Impossible to upgrade DPM 2025 to DPM 2025 UR1

M.E.ACG 11 Reputation points
2025-12-04T09:43:18.24+00:00

Trying to update a DPM 2025 server to UR1 fails, regardless of the update being served by WSUS or downloaded by catalog. While having a look to the files contained in the package which I downloaded from catalog, I found an invalid signature was used to sign the patch file (dataprotectionmanager-kb5068307.msp):

User's imageUser's image

Serial number is 330000048498e212e078a3315d000000000484.

I guess, UR1 will be re-released soon?

Windows for business | Windows Server | Devices and deployment | Set up, install, or upgrade
{count} vote

2 answers

Sort by: Most helpful
  1. VPHAN 10,795 Reputation points Independent Advisor
    2025-12-04T19:01:47.1+00:00

    Hi M.E.ACG,

    The signature validation failure you observed is the direct cause of the update failure. The 1st screenshot shows the critical error "This digital signature is not valid" for the signer "Microsoft Corporation," with a signing time stamped in the future (November 20, 2025). This future date, combined with the detailed cryptographic data in the 2ed image showing a valid certificate structure from the Microsoft Code Signing PCA 2011, points to a corrupted or improperly time-stamped signature within the .msp file itself. The system's certificate validation logic is rejecting the file because the authenticated attribute for the signing time is nonsensical, breaking the chain of trust.

    To resolve this and install UR1, you must bypass the signature check for this specific file. The most direct method is to use the msiexec command with the parameter to disable signature validation. First, extract the .msp file from the downloaded update package or locate it in the WSUS content directory, typically under C:\WSUS\WsusContent. Then, open an elevated command prompt and execute the installation directly against the installed DPM product code. You will need to identify the exact GUID for your DPM 2019 installation, which can be found in the registry under HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products. The command will resemble msiexec /p "C:\PathTo\dataprotectionmanager-kb5068307.msp" /qn /norestart DISABLE_PATCH_SIGNATURE_VALIDATION=1. This forces the installation of the patch regardless of the digital signature error.

    Prior to this, ensure your system's date and time are correct and synchronised with a reliable source, as a significant time skew can contribute to validation issues. Also, verify that the root certificate "Microsoft Code Signing PCA 2011" is present and trusted in the local computer's certificate store under Cert:\LocalMachine\Root. While a re-release of UR1 with a correctly signed package is a possibility, this manual installation workaround is the immediate solution. Proceeding with this patch should not affect your ability to install future, correctly signed updates.

    I hope you've found something useful here. If it helps you get more insight into the issue, it's appreciated to ACCEPT ANSWER then. Should you have more questions, feel free to leave a message. Have a nice day!


  2. M.E.ACG 11 Reputation points
    2025-12-08T11:15:05.6333333+00:00

    It turned out, that the situation is totally different. Yes, the extracted files were corrupt but that seems to be caused when using the onboard extractor in Server 2025. Extracting the files with another 3rd party tool on the same machine results in intact files. After the extraction, I were able to install UR1 successfully.


Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.