question

DavidEwer-9871 avatar image
0 Votes"
DavidEwer-9871 asked FanFan-MSFT commented

CertUtil: -backupKey command FAILED: 0x80092004 (-2146885628)

I am trying to perform a backup of the CA Database and Private Keys for my old SBS server before migrating to my new server running Windows Server 2019 Standard however when I run the certutil -backupkey command I receive the error "CertUtil: -backupKey command FAILED: 0x80092004 (-2146885628) CertUtil: Cannot find object or property."

Can anybody suggest how to overcome this error?

What would be the implications of not migrating the CA Database and Private Keys?

Thanks

David

windows-server-security
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

FanFan-MSFT avatar image
0 Votes"
FanFan-MSFT answered

Hi,
Thanks for sharing here!
For Migrating The Active Directory Certificate Service, i would recommend you follow the steps in the following link:
https://techcommunity.microsoft.com/t5/itops-talk-blog/step-by-step-migrating-the-active-directory-certificate-service/ba-p/697674
And check if you can backup all the database successfully.
If there are still errors , please feel free to let us know.

Best Regards,

5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

DavidEwer-9871 avatar image
0 Votes"
DavidEwer-9871 answered FanFan-MSFT commented

Thanks for coming back to me so quickly. I followed the steps in the link you sent me but received a similar error (see attached screenshots). I click OK after the first message and then received the error.

40841-1.png

40851-2.png



1.png (108.9 KiB)
2.png (93.5 KiB)
· 1
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

Crypt32 avatar image
0 Votes"
Crypt32 answered FanFan-MSFT commented

Can anybody suggest how to overcome this error?

I would say there is no supported way. Your private key is not allowed for export (even for backup purposes), so you can't backup it and transfer to another server. What I can suggest is to start over with brand new CA and issue certificates from new CA. Keep running existing CA until last client certificate is expired. When last certificate expired, you simply decommission old CA.
· 1
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

Hi,
 
Just checking in to see if the information provided was helpful.
Please let us know if you would like further assistance.
 
Best Regards,

0 Votes 0 ·