Windows IT Pro is the authoritative and independent resource for windows nt, windows 2000, windows 2003, windows xp. Features a collection of resources and magazines for windows IT professionals.
  
  
  Advanced Search 



JSI Tip 5573. Microsoft Enhanced CSP Is NOT supported for Certificate Services installations?

RSS
Subscribe to Windows IT Pro | See More Security Articles Here | Reprints | Or get the Monthly Online Pass—only $5.95 a month!


5573 » Microsoft Enhanced CSP Is NOT supported for Certificate Services installations? 01-Aug-02


NOTE: The text in the following Microsoft Knowledge Base article is provided so that the site search can find this page. Please click the Knowledge Base link to insure that you are reading the most current information.

Microsoft Knowledge Base article Q254150 contains:

With the advanced installation of Certificate Services, an administrator can choose which cryptographic service provider (CSP) the Certification Authority (CA) uses for cryptographic operations. Although the Microsoft Enhanced CSP appears to be an available option, the Microsoft Enhanced CSP is not supported for use on the key pair for the CA.

MORE INFORMATION

There is no advantage or cryptographic strength increase in using the Microsoft Enhanced CSP to generate the CA's key pair. A CA performs only signing operations, which have the same limits in the Microsoft Base CSP and the Microsoft Enhanced CSP.

The primary difference between the Microsoft Base CSP and the Microsoft Enhanced CSP is the supported key size for data encryption operations. The Base CSP supports a maximum encryption key length of 1,024 bits, and the Enhanced CSP supports a maximum encryption key length of 16,384 bits.

A CA performs signing operations on issued certificates, Certificate Revocation Lists (CRLs), and the Certificate Services database. A Certification Authority (CA) does not perform any encryption operations. There is no benefit in using the Microsoft Enhanced CSP provider with Certificate Services. The maximum key length for digital signature operations for both CSPs is 16,384 bits.

There is no relationship between the signing technology that is used by the CA and the encryption capabilities of a client. A client can choose to use any supported key length for data encryption regardless of the length of the Certification Authority's key.

If Certificate Services has already been installed with the Microsoft Enhanced CSP, you can back up the CA certificate and private key and reinstall the CA. After the CA is reinstalled, select the Microsoft Base Cryptographic Service Provider, and then choose to use an existing keyset.

For information about how to back up, remove, and reinstall the Certification Authority, see:
Q313272 HOW TO: Back Up and Restore a Certificate Authority in Windows
Q231881 How to Install/Uninstall a Public Key Certificate Authority
For additional information about how to back up and restore a Microsoft Certificate Authority, click the article number below to view the article in the Microsoft Knowledge Base:

Q298138 HOW TO: Move a Certification Authority to Another Server


End of Article



Reader Comments

You must log on before posting a comment.

If you don't have a username & password, please register now.




Top Viewed ArticlesView all articles
Friday at PASS Europe 2006

Kevin talks about the closing day of the event and shares a funny Microsoft film. ...

PsExec

This freeware utility lets you execute processes on a remote system and redirect output to the local system. ...

Escape From Yesterworld

Kevin points you to the funniest SQL Server website ever! ...


Security Whitepapers The Impact of Messaging and Web Threats

Why SaaS is the Right Solution for Log Management

Protecting (You and) Your Data with Exchange Server 2007

Related Events How IE7 & The New Extended Validation SSL Certificates Impact Your Site

Top 10 Email Security Challenges and Solutions

Check out our list of Free Email Newsletters!

Security eBooks Spam Fighting and Email Security for the 21st Century

Understanding and Leveraging Code Signing Technologies

A Guide to Windows Certification and Public Keys

Related Security Resources Become a VIP member of the Windows IT Pro community!
Get it all with the VIP CD and VIP access. A $500+ value for only $279!

Subscribe to Windows IT Pro!
Solve your toughest technical problems with our experts and access 10,000 + articles online. 30% off

Monthly Online Pass - Only $5.95!
Get instant access to 10,000+ articles from Windows IT Pro Magazine!

TechNet Virtual Labs
Evaluate and test Microsoft's newest products.


Windows IT Pro Home Register FAQ for Windows WinInfo News
Europe Edition About Us Contact Us/Customer Service Media Kit Affiliates / Licensing  
SQL Server Magazine Office & SharePoint Pro Windows Dev Pro IT Job Hound ITTV
IT Library Technology Resource Directory Connected Home Windows Excavator Windows SuperSite 
 
 Windows IT Pro is a Division of Penton Media Inc.
 Copyright © 2008 Penton Media, Inc., All rights reserved. Terms and Use | Privacy Statement | Reprints and Licensing