CA's Key on Smart Card Problem

From: Denis Holtkamp (anonymous_at_discussions.microsoft.com)
Date: 01/13/05


Date: Thu, 13 Jan 2005 06:51:57 -0800

Hi.
To improve the security of an offline root CA I want to
store the CA's private Key on a Smart Card. During the
installation process of the certificate services I
selected a Smart Card CSP (Gemplus) and activated the
checkbox "Allow this CSP to interact with the desktop".
When the setup process generates the cryptografic key I
have to enter the PIN of the Smart Card and then I got an
error message box "An error occurred when setting the
security access on the private key "Name of the CA", or
the CSP selected does not support setting security access
on private keys. Please make sure the CSP is installed
correctly or select another CSP. Not implemented
0x80004001 (-2147467263)". After this the installation of
the certificate services fails. I've already tried tested
this with different Smart Cards and different Computers,
but always got the same error.
Can anyone help me with the error, or has anyone already
installed the CA's Key on a Smart Card, which Smart Card
and CSP shoud I use?

Thanks in advance,

Denis



Relevant Pages

  • Re: CAs Key on Smart Card Problem
    ... As far as I know Microsoft is using HSMs for storing the root CA keys. ... advanced CSP may indeed be required. ... >> store the CA's private Key on a Smart Card. ...
    (microsoft.public.windows.server.security)
  • CryptImportKey fails
    ... I'm developing my own Smart Card CSP. ... my CSP is loading adn importing my private key ... CryptImportKey function fails with NTE_BAD_VERSION error. ...
    (microsoft.public.platformsdk.security)
  • Re: CAs Key on Smart Card Problem
    ... > store the CA's private Key on a Smart Card. ... > installation process of the certificate services I ... > the CSP selected does not support setting security access ... > the certificate services fails. ...
    (microsoft.public.windows.server.security)
  • Re: CAs Key on Smart Card Problem
    ... so it is no problem that the smart card ... integrated) GemPlus csp with the 8k GemPlus card. ... >- needing to access the CA's private key ...
    (microsoft.public.windows.server.security)
  • Re: windows programming cryptography(problem in implementing a Sma
    ... Normally your smart card should have on-board key pair generation, ... First,I should include it’s header file in CSP code as below: ... HCRYPTPROV and remember that it refers to your CSP and to the ...
    (microsoft.public.platformsdk.security)