ĐĂNG KÝ CHỨNG THƯ WINDOWS

Gắn chứng thư với khóa Windows được bảo vệ

Hồ sơ đăng ký bao phủ tạo CSR, gửi CA, cài chứng thư vào store, gia hạn và gắn lại khóa mà không làm suy yếu chính sách khóa riêng.

01

Trình tự đăng ký

Install signed provider package
Verify provider registration
Create non-exportable persisted key
Generate PKCS#10 CSR
Submit to approved CA/RA
Install issued certificate
Bind certificate to key container
Run sign/verify acceptance corpus

02

Hồ sơ công cụ hỗ trợ

Tool/APIUseRelease record
certreq.exeINF-driven CSR and certificate acceptanceTemplate and command line
CertEnroll COM/APIProgrammatic enrollmentInterface/version tested
Windows certificate storeCertificate discovery and bindingStore and scope
Custom enrollment clientEnterprise workflowSample and error model
Auto-enrollment/GPOOnly when specifically testedNot implied

03

Kiểm soát gia hạn và khôi phục

  • Overlap period for old/new certificate and key.
  • Key reuse versus regeneration policy.
  • Certificate-key association verification.
  • Revocation and rollback procedure.
  • Audit correlation between CSR, issuance and activation.