AD CS - user key deleted


i'm messing new pki in test environment.  i logged workstation domain administrator, encrypted file deleted certificate created on workstation in personal certificate store.  i see certificate on ca in "issued certificates" doesn't seem have private key.  how go recovering private key?  perhaps there's way i'm supposed it.  i've read key recovery agent can't find article on how use properly.  any pointers?

now not nice of it? ;)

it private key still on workstation. if certificate request id ca, can re-install grabbing ca database.

1. on ca, find certificate in issued certificates and request id

2. on client, use certreq retreive certificate again , save file. (certreq -config "<ca machine name>\<ca name>" -retrieve <requestid> <file.cer>)

3. on client, open new certificate file copy serial number.

4. while certificate open, click "install certificate...". tell install in personal store.

5. on client, use certutil re-pair certificate it's private key (certutil -user -repairstore "<serial number>")

6. should it. try opening encrypted file verify.

 

thanks,

john



Windows Server  >  Security



Comments

Popular posts from this blog

CRL Revocation always failed

Failed to query the results of bpa xpath

0x300000d errors in Microsoft Remote Desktop client