Door Erik van Straten, 09:14 uur:
als CAPI2 eventlogs geen indicatie geven over wat er mis is
Door Spiff, 13:57 uur:
Ik weet nog niet of die logs geen indicatie geven over wat er mis is.
Een flink deel van de informatie weet ik niet te interpreteren.
Misschien kan jij of kunnen jullie er wel wat mee?
Zal ik die logdetails eens hier posten?
Hieronder de CAPI2 eventlogs
voor het checken van de details van de digitale handtekeningen van EMET [4.1u1] Setup.msi.
In de hoop dat iemand er iets wetenswaardigs uit kan afleiden.
Achtereenvolgens vier logs met het niveau "Informatie",
en het laatste, vijfde log, met het niveau "Fout".
(N.B. "url"-aanduidingen heb ik vervangen door "ur|", omdat anders de weergave in de soep loopt doordat url tussen haken als BBcode wordt gelezen.)
--------------------------------------------------
- System
- Provider
[ Name] Microsoft-Windows-CAPI2
[ Guid] {5bbca4a8-b209-48dc-a8c7-b23d3e5216fb}
EventID 41
Version 0
Level 4
Task 41
Opcode 2
Keywords 0x8000000000000005
- TimeCreated
[ SystemTime] 2014-05-06T21:00:10.110Z
EventRecordID 185253
Correlation
- Execution
[ ProcessID] 3704
[ ThreadID] 12184
Channel Microsoft-Windows-CAPI2/Operational
Computer XXXXXXX
- Security
[ UserID] XXXXXXX
- UserData
- CertVerifyRevocation
- Certificate
[ fileRef] F252E794FE438E35ACE6E53762C0A234A2C52135.cer
[ subjectName] Microsoft Code Signing PCA 2011
- IssuerCertificate
[ fileRef] 8F43288AD272F3103B6FB1428485EA3014C0BCFE.cer
[ subjectName] Microsoft Root Certificate Authority 2011
- Flags
[ value] 0
- AdditionalParameters
[ timeToUse] 2014-05-06T21:00:10.094Z
[ currentTime] 2014-05-06T21:00:10.110Z
[ urlRetrievalTimeout] PT15S
- RevocationStatus
[ index] 0
[ error] 0
[ reason] 0
[ actualFreshnessTime] P51DT2H14M45S
- CertificateRevocationList
[ location] TvoCache
[ ur|] http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
[ fileRef] EB51DE8F544732860A34FDDB7FFA608AE65681FC.crl
[ issuerName] Microsoft Root Certificate Authority 2011
- EventAuxInfo
[ ProcessName] Explorer.EXE
- CorrelationAuxInfo
[ TaskId] {89359956-E4EF-4A3F-8D9A-436AC2BD8BE4}
[ SeqNumber] 4
- Result
[ value] 0
--------------------------------------------------
- System
- Provider
[ Name] Microsoft-Windows-CAPI2
[ Guid] {5bbca4a8-b209-48dc-a8c7-b23d3e5216fb}
EventID 41
Version 0
Level 4
Task 41
Opcode 2
Keywords 0x8000000000000005
- TimeCreated
[ SystemTime] 2014-05-06T21:00:10.110Z
EventRecordID 185255
Correlation
- Execution
[ ProcessID] 3704
[ ThreadID] 12184
Channel Microsoft-Windows-CAPI2/Operational
Computer XXXXXXX
- Security
[ UserID] XXXXXXX
- UserData
- CertVerifyRevocation
- Certificate
[ fileRef] 6474839AF67AB79C91007FF62FE08E2ACF016B83.cer
[ subjectName] Microsoft Corporation
- IssuerCertificate
[ fileRef] F252E794FE438E35ACE6E53762C0A234A2C52135.cer
[ subjectName] Microsoft Code Signing PCA 2011
- Flags
[ value] 0
- AdditionalParameters
[ timeToUse] 2014-05-06T21:00:10.094Z
[ currentTime] 2014-05-06T21:00:10.110Z
[ urlRetrievalTimeout] PT15S
- RevocationStatus
[ index] 0
[ error] 0
[ reason] 0
[ actualFreshnessTime] P51DT2H3M4S
- CertificateRevocationList
[ location] TvoCache
[ ur|] http://www.microsoft.com/pkiops/crl/MicCodSigPCA2011_2011-07-08.crl
[ fileRef] 5C7A33B1CD5AE5ACEA73BF8576E537F9E7244DDD.crl
[ issuerName] Microsoft Code Signing PCA 2011
- EventAuxInfo
[ ProcessName] Explorer.EXE
- CorrelationAuxInfo
[ TaskId] {89359956-E4EF-4A3F-8D9A-436AC2BD8BE4}
[ SeqNumber] 6
- Result
[ value] 0
--------------------------------------------------
- System
- Provider
[ Name] Microsoft-Windows-CAPI2
[ Guid] {5bbca4a8-b209-48dc-a8c7-b23d3e5216fb}
EventID 11
Version 0
Level 4
Task 11
Opcode 2
Keywords 0x8000000000000003
- TimeCreated
[ SystemTime] 2014-05-06T21:00:10.110Z
EventRecordID 185256
Correlation
- Execution
[ ProcessID] 3704
[ ThreadID] 12184
Channel Microsoft-Windows-CAPI2/Operational
Computer XXXXXXX
- Security
[ UserID] XXXXXXX
- UserData
- CertGetCertificateChain
- Certificate
[ fileRef] 6474839AF67AB79C91007FF62FE08E2ACF016B83.cer
[ subjectName] Microsoft Corporation
ValidationTime 2014-05-06T21:00:10.094Z
- AdditionalStore
- Certificate
[ fileRef] F252E794FE438E35ACE6E53762C0A234A2C52135.cer
[ subjectName] Microsoft Code Signing PCA 2011
- Certificate
[ fileRef] 6474839AF67AB79C91007FF62FE08E2ACF016B83.cer
[ subjectName] Microsoft Corporation
- ExtendedKeyUsage
- Usage
[ oid] 1.3.6.1.5.5.7.3.3
[ name] Handtekening bij programmacode
- Flags
[ value] 40000001
[ CERT_CHAIN_CACHE_END_CERT] true
[ CERT_CHAIN_REVOCATION_CHECK_CHAIN_EXCLUDE_ROOT] true
- ChainEngineInfo
[ context] user
- CertificateChain
[ chainRef] {C92488BE-76D0-4593-95D9-C328480D7978}
[ revocationFreshnessTime] P51DT2H14M45S
- TrustStatus
- ErrorStatus
[ value] 0
- InfoStatus
[ value] 100
[ CERT_TRUST_HAS_PREFERRED_ISSUER] true
- ChainElement
- Certificate
[ fileRef] 6474839AF67AB79C91007FF62FE08E2ACF016B83.cer
[ subjectName] Microsoft Corporation
- TrustStatus
- ErrorStatus
[ value] 0
- InfoStatus
[ value] 102
[ CERT_TRUST_HAS_KEY_MATCH_ISSUER] true
[ CERT_TRUST_HAS_PREFERRED_ISSUER] true
- ApplicationUsage
- Usage
[ oid] 1.3.6.1.5.5.7.3.3
[ name] Handtekening bij programmacode
- Usage
[ oid] 1.3.6.1.4.1.311.76.8.1
IssuanceUsage
- RevocationInfo
[ freshnessTime] P51DT2H3M4S
- RevocationResult
[ value] 0
- CertificateRevocationList
[ location] TvoCache
[ ur|] http://www.microsoft.com/pkiops/crl/MicCodSigPCA2011_2011-07-08.crl
[ fileRef] 5C7A33B1CD5AE5ACEA73BF8576E537F9E7244DDD.crl
[ issuerName] Microsoft Code Signing PCA 2011
- ChainElement
- Certificate
[ fileRef] F252E794FE438E35ACE6E53762C0A234A2C52135.cer
[ subjectName] Microsoft Code Signing PCA 2011
- TrustStatus
- ErrorStatus
[ value] 0
- InfoStatus
[ value] 102
[ CERT_TRUST_HAS_KEY_MATCH_ISSUER] true
[ CERT_TRUST_HAS_PREFERRED_ISSUER] true
- ApplicationUsage
[ any] true
- IssuanceUsage
- Usage
[ oid] 1.3.6.1.4.1.311.46.3
- RevocationInfo
[ freshnessTime] P51DT2H14M45S
- RevocationResult
[ value] 0
- CertificateRevocationList
[ location] TvoCache
[ ur|] http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
[ fileRef] EB51DE8F544732860A34FDDB7FFA608AE65681FC.crl
[ issuerName] Microsoft Root Certificate Authority 2011
- ChainElement
- Certificate
[ fileRef] 8F43288AD272F3103B6FB1428485EA3014C0BCFE.cer
[ subjectName] Microsoft Root Certificate Authority 2011
- TrustStatus
- ErrorStatus
[ value] 0
- InfoStatus
[ value] 10C
[ CERT_TRUST_HAS_NAME_MATCH_ISSUER] true
[ CERT_TRUST_IS_SELF_SIGNED] true
[ CERT_TRUST_HAS_PREFERRED_ISSUER] true
- ApplicationUsage
[ any] true
- IssuanceUsage
[ any] true
- EventAuxInfo
[ ProcessName] Explorer.EXE
- CorrelationAuxInfo
[ TaskId] {89359956-E4EF-4A3F-8D9A-436AC2BD8BE4}
[ SeqNumber] 7
- Result
[ value] 0
--------------------------------------------------
- System
- Provider
[ Name] Microsoft-Windows-CAPI2
[ Guid] {5bbca4a8-b209-48dc-a8c7-b23d3e5216fb}
EventID 90
Version 0
Level 4
Task 90
Opcode 0
Keywords 0x8000000000000200
- TimeCreated
[ SystemTime] 2014-05-06T21:00:10.110Z
EventRecordID 185257
Correlation
- Execution
[ ProcessID] 3704
[ ThreadID] 12184
Channel Microsoft-Windows-CAPI2/Operational
Computer XXXXXXX
- Security
[ UserID] XXXXXXX
- UserData
- X509Objects
- Certificate
[ fileRef] 6474839AF67AB79C91007FF62FE08E2ACF016B83.cer
[ subjectName] Microsoft Corporation
- Subject
CN Microsoft Corporation
OU MOPR
O Microsoft Corporation
L Redmond
S Washington
C US
- SubjectKeyID
[ computed] false
[ hash] 242B3DCA909C9E2875723CCF0CB33DE6AC245659
- Issuer
CN Microsoft Code Signing PCA 2011
O Microsoft Corporation
L Redmond
S Washington
C US
SerialNumber 330000001A77BB74B307D116B800000000001A
NotBefore 2013-09-24T17:41:41Z
NotAfter 2014-12-24T17:41:41Z
- Extensions
- ExtendedKeyUsage
- Usage
[ oid] 1.3.6.1.5.5.7.3.3
[ name] Handtekening bij programmacode
- Usage
[ oid] 1.3.6.1.4.1.311.76.8.1
- SubjectAltName
- DirectoryName
SERIALNUMBER 31642+2860b52e-c4a3-454d-bc1e-32c5add17e90
OU MOPR
- AuthorityKeyIdentifier
- KeyID
[ hash] 486E64E55005D382AA17373722B56DA8CA750295
- BasicConstraints
[ critical] true
[ cA] false
- Certificate
[ fileRef] F252E794FE438E35ACE6E53762C0A234A2C52135.cer
[ subjectName] Microsoft Code Signing PCA 2011
- Subject
CN Microsoft Code Signing PCA 2011
O Microsoft Corporation
L Redmond
S Washington
C US
- SubjectKeyID
[ computed] false
[ hash] 486E64E55005D382AA17373722B56DA8CA750295
- Issuer
CN Microsoft Root Certificate Authority 2011
O Microsoft Corporation
L Redmond
S Washington
C US
SerialNumber 610E90D2000000000003
NotBefore 2011-07-08T20:59:09Z
NotAfter 2026-07-08T21:09:09Z
- Extensions
- KeyUsage
[ value] 86
[ CERT_DIGITAL_SIGNATURE_KEY_USAGE] true
[ CERT_KEY_CERT_SIGN_KEY_USAGE] true
[ CERT_CRL_SIGN_KEY_USAGE] true
- BasicConstraints
[ critical] true
[ cA] true
- AuthorityKeyIdentifier
- KeyID
[ hash] 722D3A02319043B914054EE1EAA7C731D1238934
- CertificatePolicies
- Policy
[ oid] 1.3.6.1.4.1.311.46.3
- Certificate
[ fileRef] 8F43288AD272F3103B6FB1428485EA3014C0BCFE.cer
[ subjectName] Microsoft Root Certificate Authority 2011
- Subject
CN Microsoft Root Certificate Authority 2011
O Microsoft Corporation
L Redmond
S Washington
C US
- SubjectKeyID
[ computed] false
[ hash] 722D3A02319043B914054EE1EAA7C731D1238934
- Issuer
CN Microsoft Root Certificate Authority 2011
O Microsoft Corporation
L Redmond
S Washington
C US
SerialNumber 3F8BC8B5FC9FB29643B569D66C42E144
NotBefore 2011-03-22T22:05:28Z
NotAfter 2036-03-22T22:13:04Z
- Extensions
- KeyUsage
[ value] 86
[ CERT_DIGITAL_SIGNATURE_KEY_USAGE] true
[ CERT_KEY_CERT_SIGN_KEY_USAGE] true
[ CERT_CRL_SIGN_KEY_USAGE] true
- BasicConstraints
[ critical] true
[ cA] true
- Properties
FriendlyName Microsoft Root Certificate Authority 2011
- CertificateRevocationList
[ fileRef] EB51DE8F544732860A34FDDB7FFA608AE65681FC.crl
[ issuerName] Microsoft Root Certificate Authority 2011
- Issuer
CN Microsoft Root Certificate Authority 2011
O Microsoft Corporation
L Redmond
S Washington
C US
ThisUpdate 2014-03-16T18:45:25Z
NextUpdate 2014-06-15T07:05:25Z
- Extensions
- AuthorityKeyIdentifier
- KeyID
[ hash] 722D3A02319043B914054EE1EAA7C731D1238934
CRLNumber 20
NextPublishTime 2014-06-14T18:55:25Z
- CertificateRevocationList
[ fileRef] 5C7A33B1CD5AE5ACEA73BF8576E537F9E7244DDD.crl
[ issuerName] Microsoft Code Signing PCA 2011
- Issuer
CN Microsoft Code Signing PCA 2011
O Microsoft Corporation
L Redmond
S Washington
C US
ThisUpdate 2014-03-16T18:57:06Z
NextUpdate 2014-06-15T07:17:06Z
- Extensions
- AuthorityKeyIdentifier
- KeyID
[ hash] 486E64E55005D382AA17373722B56DA8CA750295
CRLNumber 23
NextPublishTime 2014-06-14T19:07:06Z
- EventAuxInfo
[ ProcessName] Explorer.EXE
- CorrelationAuxInfo
[ TaskId] {89359956-E4EF-4A3F-8D9A-436AC2BD8BE4}
[ SeqNumber] 8
--------------------------------------------------
- System
- Provider
[ Name] Microsoft-Windows-CAPI2
[ Guid] {5bbca4a8-b209-48dc-a8c7-b23d3e5216fb}
EventID 81
Version 0
Level 2
Task 80
Opcode 2
Keywords 0x8000000000000040
- TimeCreated
[ SystemTime] 2014-05-06T21:00:10.110Z
EventRecordID 185258
Correlation
- Execution
[ ProcessID] 3704
[ ThreadID] 12184
Channel Microsoft-Windows-CAPI2/Operational
Computer XXXXXXX
- Security
[ UserID] XXXXXXX
- UserData
- WinVerifyTrust
ActionID {189A3842-3041-11D1-85E1-00C04FC295EE}
- UIChoice WTD_UI_NONE
[ value] 2
- RevocationCheck
[ value] 0
- StateAction WTD_STATEACTION_VERIFY
[ value] 1
- Flags
[ value] 80000000
[ CPD_USE_NT5_CHAIN_FLAG] true
- FileInfo
[ filePath] D:\Gebruikers\XXXXXXX\Downloads\Microsoft EMET\EMET 4.1 Update 1\EMET Setup.msi
[ hasFileHandle] true
- RegPolicySetting
[ value] 23C00
[ WTPF_OFFLINEOK_IND] true
[ WTPF_OFFLINEOK_COM] true
[ WTPF_OFFLINEOKNBU_IND] true
[ WTPF_OFFLINEOKNBU_COM] true
[ WTPF_IGNOREREVOCATIONONTS] true
- CertificateChain
[ chainRef] {C92488BE-76D0-4593-95D9-C328480D7978}
- StepError
[ stepID] 32
[ stepName] TRUSTERROR_STEP_FINAL_OBJPROV
- Result De digitale handtekening van het object kan niet worden gecontroleerd.
[ value] 80096010
- EventAuxInfo
[ ProcessName] Explorer.EXE
- CorrelationAuxInfo
[ TaskId] {89359956-E4EF-4A3F-8D9A-436AC2BD8BE4}
[ SeqNumber] 9
- Result De digitale handtekening van het object kan niet worden gecontroleerd.
[ value] 80096010
--------------------------------------------------