In the daily use of the computer process, will inevitably encounter computer failure, the corresponding computer or user certificate will be lost. There are basically these things that are missing: User profile corruption, operating system crashes, man-made malicious removal, hard disk physical failure ... For this kind of situation, the key recovery agent can be solved very well.
Key recovery agent procedures are: 1 specifies that the user becomes the key recovery agent Administrator
2 Key Recovery agent Administrator retrieves certificates by certificate serial number
3 Key Recovery agent Administrator Recovery certificate, sent to user
4 User Request Certificate
Configuration process:
Step1: Specifies that the user becomes the key recovery agent Administrator
650) this.width=650; "title=" Qq20160928124016.png "alt=" wkiol1frscrbffppaac1dpsgw_w752.png-wh_50 "src="/HTTP/ S4.51cto.com/wyfs02/m01/88/2d/wkiol1frscrbffppaac1dpsgw_w752.png-wh_500x0-wm_3-wmp_4-s_2417517587.png "/>
650) this.width=650; "title=" Qq20160928133201.png "alt=" wkiol1frvepgkpcxaab6ms1so_q777.png-wh_50 "src="/HTTP/ S3.51cto.com/wyfs02/m02/88/2d/wkiol1frvepgkpcxaab6ms1so_q777.png-wh_500x0-wm_3-wmp_4-s_748107504.png "/>
650) this.width=650; "title=" Qq20160928133659.png "alt=" wkiol1frvxsclcjcaac1gf1n9fy811.png-wh_50 "src="/HTTP/ S2.51cto.com/wyfs02/m02/88/2d/wkiol1frvxsclcjcaac1gf1n9fy811.png-wh_500x0-wm_3-wmp_4-s_2995377826.png "/>
Step2: User registered key recovery agent certificate
650) this.width=650; "title=" Qq20160928140311.png "style=" Float:none "alt=" Wkiol1frxbmhfb1aaabso8u8dk0734.png-wh_ "Src=" Http://s5.51cto.com/wyfs02/M01/88/2D/wKioL1frXbmhfb1AAABSO8U8dK0734.png-wh_500x0-wm_3-wmp_4-s_ 1410397889.png "/>
650) this.width=650; "title=" Qq20160928140436.png "style=" Float:none "alt=" Wkiol1frxbrciim8aabbz6bxisk138.png-wh_ "Src=" Http://s4.51cto.com/wyfs02/M02/88/2D/wKioL1frXbrCiim8AABbz6bxisk138.png-wh_500x0-wm_3-wmp_4-s_ 4164626456.png "/>
Cut back to CA, issue KRA certificate
650) this.width=650; "title=" Qq20160928140453.png "alt=" wkiol1frxj_ygaq-aacqyxmpapm645.png-wh_50 "src="/HTTP/ S1.51cto.com/wyfs02/m01/88/2d/wkiol1frxj_ygaq-aacqyxmpapm645.png-wh_500x0-wm_3-wmp_4-s_2643525425.png "/>
650) this.width=650; "title=" Qq20160928140527.png "style=" Float:none "alt=" Wkiom1frxbvtcbhraacebznyrto062.png-wh_ "src=" Http://s1.51cto.com/wyfs02/M02/88/31/wKiom1frXbvTCBHrAACeBzNYRto062.png-wh_500x0-wm_3-wmp_4-s_40071023.png "/>
Step3: Setting up a recovery agent
650) this.width=650; "title=" Qq20160928141029.png "alt=" wkiom1frxvtsjcv8aabycao1vam232.png-wh_50 "src="/HTTP/ S2.51cto.com/wyfs02/m00/88/31/wkiom1frxvtsjcv8aabycao1vam232.png-wh_500x0-wm_3-wmp_4-s_3659545871.png "/>
650) this.width=650; "title=" Qq20160928141200.png "alt=" wkiol1frx0dy_vrmaablwtoeb8q307.png-wh_50 "src="/HTTP/ S4.51cto.com/wyfs02/m00/88/2d/wkiol1frx0dy_vrmaablwtoeb8q307.png-wh_500x0-wm_3-wmp_4-s_1426351618.png "/>
Step4: Setting up a new user certificate template, enabling archiving
650) this.width=650; "title=" Qq20160928154000.png "alt=" wkiom1frc9rqltvhaabmkybt1aq790.png-wh_50 "src="/HTTP/ S3.51cto.com/wyfs02/m00/88/33/wkiom1frc9rqltvhaabmkybt1aq790.png-wh_500x0-wm_3-wmp_4-s_1468742445.png "/>
650) this.width=650; "title=" Qq20160928141936.png "alt=" wkiol1fryqxdamziaaclk4vwozg434.png-wh_50 "src="/HTTP/ S1.51cto.com/wyfs02/m01/88/2d/wkiol1fryqxdamziaaclk4vwozg434.png-wh_500x0-wm_3-wmp_4-s_1727219060.png "/>
650) this.width=650; "title=" Qq20160928141828.png "alt=" wkiom1fryn6wouteaaawwny9gso510.png-wh_50 "src="/HTTP/ S4.51cto.com/wyfs02/m00/88/31/wkiom1fryn6wouteaaawwny9gso510.png-wh_500x0-wm_3-wmp_4-s_1309897872.png "/>
PS: Archive only for subsequent user certificates
STEP5: User request to enable archived user certificate
650) this.width=650; "title=" Qq20160928153812.png "alt=" wkiol1frc22qzle-aabhtg9vfm4800.png-wh_50 "src="/HTTP/ S1.51cto.com/wyfs02/m00/88/2f/wkiol1frc22qzle-aabhtg9vfm4800.png-wh_500x0-wm_3-wmp_4-s_3035279370.png "/>
650) this.width=650; "title=" Qq20160928153517.png "alt=" wkiol1frcszzpkujaabjlm8rms4729.png-wh_50 "src="/HTTP/ S3.51cto.com/wyfs02/m02/88/2f/wkiol1frcszzpkujaabjlm8rms4729.png-wh_500x0-wm_3-wmp_4-s_2537117729.png "/>650 ) this.width=650; "title=" Qq20160928153621.png "alt=" wkiol1frcv_gy3n0aac0qyrr_v4695.png-wh_50 "src=" http:// S5.51cto.com/wyfs02/m02/88/2f/wkiol1frcv_gy3n0aac0qyrr_v4695.png-wh_500x0-wm_3-wmp_4-s_3584866607.png "/>
STEP6: Key Recovery agent Administrator retrieves certificates
Retrieving jx001 certificates
PS: There are two user certificates in jx001, 16 is a certificate that does not have archiving enabled, and 20 is a certificate that has the archive feature enabled. Attention!!!
Open 20 certificate, copy serial number, send to kra-admin for retrieval
650) this.width=650; "title=" Qq20160928155011.png "alt=" wkiom1frdj-tp0xwaacr5fuxpdq953.png-wh_50 "src="/HTTP/ S5.51cto.com/wyfs02/m00/88/33/wkiom1frdj-tp0xwaacr5fuxpdq953.png-wh_500x0-wm_3-wmp_4-s_495037411.png "/>
650) this.width=650; "title=" Qq20160928155232.png "alt=" wkiom1frdsriqjrdaabptz_pcog729.png-wh_50 "src="/HTTP/ S2.51cto.com/wyfs02/m02/88/33/wkiom1frdsriqjrdaabptz_pcog729.png-wh_500x0-wm_3-wmp_4-s_2310579023.png "/>
650) this.width=650; "title=" Qq20160928155324.png "alt=" wkiom1frdwsttdn3aaaktur3kno146.png-wh_50 "src="/HTTP/ S2.51cto.com/wyfs02/m00/88/33/wkiom1frdwsttdn3aaaktur3kno146.png-wh_500x0-wm_3-wmp_4-s_4140018440.png "/>
Retrieving certificates
650) this.width=650; "title=" Qq20160928170901.png "alt=" wkiom1frimhbe7jbaabvv_e33hk021.png-wh_50 "src="/HTTP/ S5.51cto.com/wyfs02/m00/88/35/wkiom1frimhbe7jbaabvv_e33hk021.png-wh_500x0-wm_3-wmp_4-s_565720774.png "/>
STEP7: Recovery certificate for key recovery agent Administrator
650) this.width=650; "Src=" Http://s2.51cto.com/wyfs02/M01/88/40/wKiom1fspw_Bh4xQAAAoqmbPsK4991.png-wh_500x0-wm_3 -wmp_4-s_2736146931.png "title=" QQ20160929132437-copy. png "style=" Float:none; "alt=" Wkiom1fspw_ Bh4xqaaaoqmbpsk4991.png-wh_50 "/>
650) this.width=650; "Src=" Http://s2.51cto.com/wyfs02/M02/88/40/wKiom1fspw-gp1cbAAAx85VtWZQ198.png-wh_500x0-wm_3 -wmp_4-s_3345195347.png "title=" Qq20160929132457.png "style=" Float:none; "alt=" Wkiom1fspw-gp1cbaaax85vtwzq198.png-wh_50 "/>
650) this.width=650; "Src=" Http://s2.51cto.com/wyfs02/M02/88/3C/wKioL1fspxCTWBGiAADibTIJQyk718.png-wh_500x0-wm_3 -wmp_4-s_2081641028.png "title=" QQ20160929132554-copy. png "style=" Float:none; "alt=" Wkiol1fspxctwbgiaadibtijqyk718.png-wh_50 "/>
STEP8: Send to User and register
650) this.width=650; "Src=" Http://s2.51cto.com/wyfs02/M00/88/3C/wKioL1fspxDyQUfFAABZQI8Yixc704.png-wh_500x0-wm_3 -wmp_4-s_773166225.png "style=" Float:none; "title=" QQ20160929132756-copy. png "alt=" Wkiol1fspxdyquffaabzqi8yixc704.png-wh_50 "/>
650) this.width=650; "Src=" Http://s1.51cto.com/wyfs02/M02/88/40/wKiom1fspxGQK5-4AABRQnfHotE272.png-wh_500x0-wm_3 -wmp_4-s_3452530833.png "style=" Float:none; "title=" QQ20160929132806-copy. png "alt=" Wkiom1fspxgqk5-4aabrqnfhote272.png-wh_50 "/>
650) this.width=650; "Src=" Http://s1.51cto.com/wyfs02/M00/88/40/wKiom1fspxLAnG2bAABvo7jur_U191.png-wh_500x0-wm_3 -wmp_4-s_3170767783.png "style=" Float:none; "title=" Qq20160929132852.png "alt=" Wkiom1fspxlang2baabvo7jur_ U191.png-wh_50 "/>
650) this.width=650; "Src=" Http://s1.51cto.com/wyfs02/M02/88/3C/wKioL1fspxKxcc5dAABJOIFFjs4934.png-wh_500x0-wm_3 -wmp_4-s_1014729938.png "style=" Float:none; "title=" Qq20160929132924.png "alt=" Wkiol1fspxkxcc5daabjoiffjs4934.png-wh_50 "/>
650) this.width=650; "Src=" Http://s3.51cto.com/wyfs02/M01/88/3C/wKioL1fspxPRmqZSAACjeXxs8cs943.png-wh_500x0-wm_3 -wmp_4-s_612176265.png "style=" Float:none; "title=" Qq20160929133004.png "alt=" Wkiol1fspxprmqzsaacjexxs8cs943.png-wh_50 "/>
Problems encountered during configuration: 1. An error occurred when the user requested the user certificate to enable the Archive key feature: Certsrv_e_subject_email_required.
650) this.width=650; "title=" Qq20160928164431.png "alt=" wkiol1frgwchocwyaabwml7bil8804.png-wh_50 "src="/HTTP/ S3.51cto.com/wyfs02/m00/88/30/wkiol1frgwchocwyaabwml7bil8804.png-wh_500x0-wm_3-wmp_4-s_2221211395.png "/>
WORKAROUND: The user attribute e-mail field in the ad is written in full.
2, using Kra-admin to retrieve the certificate times wrong.
WORKAROUND: You must be on the CA to retrieve, and only the CA holds all the certificate information.
I think the retrieval of this action is not performed by Kra-admin, should be performed by the CA administrator, and then by the CA administrator to the p7b file to Kra-admin, and finally by Kra-admin recovery, passed to the user installation.
This article is from the "deep sea Big Fat Fish" blog, please be sure to keep this source http://5496038.blog.51cto.com/5486038/1857719
WINSERVER2012R2 Deploying key Recovery agents