Where is the offline CA's certificate store ? How to retrieve the issued cert's?

Where is the offline CA's certificate store ? How to retrieve the issued cert's?

Secure Home | Search | About
 Microsoft Applications Security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
Where is the offline CA's certificate store ? How to retrieve the issued cert's? Daria Morgendorffer 04-27-2006
Posted by Daria Morgendorffer on April 27, 2006, 3:49 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
Hi,

I am trying to write a tool that will export automatically all
certificates from an offline Certificate Authority to PKCS#7.


I have...

* setup a certificate authority
* create a template with certtmpl.msc that doesn't publish certificate
in Active Directory (unchecked checkbox in "General")
* autoenrolled a certificate succesfully. When I open Certificate
Authority, I can see it there when I run certsrv.msc , so I know it is
somewhere inside, but...
* although MSDN suggests that the certificates should be in enterprise
store, NTAuth, I can't see them when I browse certificate stores either
with regedit or certmgr.msc , where the certificates really are. In
fact, I couldn't find them with regedit in any part of the tree.

(Needless to say that) I failed when I was trying to evaluate the
certificate stores as documented in CryptoAPI documentation.

I have also tried filemon and regmon from sysinternals.com, but I still
couldn't identify the source.

I also didn't really find any hint or suitable sample in CAPICOM.



Please please please!!! What do I have to do in order to get the issued
certificates from the CA the programmatic way, not by clicking?

Thank you very much in advance!

Similar ThreadsPosted
retrieve server side certificate using win32 API. July 21, 2006, 4:46 am
Moving newly issued Certificate May 27, 2008, 6:16 pm
MSDN Download Error - The Server SSL certificate is issued by a ce April 21, 2008, 5:15 pm
Certificate store question February 4, 2008, 1:01 pm
Is there a way to get certificate store path from CERT_CONTEXT March 6, 2006, 11:07 am
How to make privatekey of a certificate entirely non exportable from personal store? April 6, 2007, 5:47 am
Multiple CA's? January 24, 2008, 1:40 am
Standalone CA's and CRL August 27, 2008, 9:10 pm
CA's and Certificates for MOM or System Center OM August 25, 2007, 11:28 am
retrieve deleted history January 19, 2006, 8:58 am

The site map in XML format XML site map

Contact Us | Privacy Policy