Veeam ONE 13.1 Upgrade or Installation Fails with: Signature verification failed after retries for 'Newtonsoft.Json.dll'

KB ID: 4915
Product: Veeam ONE | 13
Published: 2026-10-01
Last Modified: 2026-10-01
mailbox
Get weekly article updates
By subscribing, you are agreeing to have your personal information managed in accordance with the terms of Veeam's Privacy Notice.

Cheers for trusting us with the spot in your mailbox!

Now you’re less likely to miss what’s been brewing in our knowledge base with this weekly digest

error icon

Oops! Something went wrong.

Please, try again later.

Challenge

When attempting to upgrade or install Veeam ONE 13, the System Configuration Check stage of the setup wizard fails, and the following error is displayed:

<TBD>Signature verification failed after retries for 'C:\ProgramData\Veeam\Setup\Temp\c2fbbc7c-acd7-4e33-b1fa-915c0eca920b\bf9e5076-a5c1-4b3e-8e36-9bcfbf3178f0\Newtonsoft.Json.dll'.
Setup error example with error message in pop-up dialog box with an OK button and the System Configuration Check in the background.
Note: The two folder names in the path are generated for each setup run and will differ.

Cause

This issue occurs because the Veeam ONE setup wizard verifies the digital signature of each file that it stages before installing it, and the Windows Trusted Root Certification Authorities store on the server does not contain the root certificate that the file's signing chain terminates in. The signature check returns 0x800B0109 (CERT_E_UNTRUSTEDROOT), and setup stops.

The Trusted Root Certification Authorities store is kept current by the Microsoft automatic update mechanism, which downloads certificate trust lists from ctldl.windowsupdate.com over TCP port 80. On a server that has no internet access, or where a proxy configuration or firewall rule blocks that address, the store is not updated and the required root certificate is never added.

Confirming the Cause in the Setup Logs

The signature check and its diagnostics are recorded in ReporterServerSetup.log. An entry similar to the following is logged for each verification attempt, and the diagnostics block that follows it reports a missing authroot.stl file when the root certificate trust list has never been downloaded:

***Veeam***  VerifyAll: attempt 5 failed for '...\Newtonsoft.Json.dll' hr=0x800B0109
***Veeam***  --- signature-check diagnostics ---
  authroot.stl.path   = C:\Windows\system32\authroot.stl <GetFileAttributesExW failed, GLE=2>
--- end diagnostics ---

Solution

The root certificate list published through the Microsoft Trusted Root Program is identical across all Windows machines, so the certificate bundle can be generated on any trusted machine with internet access.

Note: If the Veeam ONE server itself has internet access, both commands below can be run on that server, and steps 4 through 6 can be skipped.

  1. Take a snapshot or checkpoint of the Veeam ONE server before making any changes.
  2. On a machine that has internet access, open Command Prompt as Administrator.
  3. Run the following command to download the current Microsoft root certificate bundle:
certutil -generateSSTFromWU roots.sst

Note: The roots.sst file is created in the folder that the Command Prompt session is currently in. Note that path for the next step.

  1. Copy roots.sst to the Veeam ONE server.
  2. On the Veeam ONE server, open Command Prompt as Administrator.
  3. Change to the folder that contains roots.sst.
  4. Run the following command to import the certificates into the Trusted Root Certification Authorities store:
certutil -addstore -f Root roots.sst

Note: If the command fails with WIN32: 2 ERROR_FILE_NOT_FOUND, the Command Prompt session is not running in the folder that contains roots.sst. Change to that folder, or pass the full path to the file.

  1. If the failed upgrade left Veeam ONE components that cannot be removed through Control Panel, mount the ISO for the Veeam ONE version that was installed before the upgrade.
  2. Run the following installers from the mounted ISO to remove the leftover components, where D: is the drive letter that the ISO is mounted to:
    • D:\Reporter\VeeamONE.Reporter.Server.x64.msi
    • D:\Reporter\VeeamONE.Reporter.WebUI.x64.msi
  3. Retry the Veeam ONE upgrade or installation.

More Information

Preventing the Issue on Future Upgrades

Windows maintains the Trusted Root Certification Authorities store through the Microsoft automatic update mechanism. To allow the Veeam ONE server to keep the store current on its own, permit outbound access to ctldl.windowsupdate.com over TCP port 80, along with DNS name resolution.

For environments where outbound internet access is not permitted, Microsoft documents a method for redirecting the automatic update mechanism to an internal file or web server that is kept synchronized with Windows Update.

Microsoft References

If this KB article did not resolve your issue or you need further assistance with Veeam software, please create a Veeam Support Case.

To submit feedback regarding this article, please click this link: Send Article Feedback
To report a typo on this page, highlight the typo with your mouse and press CTRL + Enter.

Spelling error in text

Thank you!

Thank you!

Your feedback has been received and will be reviewed.

Oops! Something went wrong.

Please, try again later.

You have selected too large block!

Please try select less.

KB Feedback/Suggestion

This form is only for KB Feedback/Suggestions, if you need help with the software open a support case

By submitting, you are agreeing to have your personal information managed in accordance with the terms of Veeam's Privacy Notice.
Verify your email to continue your product download
We've sent a verification code to:
  • Incorrect verification code. Please try again.
An email with a verification code was just sent to
Didn't receive the code? Click to resend in sec
Didn't receive the code? Click to resend
Thank you!

Thank you!

Your feedback has been received and will be reviewed.

error icon

Oops! Something went wrong.

Please, try again later.