KB4014984 doesn't install on Vista (standalone either)

Anonymous
2020-04-03T13:51:17+00:00

Hello there,

once again I have installed my beloved Vista Business (x86), everything goes fine except one of the last updates.

The system finds and suggests me to install the one which is exactly called

"April, 2017 Security and Quality Rollup for NET. Framework 2.0, 3.0, 4.5.2, 4.6 on Windows Vista SP2 and Server 2008 SP2 (KB4014984)".

Installing via Windows Update Center throws out the 800B0109 error.

What I have already tried: I do have NET. Framework 4.6 installed and there is an appropriate (?) update for it (KB4014553) as well as its standalone installer.

After successful file extracting this installer shows the same message with explanation in which it is said that

"A certificate chain processed, but terminated in a root certificate which is not trusted by the trust provider (error 800B0109)".

I also tried to download a standard Microsoft certificate file (found somewhere over the internet) and to import it to MMC (Run/mmc/etc.) - DOES NOT WORK.

But this rollup update (KB4014984) DID work during the last year, what could have happened?

Please help. Appreciated in advance.

Windows for home | Previous Windows versions | Windows update

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments
Answer accepted by question author
Anonymous
2020-04-12T16:01:54+00:00

Hi Great White North, (COMPLETE SOLUTION TO PROBLEM)

Happy Easter.

I tried the method you suggested posted by Greenhillmaniac by downloading his Microsoftrootcertificate2011.cer file and installed it by the command line method he suggested.  Like Mikey said, this method "worked like a charm", and windows update installed the April 2017 rollup perfectly.  The "meticulous scientist" in me (you can probably tell by the way I post) was curious as to why this method worked so much better than the solution I posted yesterday, so I ended up restoring the Windows Vista partition several times and running several trials to answer this question.   It turns out that his certificate file is identical to the one I exported from a Windows 7 computer; however, the "command line" method of installing this certificate is a superior method of installing it that the method I was using, which was to import the certificate into the Trusted Root Certification Authorities tab by using the import button.

To anyone else who may encounter this problem, my recommended solution is outlined below:

Obtain a copy of the Microsoft Root Certificate Authority 2011 certificate either by downloading it (see previous posts in this thread) or exporting it from a more modern up to date computer (I used a Windows 7 computer.)  I would recommend also obtaining the Microsoft Root Certificate Authority 2010 certificate, but for the purposes of this solution the 2011 certificate alone works fine.  Copy this root certificate file (or files) to your C: drive by clicking the My Computer button, then the C: hard drive icon, and move or copy the file(s) to this window (for simplicity, do not put the file inside any folder on the C drive.)  Click the start button, then move the cursor to programs, then the accessories folder, then RIGHT CLICK the command prompt icon and choose "Run as administrator" from the pop up menu that appears.  Type cd\ and hit enter.  Then type certutil -addstore "Root" "c:\XX.cer" and hit enter. Type this command exactly as written including the quotation marks except substitute the name you chose for the certificate file for the XX.  You should get a confirmation message telling you that the command action was successful.  Run this command twice if you are installing both the 2010 and 2011 certificates.   Close the command prompt window and restart the computer.  You should now be able to install the Security and Quality Rollup April 2017 now either by running Windows update (easiest way) or by using the stand alone installers that I discussed yesterday (earlier in this thread.)  You can now delete the Microsoft Root certificates from your C: drive, or move them to a storage folder, or just leave them where they are (they won't hurt anything.)  My thanks to GREAT WHITE NORTH and GREENHILLMANIAC for their contributions to this solution.

Was this answer helpful?

4 people found this answer helpful.
0 comments No comments

56 additional answers

Sort by: Oldest
  1. Anonymous
    2020-04-18T18:56:22+00:00

    Hi Peter,

    I was initially thinking along the same lines as you with regards to the Rootsupd.exe utility.  Why use a utility designed for another operating system and install a bunch of certificates you don't need when simply installing one or two certificates will fix the problem?  However, it is becoming clear that other problems will be encountered that require the root certificates to be updated.

    Sometimes when you attempt to install software or run software with a root certificate problem, the software will clue you in as to what is going on.  For example, the .net installers (ndp45(etc.) and ndp46(etc.)) told you that they could not run because of a root certificate problem and gave you a clue as to why Windows update was refusing to install the April 2017 .net rollup.  Your GPU-Z and your adobe reader are flagging you about root certificate problems.

    Sometimes software DOES NOT give you a clue as to what is going on, and simply fails to install or run properly.  In early March, my Norton security software simply lost the ability to communicate with the Norton Activation server.  I was convinced that this problem was due to Norton upgrading my subscriptions to Norton 360 (partially correct) and that my old version was not able to communicate with these subscriptions (wrong.)  I thought that a newer version of Norton Security would fix the problem (wrong again.)  I spent the better part of the last two days trying every trick I could think of to install a newer version of the software.  I even managed to obtain a stand alone installer for the latest version; however, this installer failed to run on my computer without any explanation as to why.  Prior to this work with Norton, I tried Bullguard which worked, but kept flagging me about root certificate problems (one of the reasons I did not like it.)  What kind of problems will I encounter in the future if I continue to use this Vista computer?  All of these problems went away when I ran the Rootsupd.exe.  Now the old version of Norton communicates perfectly with the server and the new version installer works perfectly.

    What finally convinced me to try the Rootsupd.exe utility was when I looked at the Trusted Root Certification Authority tab on my other Vista computer.  This computer has never had Rootsupd.exe run on it, but had 38 pages (screens) of installed trusted root certificates (the current computer had 3 pages) just from routine use and updating over the years.  The Rootsupd.exe utility put about 50 pages of certificates on this current machine.  It installed the two Mircrosoft certificates (2010 and 2011) that started this tread.  Like I said, all of the above problems went away after running the utility.  Days of scratching my head suddenly became clear.

    I have about 95% decided that this rootsupd.exe solution is the one I am going to use for this computer.  It has become clear that Microsoft will still give you the updates for Windows Vista up to June of 2017, but they no longer update the Vista root certificates (or Windows Defender, for that matter.)  The utility was originally security software from Microsoft, so I don't think it will install any malware or unsafe certificates on the computer.   Your "shoe" analogy is a good one, but I like to think the utility is fully stocking your library, and this is a good thing.  You may never need a book about the fall of the Roman empire, but it would be nice to have it if you do, especially if not having it can cause unexpected and unexplained problems.  I am going to run a few more speed and stability tests tonight, and if these tests pan out, I think this is the way to go.

    Oh, by the way, I did try the AVG antivirus, but I did not like it.  It did install and run without any obvious root certificate errors, but it slowed my boot time from about 90 seconds to close to five minutes.  Also, it kept trying to sell me other AVG products (even the paid version, which AVG allows you to try for free for 30 days.)  I would run a scan, and it would say "No viruses encountered.  But I did find these other problems.  Would you like me to fix them?"  Say yes and it installs more AVG software and asks you to buy another AVG subscription.  Now that I have gotten it working, I am completely happy with my Norton product.

    Was this answer helpful?

    1 person found this answer helpful.
    0 comments No comments
  2. lmacri 2,505 Reputation points
    2020-04-18T22:11:42+00:00

    ....Sometimes when you attempt to install software or run software with a root certificate problem, the software will clue you in as to what is going on.  For example, the .net installers (ndp45(etc.) and ndp46(etc.)) told you that they could not run because of a root certificate problem and gave you a clue as to why Windows update was refusing to install the April 2017 .net rollup.  Your GPU-Z and your adobe reader are flagging you about root certificate problems....

    ...I have about 95% decided that this rootsupd.exe solution is the one I am going to use for this computer.  It has become clear that Microsoft will still give you the updates for Windows Vista up to June of 2017, but they no longer update the Vista root certificates (or Windows Defender, for that matter.) ...

    Hi Frederick Risener:

    It's quite likely your observation about the Windows Defender definition updates for Vista SP2 is relevant to your problems installing KB4014984 (the April 2017 .NET Framework security update) and it might even have something to do with your problems with your recent Norton Security product updates.

    Vista SP2 users who were fully patched to the end of extended support on 11-Apr-2017 (i.e., who were not affected by the Windows Update "Checking for updates..." hangs) noticed that Windows Update stopped delivering new virus definitions for their Windows Defender anti-malware scanner in July 2019.  After July 2019 Vista SP2 users were able to manually install newer virus definitions by downloading the latest definition update package (mpas-fe.exe) from https://www.microsoft.com/en-us/wdsi/defenderupdates and then right-clicking and choosing "Run as Administrator", but that workaround stopped working for Vista SP2 on 21-Oct-2019.

    The Microsoft's Security Intelligence Updates for Windows Defender Antivirus and Other Microsoft Antimalware download page at https://www.microsoft.com/en-us/wdsi/defenderupdates now states ...

        "Note: Starting on Monday October 21, 2019, the Security intelligence update packageswill be SHA2 signed.  Please make sure you have the necessary update installed to support SHA2 signing, see2019 SHA-2 Code Signing Support requirement for Windows and WSUS."

    ...and the rollout schedule in the MS support article 2019 SHA-2 Code Signing Support requirement for Windows and WSUS notes that as of 28-Jan-2020 "Signatures on the Certificate Trust Lists (CTLs) for the Microsoft Trusted Root Program changed from dual-signed (SHA-1/SHA-2) to SHA-2 only**"** for new security updates for Win 7 SP1 and higher.

    Vista SP2 operating systems patched to the end of extended support on 11-Apr-2017 do not have the required security updates to support installation of newer Windows Defender update packages that are now signed exclusively with SHA-2 digital signatures (see the two images I posted on 29-Oct-2019 in the VistaForums thread Windows Defender Definition Updates as user lmacri).  I wanted to check if the latest installer for Norton Security v22.15.3.20 is dual-signed with SHA-1 / SHA-2 digital certificates, but according to Norton employee Gayathri_R's 15-Apr-2020 post <here> a downloadable v22.15.3.20 installer will only be available "in the coming weeks".  In the mean time that v22.15.3.20 product update can only be pushed out via a Norton LiveUpdate.


    32-bit Vista Home Premium SP2 * Firefox ESR v52.9.0 * Norton Security Deluxe v22.15.2.22

    HP Pavilion dv6835ca, Intel Core2Duo T5550 @ 1.83 GHz, 3 GB RAM, NVIDIA GeForce 8400M GS

    Was this answer helpful?

    0 comments No comments
  3. Anonymous
    2020-04-18T22:37:48+00:00

    Hi Great White North,

    Does Microsoft Email you when I reply to your post?

    Was this answer helpful?

    0 comments No comments
  4. Anonymous
    2020-04-19T10:43:19+00:00

    Great White North,

    I doubt I can answer your question keeping the same (as yours) level of precision,

    but maybe if I remind you the very order of encountering problems and what happened then, it gets clear.

    First, I never tried to install .NET 4.6 before 4.5.2 - ONLY one after another (4.5.2 and then 4.6).

    Then, I noticed that if I ignore the Windows Update Center's suggestion to install .NET 4.5.2 (as a recommended update), I anyway receive April, 17 Rollup.

    Due to absence of .NET 4.5.2 (which I had ignored) in my Windows this Rollup perfectly installs via Windows Update Center - just the way it is to.

    Why so?

    The only explanation I can see is that the April, 17 Rollup is compiled of 4 updates, which apply depending on those .NET's one has installed.

    And that also means (I'm fairly shure) that in this case the success message reflects that some files (of that 4-component KB4014984 update) have been used within installation, and some haven't.

    I think you know the details better than me, so please correct me if I'm wrong - KB4014561 file out of that bunch is a critical update for .NET Framework 2.0, and it seems to have been used (in this case, no 4.5.2).

    KB4014553 and KB4014559 have nothing to do with current state of things (I beg your pardon, but find it necessary to remind - no 4.5.2 yet).

    The KB3078601 (4th from the April, 17*...*) update is a blind-spot for me, but I have found out that it is just a critical security update for Vista, and may be used or not depending on its presence or absence in the system by the moment.

    Then things went as following - I refreshed the Update search and received .NET 4.5.2suggestion again.

    The very .NET 4.5.2 installed fine via Update Center.

    After having detected this version of .NET Framework the Update Center suggested to install April, 17...(KB4014984) again, meaning this time its particular component - KB4014559.

    This file (actually no matter which way to be installed) requires that missing root certificate which you, mikey8811, Frederick Risener and one more guy from another MS Community thread have successfully found after all.

    I know it is a pretty boring post to read (and my thoroughness may be pointless) but trying to answer your question I have also to add that -

    then I downloaded the NDP46 installer, which worked out fine.

    And then the time had come for KB4014553 update (as a a part of April 17 Rollup), which reacted the certificate problem just the same, as well as its solution.

    Was this answer helpful?

    0 comments No comments