Error about private key not supporting key export when backing up certificate authority


we have set new ca , deployed couple of web certificates.  

i wanted test backing before starting use large numbers of user , computer certificates.

when used ca backup wizard first backup, popup appeared saying windows cannot backup 1 or more private keys because the csp not support key export.  it allows ignore , continue.

what make sure need disaster recovery gets backed up?

based on description, did not follow standards build of ca.

when built using powershell scriptlets or server manager wizard, ca certificate , private key exportable when using microsoft software key storage provider.

if cannot certificate , private key (and based on newness of pki), tear down , redeploy before issue many certs

the ca certificate , private key *should* exportable

brian



Windows Server  >  Security



Comments

Popular posts from this blog

CRL Revocation always failed

Failed to query the results of bpa xpath

0x300000d errors in Microsoft Remote Desktop client