SmartCard and Key Archival

SmartCard and Key Archival

Secure Home | Search | About
 Microsoft Applications Security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
SmartCard and Key Archival =?Utf-8?B?UGVkcm8gTmFzY2ltZW50 03-28-2006
Posted by =?Utf-8?B?UGVkcm8gTmFzY2ltZW50 on March 28, 2006, 9:41 am
If you were  Registered and logged in, you could reply and use other advanced thread options
I'm setting up Key archival and recovery in a Windows 2003 PKI.
I've created a KRA user and issued a KRA certificate to him . Then I enabled
the CA for Key archival selecting the user just created as KRA.
I have modified a Smartcard User template , which I've been using
successfully so far , to enable key archival .
Then I tried to submit a certificate request on behalf of another user from
the web enrollment pages to issue the new certificate template .
The process fails with the following error ( logged on the CA )

I'm using E-Token from Alladin. Is this a problem with the token? If i issue
a certificate where the CSP is "Microsoft..." it wotks fine. The problem is
when I try to issue smartcard certificates

Origine evento: CertSvc
ID evento: 53
Descrizione:
Certificate Services denied request 16 because The request is missing a
required private key for archival by the server. 0x80094804 (-2146875388).
The request was for DOMAIN\pkitestuser. Additional information: Denied by
Policy Module

Posted by S. Pidgorny on March 29, 2006, 5:33 am
If you were  Registered and logged in, you could reply and use other advanced thread options
eToken CSP cannot send private key for archival because eToken is designed
to keep private keys strictly on the hardware - host PC software only has
access to it using low-level API (usually PKCS #11) for functions like
signing and encryption. Same is true for most smart cards, and for all HSMs.

What to do? Generate keys on the server, and download thse on the card.
Requires a Microsoft product that is not released yet - details are here:

http://www.alacris.com/products/products_idNexus_microsoft.htm

--
Svyatoslav Pidgorny, MS MVP - Security, MCSE
-= F1 is the key =-

> I'm setting up Key archival and recovery in a Windows 2003 PKI.
> I've created a KRA user and issued a KRA certificate to him . Then I
> enabled
> the CA for Key archival selecting the user just created as KRA.
> I have modified a Smartcard User template , which I've been using
> successfully so far , to enable key archival .
> Then I tried to submit a certificate request on behalf of another user
> from
> the web enrollment pages to issue the new certificate template .
> The process fails with the following error ( logged on the CA )
>
> I'm using E-Token from Alladin. Is this a problem with the token? If i
> issue
> a certificate where the CSP is "Microsoft..." it wotks fine. The problem
> is
> when I try to issue smartcard certificates
>
> Origine evento: CertSvc
> ID evento: 53
> Descrizione:
> Certificate Services denied request 16 because The request is missing a
> required private key for archival by the server. 0x80094804 (-2146875388).
> The request was for DOMAIN\pkitestuser. Additional information: Denied by
> Policy Module



Similar ThreadsPosted
Certificate Services: Key Archival November 22, 2005, 4:39 am
smartcard , IE August 28, 2006, 9:52 am
ANN: Smartcard component for VS.NET May 26, 2006, 9:31 am
Smartcard help! GemPlus.. April 15, 2007, 7:54 am
OCSP and smartcard logon October 21, 2005, 7:20 am
how to authenticate via IE with a smartcard certificate November 28, 2005, 5:42 pm
SmartCard logons to domain November 30, 2005, 9:17 am
Signing email using SmartCard CSP December 28, 2005, 6:56 am
DRA certificate on smartcard - vista May 1, 2007, 3:20 pm
Digital Signature with SmartCard October 20, 2007, 4:16 am

The site map in XML format XML site map

Contact Us | Privacy Policy