Fix it now
This message covers two quite different situations. Either the licence behind the installation has lapsed, or the licence is fine and something between the machine and the update server is in the way. The expiry date in the client settles it in seconds, and 12175 tells you it is the second one.
w32tm /resync
w32tm /query /status
- Open the G DATA client and read the expiry date on its licence page. If it is in the past, stop here: the fix is a renewal, not a network change.
- Restart Windows properly rather than using fast startup, then run the client as administrator and choose the update option. G DATA lists both as first steps for a client that cannot reach the update server.
- Check the proxy in two places: in the client under Settings, Updates, Internet settings, and in Windows under Internet Options, Connections, LAN settings. Remove a proxy that this network does not need.
- If you see 12175, open
certmgr.mscand confirm the DigiCert Global Root CA certificate is present under Trusted Root Certification Authorities. That is G DATA’s own documented cause for a broken secure connection. - Run an update manually and read the result rather than assuming the previous error still applies.
Do not respond to a certificate error by disabling certificate validation anywhere. It trades a broken update channel for a worse problem, and it does not fix the missing root certificate.
If the signature date moves to today, you are done. If it does not, the next section separates the licence question from the network one and shows which of the four causes you have.
Why it happens
A security client that cannot update is in the most misleading state a security product reaches. It still loads, still scans, and still reports itself as running, while the data it scans with stops moving. Nothing on screen changes on the day it stops, which is why this is usually discovered weeks late.
Two of the numbers that travel with this message do have published meanings, and both come from Microsoft rather than from G DATA. 12175 is ERROR_WINHTTP_SECURE_FAILURE, and its published meaning is narrower than it is usually given: one or more errors were found in the SSL certificate sent by the server. That is a certificate fault specifically, not a general connection failure, which is why the fix begins with the machine’s trusted roots and its clock rather than with the firewall.
That reading lines up with what G DATA itself documents. Its published causes for a client that cannot reach the update server are a pending restart, missing administrator rights, general connectivity, a router or firewall blocking the path, conflicting security software or traffic-management tools, a misconfigured proxy, a missing DigiCert Global Root CA certificate, and an incorrect system time. Two of those eight are certificate-shaped, and they are exactly what 12175 reports.
1610 is the third number and belongs to neither category. It is a Windows Installer error, ERROR_BAD_CONFIGURATION, and its published meaning is that the configuration data for the product is corrupt. That is a repair job on the installation. It is not a licence problem and it is not a network problem, so if you have 1610 the rest of this article is the wrong reading.
The licence term has ended
You have this one if The licence page in the client shows an expiry date in the past, and updates began failing at about that date.
- Confirm the date in the client rather than relying on when you think you bought it.
- Renew the licence, then register the product again so current credentials reach this installation.
- Run an update manually and confirm it completes.
- Check the signature date afterwards, because a client that has been failing for weeks has a lot to catch up on.
The trusted root certificate is missing, or the clock is wrong
You have this one if 12175, or updates that fail on every network including a mobile hotspot.
- Run
w32tm /resyncand confirm the machine’s date, time and time zone are right. - Open
certmgr.msc, expand Trusted Root Certification Authorities and then Certificates, and look for DigiCert Global Root CA. - If it is missing, obtain it and import it into Trusted Root Certification Authorities, which is G DATA’s documented remedy.
- Retry the update and confirm the signature date moves.
A proxy or TLS inspection is breaking the connection
You have this one if Updates succeed on a home connection or mobile hotspot and fail on the office network.
- Prove it by testing on a different network before changing anything.
- Check the proxy in the client under Settings, Updates, Internet settings, and in Windows under Internet Options, Connections, LAN settings.
- Ask whoever runs the gateway to exclude G DATA’s update endpoints from TLS inspection, since a substituted certificate is exactly what 12175 reports.
- Retry and confirm the signature date moves.
The client needs a restart or administrator rights
You have this one if The update option is greyed out or fails immediately, on a machine that was recently updated or is overdue a reboot.
- Restart Windows using the Restart option rather than shutting down, so the restart is a real one.
- Right-click the G DATA icon and choose Run as administrator, confirm the Windows prompt, and choose the update option.
- If it now works, the earlier failure was a rights or pending-restart problem and nothing else needs changing.
G DATA lists both of these before anything to do with the network. They are cheap to try and they resolve a surprising share of cases.
The installation itself is damaged
You have this one if 1610, or a client that is erratic in ways that go beyond updating.
- Repair the product from Settings, Apps using its own repair option where one is offered.
- If repair does not help, uninstall, restart, and reinstall from a freshly downloaded installer run as administrator.
- Register the product again so current credentials are issued.
- Update, then run a full scan to confirm the engine and signatures are both healthy.
Full reference
Deciding which problem you have
| What you find | What it means |
|---|---|
| The licence page shows a date in the past | The term has ended; renewal is the fix |
| Licence current, 12175 reported | A certificate fault: the trusted root, the clock, or an inspecting proxy |
| Licence current, updates work on another network | A gateway on this network is in the way |
| The clock is visibly wrong | Certificate validation fails before any download starts |
| 1610 | The installation’s configuration data is corrupt; repair or reinstall |
| Update option greyed out or refused | Rights, or a restart that has not happened |
What the published numbers actually say
| Code | Symbolic name | Published meaning |
|---|---|---|
| 12175 | ERROR_WINHTTP_SECURE_FAILURE | One or more errors were found in the SSL certificate sent by the server |
| 1610 | ERROR_BAD_CONFIGURATION | The configuration data for this product is corrupt |
Reading 12175 as a generic connection failure is the mistake that costs the most time here, because it sends people to the firewall when the machine is telling them about a certificate. A missing root, an expired root, a clock far enough out that a valid certificate looks invalid, and an appliance substituting its own certificate all produce it. A firewall that simply drops the traffic produces something else.
Consumer clients and managed estates are not the same product
G DATA’s business solutions use access data, a user name and password entered on the ManagementServer, and G DATA documents entering those credentials as a distinct task. That is a real mechanism and a real thing to check on a managed estate. It is not how a consumer installation is set up, so on a home PC the useful checks are the licence date and the connection, not a hunt for stored credentials that were never there.
Where to look on a managed installation
- Check the ManagementServer rather than the client. G DATA documents restarting the G DATA Management Server service where automatic signature updates have stopped.
- Confirm the access data entered on the server is current for the licence you hold.
- Check that the clients are pointed at the server rather than at the internet, and that the server itself can reach G DATA.
- Treat one client failing and every client failing as different investigations; the first is the endpoint, the second is the server or the gateway.
How urgent is it
More urgent than it looks. The client that reports this is still scanning, so nothing on the machine appears wrong, and it is scanning with whatever data it last received. A week behind is a meaningful gap. A month behind is a machine that is protected against what was circulating in the spring. Fix the update path before you spend time on anything else the product is doing.
When a licence is the actual fix
If the expiry date in the client is in the past, the licence is the fix and no amount of network work changes it. The client keeps scanning with whatever signatures it last received, which is the most misleading state a security product can be in: it looks like it is running, and it falls further behind every day. Arco supplies G DATA Total Security and can check which tier matches what you actually use and how many devices the household or office needs covered, so a renewal does not turn out to be one machine short. If you have decided to stop using G DATA, remove it properly and confirm Microsoft Defender reports itself as on in Windows Security, which gives you real-time protection at no cost. What is not worth doing is leaving an unlicensed client in place and assuming it still counts.
Every code this article covers
| Code | What it points at | Source |
|---|---|---|
Virus signatures could not be updated |
The client could not obtain new signature data, either because it was refused or because the connection failed | not published by the vendor |
12175 |
ERROR_WINHTTP_SECURE_FAILURE: one or more errors were found in the SSL certificate sent by the server. A certificate fault specifically | Microsoft Learn |
1610 |
ERROR_BAD_CONFIGURATION: the configuration data for this product is corrupt, so the installer cannot work with it as it stands | Microsoft Learn |
Confirm the fix worked
- The client reports a signature date of today after a manual update.
- The licence page shows an expiry date in the future.
- An update runs on schedule without anyone triggering it by hand.
- Where 12175 was the symptom, DigiCert Global Root CA is present under Trusted Root Certification Authorities and the clock is correct.
- A full scan completes and the client reports itself as fully up to date afterwards.
Questions people ask about this
The product still scans. Am I protected?
Partly, and less every day. It is scanning with the last signatures it received, so anything newer than that date is invisible to it. A scanner with stale data gives you the appearance of protection rather than the substance.
What does 12175 actually mean?
Microsoft publishes it as ERROR_WINHTTP_SECURE_FAILURE: one or more errors were found in the SSL certificate sent by the server. It is a certificate fault, not a general connection failure, which is why the fix starts with the trusted root store and the system clock.
Can I fix this without paying, if my licence has expired?
Not for G DATA itself: current updates need a current licence. You can stop paying entirely and use Microsoft Defender, which is included with Windows and updates at no cost. That is a legitimate choice, just make it deliberately.
Do I need to reinstall after renewing?
Usually not. Renew, then register the product again so it receives current credentials. Reinstall only if the client is also damaged, which is what 1610 would suggest.
Why does it fail only at work?
Because a corporate gateway is inspecting or blocking the connection. An appliance that substitutes its own certificate produces exactly the certificate error 12175 reports. That is a network configuration to fix with whoever runs it, and the same machine will usually update perfectly on another connection.
