Re: X.509 certificate generation

From: Jonathan (jonsteph@nospam.carolina.rr.com)
Date: 04/17/03


From: Jonathan <jonsteph@nospam.carolina.rr.com>
Date: Thu, 17 Apr 2003 03:26:03 GMT


For information on how private keys are stored in Windows 2000, review
the Windows 2000 Resource Kit. The info is available online at the
link below:

http://www.microsoft.com/technet/prodtechnol/windows2000serv/reskit/distsys/part2/dsgch15.asp

Scroll about half way down to the topic "How Certificates Are Stored".
This is followed by a discussion of "How Private Keys Are Stored".

Good cert primer:

http://java.sun.com/j2se/1.3/docs/guide/security/cert3.html#inside

Much more detailed info in this doc. Specifically, you'll be
interested in section 2.3.

http://www.cio-dpi.gc.ca/pki-icp/guidedocs/gocpki_cert_e.pdf

Query GOOGLE for more info:

x.509 AND extensions

 -- Jonathan

On 16 Apr 2003 06:20:52 -0700, sriparvathy@hotmail.com (Parvathy)
wrote:

>HI,
> I have generated X.509 certificates.
>1> I want to know where will the public/private keys be stored and
>whether they are accessible?
>
>2> Can anyone provide a document to explain about the different fields
>present in the certificate?
>
>Thanx in advance
>Parvathy



Relevant Pages

  • Re: Unable to Install Secure Certificate with use for NAFN.gov website
    ... Certificates and their associated private keys are not available when a user ... who has a roaming user profile uses a Windows 2000-based computer to log on ... SP1 under windows 2000, as a user on an AD domain. ...
    (microsoft.public.windows.inetexplorer.ie6.browser)
  • Re: Locked out; forgot my administrative password
    ... EFS, Credentials, and Private Keys from Certificates Are Unavailable After a Password Is ... Reset ... How to Log On to Windows XP If You Forget Your Password or Your Password Expires ...
    (microsoft.public.windowsxp.newusers)
  • [NT] Windows File Protection Arbitrary Certificate Chain Vulnerability
    ... Beyond Security would like to welcome Tiscali World Online ... Windows File Protection will trust any digital signature whose certificate ... chain is rooted at any one of the Trusted Root Certification Authorities. ... chains but also as valid Root CA's for code signing certificates. ...
    (Securiteam)
  • Re: How to fix broken security in Windows 2000?
    ... explicitly identify the missing certificates using SFC or some other tool. ... it turns out Windows 2000 doesn't support that feature after ... all W2K machines have the problem seems to be holding up (and I have not yet ...
    (microsoft.public.win2000.windows_update)
  • Re: How to fix broken security in Windows 2000?
    ... explicitly identify the missing certificates using SFC or some other tool. ... it turns out Windows 2000 doesn't support that feature after ... all W2K machines have the problem seems to be holding up (and I have not yet ...
    (microsoft.public.windowsupdate)