Kb2921916 что за обновление

от admin

Kb2921916 windows 7 x64

Правильно стопорит, вы необходимые драйверы на USB 3.0 и на контроллер накопителей с помощью DISM в дистрибутив интегрировали?

Neon2 Нет. Чистая семерка, на свой нетбук Асус N1201 ставил без проблем.

А на эту модель без них установить не получится, даже если вы «развернёте» на SDD/HDD установленную 7-ку из образа, то всё равно для её запуска потребуется интеграция этих драйверов.

как это сделать?

Axii, загрузиться с флешки WinPE на основе Win8/8.1/10, посмотреть ИД оборудования контроллеров, по ИД найти и скачать драйверы к ним, распаковать драйверы и через команды DISM добавить эти драйверы в boot.wim и install.wim, см. пост и статью «DISM: интегрируем драйвера в образ Windows».

Вот сделал http://rgho.st/private/6LJDgPDrV/9cf35bd. ca8d3c68f6
А 10 с диска станет без доп движений? Посоветуйте образ

Neon2 Посоветуйте образ пожалуйста

Neon2 Спасибо тебе огромное за помощь. Я сам бы никогда не смог установить Вин7. Оставшиеся драйвера установил с помощью Драйвер Пак. Вроде все наблюдал, но повторить точно не смогу. Теперь флешку надо в сейф спрятать.

А если не ставиться KB3033929-x64, что можно сделать? Пишет что у меня проц нового поколения и отказывается

Axii, для установки обновлений в этом случае нужно установить wufuc.

по моему он просто блокирует установку этого КВ

Axii, извините, но скорее всего вы, как и большинство любителей установить ODIS, напрочь проигнорировали общий совет для тех, кто хочет без проблем использовать Windows 7 на конфигурациях с новыми процессорами.

Windows 7 и ODIS

Kb2921916 windows 7 x64

При установке на Windows 7 часто возникает ошибка об отсутствии 2х обновлений:
Windows6.1-KB3033929-x64.msu
Windows6.1-KB2921916-x64.msu
Но при попытке установить вышеуказанные обновления, выскакивает сообщение о невозможности это сделать.

Kb2921916 windows 7 x64

Это связано с тем, что MS заменил старые апдейты на новые (т.е. в обновление KBXXXXXXX.msu уже входит Windows6.1-KB3033929-x64.msu).
Решение: используем утилиту dism.exe.
Запускаем командную строку от имени Администратора
1. распаковываем *.msu: Windows6.1-KB3033929-x64.msu /extract
2. пареходим в директорию куда распаковалось обновление: cd C:\Windows6.1-KB3033929-x64\
3. принудительно устанавливаем обновление: dism.exe /online /add-package /packagepath:C:\Windows6.1-KB3033929-x64\Windows6.1-KB3033929-x64.cab

Если вы не можете найти в интернете вышеуказанные обновления (вас забанили в Google, а Yandex заблокирован «РосКомНадзором), то можете обновления забрать из временной папки, которая появляется при установки ODIS: «C:\Temp\ODIS\FirstPatches\»

Если вы уверены что обновления уже установлены, или не хотите их устанавливать, а инсталлер ODIS ругается на это,

Kb2921916 windows 7 x64

можно подправить конфиг установщика.
При первом запуске инсталлятора,

Kb2921916 windows 7 x64

Kb2921916 windows 7 x64

Kb2921916 windows 7 x64

до момента сообщения об отсутствии обновления,

на диске «C:» присутствует временная папка «C:\Temp\ODIS\FirstPatches\», в которой лежит файл PATCH_FIRST.bat.

Kb2921916 windows 7 x64

Kb2921916 windows 7 x64

Копируем папку «Temp» (включая подпапки) куда нибудь, закрываем инсталлятор. В скопированной папке выбираем для редактирования PATCH_FIRST.bat.

Kb2921916 windows 7 x64

Ишем секции относящиеся к обновлениям и удаляем или комментируем их.

The «Untrusted publisher» dialog box appears when you install a driver in Windows 7 or Windows Server 2008 R2

Symptoms

Consider the following scenario:

You have a computer that is running Windows 7 or Windows Server 2008 R2.

You install a driver that is signed by an SHA256, SHA384, or SHA512 certificate, and the «Untrusted publisher» dialog box appears.

You click to select the Always trust check box and then click OK.

You uninstall the driver.

You install the same driver again.

In this scenario, the «Untrusted publisher» dialog box appears even though you already set the Always trust option to always trust the publisher.

Resolution

Hotfix information

A supported hotfix is available from Microsoft Support. However, this hotfix is intended to correct only the problem that is described in this article. Apply this hotfix only to systems that are experiencing the problem described in this article. This hotfix might receive additional testing. Therefore, if you are not severely affected by this problem, we recommend that you wait for the next software update that contains this hotfix.

If the hotfix is available for download, there is a «Hotfix download available» section at the top of this Knowledge Base article. If this section does not appear, contact Microsoft Customer Service and Support to obtain the hotfix.

Note If additional issues occur or if any troubleshooting is required, you might have to create a separate service request. The usual support costs will apply to additional support questions and issues that do not qualify for this specific hotfix. For a complete list of Microsoft Customer Service and Support telephone numbers or to create a separate service request, go to the following Microsoft website:

http://support.microsoft.com/contactus/?ws=supportNote The «Hotfix download available» form displays the languages for which the hotfix is available. If you do not see your language, it is because a hotfix is not available for that language.

Prerequisites

To apply this hotfix, you must have Service Pack 1 for Windows 7 or Windows Server 2008 R2 installed.

Restart requirement

You must restart the computer after you apply this hotfix.

Hotfix replacement information

This hotfix does not replace any previously released hotfix.

The English (United States) version of this hotfix installs files that have the attributes that are listed in the following tables. The dates and the times for these files are listed in Coordinated Universal Time (UTC). The dates and the times for these files on your local computer are displayed in your local time together with your current daylight saving time (DST) bias. Additionally, the dates and the times may change when you perform certain operations on the files.

Windows 7 and Windows Server 2008 R2 file information and notes

Important Windows 7 hotfixes and Windows Server 2008 R2 hotfixes are included in the same packages. However, hotfixes on the Hotfix Request page are listed under both operating systems. To request the hotfix package that applies to one or both operating systems, select the hotfix that is listed under «Windows 7/Windows Server 2008 R2» on the page. Always refer to the «Applies To» section in articles to determine the actual operating system that each hotfix applies to.

The files that apply to a specific product, SR_Level (RTM, SP n), and service branch (LDR, GDR) can be identified by examining the file version numbers as shown in the following table.

Windows 7 and Windows Server 2008 R2

Windows 7 and Windows Server 2008 R2

GDR service branches contain only those fixes that are widely released to address widespread, extremely important issues. LDR service branches contain hotfixes in addition to widely released fixes.

The MANIFEST files (.manifest) and the MUM files (.mum) that are installed for each environment are listed separately in the «Additional file information for Windows 7 and Windows Server 2008 R2» section. MUM and MANIFEST files, and the associated security catalog (.cat) files, are extremely important to maintain the state of the updated components. The security catalog files, for which the attributes are not listed, are signed with a Microsoft digital signature.

For all supported x86-based versions of Windows 7

win: confirm that KB2921916 installer workaround works #1051

Comments

crawshaw commented Dec 21, 2020

Windows Update does not automatically install this update as Win7 is EOL.

The text was updated successfully, but these errors were encountered:

bradfitz commented Dec 21, 2020

we don’t use an MSI yet so we can’t really bundle an MSU from what I understand?

Should we also host that file and detect at runtime if it’s necessary? We can try to fetch+install it before loading wintun.

crawshaw commented Dec 21, 2020

zx2c4 commented Dec 21, 2020

wusa.exe /quiet /warnrestart path\to\temporary\nsis\directory\blahblah.msu

See https://ss64.com/nt/wusa.html for other options. There’s no need to do this with MSI, and probably MSI would take the same approach as invoking wusa.exe anyway.

Alternatively, if you do this at runtime in the app instead of at install time from nsis, and you want to auto-fetch, please mirror those files on your own servers.

apenwarr commented Jan 14, 2021

I think #1051 perhaps eliminated the need for this?

bradfitz commented Jan 14, 2021

zx2c4 commented Jan 14, 2021

Care to share details? That link is private.

bradfitz commented Jan 14, 2021

@zx2c4, the core of that change is that at the end of the install (where it’s running with elevated privileges), it calls:

The change was primarily about eliminating the race between the driver install from the service and the GUI waiting to connect to the service.

By doing it at install time, by the time the server + GUI start later, the driver’s already been installed and the service starts up much more quickly.

But I’m not sure how that helps this issue? Isn’t KB2921916 really just some hacky fix (that Microsoft later abandoned as not a good idea?) that disables some verification? The fact that Microsoft never included KB2921916 in subsequent roll-up patch releases seems like a red flag. Or is @apenwarr saying that after the UAC elevation, the driver install works without KB2921916 somehow?

zx2c4 commented Jan 14, 2021 •

That’s not going to be robust when the driver gets removed from the store and readded by other things later.

KB2921916 isn’t hacky at all. It changes the code from:

The old code failed when sha2 was used, because 20 bytes is too small. The new code is the proper fix. The patch isn’t hacky at all and works extremely well. I reverse engineered every byte of the change of the binary and I can’t find any bugs with the new code or any idea why it’d be a problem.

KB2921916 is gone from Microsoft’s site because they pulled all the KBs when they sunsetted Windows 7.

bradfitz commented Jan 14, 2021

KB2921916 isn’t hacky at all. It changes the code from:

Ah, thanks for the explanation!

KB2921916 is gone from Microsoft’s site because they pulled all the KBs when they sunsetted Windows 7.

That’s not going to be robust when the driver gets removed from the store and readded by other things later.

We still do the pool.CreateAdapter on service start-up regardless (so if it disappears, it’ll still come back). Doing it in the installer additionally just makes the service start-up’s call to pool.CreateAdapter much faster.

Empirically it makes the Windows 7 install experience much better.

zx2c4 commented Jan 14, 2021

We still do the pool.CreateAdapter on service start-up regardless (so if it disappears, it’ll still come back). Doing it in the installer additionally just makes the service start-up’s call to pool.CreateAdapter much faster.

Except if the driver gets removed, pool.CreateAdapter will reinstall it, and then you’ll run into the sha2 issue again and installation will fail.

bradfitz commented Jan 14, 2021

Sorry, I still don’t understand how the func InstallWintunDriver code I pasted above has anything to do with KB2921916.

It’s possible you and @apenwarr are having a separate conversation over my head.

zx2c4 commented Jan 14, 2021

Alright, here’s what’s up:

On Windows 10, the driver is signed by Microsoft, and the certificate is already included in Windows, so everything works well and there’s nothing to do.

On Windows 7 and Windows 8, the driver is signed with an authenticode certificate. In order to install a driver with an authenticode signature, one must first add the certificate to the system certificate store. After that, installing a driver into the driver store works well, and silently without any popups or UI required.

Except on Windows 7, due to that 20-byte sha1-hardcoding bug I mentioned above, it can’t actually deal with the sha2 signature. So it falls back to assuming that the driver is signed with an unknown certificate, and prompts the user, «hey are you sure you want to install this?» And, since Windows services don’t have UI access, this translates into a failure.

Calling that function in the installer appears to work because it moves that UI prompt to install time, rather than service time. But if the driver is ever removed, then pool.CreateAdapter being called by the service will install it again, in which case, the service won’t have UI access and the operation will fail.

The correct solution is to install that KB, which fixes the root cause of the issue and allows the installation of the certificate into the trusted certificate store to work as intended.

zx2c4 commented Jan 20, 2021

Note that there is a difference between Windows 7 not understanding authenticode (which is a pain) and it thinking your driver is completely unsigned. There’s an old-style signing method that works with Windows 7. Before wintun.dll, we bundled two copies of wintun.sys, one signed with the new-style Windows 10 thing and one signed with the old-style Windows 7/8 thing, and installed the right one. It still popped up a prompt on Windows 7, but the prompt was: «This driver is signed by Tailscale, do you want to use it anyway?» It’s kind of a silly question, but it’s how the OS was intended to work, so I’m not sure we should be interfering with it. When we tried to include both certs on the same driver, Windows 7 would claim it was entirely unsigned, which was scary for users (and I think prevented installing on Windows 7-64bit or something) so we couldn’t do that. ᐧ

Yes, and this is what wintun.dll does. The issue is simply that the dialog box cannot be shown from a non-interactive service.

zx2c4 commented Jan 20, 2021

You are correct that my suggested solution would stop working if someone ever uninstalled the driver. But if they do that, it seems like they’re trying to break their system, so perhaps we should let it be broken.

I’m pretty sure you’re underestimating how common of a flow that winds up being. Maybe I’m wrong, but keep this in mind should you get unusual bug reports down the line. On the other hand, perhaps win7 usage won’t be high enough to warrant a real solution.

zx2c4 commented Jan 20, 2021

The problem with Microsoft hotfixes is that they are explicitly intended to be used only as an interim solution until the «real» fix gets properly tested and bundled into an actual OS patch.

Whatever your impression of Microsoft’s policies is, all I can say is that I’ve reverse engineered every byte of that hotfix and cannot think of a more straight forward way of fixing the bug.

Инструкция по установке ODIS 5.1.6, ODIS 5.1.3 и ODIS 4.4.10 К списку статей

Рекомендуемой операционной системой для работы VAS 5054A с ODIS 4.4.10 является Windows 7, при этом данная версия программы ODIS 4.4.10 на Windows 8 и 10 с VAS 5054A работать не будет. Последняя версия ODIS, которая работает с VAS 5054A на windows 10 и windows 8 является ODIS-Service 3.0.3 и ODIS-Engineering 6.6.1. В настоящий момент появилось решение позволяющее обойти это официальное ограничение и VAS 5054A может работать с Windows 10 с новыми версиями ODIS-Service и ODIS-Engineering, более подробно об установке ODIS на Windows 10 для VAS5054A в нашей следующей статье.

В настоящее время имеется новая версия ODIS 5.1.6. Инструкция по установке ODIS 5.1.6 аналогична установке программного обеспечения более ранней версии ODIS 4.4.10. При покупке диагностического сканера VAS 5054A в нашем интернет-магазине Вы получаете всегда новую актуальную версию программного обеспечения.

В рамках данной статьи рассматриваем установку на чистую операционную систему windows 7 32-bit. Перед этапом инсталлирования ODIS 4.4.10 в случае, когда на компьютере установлены более ранние версии ODIS необходимо выполнить их полное удаление.

Читать:
Как сдвинуть массив влево c

Производим установку ODIS 4.4.10

Для начала установки производим запуск OffboardDiagSetup-Service_VWMCD_4_4_10-B44_10_0_2.exe, запуск производим от имени администратора.
Выбираем язык установки. Для установки русского языка выбираем «Русский (RU)» и нажимаем OK

Kb2921916 windows 7 x64

Kb2921916 windows 7 x64

Выбираем путь установки (по умолчанию C:\Program Files (x86)\Offboard_Diagnostic_Information_System_Service) и жмем «Далее»

Kb2921916 windows 7 x64

Целевая папка компонентов диагностики (по умолчанию C:\ODIS-DIAG-MODULES) и жмем «Далее»

Kb2921916 windows 7 x64

В выборе платформы выбираем «Обычный ПК/ноутбук» и жмем «Далее»

Kb2921916 windows 7 x64

В выборе активируемого диагностического интерфейса выбираем «VAS 5054» и жмем «Далее»

Kb2921916 windows 7 x64

В следующем окне представлена информация по использованию VAS5054 с программой жмем «Далее»

Kb2921916 windows 7 x64

В выборе файла лицензии с помощью кнопки «Обзор. » выбираем файл с лицензией (license.dat) и нажимаем «Далее»

Kb2921916 windows 7 x64
Kb2921916 windows 7 x64
Kb2921916 windows 7 x64

В следующем окне нажимаем «Далее»

Kb2921916 windows 7 x64

Начинается установка программы

Kb2921916 windows 7 x64

В случае появления сообщений безопасности Windows о вопросе установки программного обеспечения для данного устройства ставим галку в поле «Всегда доверять программному обеспечению» и нажимаем «Установить»

Kb2921916 windows 7 x64

Для завершения работы мастера установки нажимаем «Готово»

Kb2921916 windows 7 x64

Kb2921916 windows 7 x64

Производим запуск программы ODIS с рабочего стола

Kb2921916 windows 7 x64

В окне ввода данных конфигурации PostSetup нажимаем «Выбор локального каталога. » и выбираем папку с обновлениями PostSetup (папка ODIS-Service_update_4_4_10-EU_20180807_s4DzQ) и нажимаем «OK»

Kb2921916 windows 7 x64
Kb2921916 windows 7 x64

Далее нажимаем на стрелку

Kb2921916 windows 7 x64

Выбираем язык установки PostSetup, для установки русского языка выбираем «Русский (RU) (ru_RU)» (остальные языки выбирать не надо) и жмем на правую стрелку

Kb2921916 windows 7 x64

Для установки обновления нажимаем на правую стрелку

Kb2921916 windows 7 x64

Начинается достаточно долгий процесс установки PostSetup

Kb2921916 windows 7 x64

После установки PostSetup открывается окно установленной программы, читаем информацию и жмем «OK»

Kb2921916 windows 7 x64

Программа готова к использованию.

Kb2921916 windows 7 x64

Подключаем VAS 5054A в USB и к автомобилю, производим установку драйвера, либо производим сопряжение трансмиттера посредством Bluetooth.

Обращаем внимание, что предлагаемые нами адаптеры VAS 5054A с оригинальным OKI M6636 (не путать с OKI M6636B, т.к. микросхемы OKI M6636 и OKI M6636B это не аналоги и имеют разную распиновку) полностью работоспособны с ODIS 4.4.10 и не требуют дополнительной доработки, а также поддерживают режим PassThru (J2534).

Подключение VAS 5054A по USB к ODIS подробно описано в нашей статье.
Подключение VAS 5054A по bluetooth к ODIS подробно описано в нашей статье.

Kb2921916 windows 7 x64

Производим диагностику транспортного средства

Kb2921916 windows 7 x64

Возможные вопросы при установке:

1) В выборе активируемого диагностического интерфейса отсутствует «VAS 5054»

Kb2921916 windows 7 x64

Установка производится на операционную систему windows 8 или windows 10, при этом VAS 5054A с ODIS 4.4.10 работает только с Windows 7. Последняя версия ODIS, которая работает с VAS 5054A на windows 10 и windows 8 является ODIS-Service 3.0.3 и ODIS-Engineering 6.6.1.

2) Во время установки PostSetup в окне ввода данных конфигурации при выборе локального каталога через «Выбор локального каталога. » появляется сообщение «По указанному URL найти действительную конфигурацию ПО не удалось. Выберите другой URL»

Kb2921916 windows 7 x64

Не верно выбрана папка с обновлениями, выбираем папку с PostSetup, содержащую обновления

Kb2921916 windows 7 x64

Kb2921916 windows 7 x64

Произвести обновление для системы безопасности Windows 7 (KB3033929) с официального сайта microsoft и продолжить установку.

4) Ошибка: Framework start failed with ’13’

Kb2921916 windows 7 x64

Данная ошибка возникает на этапе активации программы и решается повторной правильной активацией.

Kb2921916 windows 7 x64

Данная ошибка часто возникает после использования флешера GALLETTO 2 v54, для решения проверяем системную дату, установленную на компьютере и устанавливаем текущую дату.

6) При запуске программы появляется сообщение с предупреждением: ODS9013E Инфраструктура. Соединение онлайн VW.MirrorServer 2: В структуре данных обновления имеется ошибка. Обратитесь в службу поддержки.» а затем «ODS9023E Инфраструктура. Соединение онлайн VW.MirrorServer 2: Следующие языки на выбранном MirrorServer недоступны.» где будут отображаться все языки, выбранные в момент установки PostSetup (ru_RU, de_DE, en_US, en_GB и др)

Kb2921916 windows 7 x64

Данные ошибки связаны с некорректностью (невозможностью) подключения к серверу обновлений и на функциональность программы не влияют (официальным пользователям рекомендовано обратиться в службу поддержки для корректного решения данного вопроса). Для уменьшения количества данных предупреждений в меню программы ODIS заходим в «Администрирование», далее во вкладке «Общее» выбираем пункт «Обновление» и устанавливаем периодичность обновлений в 7 дней. Для того чтобы совсем отключить данное сообщение необходимо открыть с помощью блокнота файл: «C:\Program Files (x86)\Offboard_Diagnostic_Information_System_Service\configuration\.settings\org.eclipse.internal.prefs и в строке VAUDAS_Day_Of_Last_Update=1538502826322 меняем значение на VAUDAS_Day_Of_Last_Update=111111111111111111
После данной процедуры сервис обновления будет работать только в ручном режиме.

7) При запуске программы ODIS появляется сообщение с ошибкой: ODS2522E Инфраструктура: Используемое здесь аппаратное обеспечение интерфейса автомобиля не поддерживается

Kb2921916 windows 7 x64

Для решения данной ошибки запускаем файл ODS2522E_Fix_x86.exe или ODS2522E_Fix_x64.exe в зависимости от разрядности операционной системы.

Широкий выбор оборудования для компьютерной диагностики автомобилей, ремонт автомобильных диагностических сканеров и адаптеров различной степени сложности, доставка диагностического оборудования по Минску и всей территории РБ, возможна доставка в РФ.

Офис: г. Минск, ул. Скрыганова, 6-3/47 ИП Латыпов Николай Кабилжанович УНН291078028 Свидетельство выдано Минским горисполкомом 29.12.2011 г., РБ, г. Минск, ул. Скрыганова, ЧБ-9.

Windows 7 — Установка и настройка — 154 страница

Правильно стопорит, вы необходимые драйверы на USB 3.0 и на контроллер накопителей с помощью DISM в дистрибутив интегрировали?

Neon2 Нет. Чистая семерка, на свой нетбук Асус N1201 ставил без проблем.

А на эту модель без них установить не получится, даже если вы «развернёте» на SDD/HDD установленную 7-ку из образа, то всё равно для её запуска потребуется интеграция этих драйверов.

как это сделать?

Axii, загрузиться с флешки WinPE на основе Win8/8.1/10, посмотреть ИД оборудования контроллеров, по ИД найти и скачать драйверы к ним, распаковать драйверы и через команды DISM добавить эти драйверы в boot.wim и install.wim, см. пост и статью «DISM: интегрируем драйвера в образ Windows».

Вот сделал http://rgho.st/private/6LJDgPDrV/9cf35bd. ca8d3c68f6
А 10 с диска станет без доп движений? Посоветуйте образ

Разумеется без них — что в Win8.1, что в Win10 уже есть встроенные драйверы на эти контроллеры.

Neon2 Посоветуйте образ пожалуйста

Neon2 Спасибо тебе огромное за помощь. Я сам бы никогда не смог установить Вин7. Оставшиеся драйвера установил с помощью Драйвер Пак. Вроде все наблюдал, но повторить точно не смогу. Теперь флешку надо в сейф спрятать.

А если не ставиться KB3033929-x64, что можно сделать? Пишет что у меня проц нового поколения и отказывается

Axii, для установки обновлений в этом случае нужно установить wufuc.

по моему он просто блокирует установку этого КВ

Axii, извините, но скорее всего вы, как и большинство любителей установить ODIS, напрочь проигнорировали общий совет для тех, кто хочет без проблем использовать Windows 7 на конфигурациях с новыми процессорами.

Установка Yggdrasil Network на Windows

Найти общую информацию о Yggdrasil на русском языке не составляет труда. Однако, как показала практика, многие пользователи сталкиваются с трудностями при установке клиента сети. По заявкам трудящихся рассмотрим в этой статье установку и начальную конфигурацию Yggdrasil Network на компьютере под управлением операционной системы Windows.

Скачать и установить

Протокол Yggdrasil, как и официальный клиент сети, являются полностью открытыми и бесплатными. В силу этого скачивать установочные бинарные файлы можно только из официальных источников, так как любые попытки распространения программы через другие каналы вызывает опасение: вероятно, скачав с другого места, вы установите не только Yggdrasil, но и вредоносное ПО.

Для загрузки перейдите на страницу релизов официального гит-репозитория. Для Windows клиент сети Yggdrasil распространяется в виде службы (сервиса), установочный файл имеет расширение msi .

Если вы используете Windows 7 или Windows Server 2008 R2, согласно документации вам необходимо перед установкой Yggdrasil поставить патч KB2921916: x64, x32. Без него виртуальный сетевой адаптер WireGuard может работать некорректно.

Установка msi-пакета не требует каких-либо дополнительных действий кроме клика, а процесс установки занимает около минуты. После установки в системе появится служба Yggdrasil. Чтобы увидеть ее, наберите «Службы» в меню Пуск (либо «services.msc») и нажмите Enter.

Windows 10

Windows 10

Также в операционной системе появится новый сетевой адаптер WireGuard, который можно найти в Панели управления, в разделе «Центр управления сетями и общим доступом».

Чтобы открыть свойства подключения, кликните на подсвеченную кнопку «Yggdrasil».

Начальная конфигурация

По умолчанию Yggdrasil автоматически находит других участников в локальной сети. Чтобы эта опция работала практически, необходимо включить «IP версии 6» на остальных (реальных) сетевых интерфейсах компьютера.

Связь с глобальным сегментом Yggdrasil, который не ограничивается вашей локальной сетью, обеспечивается подключением к публичным пирам хотя бы одного устройства в вашей локальной сети. Для поиска публичных пиров можете воспользоваться официальным списком.

Выбирайте те, которые выделены зеленым

Выбирайте те, которые выделены зеленым

Адреса публичных пиров нужно прописать в конфигурационном файле Yggdrasil (как правило, достаточно двух). По умолчанию файл находится по адресу: %programdata%\yggdrasil\yggdrasil.conf .

Публичные пиры указываются в секции Peers следующим образом:

Если вы используете Windows 7, текстовый редактор по умолчанию может испортить кодировку конфигурационного файла, поэтому рекомендуется использовать сторонние текстовые редакторы вроде AkelPad, NotePad++ и прочие, сохраняющие исходную кодировку конфига (UTF-8).

Чтобы изменения вступили в силу, необходимо перезапустить службу Yggdrasil: клик правой кнопкой мыши на «Yggdrasil Service» в списке сервисов, затем выбор пункта «Перезапустить».

Если все сделано правильно, после перезапуска Yggdrasil ваш компьютер имеет выход в глобальный сегмент сети: вы можете открывать сайты, использовать игровые серверы и разворачивать в сети Yggdrasil свои общедоступные сервисы.

Чтобы убедиться в работоспособности, попробуйте открыть какой-нибудь адрес из официального списка публичных сервисов, которые держат энтузиасты. Например, http://[324:71e:281a:9ed3::41]/ . Если веб-браузер отобразил страницу, а не ошибку, можно праздновать победу.

Безопасность

Этот мануал был бы злом, если не упомянуть о большой опасности. После установки Yggdrasil, ваш компьютер имеет выделенный IPv6-адрес, к которому в рамках сети может обратиться любой желающий. Обыкновенно о настройке файерволла помнят лишь администраторы с опытом, а бытовой пользователь пиратской версии Windows вовсе живет с отключенной службой безопасности.

Вы должны убедиться, что служба Защитника на вашем устройстве включена. Для этого перейдите в Панель управления и выберите соответствующий пункт меню.

Для включения и отключения Брандмауэра используйте пункт меню слева, который выделен на скриншоте красной рамкой. Если какие-то приложения после включения Защитника не будут работать корректно, помните, что в интернете много материала о грамотной настройке Брандмауэра. Включение службы безопасности необходимо, так как она предотвратит большинство злонамеренных обращений к вашему компьютеру, направленных на взлом операционной системы и кражу информации. Если, конечно, это запрос не от Microsoft.

Если вы пользуетесь общими папками (протокол ActiveDirectory, SMB), нужно позаботиться о доступе к вашим «расшаренным» папкам по паролю, чтобы злоумышленники и хулиганы случайно не получили доступ к вашим файлам, подключившись через Yggdrasil. С возможностями приходит ответственность, дорогой друг!

win: confirm that KB2921916 installer workaround works #1051

Windows Update does not automatically install this update as Win7 is EOL.

The text was updated successfully, but these errors were encountered:

If you do detection, I’d recommend the hacky memmem trick that @crawshaw linked to, looking for «Signature Hash» . I reversed all the binaries and identified that as a very reliable distingusher. In practice I think it’s more reliable than querying the hotfix database on the system, which sometimes lacks the KB entry despite the dll being updated, and the version numbers and times in the dll resource are also not as reliable as they ought to be. So https://git.zx2c4.com/wireguard-windows/tree/installer/customactions.c#n145 is your best bet.

As far as bundling the MSU goes — you can do this from nsis. You probably want to do something like:

wusa.exe /quiet /warnrestart path\to\temporary\nsis\directory\blahblah.msu

See https://ss64.com/nt/wusa.html for other options. There’s no need to do this with MSI, and probably MSI would take the same approach as invoking wusa.exe anyway.

Alternatively, if you do this at runtime in the app instead of at install time from nsis, and you want to auto-fetch, please mirror those files on your own servers.

I think #1051 perhaps eliminated the need for this?

Care to share details? That link is private.

@zx2c4, the core of that change is that at the end of the install (where it’s running with elevated privileges), it calls:

The change was primarily about eliminating the race between the driver install from the service and the GUI waiting to connect to the service.

By doing it at install time, by the time the server + GUI start later, the driver’s already been installed and the service starts up much more quickly.

But I’m not sure how that helps this issue? Isn’t KB2921916 really just some hacky fix (that Microsoft later abandoned as not a good idea?) that disables some verification? The fact that Microsoft never included KB2921916 in subsequent roll-up patch releases seems like a red flag. Or is @apenwarr saying that after the UAC elevation, the driver install works without KB2921916 somehow?

That’s not going to be robust when the driver gets removed from the store and readded by other things later.

KB2921916 isn’t hacky at all. It changes the code from:

The old code failed when sha2 was used, because 20 bytes is too small. The new code is the proper fix. The patch isn’t hacky at all and works extremely well. I reverse engineered every byte of the change of the binary and I can’t find any bugs with the new code or any idea why it’d be a problem.

KB2921916 is gone from Microsoft’s site because they pulled all the KBs when they sunsetted Windows 7.

KB2921916 isn’t hacky at all. It changes the code from:

Ah, thanks for the explanation!

KB2921916 is gone from Microsoft’s site because they pulled all the KBs when they sunsetted Windows 7.

That’s not going to be robust when the driver gets removed from the store and readded by other things later.

We still do the pool.CreateAdapter on service start-up regardless (so if it disappears, it’ll still come back). Doing it in the installer additionally just makes the service start-up’s call to pool.CreateAdapter much faster.

Empirically it makes the Windows 7 install experience much better.

We still do the pool.CreateAdapter on service start-up regardless (so if it disappears, it’ll still come back). Doing it in the installer additionally just makes the service start-up’s call to pool.CreateAdapter much faster.

Except if the driver gets removed, pool.CreateAdapter will reinstall it, and then you’ll run into the sha2 issue again and installation will fail.

Sorry, I still don’t understand how the func InstallWintunDriver code I pasted above has anything to do with KB2921916.

It’s possible you and @apenwarr are having a separate conversation over my head.

Alright, here’s what’s up:

On Windows 10, the driver is signed by Microsoft, and the certificate is already included in Windows, so everything works well and there’s nothing to do.

On Windows 7 and Windows 8, the driver is signed with an authenticode certificate. In order to install a driver with an authenticode signature, one must first add the certificate to the system certificate store. After that, installing a driver into the driver store works well, and silently without any popups or UI required.

Except on Windows 7, due to that 20-byte sha1-hardcoding bug I mentioned above, it can’t actually deal with the sha2 signature. So it falls back to assuming that the driver is signed with an unknown certificate, and prompts the user, «hey are you sure you want to install this?» And, since Windows services don’t have UI access, this translates into a failure.

Calling that function in the installer appears to work because it moves that UI prompt to install time, rather than service time. But if the driver is ever removed, then pool.CreateAdapter being called by the service will install it again, in which case, the service won’t have UI access and the operation will fail.

The correct solution is to install that KB, which fixes the root cause of the issue and allows the installation of the certificate into the trusted certificate store to work as intended.

Похожие статьи