question

drClays avatar image
0 Votes"
drClays asked GaryReynolds edited

ADCS - I have problem with export private key .pfx and date of expiron certificate

Hello,

I made new certification templates for certificate request, but if I have checked "Allow private key to be exported" I can not export this cert with private key. And I have set "Validity period" at 5 years, but they generate validation at 2 years.

What am I doing wrong?

This is how it looks:

188687-2022-03-31-14h28-09.png
188764-2022-03-31-14h28-18.png
188735-2022-03-31-14h28-33.png
188801-2022-03-31-14h29-13.png


windows-server-security
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

1 Answer

GaryReynolds avatar image
0 Votes"
GaryReynolds answered GaryReynolds edited

Hi

I can't see the bottom of the certificate dialog, but it doesn't look like the private key is available. The dialog should show a key below the date if the private key is present.

The validity duration in the template is only honoured if the issuing CA has an expiry date greater than the template duration, i think it's double. It's likely that the issuing CA certificate has less than 5 years remaining.

Gary.

· 7
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

Hi,

on certificate dialog, there are not more information.

What can I do to get private key?

0 Votes 0 ·

You will need to open the certificate from the store where the private key is stored to see the private key.

Gary.

0 Votes 0 ·

I generate csr from Fortigate:

189092-image.png

Next, I request certificate via htttps://localhost/certsrv

189070-image.png



In the next step I import this .cer to Certificates>Personal and I try to export with private key, but it's not enabled.

189161-image.png


0 Votes 0 ·
image.png (321.4 KiB)
image.png (320.6 KiB)
image.png (362.9 KiB)
Show more comments