Re: Certificates -- Basic Question

From: Thomas Deml [MS] (thomad@online.microsoft.com)
Date: 10/06/02


From: "Thomas Deml [MS]" <thomad@online.microsoft.com>
Date: Sun, 6 Oct 2002 01:42:37 -0700


If you use MS Certificate Services to create a cert request (uses the COM
object XENROLL under the covers) you can mark the private key as
non-exportable (this option is not available if you request certs via the
IIS cert wizard). If a private key is marked as non-exportable you can't
create a backup file.

Hope this helps,

--
Thomas Deml
Lead Program Manager
Internet Information Services
Microsoft Corp.
"Brad Shapiro" <brad.shapiro@ny1.nospam.for.me.news.com> wrote in message
news:jq9vpugto2eoh0no2jnnhvj1jofpgb3mia@4ax.com...
> Is it possible to limit a user to installing a certificate ONCE and it
> can't be installed after that? I want to stop users from copying a
> certificate around/giving it to other colleagues to install. Or is
> there some other way to manage users/certificates and accomplish the
> same thing???


Relevant Pages

  • Re: How to exchange certificate ?
    ... certificate store (I own ONLY a public key). ... >contained in a certificate store AND having an associated private key. ... you can test any cert for an associated private key using: ...
    (microsoft.public.platformsdk.security)
  • Re: A question about CryptAcquireCertificatePrivateKey
    ... Windows stores the CSP and private key associated with the certificate in the ... This is, of course, true only when WINDOWS stores the cert. ...
    (microsoft.public.platformsdk.security)
  • Re: IAS System Rights / IAS + Win2003 SP1
    ... and imported into IIS ADMIN. ... get cert from Verisign ... > these steps dont seem to attach the private key, ... > the private key for the certificate does not exist in the certificate ...
    (microsoft.public.internet.radius)
  • Re: SSL errors
    ... > Following the articles suggestions I bound a certificate ... > to the SMTP installation on this server from a MS CA we ... > private key information property attached to it. ... > the CA installed cert did not have that property page ...
    (microsoft.public.inetserver.iis.security)
  • Re: How does WSE2 search for private key given X509 certificate?
    ... After I deleted the x509 certificate with private key from the cert store, ...
    (microsoft.public.dotnet.framework.webservices.enhancements)