using the key recovery tool on a Microsoft Windows 2003 Enterprise Edition CA

From: anth0 (totoy81_at_caramail.com)
Date: 11/26/03


Date: 26 Nov 2003 05:36:37 -0800

Hi all,

I have configured a kra user who enrolled for a KRA certificate.
Then a user enrolled for a user2 certificate. User2 is a template i
defined with adding private key archival.

In the CA properties (Recovery Agents Tab), i have activated key
recovering, and defined the key recovery agent i've talken about on
the top of the message.

When using krt (the key recovery tool from the win 2003 ressource
kit), i manage to find the user certificate which has its private key
archived. I have well configured the KRA agent, because hitting 'show
KRA' shows me the right serial number from the certificate of the user
who enrolled the KRA certificate.

But when i click on "Recover", after seeing the popup to save the pfx
file, and after having enter a password,i had the following error
message :

"Failed to decrypt the private key blob. Certutil response was :
0x8009200c-Cannot find the certificate and private key to use for
decryption"

It seems that the krt tool did not find the KRA certificate..but i
think that is not that, as the show KRA works well.

Any ideas ? solutions ?



Relevant Pages

  • Re: parsing PKCS#7 returnedy by ICertAdmin2::GetArchivedKey in .NET
    ... private key is in the underlying data that was signed, ... MS documentation says key archival blob should have ... > in the recovery blob. ... > the user certificate being recovered, the chain of the signing CA ...
    (microsoft.public.dotnet.security)
  • Re: EFS
    ... You can use the commandline tool cipher.exe. ... new recovery cert and private key. ... > EFS with Certificate Snap-In opend by Administrator ...
    (microsoft.public.windowsxp.security_admin)
  • Re: How can I share encripted files between two user accounts?
    ... If it's dual-boot, the easiest way to ... make this work is to make both users the recovery agents on their machines, ... using the same certificate and private key. ...
    (microsoft.public.windows.server.security)
  • Re: Encrypted folder or files
    ... you cannot add a recovery agent after the files were ... You need the original private key and certificate for the user ... Best Practices for implementing Windows Server 2003 PKI: ...
    (microsoft.public.platformsdk.security)
  • Re: EFS On Drive Works With >1 Computer?
    ... "An alternate procedure would involve physically transporting the recovery ... agent's private key and certificate, ... certificate, decrypting the file or folder, and then deleting the imported ...
    (microsoft.public.windowsxp.security_admin)