Unable to export Private key

Unable to export Private key

Secure Home | Search | About
 Microsoft Applications Security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
Unable to export Private key A Lake 07-27-2006
Posted by =?Utf-8?B?QSBMYWtl?= on July 27, 2006, 6:52 am
If you were  Registered and logged in, you could reply and use other advanced thread options
I'm running an Enterprise CA on Windows server 2003 (SE) and using the
certificates to secure OWA on Exhange 2003. I need to export the certificate
to an ISA 2004 Server that is not part of our domain, but when I try to
export the private key the option is disabled.

I then tried to create my own template (copying the Web Server template) to
allow export of the private key, but when I try to use the template by
selecting New-Certificate template to issue on the Certification
Authority,my template does not appear!

As the ISA server is totally seperate from our network I need to be able to
export this certificate (and the Root CA as well) but am now stumped as no
way forward exists - is this because I am using Server 2003 SE instead of
Adavanced/Datacenter and therefore I'm stuffed?

Posted by Brian Komar on July 27, 2006, 2:54 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
Answers inline...

ALake@discussions.microsoft.com says...
> I'm running an Enterprise CA on Windows server 2003 (SE) and using the
> certificates to secure OWA on Exhange 2003. I need to export the certificate
> to an ISA 2004 Server that is not part of our domain, but when I try to
> export the private key the option is disabled.

That is correct, the default is to not enable Key export.
>
> I then tried to create my own template (copying the Web Server template) to
> allow export of the private key, but when I try to use the template by
> selecting New-Certificate template to issue on the Certification
> Authority,my template does not appear!
>
> As the ISA server is totally seperate from our network I need to be able to
> export this certificate (and the Root CA as well) but am now stumped as no
> way forward exists - is this because I am using Server 2003 SE instead of
> Adavanced/Datacenter and therefore I'm stuffed?
>
You need EE or DCE to issue certs based on the v2 template. My question to you
is why you
need the *same* cert. This is not the requirement. Log on to the ISA server as
a local
administrator, connect to the http://caname/certsrv WEb site. When prompted for
creds,
provide a user who has read and enroll on the Web Server certificate template.

Then request a Web server certificate (Advanced Request) with the DNS name that
you require.
There has never been a requirement to have the *same* certificate when doing ISA
publishing,
just a certificate with the *DNS NAME* used by the clients to connect.

Brian


Similar ThreadsPosted
Help please - Can not use/export private key after domain change February 3, 2006, 8:11 pm
Private Key Export Urgent help needed !!!! March 2, 2008, 4:07 am
how do i export a cert from my ca? February 16, 2006, 10:27 pm
how to secedit export everything August 10, 2008, 9:41 am
Export IPSec Policies to XML April 25, 2006, 7:04 am
Enhanced CSP and export limitations? June 1, 2006, 1:27 pm
tool to export pfx to file October 27, 2008, 8:51 am
Export laws for IE in China and India August 19, 2005, 5:12 pm
Export current NTFS permissions. October 18, 2005, 7:31 am
Import Export Merchandising Software May 1, 2006, 10:09 pm

The site map in XML format XML site map

Contact Us | Privacy Policy