Update Root Certificates: Open Command Prompt as Administrator
👇 See all 3 solutions below
What is Error 4424?
Windows System Error Code 4424, known as ERROR_SECUREBOOT_POLICY_NOT_SIGNED, is a DNS & WINS error that occurs during DNS resolution and WINS name resolution. The error indicates that: The Secure Boot policy is either not signed or is signed by a non-trusted signer. When this error is encountered, the Windows operating system was unable to complete the requested operation within the DNS/WINS services subsystem. The error code 4424 is returned by the GetLastError() function and provides developers with a specific identifier to diagnose the root cause of the failure. The symbolic name ERROR_SECUREBOOT_POLICY_NOT_SIGNED maps directly to this numeric code and is commonly referenced in Microsoft documentation, developer forums, and system logs. Understanding this error and its context within DNS resolution and WINS name resolution is essential for effective troubleshooting.
Common Causes
- System date/time is incorrect, causing certificate validation to fail
- Root certification authorities are outdated or missing
- TLS protocol mismatch between client and server
- Antivirus or proxy is intercepting SSL traffic with an untrusted certificate
Resolving Component Store (WinSxS) Bloat and Corruption
An encyclopedia on the Windows Component Store: safely reclaiming disk space, understanding hard links, and fixing deep WinSxS corruption.
Read the full guide →Step-by-Step Solutions
- Open Command Prompt as Administrator
- Run: certutil -generateSSTFromWU roots.sst
- This downloads the latest root certificates from Microsoft
- Open certmgr.msc → Trusted Root Certification Authorities → import roots.sst
- Restart your browser and applications
Video Tutorials
Diagnostic Command
Run this PowerShell command to find related events in your system log:
Get-EventLog -LogName System -Newest 20 | Where-Object {$_.Message -like "*4424*" -or $_.Message -like "*ERROR_SECUREBOOT_POLICY_NOT_SIGNED*"} | Format-List
💡 Open PowerShell as Administrator, paste the command above, and press Enter.
Prevention Tips
- Keep your system clock synchronized (Settings → Time & Language → Sync now)
- Install Windows Updates regularly to keep root certificates current
- Disable SSL inspection in antivirus software if it causes certificate errors