Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations Mike Lewis on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Secur. certif. on MSIE 6 on WinXP 2002 SP1

Status
Not open for further replies.

Peahippo

MIS
Jul 18, 2003
91
US
I am looking for where MSIE 6 stores its security certificates (Tools, Internet Options, Content, Certificates). Amazingly, by searching for a few company names (of the CAs, like "CyberTrust") on my HDD and registry, I can't find them.

What I'm looking to do is find the area where the personal certificates are stored. Once I know that, I can inspect a machine on my company lan remotely without bothering the user. I am always looking for ways to automate customer support and to reduce the amount of time I spend sitting at customer desks saving or restoring data.
 
Use the mmc and add the Certificate Manager snap-in to a new console view.
 
Although that did show me more information, I still have the problem: I still don't know how to look for certificates remotely since I still don't know where they are physically (meaning, on the user's HDD or in their registry). The MMC is not showing the actual location of the certificates themselves.

Can the MMC be used to inspect a user's machine remotely?
 
At base, registry=hdd

So yes, they are stored on a hard disk device. Where depends on the type of logical store. The logical store depends on whether they are root, machine, or user certificates, and whether the computer is part of an AD Domain.

See:
You raised a second question: can I run the mmc remotely. Yes, use Remote Desktop or similar facility.

You implied a third: can I read the certificates stores outside the mmc. No. They are encrypted, and oddly with not just one encryption schema. The mmc has to be able to handle DER (.cer), Base-64 (.cer), PKCS #7 (.p7b) files, and #PKCS #12 (.pfx) certificates.
 
I am after personal certificates -- more pointedly, their index -- since when I replace a user's machine they are lost with the old HDD. If I can confirm they exist, I can then try to find the *.PFX files that the user obtained the certs from in the 1st place.

The problem I am running into is that a clear disk path or registry key are not being used to describe all of this virtual "store" stuff. The link you gave me doesn't say:

1. The "certificate store" is located in C:\Windows\Whatever

OR

2. The "certificate store" is located in HKEY_LOCAL_MACHINE\Software\Microsoft\EnterpriseCertificates\Whatever

The encrypting of the certificates doesn't matter, since the index to the certificates must contain plaintext of what I'm looking for.

Also, the less bothersome the inspection, the better. My goal is to inspect the user's machine remotely and without their noticing. Then I show up with their replacement machine, having pre-loaded time-consuming things like applications and printer settings, and prepared to load things like security certificates while at their desks in the minimum time.

I used the MMC (with Certificates snap-in) to connect to one user's machine who has a personal certificate, but it failed to show the existence of her certificate.
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top