Microsoft`s Silent Trusted Root Authority update is Invalid?

I was going though my Event Log today and spotted over 5000 CAPI2 (Crypto API) Errors, generating anywhere from 5-20 new errors every hour going back to November it seems...

eventlognw7.jpg


After some quick checking it seems the Trusted Root Certification Authority list is not updating correctly :huh:

For anyone who doesn't understand what the Trusted Root Certification Authority List is about or why this list is a crucial cornerstone of everyday internet use heres a excerpt from Microsoft`s documentation:

Root certificates are updated on Windows XP, Vista and all earlier versions of Windows automatically. When a user visits a secure Web site (by using HTTPS SSL), reads a secure email (S/MIME), or downloads an ActiveX control that is signed (code signing) and encounters a new root certificate, the Windows certificate chain verification software checks the appropriate Microsoft Update location for the root certificate. If it finds it, it downloads it to the system. To the user, the experience is seamless. The user does not see any security dialog boxes or warnings. The download happens automatically, behind the scenes.
Root certificates are also delivered for Windows XP and earlier. Root Updates are cumulative, so it should only be necessary to install the latest one to receive all root certificates in the Program.
Whether a user, or “relying party”, should trust a root certificate for any particular purpose can be a difficult question. CAs must be on guard against issuing certificates to people who put them to bad use, such as signing malicious software to make it seem more acceptable. CAs should have effective revocation policies and procedures to adequately deal with such certificates. Also, users are expected to scan a CA’s Certificate Practice Statement (CPS) before deciding to trust a certificate - to ensure that acceptance would not cause undue risk to a user’s security, for example. Such documents can be hundreds of pages long though, making user trust decisions complex. Microsoft’s role is to assess CAs and qualify them according to the Program requirements before enabling distribution of their root certificates.
Basically, Microsoft periodically updates the list with the latest Certificate Authorities used for Verifying the SSL certificates used by your bank, ebay, paypal and thousands of other websites using SSL certificates and also updates the list of banned certificates being used for Malware, fraudulent websites or other certificates being misused (Like these two: VeriSign issues false Microsoft digital certificates)


The latest Update can be downloaded here (URL from the Event Log): http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab

After opening the AuthRootstl.cab file you can see the Authroot.stl update list where you can see the latest Trust List Update information...

trustlistzn3.jpg


It seems however that the last Certification update Microsoft released on the 4th of November 2008 was signed using an invalid Internal Windows Code Signing certificate :eek:

Not only did Microsoft use the wrong Certificate to sign the Update, the Trust list of updated certificates itself (viewable from the second tab then under Certificate list) has a few hundred invalid and missing CA entry's :shock: :eek: :sarc:

Interestingly, when I downloaded this list on Windows 7 it had an equally destroyed Update List signed at 11:50PM the night before the Vista Update List was signed the next day at 9:50AM, they both have the same hash and thumbprint but have different signing dates (How is that even possible? :confused:) There is also no information about the CAPI2 errors found in the Windows 7 event-Log...

90475428rx0.png



It begs the following questions:

1: Why hasn't this problem be reported by anyone, anywhere else before I spotted it?

2: If the Trusted Root Update did manage to update your local system is it safe to assume the entire system`s Root Certification Store is more or less 'compromised' meaning every website using SSL, every e-mail using signing, encrypted file or anything and everything using a certificate issued by a Trusted Root Certification Authority can no longer be guaranteed or verified on your system? (affecting every Version of Windows including Windows 7)

3: Since its accumulative does that mean all current entries are overwritten with each new update? (incase a system did get this failed update is it ok to continue using without having to format the system?))

4: How does the certificate signing timestamp change between Windows 7 and Vista for the same download?

5: Why does the latest Manual update only support XP? (It seems to install but it doesn't display any information about Vista support or even if it installed sucessfully) (https://www.microsoft.com/downloads...0e-ee7e-435e-99f8-20b44d4531b0&DisplayLang=en)

6: Since theirs no CAPI2 related event-log information on Windows 7 does this mean this update is being installed on Windows 7 successfully or failing silently?

7: How did this pass their internal testing guidelines before whomever reasonable was able to release it and why hasn't it been fixed in nearly two months?

Can anyone else confirm what I have mentioned or does anyone have some more information, thoughts or ideas about this problem so I can report this to Microsoft?

Steven

(P.S. Merry Christmas for yesterday and Happy New Year for next week ;) :party:)
 
Last edited:
Here's my vista ''event log'', im not seeing the same as you mate..??
EVE.JPG

but this reads the same as yours..??
0098.JPG



:)SK
 

My Computer

System One

  • Manufacturer/Model
    ME.....
    CPU
    Q9450 @ 3.6ghz
    Motherboard
    P5K PREMIUM
    Memory
    8GB 1066mhz buffalo firestix
    Graphics Card(s)
    HD 5970
    Monitor(s) Displays
    20'' syncmaster
    Screen Resolution
    1680x1050
    Hard Drives
    160GB 7200RPM SEAGATE BARRACUDA IDE
    160GB 7200RPM SEAGATE BARRACUDA SATA 2
    PSU
    XCILIO 850w
    Case
    unknown ATX
    Cooling
    Arctic cooler pro 775
    Keyboard
    logitech EX110
    Mouse
    logitech cordless optical
    Internet Speed
    2mb
Here's my vista ''event log'', im not seeing the same as you mate..??

but this reads the same as yours..??

:)SK

Strange. I do not have any errors in Event Viewer as well.

It shows as invalid as yours though:


This is starting to get very strange, you guys dont see the errors in your event log yet your certificates are signed 11:50PM on the 3rd of November...I get the error-logs but have a certificate signed 9:50AM on the 4th of November at exactly 10 hours later at the same time :shock:

What does this mean? :huh:
 

My Computer

I am not seeing this either, not on Vista (see attached)
or on 7

Got a different date as well

I hope this helps



Thanks for the edit dmex I couldn't get the new pic in ;)

8919d1230307198-microsoft-s-silent-trusted-root-authority-update-invalid-capture11.jpg


8920d1230307598-microsoft-s-silent-trusted-root-authority-update-invalid-capture111.jpg
 

Attachments

  • Capture11.JPG
    Capture11.JPG
    114.8 KB · Views: 10,734
  • Capture111.JPG
    Capture111.JPG
    35.3 KB · Views: 10,684
Last edited:

My Computer

System One

  • Manufacturer/Model
    Self build
    CPU
    Phenom II x4 Black Edition 940-Arctic-Cooling Freezer Xtreme
    Motherboard
    Asus M3A32-MVP Deluxe
    Memory
    8 gig Samsung PC800 RAM
    Graphics Card(s)
    NVidia 9600gt
    Sound Card
    AD1988b
    Monitor(s) Displays
    22" TFT-MONITOR WIDESCREEN mit VGA/DVI 17" Video7 TFT
    Screen Resolution
    1680 : 1050 1280 : 1024
    Hard Drives
    Drive #1 - SAMSUNG HD252HJ (250 GB)
    Drive #2 - Hitachi HDT721010SLA360 (1000 GB)
    Drive #3 - SAMSUNG HD250HJ (250 GB)
    Drive #4 - SAMSUNG HD103UJ (1000 GB) External eSATA
    PSU
    Thermaltake Toughpower Cable Management 750W
    Case
    Enermax Chakra
    Cooling
    2x 120mm Front and Back 1x 250mm Side
    Keyboard
    Standard
    Mouse
    Easy Line Laser Mouse
    Internet Speed
    16000
    Other Info
    I have also used Fedora, Suse, Ubuntu Linux
    And all other Windows from 95 to date except ME
I have a feeling Microsoft use different TRA (Trusted Root Authority) updates for each language and country and their all signed using an invalid certificate ID :sarc:

Microsoft uses a hard-coded Certificate embedded in Windows for updating this list, I assume a recent update is using either the wrong certificate or they removed their embedded certificate by mistake :confused:

I also noticed after installing the 11/24/2008 Manual Root Certificate update for XP (https://www.microsoft.com/downloads...0e-ee7e-435e-99f8-20b44d4531b0&DisplayLang=en) on my Vista system it fixed the hundreds of missing Certificate Trust List entries from that certificate update offered on Windows Update but it didn't fix the "The certificate that signed this List not valid" error :confused:

Im thinking their entire batch of TRA list`s was corrupted globally somehow and my system probably got the first silent update that succeeded in installing the Invalid list before realizing too late it`s Invalid and was trying to redownload a new list but cant since its signature is also invalid hence the Eventlog reports :huh:

Heres the MSDN Info for the Event Error Im receiving: EventID 11 Automatic Root Certificates
I have tried both options but each time a new event-log error pops up with
Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab> with error: The data is invalid.
.
 

My Computer

G'Day Dmex,

First and foremost Mate, all the best for the New Year 2009.

Here is my Event Viewer>Windows Log>Application record for your same time frame;

Event Viewer-Windows Logs-Application.JPG

I do also have a problem, in that Custom Event Log Service is not running;

Event Viewer-Custom Views-Admin Events.JPG

Event Viewer-Custom Views-Network Diagnostics.JPG

Event Viewer-Custom Views-Summary Page.JPG

Is this normal? I'm no techo, however, are there any reasons why I should not have it running? If none, your recommendations, and how I can get to activate it please.

Cheers. sassofalco
 

My Computer

System One

  • Manufacturer/Model
    Acer Aspire Notebook 5633WLMi.[5630 Series]
    CPU
    Intel Centrino Duo Processor - Intel Core 2 CPU.
    Memory
    4GB DDR2 [3.07GB maximum real available]
    Graphics Card(s)
    nVidia GeForce Go 7300, 128MB
    Sound Card
    Realtek HD Audio, Ver. 6.0.1.5717, 2.08MB
    Monitor(s) Displays
    Acer Aspire Notebook - 15.4"; Acer LCD Monitor X223Wsd - 22".
    Screen Resolution
    1280x800x60Hertz [max.]
    Hard Drives
    Notebook - Samsung HM320JI 320GB HD installed 07 August 2009.
    External HDs [4];Maxtor One Touch4 - 500GB External HD [Drive M:\].Western Digital WDXMS1200TA - 120GB External HD [Drive G:\ - Windows Defender Backup Files only]. Two x LaCie 320GB Mobi
    Mouse
    Logitech Wireless V320 for Notebooks - Model M/N: M-RCD125
    Internet Speed
    Down 20000kb/sec / Up 1000kb/sec [Bigpond-Aus]
    Other Info
    Brother MFC-465CN; PC to Fax/Scan/Copy/Photo MFC. Epson Perfection V300 Photo Scanner. Siemens Speedstream 6520 Router. Wacom 'Bamboo Fun' CTE-650 PC Tablet, Stylus and Mouse. UAC - On;Activated. Browsers; [1] FireFox v3.6[2] IE8. Honorary R.S.M. to the 4th [Assault Pioneer] Troop Pune Sepoys , and 3rd Troop Jodhpur Bengali Lancers.
I recently encountered this same error while installing signed installation packages.

I started getting this problem after the certificate "Microsoft Certificate Trust List Publisher" expired on May-27-2009. If I set my system time to May-26-2009 then I do not get the error.

When I extracted authroot.stl from the cab file and installed it (right click->"Install CTL"), the error messages went away. After installation I can see the "Microsoft Certificate Trust List Publisher" certificate in certmgr under "Enterprise Trust"

I did not get this error on my "real" systems, but only on my Virtual Images I test with. My current pet theory is that if a system does not get regular updates, (I keep reverting images back to a saved state for testing) and key Microsoft certificates are not updated before they time out then the automatic certificate update facility will not update the Root List with stl files who’s signatures have invalid trust chains.


I am not sure if this is the same mechanism that caused demx to experience CAPI2 error, clearly it’s not directly related because of the date of the expiration of the certificate.
 

My Computer

Hi dmex,
Have you managed to 'nut out' what to do re this inconsistency?
Just noticed that I'm getting the same error message in Event Vwr [ Win logs / application / CAP12 ].
On checking 'Certificate Trust List' the effective date is Sat. 2nd May 2009. However The Cert. List Info. says " The certificate trust list is not valid. The certificate that signed the list is not valid."
On viewing the certificate further it states "The certificate is not valid for the selected purpose" whilst indicating it is valid from 11/04/2009 to 11/07/2010. Bit of a joke!!!!
What is your recommendation?
TIA
 
Last edited:

My Computer

System One

  • Manufacturer/Model
    LAPTOP. HP Pavilion dv7-1005TX .
    CPU
    IntelCore [email protected] x2
    Memory
    4.00 GB installed, max capacity 8 GB.
    Graphics Card(s)
    Nvidia GeForce 9600M GT & 512MB DDR2 dedicated graphics mem.
    Monitor(s) Displays
    17.0" diagonal WXGA + High definition brightview widescreen infinity display.
    Screen Resolution
    1440 x 900
    Hard Drives
    SPECS.
    Drive 1. 298.09 GB Fujitzu MHZ2320BH G2 ATA Device
    Drive 2. [ All as above.]

    CONFIG. C:\287.65 GB, D:\298.09 GB, E:\10.44 GB.
    Case
    Laptop / notebook.
    Cooling
    Stock.
    Keyboard
    IBM enhanced
    Mouse
    Synaptics PS/2 Port touch pad.
    Internet Speed
    ADSL [ Too slow.]
    Other Info
    Webcam.
This is what I see in the CTL is that the certificate stored in the authrootstl-1.cab is dated ofMay the 2nd. IF i use the link here (from the event viewer), the is the date. So question is : is my computer not updating or has MS forgotten to update the certificate. But then there should be plenty others have the same issue... weird.....
 

My Computer

System One

  • Manufacturer/Model
    Lenovo T61p, 3Gb RAM, 100Gb HDD
    CPU
    Centrino pro
    Memory
    3Go
So, welcome me to the club. This error appears in event log when a regular user logs onto my machine since the 27th of May (but not for me as admin).

Anybody found a solution?
 

My Computer

System One

  • Manufacturer/Model
    Dell XPS720
    CPU
    Intel Quad Q6600 2.40GHz
    Motherboard
    Dell 0YU822, NVIDIA nForce 680i SLI SPP / SLI MCP
    Memory
    4GB DDR2 800MHz
    Graphics Card(s)
    Gainward GeForce GTX 560 Ti, 1024 MB GDDR5
    Sound Card
    Creative SB X-Fi Xtreme Gamer
    Monitor(s) Displays
    Dell 2407WFP-HC
    Screen Resolution
    1920x1200
    Hard Drives
    NVIDIA 640GB SATA Raid 0 (2x320GB) (7200 rpm) for Vista,
    Intel X25-M G2 160 GB for W7,
    Maxtor OT III External HDD,
    WD Elements 1 TB External HDD
    Internet Speed
    100/20
    Other Info
    M779 PCIe PAL/SECAM/DVB-T Desktop TV Tuner. Broadcom NetXtreme 57xx Gigabit Controller.
Welcome to the "club with no answers" Submarine. Somebody out there MUST be able to help! I'm a born optimist.:)
 

My Computer

System One

  • Manufacturer/Model
    LAPTOP. HP Pavilion dv7-1005TX .
    CPU
    IntelCore [email protected] x2
    Memory
    4.00 GB installed, max capacity 8 GB.
    Graphics Card(s)
    Nvidia GeForce 9600M GT & 512MB DDR2 dedicated graphics mem.
    Monitor(s) Displays
    17.0" diagonal WXGA + High definition brightview widescreen infinity display.
    Screen Resolution
    1440 x 900
    Hard Drives
    SPECS.
    Drive 1. 298.09 GB Fujitzu MHZ2320BH G2 ATA Device
    Drive 2. [ All as above.]

    CONFIG. C:\287.65 GB, D:\298.09 GB, E:\10.44 GB.
    Case
    Laptop / notebook.
    Cooling
    Stock.
    Keyboard
    IBM enhanced
    Mouse
    Synaptics PS/2 Port touch pad.
    Internet Speed
    ADSL [ Too slow.]
    Other Info
    Webcam.
As this error only occurs on one user on my computer, I think it is a local error and nothing to blame MS for (maybe, maybe). On this link other people are discussing the same error.
 

My Computer

System One

  • Manufacturer/Model
    Dell XPS720
    CPU
    Intel Quad Q6600 2.40GHz
    Motherboard
    Dell 0YU822, NVIDIA nForce 680i SLI SPP / SLI MCP
    Memory
    4GB DDR2 800MHz
    Graphics Card(s)
    Gainward GeForce GTX 560 Ti, 1024 MB GDDR5
    Sound Card
    Creative SB X-Fi Xtreme Gamer
    Monitor(s) Displays
    Dell 2407WFP-HC
    Screen Resolution
    1920x1200
    Hard Drives
    NVIDIA 640GB SATA Raid 0 (2x320GB) (7200 rpm) for Vista,
    Intel X25-M G2 160 GB for W7,
    Maxtor OT III External HDD,
    WD Elements 1 TB External HDD
    Internet Speed
    100/20
    Other Info
    M779 PCIe PAL/SECAM/DVB-T Desktop TV Tuner. Broadcom NetXtreme 57xx Gigabit Controller.
As this error only occurs on one user on my computer, I think it is a local error and nothing to blame MS for (maybe, maybe). On this link other people are discussing the same error.

Thanks for the link. Lots of reading to thoroughly wade through. [On a quick look there appears no answer - yet.]
Guess it's comforting to know that one is not alone wondering "why it is so?"
 

My Computer

System One

  • Manufacturer/Model
    LAPTOP. HP Pavilion dv7-1005TX .
    CPU
    IntelCore [email protected] x2
    Memory
    4.00 GB installed, max capacity 8 GB.
    Graphics Card(s)
    Nvidia GeForce 9600M GT & 512MB DDR2 dedicated graphics mem.
    Monitor(s) Displays
    17.0" diagonal WXGA + High definition brightview widescreen infinity display.
    Screen Resolution
    1440 x 900
    Hard Drives
    SPECS.
    Drive 1. 298.09 GB Fujitzu MHZ2320BH G2 ATA Device
    Drive 2. [ All as above.]

    CONFIG. C:\287.65 GB, D:\298.09 GB, E:\10.44 GB.
    Case
    Laptop / notebook.
    Cooling
    Stock.
    Keyboard
    IBM enhanced
    Mouse
    Synaptics PS/2 Port touch pad.
    Internet Speed
    ADSL [ Too slow.]
    Other Info
    Webcam.
So here is the latest development.
Finally I managed to get this error not only for the regular user at startup, but also for myself as admin, and this when the computer was up an running since hours. This made me suspect the Media Player and I disabled the Windows Media Player Network Sharing Service - WMPNetworkSvc. The error message disappeared!

So why did this happen? A conflict? I rather suspect that disabling the service prevented Vista from either identifying a need to check this trusted root certificate or prevented the start of the update service itself.

Anyone having an idea what on earth is going on here?
 

My Computer

System One

  • Manufacturer/Model
    Dell XPS720
    CPU
    Intel Quad Q6600 2.40GHz
    Motherboard
    Dell 0YU822, NVIDIA nForce 680i SLI SPP / SLI MCP
    Memory
    4GB DDR2 800MHz
    Graphics Card(s)
    Gainward GeForce GTX 560 Ti, 1024 MB GDDR5
    Sound Card
    Creative SB X-Fi Xtreme Gamer
    Monitor(s) Displays
    Dell 2407WFP-HC
    Screen Resolution
    1920x1200
    Hard Drives
    NVIDIA 640GB SATA Raid 0 (2x320GB) (7200 rpm) for Vista,
    Intel X25-M G2 160 GB for W7,
    Maxtor OT III External HDD,
    WD Elements 1 TB External HDD
    Internet Speed
    100/20
    Other Info
    M779 PCIe PAL/SECAM/DVB-T Desktop TV Tuner. Broadcom NetXtreme 57xx Gigabit Controller.
Good work. Keep at it Submarine. I'm surprised that no one else is "interested" in offering help & suggestions.
 

My Computer

System One

  • Manufacturer/Model
    LAPTOP. HP Pavilion dv7-1005TX .
    CPU
    IntelCore [email protected] x2
    Memory
    4.00 GB installed, max capacity 8 GB.
    Graphics Card(s)
    Nvidia GeForce 9600M GT & 512MB DDR2 dedicated graphics mem.
    Monitor(s) Displays
    17.0" diagonal WXGA + High definition brightview widescreen infinity display.
    Screen Resolution
    1440 x 900
    Hard Drives
    SPECS.
    Drive 1. 298.09 GB Fujitzu MHZ2320BH G2 ATA Device
    Drive 2. [ All as above.]

    CONFIG. C:\287.65 GB, D:\298.09 GB, E:\10.44 GB.
    Case
    Laptop / notebook.
    Cooling
    Stock.
    Keyboard
    IBM enhanced
    Mouse
    Synaptics PS/2 Port touch pad.
    Internet Speed
    ADSL [ Too slow.]
    Other Info
    Webcam.
JMH.....It might be because we all keep coming to this post to see if anyone DOES have an answer..I know I do...although I have not struck anything like this particular issue..I'm sure it's only a matter of time before a customer complains of the same problem. Soooo.....now you know why a lot of us troll though the postings,offering a little help to people we feel are capable of fixing their own system on the way. I like to keep up with the latest issues that affect the modern PC,apart from the PEBKAC and ID 10 T , of course. roflmao. :p
 

My Computer

Well thanks tasaholic, that was helpful. We are indeed all waiting for a solution.
 

My Computer

System One

  • Manufacturer/Model
    Dell XPS720
    CPU
    Intel Quad Q6600 2.40GHz
    Motherboard
    Dell 0YU822, NVIDIA nForce 680i SLI SPP / SLI MCP
    Memory
    4GB DDR2 800MHz
    Graphics Card(s)
    Gainward GeForce GTX 560 Ti, 1024 MB GDDR5
    Sound Card
    Creative SB X-Fi Xtreme Gamer
    Monitor(s) Displays
    Dell 2407WFP-HC
    Screen Resolution
    1920x1200
    Hard Drives
    NVIDIA 640GB SATA Raid 0 (2x320GB) (7200 rpm) for Vista,
    Intel X25-M G2 160 GB for W7,
    Maxtor OT III External HDD,
    WD Elements 1 TB External HDD
    Internet Speed
    100/20
    Other Info
    M779 PCIe PAL/SECAM/DVB-T Desktop TV Tuner. Broadcom NetXtreme 57xx Gigabit Controller.
Thanks, the solution worked fine. But I still wonder why MS is not updating it
 

My Computer

System One

  • Manufacturer/Model
    Lenovo T61p, 3Gb RAM, 100Gb HDD
    CPU
    Centrino pro
    Memory
    3Go

My Computer

System One

  • Manufacturer/Model
    LAPTOP. HP Pavilion dv7-1005TX .
    CPU
    IntelCore [email protected] x2
    Memory
    4.00 GB installed, max capacity 8 GB.
    Graphics Card(s)
    Nvidia GeForce 9600M GT & 512MB DDR2 dedicated graphics mem.
    Monitor(s) Displays
    17.0" diagonal WXGA + High definition brightview widescreen infinity display.
    Screen Resolution
    1440 x 900
    Hard Drives
    SPECS.
    Drive 1. 298.09 GB Fujitzu MHZ2320BH G2 ATA Device
    Drive 2. [ All as above.]

    CONFIG. C:\287.65 GB, D:\298.09 GB, E:\10.44 GB.
    Case
    Laptop / notebook.
    Cooling
    Stock.
    Keyboard
    IBM enhanced
    Mouse
    Synaptics PS/2 Port touch pad.
    Internet Speed
    ADSL [ Too slow.]
    Other Info
    Webcam.
I wonder if it could be related to DRM?
 

My Computer

System One

  • Manufacturer/Model
    Dell XPS720
    CPU
    Intel Quad Q6600 2.40GHz
    Motherboard
    Dell 0YU822, NVIDIA nForce 680i SLI SPP / SLI MCP
    Memory
    4GB DDR2 800MHz
    Graphics Card(s)
    Gainward GeForce GTX 560 Ti, 1024 MB GDDR5
    Sound Card
    Creative SB X-Fi Xtreme Gamer
    Monitor(s) Displays
    Dell 2407WFP-HC
    Screen Resolution
    1920x1200
    Hard Drives
    NVIDIA 640GB SATA Raid 0 (2x320GB) (7200 rpm) for Vista,
    Intel X25-M G2 160 GB for W7,
    Maxtor OT III External HDD,
    WD Elements 1 TB External HDD
    Internet Speed
    100/20
    Other Info
    M779 PCIe PAL/SECAM/DVB-T Desktop TV Tuner. Broadcom NetXtreme 57xx Gigabit Controller.
Back
Top