Door Erik van Straten, 09:14 uur:
als CAPI2 eventlogs geen indicatie geven over wat er mis is
Door Spiff, 13:57 uur:
Ik weet nog niet of die logs geen indicatie geven over wat er mis is.
Een flink deel van de informatie weet ik niet te interpreteren.
Misschien kan jij of kunnen jullie er wel wat mee?
Zal ik die logdetails eens hier posten?
Hieronder de CAPI2 eventlogs
voor het checken van de details van de digitale handtekeningen van EMET [4.1u1] Setup.msi.
In de hoop dat iemand er iets wetenswaardigs uit kan afleiden.
Achtereenvolgens vier logs met het niveau "Informatie",
en het laatste, vijfde log, met het niveau "Fout".
(N.B. "url"-aanduidingen heb ik vervangen door "ur|", omdat anders de weergave in de soep loopt doordat url tussen haken als BBcode wordt gelezen.)
--------------------------------------------------
- System 
  - Provider 
   [ Name]  Microsoft-Windows-CAPI2 
   [ Guid]  {5bbca4a8-b209-48dc-a8c7-b23d3e5216fb}  
   EventID 41  
   Version 0  
   Level 4  
   Task 41  
   Opcode 2  
   Keywords 0x8000000000000005  
  - TimeCreated 
   [ SystemTime]  2014-05-06T21:00:10.110Z  
   EventRecordID 185253  
   Correlation  
  - Execution 
   [ ProcessID]  3704 
   [ ThreadID]  12184  
   Channel Microsoft-Windows-CAPI2/Operational  
   Computer XXXXXXX  
  - Security 
   [ UserID]  XXXXXXX 
- UserData 
  - CertVerifyRevocation 
  - Certificate 
   [ fileRef]  F252E794FE438E35ACE6E53762C0A234A2C52135.cer 
   [ subjectName]  Microsoft Code Signing PCA 2011  
  - IssuerCertificate 
   [ fileRef]  8F43288AD272F3103B6FB1428485EA3014C0BCFE.cer 
   [ subjectName]  Microsoft Root Certificate Authority 2011  
  - Flags 
   [ value]  0  
  - AdditionalParameters 
   [ timeToUse]  2014-05-06T21:00:10.094Z 
   [ currentTime]  2014-05-06T21:00:10.110Z 
   [ urlRetrievalTimeout]  PT15S  
  - RevocationStatus 
   [ index]  0 
   [ error]  0 
   [ reason]  0 
   [ actualFreshnessTime]  P51DT2H14M45S  
  - CertificateRevocationList 
   [ location]  TvoCache 
   [ ur|]  http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl 
   [ fileRef]  EB51DE8F544732860A34FDDB7FFA608AE65681FC.crl 
   [ issuerName]  Microsoft Root Certificate Authority 2011  
  - EventAuxInfo 
   [ ProcessName]  Explorer.EXE  
  - CorrelationAuxInfo 
   [ TaskId]  {89359956-E4EF-4A3F-8D9A-436AC2BD8BE4} 
   [ SeqNumber]  4  
  - Result 
   [ value]  0 
--------------------------------------------------
- System 
  - Provider 
   [ Name]  Microsoft-Windows-CAPI2 
   [ Guid]  {5bbca4a8-b209-48dc-a8c7-b23d3e5216fb}  
   EventID 41  
   Version 0  
   Level 4  
   Task 41  
   Opcode 2  
   Keywords 0x8000000000000005  
  - TimeCreated 
   [ SystemTime]  2014-05-06T21:00:10.110Z  
   EventRecordID 185255  
   Correlation  
  - Execution 
   [ ProcessID]  3704 
   [ ThreadID]  12184  
   Channel Microsoft-Windows-CAPI2/Operational  
   Computer XXXXXXX  
  - Security 
   [ UserID]  XXXXXXX 
- UserData 
  - CertVerifyRevocation 
  - Certificate 
   [ fileRef]  6474839AF67AB79C91007FF62FE08E2ACF016B83.cer 
   [ subjectName]  Microsoft Corporation  
  - IssuerCertificate 
   [ fileRef]  F252E794FE438E35ACE6E53762C0A234A2C52135.cer 
   [ subjectName]  Microsoft Code Signing PCA 2011  
  - Flags 
   [ value]  0  
  - AdditionalParameters 
   [ timeToUse]  2014-05-06T21:00:10.094Z 
   [ currentTime]  2014-05-06T21:00:10.110Z 
   [ urlRetrievalTimeout]  PT15S  
  - RevocationStatus 
   [ index]  0 
   [ error]  0 
   [ reason]  0 
   [ actualFreshnessTime]  P51DT2H3M4S  
  - CertificateRevocationList 
   [ location]  TvoCache 
   [ ur|]  http://www.microsoft.com/pkiops/crl/MicCodSigPCA2011_2011-07-08.crl 
   [ fileRef]  5C7A33B1CD5AE5ACEA73BF8576E537F9E7244DDD.crl 
   [ issuerName]  Microsoft Code Signing PCA 2011  
  - EventAuxInfo 
   [ ProcessName]  Explorer.EXE  
  - CorrelationAuxInfo 
   [ TaskId]  {89359956-E4EF-4A3F-8D9A-436AC2BD8BE4} 
   [ SeqNumber]  6  
  - Result 
   [ value]  0 
--------------------------------------------------
- System 
  - Provider 
   [ Name]  Microsoft-Windows-CAPI2 
   [ Guid]  {5bbca4a8-b209-48dc-a8c7-b23d3e5216fb}  
   EventID 11  
   Version 0  
   Level 4  
   Task 11  
   Opcode 2  
   Keywords 0x8000000000000003  
  - TimeCreated 
   [ SystemTime]  2014-05-06T21:00:10.110Z  
   EventRecordID 185256  
   Correlation  
  - Execution 
   [ ProcessID]  3704 
   [ ThreadID]  12184  
   Channel Microsoft-Windows-CAPI2/Operational  
   Computer XXXXXXX  
  - Security 
   [ UserID]  XXXXXXX 
- UserData 
  - CertGetCertificateChain 
  - Certificate 
   [ fileRef]  6474839AF67AB79C91007FF62FE08E2ACF016B83.cer 
   [ subjectName]  Microsoft Corporation  
   ValidationTime 2014-05-06T21:00:10.094Z  
  - AdditionalStore 
  - Certificate 
   [ fileRef]  F252E794FE438E35ACE6E53762C0A234A2C52135.cer 
   [ subjectName]  Microsoft Code Signing PCA 2011  
  - Certificate 
   [ fileRef]  6474839AF67AB79C91007FF62FE08E2ACF016B83.cer 
   [ subjectName]  Microsoft Corporation 
- ExtendedKeyUsage 
  - Usage 
   [ oid]  1.3.6.1.5.5.7.3.3 
   [ name]  Handtekening bij programmacode 
- Flags 
   [ value]  40000001 
   [ CERT_CHAIN_CACHE_END_CERT]  true 
   [ CERT_CHAIN_REVOCATION_CHECK_CHAIN_EXCLUDE_ROOT]  true  
  - ChainEngineInfo 
   [ context]  user  
  - CertificateChain 
   [ chainRef]  {C92488BE-76D0-4593-95D9-C328480D7978} 
   [ revocationFreshnessTime]  P51DT2H14M45S 
  - TrustStatus 
  - ErrorStatus 
   [ value]  0  
  - InfoStatus 
   [ value]  100 
   [ CERT_TRUST_HAS_PREFERRED_ISSUER]  true 
- ChainElement 
  - Certificate 
   [ fileRef]  6474839AF67AB79C91007FF62FE08E2ACF016B83.cer 
   [ subjectName]  Microsoft Corporation  
  - TrustStatus 
  - ErrorStatus 
   [ value]  0  
  - InfoStatus 
   [ value]  102 
   [ CERT_TRUST_HAS_KEY_MATCH_ISSUER]  true 
   [ CERT_TRUST_HAS_PREFERRED_ISSUER]  true 
- ApplicationUsage 
  - Usage 
   [ oid]  1.3.6.1.5.5.7.3.3 
   [ name]  Handtekening bij programmacode  
  - Usage 
   [ oid]  1.3.6.1.4.1.311.76.8.1 
IssuanceUsage  
  - RevocationInfo 
   [ freshnessTime]  P51DT2H3M4S 
  - RevocationResult 
   [ value]  0  
  - CertificateRevocationList 
   [ location]  TvoCache 
   [ ur|]  http://www.microsoft.com/pkiops/crl/MicCodSigPCA2011_2011-07-08.crl 
   [ fileRef]  5C7A33B1CD5AE5ACEA73BF8576E537F9E7244DDD.crl 
   [ issuerName]  Microsoft Code Signing PCA 2011 
- ChainElement 
  - Certificate 
   [ fileRef]  F252E794FE438E35ACE6E53762C0A234A2C52135.cer 
   [ subjectName]  Microsoft Code Signing PCA 2011  
  - TrustStatus 
  - ErrorStatus 
   [ value]  0  
  - InfoStatus 
   [ value]  102 
   [ CERT_TRUST_HAS_KEY_MATCH_ISSUER]  true 
   [ CERT_TRUST_HAS_PREFERRED_ISSUER]  true 
- ApplicationUsage 
   [ any]  true  
  - IssuanceUsage 
  - Usage 
   [ oid]  1.3.6.1.4.1.311.46.3 
- RevocationInfo 
   [ freshnessTime]  P51DT2H14M45S 
  - RevocationResult 
   [ value]  0  
  - CertificateRevocationList 
   [ location]  TvoCache 
   [ ur|]  http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl 
   [ fileRef]  EB51DE8F544732860A34FDDB7FFA608AE65681FC.crl 
   [ issuerName]  Microsoft Root Certificate Authority 2011 
- ChainElement 
  - Certificate 
   [ fileRef]  8F43288AD272F3103B6FB1428485EA3014C0BCFE.cer 
   [ subjectName]  Microsoft Root Certificate Authority 2011  
  - TrustStatus 
  - ErrorStatus 
   [ value]  0  
  - InfoStatus 
   [ value]  10C 
   [ CERT_TRUST_HAS_NAME_MATCH_ISSUER]  true 
   [ CERT_TRUST_IS_SELF_SIGNED]  true 
   [ CERT_TRUST_HAS_PREFERRED_ISSUER]  true 
- ApplicationUsage 
   [ any]  true  
  - IssuanceUsage 
   [ any]  true 
- EventAuxInfo 
   [ ProcessName]  Explorer.EXE  
  - CorrelationAuxInfo 
   [ TaskId]  {89359956-E4EF-4A3F-8D9A-436AC2BD8BE4} 
   [ SeqNumber]  7  
  - Result 
   [ value]  0 
--------------------------------------------------
- System 
  - Provider 
   [ Name]  Microsoft-Windows-CAPI2 
   [ Guid]  {5bbca4a8-b209-48dc-a8c7-b23d3e5216fb}  
   EventID 90  
   Version 0  
   Level 4  
   Task 90  
   Opcode 0  
   Keywords 0x8000000000000200  
  - TimeCreated 
   [ SystemTime]  2014-05-06T21:00:10.110Z  
   EventRecordID 185257  
   Correlation  
  - Execution 
   [ ProcessID]  3704 
   [ ThreadID]  12184  
   Channel Microsoft-Windows-CAPI2/Operational  
   Computer XXXXXXX  
  - Security 
   [ UserID]  XXXXXXX 
- UserData 
  - X509Objects 
  - Certificate 
   [ fileRef]  6474839AF67AB79C91007FF62FE08E2ACF016B83.cer 
   [ subjectName]  Microsoft Corporation 
  - Subject 
   CN Microsoft Corporation  
   OU MOPR  
   O Microsoft Corporation  
   L Redmond  
   S Washington  
   C US 
- SubjectKeyID 
   [ computed]  false 
   [ hash]  242B3DCA909C9E2875723CCF0CB33DE6AC245659  
  - Issuer 
   CN Microsoft Code Signing PCA 2011  
   O Microsoft Corporation  
   L Redmond  
   S Washington  
   C US 
SerialNumber 330000001A77BB74B307D116B800000000001A  
   NotBefore 2013-09-24T17:41:41Z  
   NotAfter 2014-12-24T17:41:41Z  
  - Extensions 
  - ExtendedKeyUsage 
  - Usage 
   [ oid]  1.3.6.1.5.5.7.3.3 
   [ name]  Handtekening bij programmacode  
  - Usage 
   [ oid]  1.3.6.1.4.1.311.76.8.1 
- SubjectAltName 
  - DirectoryName 
   SERIALNUMBER 31642+2860b52e-c4a3-454d-bc1e-32c5add17e90  
   OU MOPR 
- AuthorityKeyIdentifier 
  - KeyID 
   [ hash]  486E64E55005D382AA17373722B56DA8CA750295 
- BasicConstraints 
   [ critical]  true 
   [ cA]  false 
- Certificate 
   [ fileRef]  F252E794FE438E35ACE6E53762C0A234A2C52135.cer 
   [ subjectName]  Microsoft Code Signing PCA 2011 
  - Subject 
   CN Microsoft Code Signing PCA 2011  
   O Microsoft Corporation  
   L Redmond  
   S Washington  
   C US 
- SubjectKeyID 
   [ computed]  false 
   [ hash]  486E64E55005D382AA17373722B56DA8CA750295  
  - Issuer 
   CN Microsoft Root Certificate Authority 2011  
   O Microsoft Corporation  
   L Redmond  
   S Washington  
   C US 
SerialNumber 610E90D2000000000003  
   NotBefore 2011-07-08T20:59:09Z  
   NotAfter 2026-07-08T21:09:09Z  
  - Extensions 
  - KeyUsage 
   [ value]  86 
   [ CERT_DIGITAL_SIGNATURE_KEY_USAGE]  true 
   [ CERT_KEY_CERT_SIGN_KEY_USAGE]  true 
   [ CERT_CRL_SIGN_KEY_USAGE]  true  
  - BasicConstraints 
   [ critical]  true 
   [ cA]  true  
  - AuthorityKeyIdentifier 
  - KeyID 
   [ hash]  722D3A02319043B914054EE1EAA7C731D1238934 
- CertificatePolicies 
  - Policy 
   [ oid]  1.3.6.1.4.1.311.46.3 
- Certificate 
   [ fileRef]  8F43288AD272F3103B6FB1428485EA3014C0BCFE.cer 
   [ subjectName]  Microsoft Root Certificate Authority 2011 
  - Subject 
   CN Microsoft Root Certificate Authority 2011  
   O Microsoft Corporation  
   L Redmond  
   S Washington  
   C US 
- SubjectKeyID 
   [ computed]  false 
   [ hash]  722D3A02319043B914054EE1EAA7C731D1238934  
  - Issuer 
   CN Microsoft Root Certificate Authority 2011  
   O Microsoft Corporation  
   L Redmond  
   S Washington  
   C US 
SerialNumber 3F8BC8B5FC9FB29643B569D66C42E144  
   NotBefore 2011-03-22T22:05:28Z  
   NotAfter 2036-03-22T22:13:04Z  
  - Extensions 
  - KeyUsage 
   [ value]  86 
   [ CERT_DIGITAL_SIGNATURE_KEY_USAGE]  true 
   [ CERT_KEY_CERT_SIGN_KEY_USAGE]  true 
   [ CERT_CRL_SIGN_KEY_USAGE]  true  
  - BasicConstraints 
   [ critical]  true 
   [ cA]  true 
- Properties 
   FriendlyName Microsoft Root Certificate Authority 2011 
- CertificateRevocationList 
   [ fileRef]  EB51DE8F544732860A34FDDB7FFA608AE65681FC.crl 
   [ issuerName]  Microsoft Root Certificate Authority 2011 
  - Issuer 
   CN Microsoft Root Certificate Authority 2011  
   O Microsoft Corporation  
   L Redmond  
   S Washington  
   C US 
ThisUpdate 2014-03-16T18:45:25Z  
   NextUpdate 2014-06-15T07:05:25Z  
  - Extensions 
  - AuthorityKeyIdentifier 
  - KeyID 
   [ hash]  722D3A02319043B914054EE1EAA7C731D1238934 
CRLNumber 20  
   NextPublishTime 2014-06-14T18:55:25Z 
- CertificateRevocationList 
   [ fileRef]  5C7A33B1CD5AE5ACEA73BF8576E537F9E7244DDD.crl 
   [ issuerName]  Microsoft Code Signing PCA 2011 
  - Issuer 
   CN Microsoft Code Signing PCA 2011  
   O Microsoft Corporation  
   L Redmond  
   S Washington  
   C US 
ThisUpdate 2014-03-16T18:57:06Z  
   NextUpdate 2014-06-15T07:17:06Z  
  - Extensions 
  - AuthorityKeyIdentifier 
  - KeyID 
   [ hash]  486E64E55005D382AA17373722B56DA8CA750295 
CRLNumber 23  
   NextPublishTime 2014-06-14T19:07:06Z 
- EventAuxInfo 
   [ ProcessName]  Explorer.EXE  
  - CorrelationAuxInfo 
   [ TaskId]  {89359956-E4EF-4A3F-8D9A-436AC2BD8BE4} 
   [ SeqNumber]  8 
--------------------------------------------------
- System 
  - Provider 
   [ Name]  Microsoft-Windows-CAPI2 
   [ Guid]  {5bbca4a8-b209-48dc-a8c7-b23d3e5216fb}  
   EventID 81  
   Version 0  
   Level 2  
   Task 80  
   Opcode 2  
   Keywords 0x8000000000000040  
  - TimeCreated 
   [ SystemTime]  2014-05-06T21:00:10.110Z  
   EventRecordID 185258  
   Correlation  
  - Execution 
   [ ProcessID]  3704 
   [ ThreadID]  12184  
   Channel Microsoft-Windows-CAPI2/Operational  
   Computer XXXXXXX  
  - Security 
   [ UserID]  XXXXXXX 
- UserData 
  - WinVerifyTrust 
   ActionID {189A3842-3041-11D1-85E1-00C04FC295EE}  
  - UIChoice WTD_UI_NONE 
   [ value]  2  
  - RevocationCheck 
   [ value]  0  
  - StateAction WTD_STATEACTION_VERIFY 
   [ value]  1  
  - Flags 
   [ value]  80000000 
   [ CPD_USE_NT5_CHAIN_FLAG]  true  
  - FileInfo 
   [ filePath]  D:\Gebruikers\XXXXXXX\Downloads\Microsoft EMET\EMET 4.1 Update 1\EMET Setup.msi 
   [ hasFileHandle]  true  
  - RegPolicySetting 
   [ value]  23C00 
   [ WTPF_OFFLINEOK_IND]  true 
   [ WTPF_OFFLINEOK_COM]  true 
   [ WTPF_OFFLINEOKNBU_IND]  true 
   [ WTPF_OFFLINEOKNBU_COM]  true 
   [ WTPF_IGNOREREVOCATIONONTS]  true  
  - CertificateChain 
   [ chainRef]  {C92488BE-76D0-4593-95D9-C328480D7978}  
  - StepError 
   [ stepID]  32 
   [ stepName]  TRUSTERROR_STEP_FINAL_OBJPROV 
  - Result De digitale handtekening van het object kan niet worden gecontroleerd. 
   [ value]  80096010 
- EventAuxInfo 
   [ ProcessName]  Explorer.EXE  
  - CorrelationAuxInfo 
   [ TaskId]  {89359956-E4EF-4A3F-8D9A-436AC2BD8BE4} 
   [ SeqNumber]  9  
  - Result De digitale handtekening van het object kan niet worden gecontroleerd. 
   [ value]  80096010 
--------------------------------------------------