Re: MakeCert question

From: Chris Gilbert (Chris.Gilbert@Consignia.com)
Date: 07/04/02


From: "Chris Gilbert" <Chris.Gilbert@Consignia.com>
Date: Thu, 4 Jul 2002 09:59:37 +0100


Eric wrote

> Is there a way, when using MakeCert to create a test certificate, to make
> this certificate exportable with its private key as a PKCS #12 file?
> When I register my certificate and try to export it the PKCS #12 option is
> greyed out...

You will have to create a certificate that includes the OID for
AllowCAPIExport
in the ExtendedKeyUsage field. Without this OID you will not be able to
export
the private key.

Chris



Relevant Pages

  • RE: SIMple SSL question ??
    ... I believe your book is instructing you to keep the private key secure. ... you use the certificate request wizard in IIS to install the cert after it's ... the certificate that's just been installed. ... If an attacker retrievs the SSL certificate, ...
    (microsoft.public.dotnet.security)
  • RE: SIMple SSL question ??
    ... I believe your book is instructing you to keep the private key secure. ... you use the certificate request wizard in IIS to install the cert after it's ... the certificate that's just been installed. ... If an attacker retrievs the SSL certificate, ...
    (microsoft.public.dotnet.security)
  • Generate/Export PKCS #12 certificate from Win2k3 CA
    ... I am using a 3rd party VPN client which requires a PKCS #12 certificate ... certificate on our Win2k3 CA using the User Certificate Template, ... 'Mark keys as exportable' and enabled strong private key protection. ... The format required for the VPN client (from what I've been ...
    (microsoft.public.windows.server.general)
  • Generate/Export PKCS #12 certificate from Win2k3 CA
    ... I am using a 3rd party VPN client which requires a PKCS #12 certificate ... certificate on our Win2k3 CA using the User Certificate Template, ... 'Mark keys as exportable' and enabled strong private key protection. ... The format required for the VPN client (from what I've been ...
    (microsoft.public.windows.server.security)
  • Re: Certificates, Keys, Mobile Users, Intended Usage
    ... Option that you think about uses self signed EFS certificates. ... Better then exporting user's private key as backup is to setup DRA (Data ... there is no EFS certificate and it will generate a new one. ... Mobile computer users benefit from encrypting sensitive ...
    (microsoft.public.win2000.security)