Jump to content
Strawberry Orange Banana Lime Leaf Slate Sky Blueberry Grape Watermelon Chocolate Marble
Strawberry Orange Banana Lime Leaf Slate Sky Blueberry Grape Watermelon Chocolate Marble

MSFN is made available via donations, subscriptions and advertising revenue. The use of ad-blocking software hurts the site. Please disable ad-blocking software or set an exception for MSFN. Alternatively, register and become a site sponsor/subscriber and ads will be disabled automatically. 

Sign in to follow this  
Guest

KB2728973 , rvkroots.exe, will throw up an error when trying to integr

Recommended Posts

Guest   
Guest

KB2728973 , rvkroots.exe (Revoked Roots Update), will throw up an error when trying to integrate with nLite... Fixed in the new nLite. nLite



I have created an add-on creator that correctly adds it to the SVCPACK folder. Download here: Add-on no longer needed. Use the new nLite. nLite

This is for those that don't use my UDC script. For those that do, sit tight while I add it to this months update.

More info: KB Article Security Advisory

Note: This update replaces KB2718704 and will probably be the way MS handles those pesky Digital Certificates from now on.

Edited by -X-

Share this post


Link to post
Share on other sites
Explorer09    4

What about the crypt32.dll file in the KB2718704 update? Does KB2728973 patch that file?

EDIT: I figured it out. No, rvkroots.exe does not contain the file, so it does NOT replace KB2718704.

Edited by Explorer09

Share this post


Link to post
Share on other sites
Explorer09    4

Double post.

I've installed the update and extracted 28 new registry entries in the update. I think this could make slipstreaming much easier.

See the attached .reg file.

rvkroots.exe should modify other certificate entries as well, but I found that it was only the header that was changed, so it won't matter.

Edit (14 July 2012): I upload a new version because I forgot this registry entry in the previous one:

; Windows Update checks this.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{C3C986D6-06B1-43BF-90DD-BE30756C00DE}]
"Version"="1,0,2195,0"

Mirrors: http://ge.tt/9Xyy0VK/v/0 , http://dl.dropbox.com/u/70170658/msfn/rvkroots-certs.reg

rvkroots-certs.reg

Edited by Explorer09

Share this post


Link to post
Share on other sites
Guest   
Guest

Yeah, I have a reg file already.

I forgot about crypt32.dll....

Known issues with this security update

This security update does not include the functionality to remove trust of non-leaf certificates in Windows XP and in Windows Server 2003. To add the functionality for removing trust of non-leaf certificates for Windows XP and for Windows Server 2003, you must install one of the following security updates:

2616676 Microsoft Security Advisory: Fraudulent digital certificates could allow spoofing

2641690 Microsoft Security Advisory: Fraudulent digital certificates could allow spoofing

2718704 Unauthorized digital certificates could allow spoofing

Share this post


Link to post
Share on other sites
Explorer09    4

When I attached my .reg file, I mean it is possible to integrate those registry entries directly into nLite.inf, just like the old KB2718704 update did.

Your UDC script only scheduled the program to run when the Windows setup starts to install hotfixes. I personally don't like your method.

Share this post


Link to post
Share on other sites
Guest   
Guest

Here's your preferred method for those that want it.

This attachment is now obsolete. Removed.

Edited by -X-

Share this post


Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now

Sign in to follow this  

  • Recently Browsing   0 members

    No registered users viewing this page.

×