Assign Existing Private Key to a New Certificate (2024)

In some cases administrators may generate a new CSR, but install an 'old' certificate while waiting for the new certificate to arrive. An unfortunate consequence of this action is that the link between IIS and the location of the private key is broken. This then becomes a problem when a user attempts to import the new certificate later, since the Certificate Wizard will display an error message saying it is unable to locate the private key.

Note: Use for the replacement of an EV (Extended Validation) certificate in IIS this manual.

Solution

First all pending requests that are still open have to be removed, after which the new certificate can be imported manually in the Local Machine Certificate Store. Then the certificate can be reconnected with the private key by using CertUtil.exe.

Removing Pending Requests (IIS6 only)

  1. Log in to the server that contains the CSR with an Administrator account.
  2. Remove any pending requests still open within IIS:
    1. Open the IIS Manager.
    2. Right-click the relevant website and choose Properties.
    3. Click Server Certificate... located within the Directory Security tab and follow the instructions.

Open the Local Machine Certificate Store

  1. Click StartRun, type mmc and select OK.Assign Existing Private Key to a New Certificate (1)
  2. Go to the File menu and select Add/Remove Snap in.Assign Existing Private Key to a New Certificate (2)
  3. Select Certificates from the Add or Remove Snap-ins box and click Add.Assign Existing Private Key to a New Certificate (3)
  4. Select Computer Account and click Next.
  5. Select Local Computer and click Finish.
    Assign Existing Private Key to a New Certificate (4)
  6. Close the Add Standalone Snap-in box by clicking OK and return to the mmc.

Installation New Certificate

  1. Expand Certificates in the Certificates snap-in dialogue window. Right-click Personal folder, go to All Tasks and click Import.
  2. Click Next on the Welcome to the Certificate Import Wizard.
  3. Select Browse... on the File to Import page.
  4. Navigate to the new Certificate, select it and click Open. Click Next.
  5. On the Certificate Store page, click Place all certificates in the following store, and click on Browse.
  6. Choose the Personal certificate store in the Select Certificate Store window and click OK.
  7. Click Next and then Finish to finish the import process.

Connecting the New Certificate to the Private Key

  1. In the Certificates snap-in, double-click on the imported certificate that can be found in the Personal folder.
  2. Select the Details tab in the Certificate dialogue window.
  3. Click Serial Number in the Field column of the Details tab and write down the serial number.
  4. Click StartRun, type cmd and click OK. A command prompt will open.
  5. Type the following line in the command prompt:
    certutil -repairstore my "serialnumber"
    Note: replace serialnumber with the serial number that was written down in step 3.
  6. Right-click Certificates in the Certificates Snap-In window and select Refresh. The certificate should now have a corresponding private key. You can check this by double-clicking the certificate. The following message should appear at the bottom: You have a private key that corresponds with this certificate.
  7. The certificate now has a corresponding private key. The IIS manager can be used to assign the re-connected key-pair (certificate) to the website.
Assign Existing Private Key to a New Certificate (2024)
Top Articles
LCY
10 Ways to Get Virtual Numbers For WhatsApp - TimelinesAI
2018 Jeep Wrangler Unlimited All New for sale - Portland, OR - craigslist
Us 25 Yard Sale Map
Mail Healthcare Uiowa
Weapons Storehouse Nyt Crossword
Top Golf 3000 Clubs
Cranberry sauce, canned, sweetened, 1 slice (1/2" thick, approx 8 slices per can) - Health Encyclopedia
Syracuse Jr High Home Page
Charmeck Arrest Inquiry
MindWare : Customer Reviews : Hocus Pocus Magic Show Kit
Lenscrafters Huebner Oaks
2016 Ford Fusion Belt Diagram
Chelactiv Max Cream
Voy Boards Miss America
Richland Ecampus
Water Trends Inferno Pool Cleaner
Apple Original Films and Skydance Animation’s highly anticipated “Luck” to premiere globally on Apple TV+ on Friday, August 5
Chase Bank Pensacola Fl
Yugen Manga Jinx Cap 19
Everything To Know About N Scale Model Trains - My Hobby Models
Lovindabooty
Free T33N Leaks
Hrconnect Kp Login
Gasbuddy Lenoir Nc
Pnc Bank Routing Number Cincinnati
A Small Traveling Suitcase Figgerits
Devin Mansen Obituary
The Mad Merchant Wow
Tal 3L Zeus Replacement Lid
Austin Automotive Buda
Pp503063
Trivago Myrtle Beach Hotels
Bianca Belair: Age, Husband, Height & More To Know
Dr Adj Redist Cadv Prin Amex Charge
Blackwolf Run Pro Shop
R/Moissanite
Danielle Ranslow Obituary
Dinar Detectives Cracking the Code of the Iraqi Dinar Market
Poe Self Chill
Advance Auto.parts Near Me
Ucla Basketball Bruinzone
Perc H965I With Rear Load Bracket
Syrie Funeral Home Obituary
Unblocked Games 6X Snow Rider
Who uses the Fandom Wiki anymore?
Swissport Timecard
Varsity Competition Results 2022
Latest Posts
Article information

Author: Kerri Lueilwitz

Last Updated:

Views: 6412

Rating: 4.7 / 5 (67 voted)

Reviews: 90% of readers found this page helpful

Author information

Name: Kerri Lueilwitz

Birthday: 1992-10-31

Address: Suite 878 3699 Chantelle Roads, Colebury, NC 68599

Phone: +6111989609516

Job: Chief Farming Manager

Hobby: Mycology, Stone skipping, Dowsing, Whittling, Taxidermy, Sand art, Roller skating

Introduction: My name is Kerri Lueilwitz, I am a courageous, gentle, quaint, thankful, outstanding, brave, vast person who loves writing and wants to share my knowledge and understanding with you.