Article ID: 919074 - Last Review: December 3, 2007 - Revision: 1.2 You receive an error message when you try to import an SSL private key certificate (.pfx) file into the local computer personal certificate store by using IIS ManagerImportant This article contains information about how to modify the registry. Make sure to back up the registry before you modify it. Make sure that you know how to restore the registry if a problem occurs. For more information about how to back up, restore, and modify the registry, click the following article number to view the article in the Microsoft Knowledge Base: 256986
(http://support.microsoft.com/kb/256986/
)
Description of the Microsoft Windows registry On This PageSYMPTOMSYou try to import a Secure Sockets Layer (SSL) private key certificate (.pfx) file into the local computer personal certificate store. When you do this, you may experience one of the following symptoms depending on how you try to import the .pfx file:
CAUSEThis behavior occurs when one or more of the following conditions are true:
RESOLUTIONTo resolve this behavior, use one or more of the following methods, as appropriate for your situation. Method 1: Set the correct permissions for the MachineKeys folderIf you have insufficient permissions to access the DriveLetter:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys folder on the computer, set the correct permissions for the folder. For more information about how to set the permissions for the MachineKeys folder, click the following article number to view the article in the Microsoft Knowledge Base:278381
(http://support.microsoft.com/kb/278381/
)
Default permissions for the MachineKeys folders
Method 2: Delete the third-party registry subkeyWarning Serious problems might occur if you modify the registry incorrectly by using Registry Editor or by using another method. These problems might require that you reinstall your operating system. Microsoft cannot guarantee that these problems can be solved. Modify the registry at your own risk.If the following registry subkey exists, delete it: HKEY_USERS\Default\Software\Microsoft\Cryptography\Providers\Type 001 After you delete this registry subkey, IIS can access the cryptographic service provider.Method 3: Store the user profile for the Terminal Services session locallyIf the user profile for the Terminal Services session is not stored locally on the server that has Terminal Services enabled, move the user profile to the server that has Terminal Services enabled. Alternatively, use roaming profiles. For more information about how to set up and administer user profiles, visit the following Microsoft Web site:http://technet2.microsoft.com/WindowsServer/en/library/23ee2a30-5883-4ffa-b4cf-4cfff3ff8cb71033.mspx
(http://technet2.microsoft.com/WindowsServer/en/library/23ee2a30-5883-4ffa-b4cf-4cfff3ff8cb71033.mspx)
STATUS This behavior is by design. | Article Translations
|
Back to the top
