Re: Can a Windows service find a certificate ?

From: Alun Jones [MS MVP] (alun_at_texis.com)
Date: 09/26/03


Date: Fri, 26 Sep 2003 19:24:58 GMT


In article <O#NiH$3gDHA.3204@TK2MSFTNGP11.phx.gbl>, "Sergio Dutra [MS]" <sergiod@online.microsoft.com> wrote:
>Other than that, you can simply import the certificate and private key (if
>in a PFX format) into the local machine "MY" store, which will make the
>certificate available to any account - even those running as a service - but
>the corresponding private key will be accessible only by the account that
>generated it.

What is the point of importing the certificate and private key from a PFX
file into the local machine store, if the private key is not then accessible
to anyone authorised to get to the local machine store?

Alun.
~~~~

[Please don't email posters, if a Usenet response is appropriate.]

-- 
Texas Imperial Software   | Find us at http://www.wftpd.com or email
1602 Harvest Moon Place   | alun@texis.com.
Cedar Park TX 78613-1419  | WFTPD, WFTPD Pro are Windows FTP servers.
Fax/Voice +1(512)258-9858 | Try our NEW client software, WFTPD Explorer.


Relevant Pages

  • RE: SIMple SSL question ??
    ... I believe your book is instructing you to keep the private key secure. ... you use the certificate request wizard in IIS to install the cert after it's ... the certificate that's just been installed. ... If an attacker retrievs the SSL certificate, ...
    (microsoft.public.dotnet.security)
  • RE: SIMple SSL question ??
    ... I believe your book is instructing you to keep the private key secure. ... you use the certificate request wizard in IIS to install the cert after it's ... the certificate that's just been installed. ... If an attacker retrievs the SSL certificate, ...
    (microsoft.public.dotnet.security)
  • Re: Certificates, Keys, Mobile Users, Intended Usage
    ... Option that you think about uses self signed EFS certificates. ... Better then exporting user's private key as backup is to setup DRA (Data ... there is no EFS certificate and it will generate a new one. ... Mobile computer users benefit from encrypting sensitive ...
    (microsoft.public.win2000.security)
  • Re: CertSetContextProperty/CERT_KEY_PROV_INFO_PROP_ID
    ... > my Private key Blobin the Certificate ... [Please don't email posters, if a Usenet response is appropriate.] ... Texas Imperial Software | Find us at http://www.wftpd.com or email ... Washington WA 98072-8661 | WFTPD, WFTPD Pro are Windows FTP servers. ...
    (microsoft.public.platformsdk.security)
  • Re: PFXExportCertStoreEx
    ... which contains the actual PFX and write that to the disk. ... methods to export certificate + private key from the IE store. ...
    (microsoft.public.platformsdk.security)