Help please - Can not use/export private key after domain change

Help please - Can not use/export private key after domain change

Secure Home | Search | About
 Microsoft Applications Security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
Help please - Can not use/export private key after domain change sandeepk99 02-03-2006
Posted by on February 3, 2006, 8:11 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
I have a self signed certificate in Windows XP (private/pulic key
pair). Recently my company changed my login domain (keeping the same
password and Profile directory). But after that I can not use my
certificate (private key). Looking at the password manager, it shows
the certificate, also when I view it, it says that I have private key
corresponding to the certificate. But when I try to export it greys out

the option for private key export saying "The associated provate key
can not be found. Only the certificate can be exported." I guess the
reason might be that the key was encrypted based on password + domain
name. Just my guess, based on my limited understanding from what I
found on the net:

"Windows XP protects you against such attacks. Windows XP encrypts the
private key with a derivative of your password. If the password is
changed and you don't provide the old password, access to the public
key will be permanently blocked, and you or a thief can no longer
decrypt files with this key."

Is the only way to recover the key to ask for switching back to the old

domain ? Please advise, I would really be very greatful for any help to

recover my key.

Thanks a lot,
Sandeep


Posted by Roger Abell [MVP] on February 4, 2006, 12:03 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
Let's try to separate issues.
Can you access a previously EFS encrypted file ?
It is possible to have the key in the store so that it is not
exportable (but still usable).
You see only one EFS certificate in your private cert store?
If it is not usable then you should contact the admins that managed
the transition. They would (should) certainly want to know of the
problem before they migrate any more accounts/profiles.
On the other hand, if it is usable, then this may be due to policies
enforced in the new domain, which may or may not be what they
have intended to happen.

>I have a self signed certificate in Windows XP (private/pulic key
> pair). Recently my company changed my login domain (keeping the same
> password and Profile directory). But after that I can not use my
> certificate (private key). Looking at the password manager, it shows
> the certificate, also when I view it, it says that I have private key
> corresponding to the certificate. But when I try to export it greys out
>
> the option for private key export saying "The associated provate key
> can not be found. Only the certificate can be exported." I guess the
> reason might be that the key was encrypted based on password + domain
> name. Just my guess, based on my limited understanding from what I
> found on the net:
>
> "Windows XP protects you against such attacks. Windows XP encrypts the
> private key with a derivative of your password. If the password is
> changed and you don't provide the old password, access to the public
> key will be permanently blocked, and you or a thief can no longer
> decrypt files with this key."
>
> Is the only way to recover the key to ask for switching back to the old
>
> domain ? Please advise, I would really be very greatful for any help to
>
> recover my key.
>
> Thanks a lot,
> Sandeep
>



Similar ThreadsPosted
Password policy change on domain September 28, 2006, 9:25 am
how to change all domain user account passwords at once July 8, 2005, 11:01 am
NTFS permission change when migrating to new Domain September 29, 2008, 12:16 pm
Change 2003 Domain Password over Internet (No outlook, no vpn)... February 17, 2007, 12:47 pm
domaine vergabe free de domains domain de eu domain name registrieren de be domain July 28, 2008, 4:14 pm
Where's my private key? February 16, 2007, 4:57 pm
No permssions on private key March 30, 2006, 11:15 am
Private or encryption box? November 20, 2006, 4:18 pm
Private or encryption box? November 20, 2006, 5:35 pm
Public - Private key June 28, 2007, 11:46 am

The site map in XML format XML site map

Contact Us | Privacy Policy