MSFN Forum: KB2728973 , rvkroots.exe, will throw up an error when trying to integr - MSFN Forum

Jump to content


If you are having issues with Windows after removing components and have come to ask for help, please attach (not paste) your Last Session.ini file to your post to facilitate quicker assistance.
Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

KB2728973 , rvkroots.exe, will throw up an error when trying to integr Use this add-on creator instead. Rate Topic: -----

#1 User is offline   -X- 

  • Member
  • Group: Patrons
  • Posts: 2,050
  • Joined: 08-January 04
  • OS:XP Pro x86
  • Country: Country Flag

Posted 10 July 2012 - 02:42 PM

KB2728973 , rvkroots.exe (Revoked Roots Update), will throw up an error when trying to integrate with nLite...

Posted Image

Posted Image

I have created an add-on creator that correctly adds it to the SVCPACK folder. Download here: rvkroots.Add-on.Creator.zip

This is for those that don't use my UDC script. For those that do, sit tight while I add it to this months update.

More info: KB Article Security Advisory

Note: This update replaces KB2718704 and will probably be the way MS handles those pesky Digital Certificates from now on.

This post has been edited by -X-: 10 July 2012 - 09:37 PM



#2 User is offline   Explorer09 

  • Member
  • PipPip
  • Group: Members
  • Posts: 132
  • Joined: 12-September 11

Posted 10 July 2012 - 08:08 PM

What about the crypt32.dll file in the KB2718704 update? Does KB2728973 patch that file?

EDIT: I figured it out. No, rvkroots.exe does not contain the file, so it does NOT replace KB2718704.

This post has been edited by Explorer09: 10 July 2012 - 08:54 PM


#3 User is offline   Explorer09 

  • Member
  • PipPip
  • Group: Members
  • Posts: 132
  • Joined: 12-September 11

Posted 10 July 2012 - 08:50 PM

Double post.

I've installed the update and extracted 28 new registry entries in the update. I think this could make slipstreaming much easier.

See the attached .reg file.

rvkroots.exe should modify other certificate entries as well, but I found that it was only the header that was changed, so it won't matter.

Edit (14 July 2012): I upload a new version because I forgot this registry entry in the previous one:
; Windows Update checks this.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{C3C986D6-06B1-43BF-90DD-BE30756C00DE}]
"Version"="1,0,2195,0"


Mirrors: http://ge.tt/9Xyy0VK/v/0 , http://dl.dropbox.co...roots-certs.reg

Attached File(s)


This post has been edited by Explorer09: 14 July 2012 - 09:54 AM


#4 User is offline   -X- 

  • Member
  • Group: Patrons
  • Posts: 2,050
  • Joined: 08-January 04
  • OS:XP Pro x86
  • Country: Country Flag

Posted 10 July 2012 - 09:39 PM

Yeah, I have a reg file already.

I forgot about crypt32.dll....

Quote

Known issues with this security update

This security update does not include the functionality to remove trust of non-leaf certificates in Windows XP and in Windows Server 2003. To add the functionality for removing trust of non-leaf certificates for Windows XP and for Windows Server 2003, you must install one of the following security updates:
2616676 Microsoft Security Advisory: Fraudulent digital certificates could allow spoofing
2641690 Microsoft Security Advisory: Fraudulent digital certificates could allow spoofing
2718704 Unauthorized digital certificates could allow spoofing


#5 User is offline   Explorer09 

  • Member
  • PipPip
  • Group: Members
  • Posts: 132
  • Joined: 12-September 11

Posted 13 July 2012 - 12:06 AM

When I attached my .reg file, I mean it is possible to integrate those registry entries directly into nLite.inf, just like the old KB2718704 update did.

Your UDC script only scheduled the program to run when the Windows setup starts to install hotfixes. I personally don't like your method.

#6 User is offline   -X- 

  • Member
  • Group: Patrons
  • Posts: 2,050
  • Joined: 08-January 04
  • OS:XP Pro x86
  • Country: Country Flag

Posted 13 July 2012 - 12:52 AM

Here's your preferred method for those that want it.

This attachment is now obsolete. Removed.

This post has been edited by -X-: 04 January 2013 - 01:56 AM


Share this topic:


Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

1 User(s) are reading this topic
0 members, 1 guests, 0 anonymous users



All trademarks mentioned on this page are the property of their respective owners
Copyright © 2001 - 2013 msfn.org
Privacy Policy