Re: Getting rid of my Certification Authority



"Brian Komar (MVP)" wrote:

inline...

If decommissions, and you have not maintained the KRA certificate and
private key or the DRA certificate and private key, they are out of luck.
Decommissioning a CA does not decrypt files.

Okay, then is there a way I can test this? For instance, can I stop a CA
service on the server to "simulate" removal of the CA? Something that I can
test and then if somebody screams (unlikely, but you never know), I can just
turn it back on and dig in further to help them get their stuff unencrypted?


They will fail for LDAP/SSL connections. You should remove all of the DC
certs
certutil -dcinfo DELETEALL

Running this on the CA will remove them and I'll be okay?

Thanks for the help,
Mark
.



Relevant Pages

  • Re: making administrator account the DRA in XP Profession
    ... decrypt files as the RA. ... The .cer file contains the certificate and only the ... The .pfx file would contain the private key. ... I wish to be able to access to them from the admin account. ...
    (microsoft.public.windowsxp.security_admin)
  • Re: EFS
    ... and private key in case when system on the first machine ... Export the user's certificate and private key on ... >> It is possible to decrypt files on one w2k system that ...
    (microsoft.public.win2000.file_system)
  • GnuPG <-> RSACryptoServiceProvider key translation
    ... I'm trying to create a .net program that can decrypt files that will ... of my public key, but the private key looks much the same): ...
    (microsoft.public.dotnet.security)
  • Re: CAUTION: Moving EFS certificate from Vista to XP
    ... Does this posting belong to the one "How to decrypt files that i can ... with certificates from another operating system. ... protect their private key. ...
    (microsoft.public.windows.file_system)

Loading