Migrate the CSP of the CA certificate to another HSM


hello,

i try migrate hsm microsoft ca uses.

i running microsoft ca on windows server 2008 (32bit) eracom protect server external.

i managed export certificate+privkey , import new hsm, safenet lunasa.

(i know, evil , keys compromised...)

i ran

certutil -csp "luna cryptographic services microsoft windows" -repairstore <serial>

now can see in

certutil -store my
certificate correct associated lunasa csp. looks fine far.

my goal now, have ca find certificate on new hsm, lunasa.

i think there should 2 possibilities:

1. reinstall ca , choose existing certificate , private key, when initializing ca

2. voodoo , edit registry, altough "there no direct supported way change csp ca." ;-)

anyway: when reinstall ca , choose select existing certificate privkey, ms ca installer not see private key nor certifcate.

so wondering how ca installer tries locate existing ca certificates on machine on why not find mine.

any hint deeper understanding highly appreciated.

thanks lot , kind regards

cornelius

afaik, there no way change csp without reinstall. need install existing certificate , private key new hsm, perform ca backup (full), uninstall role , install again specifying existing certificate on hsm. and, of course, restore backup.

my weblog: http://en-us.sysadmins.lv
powershell pki module: http://pspki.codeplex.com
check out new: powershell fciv tool.



Windows Server  >  Security



Comments

Popular posts from this blog

Error: 0x80073701 when trying to add Print Services Role in Windows 2012 Standard

Disconnecting from a Windows Server 2012 R2 file sharing session on a Windows 7,8,10 machine

Event ID 64,77,1008 Certificates Events Windows Server 2008, 2008R2