Want to win a PS4? Go Premium and enter to win our High-Tech Treats giveaway. Enter to Win


Imported Certificate Problems - signing data with your private exchange key

Posted on 2004-08-04
Medium Priority
Last Modified: 2013-12-04

We have a website that requires certificates.  We have imported the certificate onto our system (windows 2000 SP4) at a client site (not within our domain).  When the user gets in to use the application, the application works but they receive continuous messages (depending on what we do within the application), with a window titled Private Key Container and is an informational window stating 'signing data with your private exchange key' but does not ask for a password.  We did have two certificates for the same site on the system, but have since removed one eventhough it did ask us which one we wanted to use for the site.

We have reviewed security settings for the internet, SSL on the web server but have not found the culprit.  We still have not tested it on another system at the client site, that is happening later this week.

If anyone understands why we are receiveing this informational window we would greatly appreciate the feedback.


Question by:spinewr
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
  • 2

Expert Comment

ID: 11716926
You need to make sure the cert is configured for the url you are using.

Author Comment

ID: 11717058
Thanks for the info.  
The cert is an actual working one for the application.  It was exported and emailed to the client.  The client imported it and here we are with this problem.  I wish I was more familiar with configuring certs for urls, but I am not.  Is there a way to check and make sure it is configured for the url?  Or is there a way to check to see if it is corrupt?

Both of these answers could narrow down the hunt!


Expert Comment

ID: 11717120
When you or verisign build the certificate you have to enter the url (or give it to them) of the site exactly so if its http://xxx.xxxxx.com that’s what you have to enter.

Author Comment

ID: 11720067
Yes, after checking this out it was done correctly.  Can anyone answer my other question?  How can you tell you have a corrupt cert.  The problem may just be on one pc and not all over.  The problem is I need to have the certificate reissued or export the certificate onto the next box, but I can't tell if the certificate I am using is ok or not.  I am also a long way from home so I can't test this exported cert on a box I know normally works.

Any help would be great!
LVL 34

Accepted Solution

Dave_Dietz earned 750 total points
ID: 11726415
This is default behavior for a Personal Certificate that has been set to use Medium Security when imported.  If it was set to High you would be prompted for a password every time the certificate was accessed.

The URL has nothing to do with it - that requirement is for SSL Cewrtificates, not for Personal (Client) Certificates. (Additionally, if you include the http:// in the common name of the certificate it will not function properly since that is not part of the Host field in a standard HTTP/1.1 compliant request)

If your certificate was corrupt you would likely not even get to the point of being told it was being used.  To make sure you could try sending an encrypted or digitally signed message to yourself.  If you can read it properly your certificate is fine.

Hope this helps.

Dave Dietz


Featured Post

Q2 2017 - Latest Malware & Internet Attacks

WatchGuard’s Threat Lab is a group of dedicated threat researchers committed to helping you stay ahead of the bad guys by providing in-depth analysis of the top security threats to your network.  Check out our latest Quarterly Internet Security Report!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Since pre-biblical times, humans have sought ways to keep secrets, and share the secrets selectively.  This article explores the ways PHP can be used to hide and encrypt information.
Ransomware is a growing menace to anyone using a computer or mobile device. Here are answers to some common questions about this vicious new form of malware.
With Secure Portal Encryption, the recipient is sent a link to their email address directing them to the email laundry delivery page. From there, the recipient will be required to enter a user name and password to enter the page. Once the recipient …
The Email Laundry PDF encryption service allows companies to send confidential encrypted  emails to anybody. The PDF document can also contain attachments that are embedded in the encrypted PDF. The password is randomly generated by The Email Laundr…
Suggested Courses

618 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question