pkcs12 into IE5.5, stubborn priv keys

2000-10-05 Thread admin

Hi,

I import my pkcs12 personal certificate (openssl generated) into IE5.5.  It 
takes it without a problem and puts everything in its place:  CA cert, 
personal cert, private key.

The problem is that once I set up the initial security level on the private 
key (low, medium, high, and the password for 'high'), I can no longer 
change it.

Removing the associated personal certificate and CA certificate does not 
remove the private key.   I had to nuke the registry and re-install to get 
the priv key security dialogs back.  Is there a cleaner way?

-Erik

__
OpenSSL Project http://www.openssl.org
User Support Mailing List[EMAIL PROTECTED]
Automated List Manager   [EMAIL PROTECTED]



Re: pkcs12 into IE5.5, stubborn priv keys

2000-10-05 Thread Dr S N Henson

admin wrote:
 
 Hi,
 
 I import my pkcs12 personal certificate (openssl generated) into IE5.5.  It
 takes it without a problem and puts everything in its place:  CA cert,
 personal cert, private key.
 
 The problem is that once I set up the initial security level on the private
 key (low, medium, high, and the password for 'high'), I can no longer
 change it.
 
 Removing the associated personal certificate and CA certificate does not
 remove the private key.   I had to nuke the registry and re-install to get
 the priv key security dialogs back.  Is there a cleaner way?
 

The only documented way to change the level is to delete the container
and recreate it.

You can do things by deleting the key container at a CryptoAPI level,
but you need a fair knowledge of CryptoAPI to do that. 

I recall Outlook (maybe Outlook express too) had an option to delete the
key when it was exported, you could try that.


Steve.
-- 
Dr Stephen N. Henson.   http://www.drh-consultancy.demon.co.uk/
Personal Email: [EMAIL PROTECTED] 
Senior crypto engineer, Celo Communications: http://www.celocom.com/
Core developer of the   OpenSSL project: http://www.openssl.org/
Business Email: [EMAIL PROTECTED] PGP key: via homepage.

__
OpenSSL Project http://www.openssl.org
User Support Mailing List[EMAIL PROTECTED]
Automated List Manager   [EMAIL PROTECTED]