Identify a key recovery agent
Updated: November 5, 2012
Applies To: Windows Server 2003, Windows Server 2003 R2, Windows Server 2003 with SP1, Windows Server 2003 with SP2
To identify a key recovery agent
Log on to the system as a Certification Authority Administrator.
Open Certification Authority.
In the console tree, click the name of the certification authority (CA).
Certification Authority (Computer)/CA name
- Certification Authority (Computer)/CA name
On the Action menu, click Properties.
On the Recovery Agents tab, click Archive the key.
In the Number of recovery agents to use box, type the number of key recovery agents that will be used to encrypt the archived key.
Click Add to add key recovery agent certificates.
To open Certification Authority, click Start, click Control Panel, double-click Administrative Tools, and then double-click Certification Authority.
To add key recovery agents, the Number of recovery agents to use must be 1 or more.
If the Number of recovery agents to use value exceeds the number of recovery agent certificates with the status of "Valid," enrollment requests that require key archival will fail.
This procedure configures a certification authority to archive private keys when issuing certificates based on templates that have key archival configured. For more information about configuring certificate templates for key archival, see Related Topics.
When the recovery agent certificates are added to the CA, a status is displayed for each certificate. Status can be one of the following values and causes:
The certificate's expiration date has passed so the certificate cannot be used.
The certificate may be malformed or causes and error when loading.
The certificate was configured but cannot be located by the CA.
The certificate was configured but has not yet been loaded by the CA.
The certificate has been revoked and cannot be used.
The root CA for this certificate is not trusted by the CA.
The certificate has been loaded by the CA and is operating normally.
Information about functional differences
Your server might function differently based on the version and edition of the operating system that is installed, your account permissions, and your menu settings. For more information, see Viewing Help on the Web.