Windows 2003 CA bug?

From: Scott Shorter (shorter_at_rocketmail.com)
Date: 09/04/03


Date: 4 Sep 2003 10:27:45 -0700


I'm encountering a problem attempting to import a key pair to use as
my standalone subordinate CA key. The following steps describe the
sequence I follow and the problem I encounter:

1. Add/Remove Programs -> Add/Remove Windows Components

2. Click "Certificate Services" checkbox, and click "Yes" to the
warning box.

3. Click Next

4. Select "Stand-alone subordinate CA" and "Use custom settings to
generate the key pair and certificate"

5. Click Next

6. Click Import...

7. Select a PKCS12 file or a PFX file containing an RSA private key
and certificate. Enter the appropriate password to unlock the private
key.

8. (If you've done this step before, click Yes to the question about
overwriting the key and certificate)

9. Click Next.

10. Look at the Subject DN from the certificate you imported in step
7.

11. Click Next.

12. Error dialog box comes up, saying "The key 'keyname' is either
corrupted or cannot be used for signing. Select another key. Keyset
does not exist 0x80090016 (-2146893082)"

This error occurs whether I use an OpenSSL generated PKCS#12 file or a
Windows created PFX file.

Am I doing something wrong, or is there a bug in the import function?

--
Scott Shorter
Orion Security Solutions
sshorter (at) orionsec (dot) com


Relevant Pages

  • Re: Auto certificate and key generation to pfx
    ... No, certificate server does not return a PFX file, you would have to export ... the key pair and certificate after it had been generated and issued. ... Best Practices for implementing Windows Server 2003 PKI: ...
    (microsoft.public.platformsdk.security)
  • Re: Incorrect key when certificate imported
    ... I am importing the certificate + key from a pfx file. ... >> I have created a certificate with an RSA key pair using the Microsoft ...
    (microsoft.public.win2000.security)
  • Re: Odd certificate issue with Companyweb
    ... Based on my research, CEICW does not support .pfx file, so let's manually ... In the Certificate snap-in window, ... Microsoft CSS Online Newsgroup Support ...
    (microsoft.public.windows.server.sbs)
  • Re: EFS experiment - need help
    ... They are the same cert. ... You should never import the PFX file unless you want to do ... You do not import the cer file to create the recovery policy. ... > Rclick, Open Encryption File System certificate, thumbprint is 3a 2b.. ...
    (microsoft.public.windowsxp.security_admin)
  • RE: AT_SIGNATURE and AT_KEYEXCHANGE
    ... The certificate EXTENSIONwill tell what the key is valid for. ... private key is valid ONLY for signature than it will be set as AT_SIGNATURE. ... key pair and one cert. ...
    (microsoft.public.platformsdk.security)