WINSERVER2012R2 Deploying key Recovery agents

Source: Internet
Author: User

In the daily use of the computer process, will inevitably encounter computer failure, the corresponding computer or user certificate will be lost. There are basically these things that are missing: User profile corruption, operating system crashes, man-made malicious removal, hard disk physical failure ... For this kind of situation, the key recovery agent can be solved very well.

Key recovery agent procedures are: 1 specifies that the user becomes the key recovery agent Administrator

2 Key Recovery agent Administrator retrieves certificates by certificate serial number

3 Key Recovery agent Administrator Recovery certificate, sent to user

4 User Request Certificate

Configuration process:

Step1: Specifies that the user becomes the key recovery agent Administrator

650) this.width=650; "title=" Qq20160928124016.png "alt=" wkiol1frscrbffppaac1dpsgw_w752.png-wh_50 "src="/HTTP/ S4.51cto.com/wyfs02/m01/88/2d/wkiol1frscrbffppaac1dpsgw_w752.png-wh_500x0-wm_3-wmp_4-s_2417517587.png "/>

650) this.width=650; "title=" Qq20160928133201.png "alt=" wkiol1frvepgkpcxaab6ms1so_q777.png-wh_50 "src="/HTTP/ S3.51cto.com/wyfs02/m02/88/2d/wkiol1frvepgkpcxaab6ms1so_q777.png-wh_500x0-wm_3-wmp_4-s_748107504.png "/>

650) this.width=650; "title=" Qq20160928133659.png "alt=" wkiol1frvxsclcjcaac1gf1n9fy811.png-wh_50 "src="/HTTP/ S2.51cto.com/wyfs02/m02/88/2d/wkiol1frvxsclcjcaac1gf1n9fy811.png-wh_500x0-wm_3-wmp_4-s_2995377826.png "/>

Step2: User registered key recovery agent certificate

650) this.width=650; "title=" Qq20160928140311.png "style=" Float:none "alt=" Wkiol1frxbmhfb1aaabso8u8dk0734.png-wh_ "Src=" Http://s5.51cto.com/wyfs02/M01/88/2D/wKioL1frXbmhfb1AAABSO8U8dK0734.png-wh_500x0-wm_3-wmp_4-s_ 1410397889.png "/>

650) this.width=650; "title=" Qq20160928140436.png "style=" Float:none "alt=" Wkiol1frxbrciim8aabbz6bxisk138.png-wh_ "Src=" Http://s4.51cto.com/wyfs02/M02/88/2D/wKioL1frXbrCiim8AABbz6bxisk138.png-wh_500x0-wm_3-wmp_4-s_ 4164626456.png "/>

Cut back to CA, issue KRA certificate

650) this.width=650; "title=" Qq20160928140453.png "alt=" wkiol1frxj_ygaq-aacqyxmpapm645.png-wh_50 "src="/HTTP/ S1.51cto.com/wyfs02/m01/88/2d/wkiol1frxj_ygaq-aacqyxmpapm645.png-wh_500x0-wm_3-wmp_4-s_2643525425.png "/>

650) this.width=650; "title=" Qq20160928140527.png "style=" Float:none "alt=" Wkiom1frxbvtcbhraacebznyrto062.png-wh_ "src=" Http://s1.51cto.com/wyfs02/M02/88/31/wKiom1frXbvTCBHrAACeBzNYRto062.png-wh_500x0-wm_3-wmp_4-s_40071023.png "/>

Step3: Setting up a recovery agent

650) this.width=650; "title=" Qq20160928141029.png "alt=" wkiom1frxvtsjcv8aabycao1vam232.png-wh_50 "src="/HTTP/ S2.51cto.com/wyfs02/m00/88/31/wkiom1frxvtsjcv8aabycao1vam232.png-wh_500x0-wm_3-wmp_4-s_3659545871.png "/>

650) this.width=650; "title=" Qq20160928141200.png "alt=" wkiol1frx0dy_vrmaablwtoeb8q307.png-wh_50 "src="/HTTP/ S4.51cto.com/wyfs02/m00/88/2d/wkiol1frx0dy_vrmaablwtoeb8q307.png-wh_500x0-wm_3-wmp_4-s_1426351618.png "/>

Step4: Setting up a new user certificate template, enabling archiving

650) this.width=650; "title=" Qq20160928154000.png "alt=" wkiom1frc9rqltvhaabmkybt1aq790.png-wh_50 "src="/HTTP/ S3.51cto.com/wyfs02/m00/88/33/wkiom1frc9rqltvhaabmkybt1aq790.png-wh_500x0-wm_3-wmp_4-s_1468742445.png "/>

650) this.width=650; "title=" Qq20160928141936.png "alt=" wkiol1fryqxdamziaaclk4vwozg434.png-wh_50 "src="/HTTP/ S1.51cto.com/wyfs02/m01/88/2d/wkiol1fryqxdamziaaclk4vwozg434.png-wh_500x0-wm_3-wmp_4-s_1727219060.png "/>

650) this.width=650; "title=" Qq20160928141828.png "alt=" wkiom1fryn6wouteaaawwny9gso510.png-wh_50 "src="/HTTP/ S4.51cto.com/wyfs02/m00/88/31/wkiom1fryn6wouteaaawwny9gso510.png-wh_500x0-wm_3-wmp_4-s_1309897872.png "/>

PS: Archive only for subsequent user certificates

STEP5: User request to enable archived user certificate

650) this.width=650; "title=" Qq20160928153812.png "alt=" wkiol1frc22qzle-aabhtg9vfm4800.png-wh_50 "src="/HTTP/ S1.51cto.com/wyfs02/m00/88/2f/wkiol1frc22qzle-aabhtg9vfm4800.png-wh_500x0-wm_3-wmp_4-s_3035279370.png "/>

650) this.width=650; "title=" Qq20160928153517.png "alt=" wkiol1frcszzpkujaabjlm8rms4729.png-wh_50 "src="/HTTP/ S3.51cto.com/wyfs02/m02/88/2f/wkiol1frcszzpkujaabjlm8rms4729.png-wh_500x0-wm_3-wmp_4-s_2537117729.png "/>650 ) this.width=650; "title=" Qq20160928153621.png "alt=" wkiol1frcv_gy3n0aac0qyrr_v4695.png-wh_50 "src=" http:// S5.51cto.com/wyfs02/m02/88/2f/wkiol1frcv_gy3n0aac0qyrr_v4695.png-wh_500x0-wm_3-wmp_4-s_3584866607.png "/>

STEP6: Key Recovery agent Administrator retrieves certificates

Retrieving jx001 certificates

PS: There are two user certificates in jx001, 16 is a certificate that does not have archiving enabled, and 20 is a certificate that has the archive feature enabled. Attention!!!

Open 20 certificate, copy serial number, send to kra-admin for retrieval

650) this.width=650; "title=" Qq20160928155011.png "alt=" wkiom1frdj-tp0xwaacr5fuxpdq953.png-wh_50 "src="/HTTP/ S5.51cto.com/wyfs02/m00/88/33/wkiom1frdj-tp0xwaacr5fuxpdq953.png-wh_500x0-wm_3-wmp_4-s_495037411.png "/>

650) this.width=650; "title=" Qq20160928155232.png "alt=" wkiom1frdsriqjrdaabptz_pcog729.png-wh_50 "src="/HTTP/ S2.51cto.com/wyfs02/m02/88/33/wkiom1frdsriqjrdaabptz_pcog729.png-wh_500x0-wm_3-wmp_4-s_2310579023.png "/>

650) this.width=650; "title=" Qq20160928155324.png "alt=" wkiom1frdwsttdn3aaaktur3kno146.png-wh_50 "src="/HTTP/ S2.51cto.com/wyfs02/m00/88/33/wkiom1frdwsttdn3aaaktur3kno146.png-wh_500x0-wm_3-wmp_4-s_4140018440.png "/>

Retrieving certificates

650) this.width=650; "title=" Qq20160928170901.png "alt=" wkiom1frimhbe7jbaabvv_e33hk021.png-wh_50 "src="/HTTP/ S5.51cto.com/wyfs02/m00/88/35/wkiom1frimhbe7jbaabvv_e33hk021.png-wh_500x0-wm_3-wmp_4-s_565720774.png "/>

STEP7: Recovery certificate for key recovery agent Administrator

650) this.width=650; "Src=" Http://s2.51cto.com/wyfs02/M01/88/40/wKiom1fspw_Bh4xQAAAoqmbPsK4991.png-wh_500x0-wm_3 -wmp_4-s_2736146931.png "title=" QQ20160929132437-copy. png "style=" Float:none; "alt=" Wkiom1fspw_ Bh4xqaaaoqmbpsk4991.png-wh_50 "/>

650) this.width=650; "Src=" Http://s2.51cto.com/wyfs02/M02/88/40/wKiom1fspw-gp1cbAAAx85VtWZQ198.png-wh_500x0-wm_3 -wmp_4-s_3345195347.png "title=" Qq20160929132457.png "style=" Float:none; "alt=" Wkiom1fspw-gp1cbaaax85vtwzq198.png-wh_50 "/>

650) this.width=650; "Src=" Http://s2.51cto.com/wyfs02/M02/88/3C/wKioL1fspxCTWBGiAADibTIJQyk718.png-wh_500x0-wm_3 -wmp_4-s_2081641028.png "title=" QQ20160929132554-copy. png "style=" Float:none; "alt=" Wkiol1fspxctwbgiaadibtijqyk718.png-wh_50 "/>

STEP8: Send to User and register


650) this.width=650; "Src=" Http://s2.51cto.com/wyfs02/M00/88/3C/wKioL1fspxDyQUfFAABZQI8Yixc704.png-wh_500x0-wm_3 -wmp_4-s_773166225.png "style=" Float:none; "title=" QQ20160929132756-copy. png "alt=" Wkiol1fspxdyquffaabzqi8yixc704.png-wh_50 "/>


650) this.width=650; "Src=" Http://s1.51cto.com/wyfs02/M02/88/40/wKiom1fspxGQK5-4AABRQnfHotE272.png-wh_500x0-wm_3 -wmp_4-s_3452530833.png "style=" Float:none; "title=" QQ20160929132806-copy. png "alt=" Wkiom1fspxgqk5-4aabrqnfhote272.png-wh_50 "/>


650) this.width=650; "Src=" Http://s1.51cto.com/wyfs02/M00/88/40/wKiom1fspxLAnG2bAABvo7jur_U191.png-wh_500x0-wm_3 -wmp_4-s_3170767783.png "style=" Float:none; "title=" Qq20160929132852.png "alt=" Wkiom1fspxlang2baabvo7jur_ U191.png-wh_50 "/>

650) this.width=650; "Src=" Http://s1.51cto.com/wyfs02/M02/88/3C/wKioL1fspxKxcc5dAABJOIFFjs4934.png-wh_500x0-wm_3 -wmp_4-s_1014729938.png "style=" Float:none; "title=" Qq20160929132924.png "alt=" Wkiol1fspxkxcc5daabjoiffjs4934.png-wh_50 "/>

650) this.width=650; "Src=" Http://s3.51cto.com/wyfs02/M01/88/3C/wKioL1fspxPRmqZSAACjeXxs8cs943.png-wh_500x0-wm_3 -wmp_4-s_612176265.png "style=" Float:none; "title=" Qq20160929133004.png "alt=" Wkiol1fspxprmqzsaacjexxs8cs943.png-wh_50 "/>




Problems encountered during configuration: 1. An error occurred when the user requested the user certificate to enable the Archive key feature: Certsrv_e_subject_email_required.

650) this.width=650; "title=" Qq20160928164431.png "alt=" wkiol1frgwchocwyaabwml7bil8804.png-wh_50 "src="/HTTP/ S3.51cto.com/wyfs02/m00/88/30/wkiol1frgwchocwyaabwml7bil8804.png-wh_500x0-wm_3-wmp_4-s_2221211395.png "/>

WORKAROUND: The user attribute e-mail field in the ad is written in full.

2, using Kra-admin to retrieve the certificate times wrong.

WORKAROUND: You must be on the CA to retrieve, and only the CA holds all the certificate information.

I think the retrieval of this action is not performed by Kra-admin, should be performed by the CA administrator, and then by the CA administrator to the p7b file to Kra-admin, and finally by Kra-admin recovery, passed to the user installation.

This article is from the "deep sea Big Fat Fish" blog, please be sure to keep this source http://5496038.blog.51cto.com/5486038/1857719

WINSERVER2012R2 Deploying key Recovery agents

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.