Re: CertEnumCertificatesInStore() and IE

From: Sergio Dutra [MS] (sergiod_at_online.microsoft.com)
Date: 12/11/03


Date: Thu, 11 Dec 2003 09:52:12 -0800

The private key is NOT issued by a CA and it's NOT re-generated simply
because a fresher certificate is generated. In the case of roll-over, a
fresher certificate will be generated and associated with the existing
private key, and typically the older certificate has the archive bit set on
it.

-- 
This posting is provided "AS IS" with no warranties, and confers no rights.
Use of included script samples are subject to the terms specified at
http://www.microsoft.com/info/cpyright.htm
"Oliver Young" <none> wrote in message 
news:%2362iBrmvDHA.3496@TK2MSFTNGP11.phx.gbl...
>
>> Persons may wish to delete certificates without deleting the 
>> corresponding
>> private key.
> Nonsense.
>
>> Especially in corporate environments certificates can be
>> "rolled over", meaning a new certificate is issued which corresponds to
> the
>> same private key as the old one but with name and/or validity periods
>> updated.
> New "refreshed" certificate could be issued with (old) private key. There 
> is
> no need to leave private key when certificate was removed.
>
> 


Relevant Pages

  • RE: SIMple SSL question ??
    ... I believe your book is instructing you to keep the private key secure. ... you use the certificate request wizard in IIS to install the cert after it's ... the certificate that's just been installed. ... If an attacker retrievs the SSL certificate, ...
    (microsoft.public.dotnet.security)
  • RE: SIMple SSL question ??
    ... I believe your book is instructing you to keep the private key secure. ... you use the certificate request wizard in IIS to install the cert after it's ... the certificate that's just been installed. ... If an attacker retrievs the SSL certificate, ...
    (microsoft.public.dotnet.security)
  • Re: Certificates, Keys, Mobile Users, Intended Usage
    ... Option that you think about uses self signed EFS certificates. ... Better then exporting user's private key as backup is to setup DRA (Data ... there is no EFS certificate and it will generate a new one. ... Mobile computer users benefit from encrypting sensitive ...
    (microsoft.public.win2000.security)
  • Re: PFXExportCertStoreEx
    ... which contains the actual PFX and write that to the disk. ... methods to export certificate + private key from the IE store. ...
    (microsoft.public.platformsdk.security)
  • Re: EFS On Drive Works With >1 Computer?
    ... >I just went to Help and Support Center to see if it says anything. ... > agent's private key and certificate, ... > certificate, decrypting the file or folder, and then deleting the imported ... Try to decrypt it on a computer that is not and has ...
    (microsoft.public.windowsxp.security_admin)

Quantcast