Accidentally deleted RSA Machine key from one cluster member

JB 21 Reputation points
2021-03-01T22:06:05.797+00:00

We accidentally deleted the key 4f692a7dc1b824e1f679f93fadd08a3b-[Machine-GUID] off a cluster member inside C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys. It wasn't protected by a backup, but this key is on all the other cluster members, and appears to be a well-known cluster key identifier, as it's on all of our clusters. We'd like to export the certificate with key from a different cluster member, but can't seem to find a certificate that corresponds to that key in any view (local computer, service\cluster, service\SMB Witness). At character # 40, the name of the key seems to be 'ClusterSecret-BLOB' We did successfully export and import the ClusInfraCert certificate with key, but this appears to be separate from that.

Windows Server Clustering
Windows Server Clustering
Windows Server: A family of Microsoft server operating systems that support enterprise-level management, data storage, applications, and communications.Clustering: The grouping of multiple servers in a way that allows them to appear to be a single unit to client computers on a network. Clustering is a means of increasing network capacity, providing live backup in case one of the servers fails, and improving data security.
958 questions
0 comments No comments
{count} votes

Accepted answer
  1. Xiaowei He 9,871 Reputation points
    2021-03-02T05:59:29.853+00:00

    Hi,

    I checked the folderC:\ProgramData\Microsoft\Crypto\RSA\MachineKeys in my cluster, it seems the key in each node is different. Below is the example in my lab.

    Node 1:

    73240-image.png

    Node 2:

    73255-image.png

    If you worry about the missing key will cause corruption to the cluster, we may try to evict the node from the cluster then re-add it into the cluster, check if the certificate will be reissued.

    Thanks for your time!
    Best Regards,
    Anne

    -----------------------------

    If the Answer is helpful, please click "Accept Answer" and upvote it.
    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.


0 additional answers

Sort by: Most helpful