Quantcast
Channel: Security forum
Viewing all articles
Browse latest Browse all 12072

AD CS Key Recovery Agent problem

$
0
0
Hi,

I currently have a 2008 AD CS setup with an offline root and an entrprise subordinate CA.  I am testing out key recovery on the EntCA. I found a article Certificate Services example implementation: Key archival and recovery http://technet.microsoft.com/en-us/library/cc781351.aspx on how to do this.  I was following the process and everything works until Task 6, step 3.b.  When running certutil -user -recoverkey outputblob keytest.pfx it fails with the following error:
    CertUtil: -RecoverKey command FAILED: 0x8009200c (-2146885620)
    CertUtil: Cannot find the certificate and private key to use for decryption.

While searching the internet for an answer I saw someone who had the exact same problem however no answer was provided.

Does anyone have any ideas how to resolve this?  or a checklist or process that works?

Thanks,
Craig

Viewing all articles
Browse latest Browse all 12072

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>