Loading...
Loading...
When attempting to upgrade or install Veeam ONE 13, the System Configuration Check stage of the setup wizard fails, and the following error is displayed: <TBD>Signature verification failed after retries for 'C:\ProgramData\Veeam\Setup\Temp\c2fbbc7c-acd7-4e33-b1fa-915c0eca920b\bf9e5076-a5c1-4b3e-8e36-9bcfbf3178f0\Newtonsoft.Json.dll'.
This issue occurs because the Veeam ONE setup wizard verifies the digital signature of each file that it stages before installing it, and the Windows Trusted Root Certification Authorities store on the server does not contain the root certificate that the file's signing chain terminates in. The signature check returns 0x800B0109 (CERT_E_UNTRUSTEDROOT), and setup stops. The Trusted Root Certification Authorities store is kept current by the Microsoft automatic update mechanism, which downloads certificate trust lists from ctldl.windowsupdate.com over TCP port 80. On a server that has no internet access, or where a proxy configuration or firewall rule blocks that address, the store is not updated and the required root certificate is never added. Confirming the Cause in the Setup Logs The signature check and its diagnostics are recorded in ReporterServerSetup.log. An entry similar to the following is logged for each verification attempt, and the diagnostics block that follows it reports a missing authroot.stl file when the root certificate trust list has never been downloaded: ***Veeam*** VerifyAll: attempt 5 failed for '...\Newtonsoft.Json.dll' hr=0x800B0109 ***Veeam*** --- signature-check diagnostics --- authroot.stl.path = C:\Windows\system32\authroot.stl <GetFileAttributesExW failed, GLE=2> --- end diagnostics ---
The root certificate list published through the Microsoft Trusted Root Program is identical across all Windows machines, so the certificate bundle can be generated on any trusted machine with internet access.Note: If the Veeam ONE server itself has internet access, both commands below can be run on that server, and steps 4 through 6 can be skipped. Take a snapshot or checkpoint of the Veeam ONE server before making any changes. On a machine that has internet access, open Command Prompt as Administrator. Run the following command to download the current Microsoft root certificate bundle:
Preventing the Issue on Future Upgrades Windows maintains the Trusted Root Certification Authorities store through the Microsoft automatic update mechanism. To allow the Veeam ONE server to keep the store current on its own, permit outbound access to ctldl.windowsupdate.com over TCP port 80, along with DNS name resolution. For environments where outbound internet access is not permitted, Microsoft documents a method for redirecting the automatic update mechanism to an internal file or web server that is kept synchronized with Windows Update. Microsoft References Microsoft Learn: certutil command reference Microsoft Learn: Configure Trusted Roots and Disallowed Certificates
Click on a version to see all relevant bugs
Veeam Integration
Learn more about where this data comes from
BugZero Plan
Streamline upgrades with automated vendor bug scrubs
BugZero Prevent
Wish you caught this bug sooner? Get proactive today.