Removing certificates on MS Windows.



Hi,
This applies for all MS Windows versions.

If you have a certificate installed on HD (i.e. using the MS Enhaced
CSP), then, following Microsoft, you can remove it using IExplorer, on
the 'Tools' menu, you click 'Internet Options', then you click the
'Content' tab, and then click Remove. This is a well known action
described in
http://www.microsoft.com/technet/prodtechnol/ie/reskit/6/part2/c06ie6rk.mspx?mfr=true

Doing this, you effectively remove the certificate, but THE PRIVATE KEY
REMAINS IN THE HD.
You can find a lot of scenarios where this can be a problem. Suppose you
go to a friend's home, you install a pkcs12 file containing your
certificate and private key with "Medium" security level (the default),
then you use it, and when you finishes your work, you remove the
certificate (but NO the private key). Then your friend takes your
certificate (is a public document) and installs it, having your private
key working for him.

The program cleancapi deletes the private keys that are not used by any
certificate.
Source code: http://dwnl.nisu.org/dwnl?fic=cleancapi_0_2_src.zip
Precompiled version: http://dwnl.nisu.org/dwnl?fic=cleancapi_0_2_bin.zip
.



Relevant Pages

  • Re: RPC over HTTP scenario
    ... there is no such way to make the certificate installation happen ... Only the domain computer can be trusted by SBS and install ... thank you for using Microsoft newsgroup. ...
    (microsoft.public.windows.server.sbs)
  • Re: Suppressing security dialogs when app opens
    ... "Adding the above two keys to the install makes the runtime install ... I'm not comfortable altering the security mechanism of a machine without the user's knowledge ... ... Because a digital certificate you create yourself isn't issued by a formal certification authority, ... Microsoft Office will only trust a self-signed certificate on a computer that has the private key for that certificate ...
    (comp.databases.ms-access)
  • Re: Error: 0x80090016
    ... I have asked the user to look for the machinekeys folder but she can only ... Will the certificate want to install to a profile ... > Microsoft Online Partner Support ...
    (microsoft.public.windowsxp.general)
  • Re: Windows Update repeats
    ... You cannot install some updates or programs ... to a Windows component, install a service pack for Windows or for a Windows ... The Microsoft digital signature affirms that software has been tested with ... Publishers certificate store. ...
    (microsoft.public.windowsupdate)
  • RE: updates after format
    ... if the Microsoft Server is down. ... software you are installing has not passed Windows Logo testing verify its ... When you try to download an ActiveX control, install an update to Windows ... and you do not have the appropriate certificate in your Trusted Publishers ...
    (microsoft.public.windows.mediacenter)