{"id":890,"date":"2016-06-21T13:28:20","date_gmt":"2016-06-21T11:28:20","guid":{"rendered":"http:\/\/dety.net.ua\/?p=890"},"modified":"2016-06-21T13:28:20","modified_gmt":"2016-06-21T11:28:20","slug":"certificate-add-a-private-key","status":"publish","type":"post","link":"https:\/\/dety.net.ua\/?p=890","title":{"rendered":"Certificate + Add a private key"},"content":{"rendered":"<h2>Copy-pasted from: <a href=\"http:\/\/www.entrust.net\/knowledge-base\/technote.cfm?tn=7905\">http:\/\/www.entrust.net\/knowledge-base\/technote.cfm?tn=7905<\/a><\/h2>\n<h2>Entrust Certificate Services Support Knowledge Base<\/h2>\n<p><strong>Audience:<\/strong> General<br \/>\n<strong>Last Modified:<\/strong> 2011-01-18 08:42:02.0<\/p>\n<p><strong>TN 7905 &#8211; What are the steps to recover the private key of an SSL certificate in an IIS environment?<\/strong><\/p>\n<p>Problem:<\/p>\n<p>The SSL certificate is installed but the private key is missing. What are the steps to recover the private key of an SSL certificate in a Microsoft Internet Information Services (IIS) environment?<\/p>\n<p>Cause:<\/p>\n<p>Entrust SSL certificates do not include a private key. The private key resides on the server that generated the Certificate Signing Request (CSR). When installed correctly, the Server Certificate will match up with the private key as displayed below.<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/secure.entrust.com\/kbimages\/pk11.jpg\" alt=\"\" border=\"0\" \/><\/p>\n<p>If the private key is missing, this could mean:<\/p>\n<ul type=\"disc\">\n<li>The certificate is not being installed on the same server that generated the CSR.<\/li>\n<li>The pending request was deleted from IIS.<\/li>\n<li>The certificate was installed through the Certificate Import Wizard rather than through IIS.<\/li>\n<\/ul>\n<p><strong><br \/>\nSolution:<br \/>\n<\/strong><br \/>\nTo\u00a0recover the private key, follow the procedures below.<\/p>\n<p><u><strong>Part 1 &#8211; Snap-In Configuration<\/strong><br \/>\n<\/u><br \/>\nUse the following steps to add the Certificates snap-in:<\/p>\n<ol type=\"1\">\n<li>Click <strong>Start<\/strong>, and then click <strong>Run<\/strong>.<\/li>\n<li>Type in <em><strong>mmc<\/strong><\/em> and click <strong>OK<\/strong>.<\/li>\n<li>From the File menu, choose <strong>Add\/Remove Snap-in<\/strong>.<\/li>\n<li>In the new window that appears, click <strong>Add<\/strong>.<\/li>\n<li>Select <strong>Certificates<\/strong> and then click <strong>Add<\/strong>.\n<p><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/secure.entrust.com\/kbimages\/pk4.jpg\" alt=\"\" width=\"492\" height=\"421\" border=\"0\" \/><\/li>\n<\/ol>\n<ol start=\"6\" type=\"1\">\n<li>Choose the <strong>Computer account<\/strong> option and click <strong>Next<\/strong>.\n<p><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/secure.entrust.com\/kbimages\/pk5.jpg\" alt=\"\" width=\"468\" height=\"339\" border=\"0\" \/><\/li>\n<\/ol>\n<ol start=\"7\" type=\"1\">\n<li>Select <strong>Local Computer<\/strong> and then click <strong>Finish<\/strong>.\n<p><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/secure.entrust.com\/kbimages\/pk6.jpg\" alt=\"\" width=\"473\" height=\"338\" border=\"0\" \/><\/li>\n<\/ol>\n<ol start=\"8\" type=\"1\">\n<li>Click <strong>Close<\/strong>, and then click <strong>OK<\/strong>. The snap-in for <strong>Certificates (Local Computer)<\/strong> appears in the console.\n<p><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/secure.entrust.com\/kbimages\/pk7.jpg\" alt=\"\" width=\"515\" height=\"449\" border=\"0\" \/><\/li>\n<\/ol>\n<p><u><strong><br \/>\nPart 2 &#8211; Import the Server Certificate<br \/>\n<\/strong><br \/>\n<\/u>Use the following steps to import your Server Certificate into the Personal certificate store. (If the Server Certificate has already been imported into the Personal store, you may skip this step.)<\/p>\n<p>From the MMC console opened in the above steps:<\/p>\n<ol type=\"1\">\n<li>Expand the <strong>Certificates (Local Computer)<\/strong> tree in the left preview panel.\n<p><img decoding=\"async\" src=\"https:\/\/secure.entrust.com\/kbimages\/pk8.jpg\" alt=\"\" border=\"0\" \/><\/li>\n<\/ol>\n<ol start=\"2\" type=\"1\">\n<li>Right-click <strong>Personal<\/strong> and select <strong>All Tasks &gt; Import<\/strong>.<\/li>\n<\/ol>\n<p><img decoding=\"async\" src=\"https:\/\/secure.entrust.com\/kbimages\/pk9.jpg\" alt=\"\" border=\"0\" \/><\/p>\n<ol start=\"3\" type=\"1\">\n<li>The Certificate Import Wizard appears. Click <strong>Next<\/strong>.<\/li>\n<li>Browse to the location of your Server Certificate file and click <strong>Next<\/strong>.\n<p><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/secure.entrust.com\/kbimages\/pk10.jpg\" alt=\"\" width=\"457\" height=\"343\" border=\"0\" \/><\/li>\n<\/ol>\n<ol start=\"5\" type=\"1\">\n<li>Select <strong>Place all certificates in the following store<\/strong> and click <strong>Next<\/strong>.<br \/>\n<b><u><br \/>\n<img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/secure.entrust.com\/kbimages\/pk111.jpg\" alt=\"\" width=\"457\" height=\"344\" border=\"0\" \/><\/u><\/b><\/li>\n<\/ol>\n<ol start=\"6\" type=\"1\">\n<li>Click <strong>Finish<\/strong> to complete the Certificate Import Wizard.\n<p><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/secure.entrust.com\/kbimages\/pk15.jpg\" alt=\"\" width=\"457\" height=\"344\" border=\"0\" \/><\/li>\n<\/ol>\n<ol start=\"7\" type=\"1\">\n<li>A dialog box appears\u00a0indicating the import was successful. Click <strong>OK<\/strong>.\n<p><img decoding=\"async\" src=\"https:\/\/secure.entrust.com\/kbimages\/import5.jpg\" alt=\"\" border=\"0\" \/><\/li>\n<\/ol>\n<p><u><strong><br \/>\nPart 3 &#8211; Recover the Private Key<br \/>\n<\/strong><\/u><br \/>\nUse the following steps to\u00a0recover your private key using the <b>certutil<\/b> command.<\/p>\n<ol type=\"1\">\n<li>Locate your Server Certificate file (for example, server.cer) and double-click it. The Certificate dialog box appears.\n<p><img decoding=\"async\" src=\"https:\/\/secure.entrust.com\/kbimages\/pk121.jpg\" alt=\"\" border=\"0\" \/><\/li>\n<\/ol>\n<ol start=\"2\" type=\"1\">\n<li>Click the <strong>Details<\/strong> tab. Write down the 8-character\u00a0serial number of the certificate.\n<p><img decoding=\"async\" src=\"https:\/\/secure.entrust.com\/kbimages\/pk13.jpg\" alt=\"\" border=\"0\" \/><\/li>\n<\/ol>\n<ol start=\"3\" type=\"1\">\n<li>Click <strong>Start &gt;<\/strong>\u00a0<strong>Run<\/strong>.<\/li>\n<li>Type <b><em>cmd<\/em><\/b> and click <strong>OK<\/strong>. A Command Prompt window opens.<\/li>\n<li>Enter the following command at the prompt:<\/li>\n<\/ol>\n<p><em><b>certutil \u2013repairstore my <\/b>&lt;serial number&gt;<\/em><b><\/b><\/p>\n<p>Where <em>&lt;serial number&gt;<\/em> is the 8-character\u00a0serial number obtained in Step 2 (spaces removed).<\/p>\n<p>6.\u00a0\u00a0\u00a0\u00a0\u00a0 If Windows is able to recover the private key, you see the following message:<\/p>\n<p align=\"left\"><b>CertUtil:\u00a0 -repairstore command completed successfully.<\/p>\n<p><\/b><\/p>\n<p><b><img decoding=\"async\" src=\"https:\/\/secure.entrust.com\/kbimages\/pk2.jpg\" alt=\"\" border=\"0\" \/><\/b><\/p>\n<p><b>7.\u00a0\u00a0\u00a0\u00a0 <\/b>If your private key was recovered successfully, your Server Certificate installation is complete. <u>If the private key was not recovered successfully<\/u>, you will need to <a href=\"http:\/\/www.entrust.net\/knowledge-base\/technote.cfm?tn=8138\">generate a new Certificate Signing Request<\/a> and submit it to Entrust to have your certificate re-issued.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Copy-pasted from: http:\/\/www.entrust.net\/knowledge-base\/technote.cfm?tn=7905 Entrust Certificate Services Support Knowledge Base Audience: General Last Modified: 2011-01-18 08:42:02.0 TN 7905 &#8211; What are the steps to recover the private key of an SSL certificate in an IIS environment? Problem: The SSL certificate is installed but the private key is missing. What are the steps to recover the private [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[13,12],"tags":[],"class_list":["post-890","post","type-post","status-publish","format-standard","hentry","category-novosti","category-windows"],"_links":{"self":[{"href":"https:\/\/dety.net.ua\/index.php?rest_route=\/wp\/v2\/posts\/890","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/dety.net.ua\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/dety.net.ua\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/dety.net.ua\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/dety.net.ua\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=890"}],"version-history":[{"count":1,"href":"https:\/\/dety.net.ua\/index.php?rest_route=\/wp\/v2\/posts\/890\/revisions"}],"predecessor-version":[{"id":891,"href":"https:\/\/dety.net.ua\/index.php?rest_route=\/wp\/v2\/posts\/890\/revisions\/891"}],"wp:attachment":[{"href":"https:\/\/dety.net.ua\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=890"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/dety.net.ua\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=890"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/dety.net.ua\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=890"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}