{"id":8959,"date":"2019-03-19T00:09:00","date_gmt":"2019-03-18T23:09:00","guid":{"rendered":"http:\/\/159.69.82.204\/win\/?p=8959"},"modified":"2022-03-18T06:02:55","modified_gmt":"2022-03-18T05:02:55","slug":"windows-7-updates-for-sha-2-support","status":"publish","type":"post","link":"https:\/\/borncity.com\/win\/2019\/03\/19\/windows-7-updates-for-sha-2-support\/","title":{"rendered":"Windows 7: Updates for SHA-2 support"},"content":{"rendered":"<p><img loading=\"lazy\" decoding=\"async\" style=\"float: left; margin: 0px 10px 0px 0px; display: inline; border-width: 0px;\" title=\"win7\" src=\"https:\/\/www.borncity.com\/blog\/wp-content\/uploads\/2012\/03\/win7_thumb1.jpg\" alt=\"win7\" width=\"44\" height=\"42\" align=\"left\" border=\"0\" \/>[<a href=\"https:\/\/www.borncity.com\/blog\/2019\/03\/13\/windows-7-updates-rsten-sha-2-support-nach\/\" target=\"_blank\" rel=\"noopener noreferrer\">German<\/a>]On March 12, 2019, Microsoft released updates for SHA-2 support for Windows 7 SP1 and Windows Server 2008\/R2 as well as WSUS 3.0 SP2. Here is some information about this topic and some hints about first issues.<\/p>\n<p><!--more--><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/vg06.met.vgwort.de\/na\/c3bbc70f45084aaba1009d2c88d824ce\" alt=\"\" width=\"1\" height=\"1\" \/>The blog post is an attempt to pick up some loose ends and bring them together to an article describing the odds and evens. You can add missing information to the comments..<\/p>\n<h2>What is SHA-2 support about?<\/h2>\n<p>Microsoft had announced in 2018 that it would only add SHA-2 signatures to its Windows updates from mid-2019 onwards &#8211; signing with SHA-1 would then no longer be necessary for security reasons. I've had published the article <a href=\"https:\/\/borncity.com\/win\/2018\/11\/21\/windows-7-from-april-2019-sha-2-support-is-required\/\">Windows 7: From April 2019 'SHA-2-Support' is <\/a>about that.<\/p>\n<p>Users of Windows 7 SP1 (as well as its server counterparts) and WSUS will therefore need a special update from April 2019, which will enable the machine for SHA-2 code signatures. Without this update, these machines will not be able to process new updates in the future. In the blog post <a href=\"https:\/\/borncity.com\/win\/2019\/02\/18\/sha-2-patch-for-windows-7-arrives-on-march-2019\/\">SHA-2 patch for Windows 7 arrives on March 2019<\/a> I had announced an update for this month, but I had to leave some details to it. As of March 12, 2019, Microsoft has provided the required updates as part of the patchday.<\/p>\n<h2>Updates KB4474419 and KB4490628<\/h2>\n<p>Effective March 12, 2019, Microsoft has extended the support article <a href=\"https:\/\/web.archive.org\/web\/20201231202502\/https:\/\/support.microsoft.com\/en-us\/help\/4472027\/2019-sha-2-code-signing-support-requirement-for-windows-and-wsus\">4472027<\/a> titled <em>2019 SHA-2 Code Signing Support requirement for Windows and WSUS<\/em> with the details and named the required updates.<\/p>\n<h3>Security Update KB4474419<\/h3>\n<p>Update <a href=\"https:\/\/support.microsoft.com\/en-us\/help\/4474419\">KB4474419<\/a> (SHA-2 code signing support update for Windows Server 2008 R2 and Windows 7: March 12, 2019) adds support for SHA-2 signature evaluation for Windows 7 SP1 and its server pendants. The update is automatically downloaded and installed via Windows Update. The update is also available via Windows Server Update Services (WSUS) or for manual download via <a href=\"http:\/\/catalog.update.microsoft.com\/v7\/site\/search.aspx?q=kb4474419\">Microsoft Update Catalog<\/a>. The update is also linked to the Microsoft Update Catalog on the <a href=\"https:\/\/web.archive.org\/web\/20201004024648\/https:\/\/portal.msrc.microsoft.com\/en-US\/security-guidance\/advisory\/adv190009\">ADV90009<\/a> advisory page.<\/p>\n<h3>Servicing Stack Update KB4490628<\/h3>\n<p>In addition, the Servicing Stack Update (SSUs) <a href=\"https:\/\/support.microsoft.com\/en-us\/help\/4490628\/servicing-stack-update-for-windows-7-sp1-and-windows-server-2008-r2\">KB4490628<\/a> was released for Windows 7 SP1 and Windows Server 2008 R2 SP1. This update fixes a problem with the Servicing Stack when installing updates that were signed using only the SHA-2 hash algorithm. I already pointed this out in the blog post <a href=\"https:\/\/borncity.com\/win\/2019\/03\/13\/patchday-updates-for-windows-7-8-1-server-march-12-2019\/\">Patchday: Updates for Windows 7\/8.1\/Server (March 12, 2019)<\/a>.<\/p>\n<h2>More issues with these updates<\/h2>\n<p>When installing the updates mentioned above to support SHA-2 only update packages, various errors and issues may occur. Microsoft states that the SSU need to be installed before installing the March 2019 updates to avoid subsequent errors and installation problems. But that seems not true \u2013 because on my systems this update had been offered only after installing Update KB4474419 first.<\/p>\n<h3>Update KB4490628 hangs on reboot<\/h3>\n<p>Update KB4490628 comes with a known issue during its installation, which Microsoft lists <a href=\"https:\/\/support.microsoft.com\/en-us\/help\/4490628\/servicing-stack-update-for-windows-7-sp1-and-windows-server-2008-r2\" target=\"_blank\" rel=\"noopener noreferrer\">here<\/a>. After you have installed the SSU together with other updates, a restart may be required to complete the installation.<\/p>\n<p>(Update hangs, Source: Microsoft)<\/p>\n<p>During this reboot, the system may hang when the message \"Level 2 of 2\" or \"Level 3 of 3\" appears. If this problem occurs, press Ctrl+Alt+Del to log on to Windows. This problem should occur only once.<\/p>\n<h3>Update KB4490628 is not offered<\/h3>\n<p>In KB article <a href=\"https:\/\/support.microsoft.com\/en-us\/help\/4490628\/servicing-stack-update-for-windows-7-sp1-and-windows-server-2008-r2\">4490628<\/a>, Microsoft states that this update is offered automatically by Windows Update. In <a href=\"https:\/\/www.borncity.com\/blog\/2019\/03\/13\/patchday-updates-fr-windows-7-8-1-server-12-mrz-2019\/#comment-69286\" target=\"_blank\" rel=\"noopener noreferrer\">this comment<\/a> blog reader Joe_Gerhard points out that the update is not offered to him. I checked it on my machine &#8211; this update was missing there as well, while update KB4474419 has been offered. Later I learned (see my remark above), that update KB4474419 is required, before update is KB4490628 offered. If required, the <a href=\"http:\/\/catalog.update.microsoft.com\/v7\/site\/search.aspx?q=4490628\">Microsoft Update Catalog<\/a> is also available for download.<\/p>\n<p>German blog reader Markus B. informed me a few days ago via e-mail about an observation:<\/p>\n<blockquote><p>I was able to install the Win7 cumulative first via the WSUS. Then I installed the SSU. MS it says in its support article, that there would be some issues, but that seems not be true. Installing SSU after the cumulative update, does not need a restart.<\/p>\n<p>In an other installation order with SSU first and then the cumulative for SHA-2 support, it would take much longer to distribute the patches. Because I would need to wait, until the maintenance windows has bee shown \u2013 in cause, Windows need some administrator prompts.<\/p><\/blockquote>\n<p>Thank to Markus for his feedback. There is now a huge discussion thread beneath my <a href=\"https:\/\/www.borncity.com\/blog\/2019\/03\/13\/windows-7-updates-rsten-sha-2-support-nach\/\" target=\"_blank\" rel=\"noopener noreferrer\">German blog post<\/a> about issues.<\/p>\n<h3>Restart loop in 32-bit Windows 7<\/h3>\n<p>Within <a href=\"https:\/\/www.borncity.com\/blog\/2018\/11\/21\/windows-7-ab-april-2019-wird-ein-sha-2-update-bentigt\/#comment-69285\" target=\"_blank\" rel=\"noopener noreferrer\">this comment<\/a> (German) blog reader Gregor (thanks) writes, that the SHA-2 support update led to a reboot loop on three 32-bit Windows 7 machines. Gregor does not specify which update KB4474419 or KB4490628 is meant. Has anyone ever had similar experiences?<\/p>\n<h2>Update KB4484071 for WSUS 3.0 SP2<\/h2>\n<p>In addition, Microsoft has provided the standalone update <a href=\"https:\/\/support.microsoft.com\/en-us\/help\/4484071\" target=\"_blank\" rel=\"noopener noreferrer\">KB4484071<\/a> for WSUS 3.0 SP2 (SHA-2 Support for Windows Server Update Services 3.0 SP2) in <a href=\"https:\/\/web.archive.org\/web\/20201231202502\/https:\/\/support.microsoft.com\/en-us\/help\/4472027\/2019-sha-2-code-signing-support-requirement-for-windows-and-wsus\" target=\"_blank\" rel=\"noopener noreferrer\">this support article<\/a>. This update enabled WSUS 3.0 SP2 for SHA-2 support.<\/p>\n<p>Administrators using WSUS 3.0 SP2 need to install this update manually until June 18, 2019. This ensures that updates for Windows 7 and Windows Server 2008\/R2 can be redistributed via WSUS 3.0 SP2 from that point. However, the prerequisite for manually installing update KB4484071 is that the following updates:<\/p>\n<ul>\n<li>Windows Monthly Rollup <a href=\"https:\/\/support.microsoft.com\/de-de\/help\/4489880\">KB4489880<\/a> (or newer) for Windows Server 2008 SP2<\/li>\n<li><a href=\"https:\/\/support.microsoft.com\/de-de\/help\/4489878\">KB4489878<\/a> (or newer) for Windows Server 2008 R2 SP1<\/li>\n<li>and .NET 3.5 need to be installed first<\/li>\n<\/ul>\n<p>If this is overlooked, errors may occur during installation. Microsoft also recommends backing up the WSUS database before installing these updates.<\/p>\n<p><strong>Similar articles<br \/>\n<\/strong><a href=\"https:\/\/borncity.com\/win\/2018\/11\/21\/windows-7-from-april-2019-sha-2-support-is-required\/\">Windows 7: From April 2019 'SHA-2-Support' is required<\/a><br \/>\n<a href=\"https:\/\/borncity.com\/win\/2019\/02\/18\/sha-2-patch-for-windows-7-arrives-on-march-2019\/\">SHA-2 patch for Windows 7 arrives on March 2019<\/a><br \/>\n<a href=\"https:\/\/borncity.com\/win\/2019\/03\/13\/patchday-updates-for-windows-7-8-1-server-march-12-2019\/\">Patchday: Updates for Windows 7\/8.1\/Server (March 12, 2019)<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>[German]On March 12, 2019, Microsoft released updates for SHA-2 support for Windows 7 SP1 and Windows Server 2008\/R2 as well as WSUS 3.0 SP2. Here is some information about this topic and some hints about first issues.<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[22,2],"tags":[1823,195,17],"class_list":["post-8959","post","type-post","status-publish","format-standard","hentry","category-update","category-windows","tag-sha-2","tag-update","tag-windows-7"],"_links":{"self":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts\/8959","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/comments?post=8959"}],"version-history":[{"count":0,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts\/8959\/revisions"}],"wp:attachment":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/media?parent=8959"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/categories?post=8959"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/tags?post=8959"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}