Skip to main content
Skip table of contents

Key Archival: Recovery

EJBCA allows the CA Administrator to recover the private key, given that key recovery was enabled for the end entity profile when the certificate was created. For information on enabling key recovery for end entity profiles, see Part 3a: EJBCA Configuration.

To recover the private key, do the following:

  1. Open the Microsoft Management Console (mmc.exe).
  2. Click File, then click Add/Remove Snap-in.
  3. Choose Certificates and then click Add, then click OK.
  4. Expand Certificates - Current User, then expand Personal, and click Certificates.
  5. Double-click the certificate for which the private key needs to be recovered, to open the certificate information window.
  6. Open the Details tab.
  7. Select the Serial number row to display the serial number in the text area below the list.
  8. Copy the HEX formatted serial number.
  9. In EJBCA, click RA Web.
  10. Hold the pointer over Search, and then click Certificates to open search certificate page.
  11. On the Search for Certificates page, paste the serial number in the search text field.
  12. Remove spaces between the letters in the serial number to display a row of information about the certificate.
  13. Click View at the end of the row to view the certificate details.
  14. Click Recover Key and enter the following:
    • Enter Enrollment Code (New).
    • Enter Confirm Enrollment Code.
    • Copy End Entity Identifier (username).
  15. Click Confirm request to display a confirmation message at the top of the page saying Key recovery performed successfully. Certificate ready for enrollment.
  16. Click Use Username under Enroll.
  17. On the Enroll with Enrollment code page:
    • Paste the Username.
    • Enter an Enrollment code.
  18. Click Check.
  19. Click Download PKCS#12 to download the .p12 file containing the private key.
  20. Transfer the file to the target computer.
  21. Right-click the file, select Install PFX and follow the on-screen instructions.

You have now completed the steps to recover the private key.


JavaScript errors detected

Please note, these errors can depend on your browser setup.

If this problem persists, please contact our support.