates.

    Was this answer helpful?

    0 comments No comments
  2. lmacri 2,505 Reputation points
    2020-04-18T15:03:39+00:00

    ...I tried to install "April, 17 Rollup"...etc. BEFORE installing .NET Framework 4.5.2, and for some reason it did install....

    UPDATE: after that Vista received all the following updates, including Cumulative Update for Internet Explorer 9, and then there appeared one recommended update: .NET Framework 4.5.2.It did install.

    And then - oh man...KB4014984 crawled out (?!?!!!) and failed again.

    Again error 800B0109....

    Hi Peter Starling / Frederick Risener:

    Going back to the missing trust certificate problem you both had when Windows Update tried to install KB4014984 (Security and Quality Rollup for .NET Framework 2.0, 3.0, 4.5.2, 4.6 on Windows Vista SP2 and Server 2008 SP2: April 11, 2017) during your clean reinstall of Vista SP2, can you both clarify something for me?

    Is the .NET Framework v4.5.2 and/or v4.6 currently installed, and if so did you install either of these .NET Frameworks manually (e.g. by running the standalone v4.5.2 installer NDP452-KB2901907-x86-x64-AllOS-ENU.exe from https://www.microsoft.com/en-ca/do.nload/details.aspx?id=42642) or were they only installed by Windows Update as an optional update(s)?

    And if you tried a manual installation of KB4014984 (which the title of this thread suggests) did you install all four standalone installers listed for this update on the Microsoft Update Catalog at https://www.catalog.update.microsoft.com/Search.aspx?q=KB4014984 after the Download button is clicked?

    According to the Microsoft support article Security Update Deployment Information: April 11, 2017 the NDP45-KB4014559-xxx installers (both the x86 and x64 versions) are required for .NET Framework v4.5.2, while the NDP46-KB4014559xxx installers (both the x86 and x64 versions) are required for .NET Framework v4.6.  I'm beginning to wonder now if those NDP45 and NDP46 installers add the missing trust certificates required to run newer .NET Frameworks like v4.5.2 and v4.6 on a Vista SP2 machine.

    I'm also beginning to wonder if the latest Norton Security v22.15.3.20 released 15-Apr-2020 (the legacy version for Win XP/Vista - see the release notes <here> which mentions "pre-seeding of certificates" in the "What's New" section) is causing problems on some Win XP and Vista SP2 machines because of the digital certificate Symantec is using to sign the v22.15.3.20 installer?


    32-bit Vista Home Premium SP2 * Firefox ESR v52.9.0 * Norton Security Deluxe v22.15.2.22

    HP Pavilion dv6835ca, Intel Core2Duo T5550 @ 1.83 GHz, 3 GB RAM, NVIDIA GeForce 8400M GS

    Was this answer helpful?

    0 comments No comments
  3. Anonymous
    2020-04-18T08:55:02+00:00

    Hi Frederick,

    it is really funny to watch this kind of U-turn back to the start of my thread,

    I think there can be 2 different points of view on what rootsupd.exe does.

    What I DIDN'T like (I wrote about that somewhere on page 1) was that we get huge list of certificates as a result of rootsupd.exe usage, and I'm pretty sure that at least 75% of them is needless.

    So - that was great to get your (and Great White North's) help with getting that only certificate I needed for Vista.

    Unfortunately, in my turn I couldn't suggest you anything useful about Norton, because I use AVG on all my machines (including 2 of them running XP SP3),

    I know how they mask their paid suggestions and always reject them (sometimes with Task Manager when a dialogue window has no cross to click).

    The only bothering thing is time spent for scanning the system when it starts, this takes a bit too long but even my oldest computer (Athlon 64 3800+ S939, RAM 3 Gb dual channel) used to carry it out rather easy .

    BUT! I noticed that with getting all that useless (at first sight) certificates I got rid of several more problems.

    For instance, I use GPU-Z tool to watch after graphic card (in terms of risk of overheating). Once I installed it on my new (-old) laptop, it started requesting certificates when launching (?) just like "The certificate is not trusted, do you really want to proceed?" Yes-yes [damn] yes [what the hell].

    It was quite a surprise, because I have the same Vista Business on my desktop on which I experienced with rootsupd.exe, there is also GPU-Z installed, and no problem.

    I also started encountering certificate request in Adobe Reader when trying to check for updates. And - same situation: no request on desktop with rootsupd.exe used.

    The way it works looks like coming to a shoestore with a question like "I need a pair of shoes, but I don't know what size and what colour of, and maybe it should be a pair of sneakers, I'm not sure" - "Take these all, it won't be wrong".

    And you get a huge bunch of shoes where there really is a right pair, and two or three more for some cases.

    If you have time to dig it more, there is an interesting LINK.

    This is where I took that solution via rootsupd.exe from.

    Cheers.

    Was this answer helpful?

    0 comments No comments
  4. Anonymous
    2020-04-17T21:56:46+00:00

    Hi Great White North,

    Thanks for all of your help with the Norton issues.  After 2 days of running "experiments" on the computer, I solved the issues with Norton.  Turns out the problem was the same problem that started this thread, missing Trusted Root Certification Authority certificates.  As I posted earlier today, I noticed that my other Vista computer had 38 pages of trusted root cerificates, this one only had 3.  So I used Rootupd.exe as suggested by Peter Starling.  After using this utility, not only does Microsoft update work perfectly, but the Norton installers for Norton Security 22.15.0.88 (as well as the installer for 22.15.3.20 that Norton does not want you to know about) all worked perfectly.  Apparently when Norton upgraded all the Subscriptions to Norton 360, the upgrade changed the trusted root certificate needed to access the activation server.  The utility added about 50 pages of Trusted Root Certification Authority certificates.  Apparently when you do a clean install of Vista, Microsoft will still give you the updates until April of 2017, but no longer updates the root certificates.   Thanks again for all your help.

    Was this answer helpful?

    0 comments No comments