all groups > iis security > august 2004 >
You're in the

iis security

group:

migrating certificates (export the private key not available)


migrating certificates (export the private key not available) etown9799 NO[at]SPAM yahoo.com
8/30/2004 10:08:30 AM
iis security:
We are trying to migrate the SSL Cert to a new server and have run
into a snag. When we start the export wizrd the "export the private
key" option is not available. (Also, the do not delete the key once
exported is not available)

I tried turning off IIS 5.0 to see if that would solve the problem,
but it didn't work.

Has anyone seen this, and can you give me apush in the right
Re: migrating certificates (export the private key not available) Jerry Pisk
8/30/2004 6:25:52 PM
You actually set this yourself when you're importing the certificate. The CA
has no say in this.

To fix Adam's problem - you need to find the private key, you had to import
it to the certificate store from somewhere. If you don't have it you have to
create yourself a new one and request a new certificate. And remember to
back it up, including the private key. Not just in case you want to move the
server to a different box, but for cases your box crashes, when you won't be
able to export anything.

Jerry

[quoted text, click to view]

Re: migrating certificates (export the private key not available) Miha Pihler
8/30/2004 7:17:15 PM
Hi Adam,

This is property of certificate and should be set before it was issued on CA
server ("Mark keys as exportable"). Once certificate is issued this can not
be changed.

Mike

[quoted text, click to view]

Re: migrating certificates (export the private key not available) Miha Pihler
8/31/2004 8:12:27 AM
Jerry,

If certificate was issued in Microsoft CA based on certificate template that
does not allow certificates to be exported you can't later mark them as
exportable.

If some other template or policy or CA was used I agree with your, this can
be set when importing certificate, but can't be changed once certificate is
successfully imported.

Mike

[quoted text, click to view]

AddThis Social Bookmark Button