Sign in
Windows PKI blog
News and information for public key infrastructure (PKI) and Active Directory Certificate Services (AD CS) professionals
Translate This Page
Translate this page
Powered by
Microsoft® Translator
Options
Email Blog Author
RSS for posts
Atom
RSS for comments
OK
Search Blogs
Tags
A Certificate could not be created
Active Directory Domain Services
AD CS
AD CS documentation updates
architecture
Backup Private Keys ADCS 2008 R2 p12 CA
CA
CA maintenance
certificate
certificate requests
certificates
Certification authority
certifiication authority
certutil
Configuration
CRL
cryptography
Data Recvoery
Homeland Security Presidential Directive 12
HSPD-12
key management
PKI
setup
SHA2 NIST SP800-78-2 SP800-57
whitepaper
Archive
Archives
May 2013
(1)
March 2013
(3)
December 2012
(3)
October 2012
(1)
August 2012
(1)
July 2012
(1)
June 2012
(3)
May 2012
(2)
April 2012
(2)
March 2012
(2)
February 2012
(1)
January 2012
(2)
December 2011
(1)
October 2011
(3)
September 2011
(2)
August 2011
(3)
June 2011
(2)
March 2011
(2)
February 2011
(3)
September 2010
(1)
August 2010
(3)
June 2010
(2)
May 2010
(2)
April 2010
(2)
March 2010
(2)
February 2010
(1)
January 2010
(2)
December 2009
(2)
November 2009
(2)
October 2009
(2)
September 2009
(7)
August 2009
(10)
July 2009
(1)
June 2009
(2)
May 2009
(2)
April 2009
(2)
February 2009
(1)
January 2009
(4)
December 2008
(2)
October 2008
(3)
September 2008
(1)
July 2008
(1)
June 2008
(1)
May 2008
(1)
April 2008
(1)
February 2008
(2)
January 2008
(1)
November 2007
(1)
October 2007
(1)
September 2007
(1)
August 2007
(2)
July 2007
(2)
May 2007
(2)
April 2007
(1)
February 2007
(4)
January 2007
(1)
December 2006
(3)
November 2006
(1)
TechNet Blogs
>
Windows PKI blog
Posts
Subscribe via RSS
Sort by:
Most Recent
|
Most Views
|
Most Comments
Excerpt View
|
Full Post View
Windows PKI blog
Windows PowerShell CRL Copy v2 posted to the gallery
Posted
10 days ago
by
Kurt L Hudson MSFT
0
Comments
Paul Fox has uploaded a revision of his former Windows PowerShell CRL Copy script. The new script is posted at the TechNet Gallery as Windows PowerShell Copy 2 . The Windows PowerShell script monitors the remaining lifetime of a CRL, publishes a CRL to...
Windows PKI blog
PKI Library (PKI Documentation and Reference Library Updated)
Posted
1 month ago
by
Kurt L Hudson MSFT
1
Comments
Tonight I spent a couple of hours reorganizing the PKI Documentation and Reference Library . I also created a vanity short URL to it http://aka.ms/pkilibrary . Finding all our different information on AD CS and PKI can be challenging, so this reorganization...
Windows PKI blog
Windows Server 2012 Active Directory Certificate Services System State Backup and Restore
Posted
1 month ago
by
Amerk [MSFT]
0
Comments
Windows Server 2012 System State Backup allows an administrator to back-up several Operating System components including those required for a successful restore of a Certification Authority. Any certification authority backup should include the private...
Windows PKI blog
Certutil and Certreq
Posted
2 months ago
by
Kurt L Hudson MSFT
8
Comments
I have consolidated and updated two command line utilities recently: Certreq Certutil I took all the older links that I could find and pointed them to the locations above and then pointed out to the examples that we have already. Feel free to...
Windows PKI blog
Query for Advanced CA Configuration Options
Posted
4 months ago
by
Amerk [MSFT]
0
Comments
It is very common to check the configuration of any certification authority using certutil –getreg command. The command will allow a CA administrator to view the configured settings at a glance. But what if you need to configure advanced...
Windows PKI blog
Viewing Expired Certificate Revocation List (CRL)
Posted
4 months ago
by
Amerk [MSFT]
1
Comments
Many customers must perform a regulatory audit annually to comply with industry standards and business trends. Recently I was contacted by one of my customers, who was not able to view all of Certificate Revocation Lists (CRLs) issued by their Enterprise...
Windows PKI blog
Certificate for WinRT devices and non-domain member devices
Posted
5 months ago
by
Chunhua Chen
Hi there, I am a test engineer in the Windows team working on certificate enrollment related areas. Today I want to talk about certificates for Windows RT devices Windows RT devices run on ARM processor , which is different from a typical computer...
Windows PKI blog
Group Protected PFX
Posted
7 months ago
by
Kurt L Hudson MSFT
A new feature is available in Windows Server 2012 and Windows 8 that allows you to protect exported PFX files (those in PKCS#12) to Active Directory Domain Services (AD DS) accounts. The feature is available only if you have a Windows Server 2012 domain...
Windows PKI blog
Blocking RSA keys less than 1024 bits (part 3)
Posted
9 months ago
by
Kurt L Hudson MSFT
Microsoft released a security advisory, KB article, and software update for all supported versions of Windows that blocks RSA certificates with keys less than 1024 bits. The software update was released to the Download Center. The security advisory...
Windows PKI blog
Blocking RSA Keys less than 1024 bits (part 2)
Posted
10 months ago
by
Kurt L Hudson MSFT
On August 14, 2012, Microsoft will issue a critical non-security update (KB 2661254) for Windows XP, Windows Server 2003, Windows Server 2003 R2, Windows Vista, Windows Server 2008, Windows 7, and Windows Server 2008 R2. The update will block the use...
Windows PKI blog
How to determine if a smart card was used for logon
Posted
11 months ago
by
Kurt L Hudson MSFT
0
Comments
Fabian Müller, Premier Field Engineer (PFE) in Germany, just wrote a detailed article discussing a commonly asked question: how do I determine if a smart card was used for logon ? The article is posted on the TechNet Wiki with a link to the Script...
Windows PKI blog
RSA keys under 1024 bits are blocked
Posted
11 months ago
by
Kurt L Hudson MSFT
58
Comments
Public key based cryptographic algorithms strength is determined based on the time taken to derive the private key using brute force methods. The algorithm is deemed to be strong enough when the time required to derive private key is prohibitive enough...
Windows PKI blog
Announcing the automated updater of untrustworthy certificates and keys
Posted
11 months ago
by
Kurt L Hudson MSFT
14
Comments
There are a number of known untrusted certificates and compromised keys that have been issued by standard trusted root certification authorities. To help customers avoid interacting with these untrusted or compromised certificates and keys, an Automatic...
Windows PKI blog
Request File Can’t be Located during CA Certificate Renewal
Posted
11 months ago
by
Amerk [MSFT]
0
Comments
During my work with a customer renewing their Issuing CA’s certificate based on the steps documented in this article , I discovered that the Request file generated couldn’t be located in the default location of %systemDrive% . The Issuing...
Windows PKI blog
Visual Basic for Applications and SHA2
Posted
over 1 year ago
by
Adam Stasiniewicz
0
Comments
I was recently helping a customer deploy a SHA-256 based PKI. As part of the retirement of their old PKI, we reissued the code signing certificates used by their developers. We found that the Visual Studio 2010 developers had no issue with the new code...
Windows PKI blog
Best Practice for Configuring Certificate Template Cryptography
Posted
over 1 year ago
by
Kurt L Hudson MSFT
2
Comments
Starting with Windows Vista and Windows Server 2008, the option to utilize Key Storage Providers (KSPs) in addition to Cryptographic Service Providers (CSPs) was added. These options are available when you create a Certificate Template and configure the...
Windows PKI blog
Network Device Enrollment Service (NDES) now on the TechNet Wiki
Posted
over 1 year ago
by
Kurt L Hudson MSFT
0
Comments
The Network Device Enrollment Service (NDES) whitepaper is now on the TechNet Wiki and I have already made a few updates that were requested. The old download center location has been updated to reflect that we've posted to the update to the TechNet Wiki...
Windows PKI blog
Offline CA articles posted to the TechNet Wiki
Posted
over 1 year ago
by
Kurt L Hudson MSFT
1
Comments
Amer Kamal recently posted two articles regarding the security and maintenance of offline CAs based on frequently asked questions from customers. These articles posted as: Security Best Practices for Offline CAs and Offline CA Maintenance Tasks...
Windows PKI blog
HSPD-12 Logical Access Authentication and 2008 Active Directory Domains on Download Center
Posted
over 1 year ago
by
Kurt L Hudson MSFT
3
Comments
A follow-up document to the original HSPD-12 Logical Access Authentication and Active DIrectory Domains document has just been posted to the download center. The follow-up document demonstrates the increased flexibility of FIPS 201 PIV-II compliant smart...
Windows PKI blog
Connecting iPads to an Enterprise Wireless 802.1x Network Using Certificates and Network Device Enrollment Services (NDES)
Posted
over 1 year ago
by
Amerk [MSFT]
7
Comments
Important notice : Microsoft does not support any apple products, if you need to troubleshoot any problem related to apple products, please refer to http://www.apple.com/support I am often asked by customers how to deploy certificates to iPads using...
Windows PKI blog
Decommissioning an Old Certification Authority without affecting Previously Issued Certificates and then Switching Operations to a New One
Posted
over 1 year ago
by
Amerk [MSFT]
5
Comments
Jonathan Stephens posted an excellent Blog about this topic ; however, it didn’t include the steps. As a result, I decided to type this Blog detailing the steps required. The following assumptions have to be met before proceeding with these steps...
Windows PKI blog
EFS Certificates may be recovered as CNG certificates when CAPI CSP is required
Posted
over 1 year ago
by
Kurt L Hudson MSFT
0
Comments
If a Key Recovery Agent (KRA) certificate is stored in a Cryptography Next Generation (CNG) Key Service Provider (KSP), the certutil -RecoverKey command will by default recover a key as a CNG certificate. This default behavior could cause an issue if...
Windows PKI blog
Windows PowerShell script for Setting up a CA on Windows Server 2008 and Windows Server 2008 R2
Posted
over 2 years ago
by
Kurt L Hudson MSFT
0
Comments
Microsoft MVP, Vadims Podans , has written and posted a Windows PowerShell script that can be used to setup a certification authority (CA). He posted his Windows PowerShell Script on the TechNet Script Repository as Setup Certification Authority with...
Windows PKI blog
Key Recovery vs Data Recovery Differences
Posted
over 2 years ago
by
Amerk [MSFT]
1
Comments
I am often asked when talking to my customers about the differences between Key Recovery and Data Recovery for encrypted files, in addition to which method to use. As a result, This Blog will focus on both areas, explaining the differences and best practices...
Windows PKI blog
How to decommission a Windows enterprise certification authority and how to remove all related objects
Posted
over 2 years ago
by
Kurt L Hudson MSFT
1
Comments
The Windows KB article 889250 titled "How to decommission a Windows enterprise certification authority and how to remove all related objects from Windows Server 2003 and from Windows Server 2000" has been revised on the TechNet Wiki to include information...
Page 1 of 5 (120 items)
1
2
3
4
5