ĐĂNG KÝ CHỨNG THƯ WINDOWS
Gắn chứng thư với khóa Windows được bảo vệ
Hồ sơ đăng ký bao phủ tạo CSR, gửi CA, cài chứng thư vào store, gia hạn và gắn lại khóa mà không làm suy yếu chính sách khóa riêng.
01
Trình tự đăng ký
Install signed provider package
Verify provider registration
Create non-exportable persisted key
Generate PKCS#10 CSR
Submit to approved CA/RA
Install issued certificate
Bind certificate to key container
Run sign/verify acceptance corpus02
Hồ sơ công cụ hỗ trợ
| Tool/API | Use | Release record |
|---|---|---|
| certreq.exe | INF-driven CSR and certificate acceptance | Template and command line |
| CertEnroll COM/API | Programmatic enrollment | Interface/version tested |
| Windows certificate store | Certificate discovery and binding | Store and scope |
| Custom enrollment client | Enterprise workflow | Sample and error model |
| Auto-enrollment/GPO | Only when specifically tested | Not implied |
03
Kiểm soát gia hạn và khôi phục
- Overlap period for old/new certificate and key.
- Key reuse versus regeneration policy.
- Certificate-key association verification.
- Revocation and rollback procedure.
- Audit correlation between CSR, issuance and activation.
