Re: Does deleting a certificate cause private key deletion?

From: Ohaya (ohaya_at_NO_SPAM.cox.net)
Date: 10/29/03


Date: Tue, 28 Oct 2003 18:27:14 -0500

Michel,

It says: Version: 1.4.2, JVM Version: Sun Microsystems Inc.

Machine is Win2K SP4, IE 6.0.

Jim

Michel Gallant wrote:
>
> What OS and what version of IE are you using?
> That method uses a scripted method into a signed Java applet, and
> requires you have the Microsoft JVM.
> Do detect which JVM your browser is currently using, what does
> this page indicate:
> http://pages.istar.ca/~neutron/detectjvm
>
> Thanks,
> - Mitch
>
> "Ohaya" <ohaya@NO_SPAM.cox.net> wrote in message news:3F9EE8B1.6C7F6A48@NO_SPAM.cox.net...
> > Michel,
> >
> > BTW, when I use IE to go to the linke for your KeyContainerTool, I am
> > getting an error:
> >
> > Line 85: Object doesn't support this property or method:
> > 'document.aplets(...).getAllCUContainers'
> >
> > Any idea why, and how to fix this?
> >
> > Thanks!
> >
> >
> >
> >
> > Michel Gallant wrote:
> > >
> > > The Certificates panels "Export" dialog has a checkbox:
> > > "Delete the private key if the export is successful"
> > > which is *unchecked* by default (so private key container persists).
> > >
> > > If you didn't check that box, you can use this web tool (requires CAPICOM)
> > > to remove the unwanted key container (listed at bottom of page):
> > > http://pages.istar.ca/~neutron/KeyContainerTool
> > > The way this utility works is that any keycontainers (which contain protected
> > > asymmetric keypairs) NOT currently associated with a certificate are listed
> > > at end of display. So, if you look at the display, then delete a cert *without* deleting
> > > the private key, and look at the display again, you will see a new keycontainer listed
> > > at the bottom. That is the one you want to delete using the supplied text-field.
> > >
> > > - Michel Gallant
> > > Visual Security MVP
> > >
> > > "David Cross [MS]" <dcross@online.microsoft.com> wrote in message
> > > news:uwTe%23F%23mDHA.2200@TK2MSFTNGP12.phx.gbl...
> > > > No, deleting the cert does not delete the provate key. to delete the
> > > > provate key, you have to export the key and delete or manually delete the
> > > > actual key file from the file system.
> > > >
> > > > --
> > > >
> > > >
> > > > David B. Cross [MS]
> > > >
> > > > --
> > > > This posting is provided "AS IS" with no warranties, and confers no rights.
> > > >
> > > > http://support.microsoft.com
> > > >
> > > > "Ohaya" <ohaya@cox.net.NO_SPAM> wrote in message
> > > > news:3F998E55.93875B77@cox.net.NO_SPAM...
> > > > > Hi,
> > > > >
> > > > > I'm cross-posting this because I am not sure which group this belongs
> > > > > in. My apologies.
> > > > >
> > > > > This is a relatively quick question:
> > > > >
> > > > > If I have a certificate installed on a system (Local Computer, Personal)
> > > > > where there's initially a corresponding private key on the machine, and
> > > > > I delete the certificate using the MMC-Certificates snap-in, does the
> > > > > private key also get deleted from the machine?
> > > > >
> > > > >
> > > > > More detail:
> > > > >
> > > > > 1) I used IIS to request a server certificate
> > > > > 2) When I got the certificate (as a .CER file), I used IIS Server
> > > > > Certificate wizard to install the certificate from the .CER file.
> > > > > 3) If I use MMC Certificates snap-in to look at the certificate it shows
> > > > > "You have the private key".
> > > > > 4) Using MMC Certificates snap-in, I delete the server certificate.
> > > > > 5) Then, using MMC Certificate snap-in, I import the original .CER file
> > > > > into Local Computer, Personal store again.
> > > > >
> > > > > Now, if I use MMC Certificate snap-in to look at the certificate in
> > > > > Local Computer, Personal, the area where it said "You have the private
> > > > > key" is BLANK (i.e., it thinks that the private key is not there).
> > > > >
> > > > >
> > > > > The reason that I'm asking this is that I was doing some testing of
> > > > > something else, and all of a sudden, the private key was missing. I
> > > > > don't know exactly what I was doing (you know how it is when you're
> > > > > testing), but I found that the above steps seem to reproduce the
> > > > > condition of making the private key disappear.
> > > > >
> > > > > I'm trying to understand this so that I can avoid this in the future, so
> > > > > I hope that someone out there knows????
> > > > >
> > > > >
> > > > > Thanks in advance!!
> > > > >
> > > > > Jim
> > > >
> > > >



Relevant Pages


Loading