Migrating the CA from 2008 to 2012 PKI ?

Hi All,
I am using the HSM in my PKI environment and i performing the migration of CA from 2008 PKI to 2012 PKI. What i noticed is if the private key of CA is protected by OCS card then i don't see the CA certificate while running the  Microsoft wizard at the
option of choose the existing certficate and private key but if i change the protection of private key to module or default protection then i am able to see the certificate and able to complete the migration.
So is there a way i can still do the migration of CA without changing the protection of private key from OCS to module or default protection ?? 
Puneet Singh

Hi Brian ,
I tried your solution but its not working please find the details below. Can you please let me know if i have missed anything while trying it .
Note : OCS card are PIN protected .
1) install the nCipher software. (Successfull)
2) Copy the %nfast_kmdata%\local folder and %nfast_kmdata%\config folders to the 2012 R2 server ( Sucessfull verified by
running enquiry and nfkminfo)
3) Import the CA certificate into the MY store (certutil -addstore my CA.crt) ( Successfull ) 
4) Re-attach the key (certutil -repairstore MY serialnumber)
( Sucessfull as i got the below output 
C:\Program Files (x86)\nCipher\nfast\bin>certutil -repairstore MY "1d 37 f3 31 d
2 06 b5 9c 43 3a 59 d3 d8 a2 96 90"
MY "Personal"
================ Certificate 0 ================
Serial Number: 1d37f331d206b59c433a59d3d8a29690
Issuer: CN=ROOT-CA-SRC-CA
 NotBefore: 2/7/2015 12:23 PM
 NotAfter: 2/7/2020 12:29 PM
Subject: CN=ROOT-CA-SRC-CA
CA Version: V0.0
Signature matches Public Key
Root Certificate: Subject matches Issuer
Cert Hash(sha1): 5a b6 38 e9 fd bb e4 1c c8 a2 a0 94 b7 ba 45 c0 44 3a 5b 9a
  Key Container = ROOT-CA-SRC-CA
  Provider = nCipher Security World Key Storage Provider
Private key is NOT exportable
Signature test passed
CertUtil: -repairstore command completed successfully.
5)
Run the installation wizard using the existing key pair (will now be visible) ( Failed : I started the wizard and i didn't see the cert 
Please
find the screen shot below
Puneet Singh

Similar Messages

  • Is it possible to migrate the app from latest version to older version

    Hi all,
    I have a adf application in jdeveloper 11.1.1.4.0.Due to some issues i have to do it in jdeveloper 11g release 2 (11.1.1.2.0).Is it possible to migrate the application from latest version to older version of jdev.
    Thanks.

    It's not officially supported, but you can try a couple of things - first open the application in the old version and see if it works.
    If it doesn't you can try creating a new application in the old version and then use the create project from existing source option to map to your existing code.
    This all of course assumes that you didn't use features in the new version that are not available in the old version.

  • How to migrate the data from DB to another DB

    Hi folks,
                 In my project I have one requirement. Let me explain in detail we are maintain two databases one for
                 master database called *GIIS* and one is history database HIST. Both DB version is 10g R1.
                 (Both DB’s have same no table as well structures)
                 1.  The GIIS database contains nearly 400 tables (master table as well as temporary table)   
                       each Master table having it’s own temporary table.
                 2. Whenever we made the entry first it will go to temporary table after authorized that entry it will move to the master table
                 3. But the temporary table contains the data after move to master table .
                 4.     The temporary table data’s will be move to the HIST database each and every day at the night.
                    This migration we done through the procedure.  After migration complete the temporary table data’s will de deleted.
    My Question:
               1.     Whether it’s good practice to migrate the data from GIIS DB to another HIST DB using oracle stored procedure.
                     (we created the DB link from GIIS to HIST) 
               2.     If not can any one suggest me the way to migrate the data from GIIS to HIST.?
               3.     Is there any other possibility to migrate the data from GIIS to HIST with out using procedure?Thanks
    Arun

    Arun wrote:
    Hi Mr.Aman Brother
    First of all sorry . I am not saying that don't command my requirement. Just i want know the way of migrate the data from one DB to another DB.
    you saying that IMPORT/EXPORT is one of the way to do migration.
    But in client side they don't know how to do the IMPORT & EXPORT the database..
    Can you suggest me the another way to do that
    Arun,
    If the client doesn't know how to do exp/imp, I would really doubt and would be immensely concerned before suggesting the client any other way. If they don't know, tell them that there is a concept called test database which is used for learning so they should invest time to learn this technique since the other options suggested by fellow members are far more tougher than this one.
    Aman....

  • Hi, i try to migrate the HSC0 from version 6.1 to version 7.1 HELP !!!

    Hi, i try to migrate the HSC0 from version 6.1 to version 7.1 and take this opportunity to consult on the installation of HSC0 where the PARMLIB member LKEYINFO (LKEYDEF) Product for this new version V 7.1 is telling me no longer supported, please I would like to confirm if this is so, and where i set the license application for this new version.
    SLS1511I LKEYDEF DSN('SYS3.ORA.ELS.V700.TGT.VEN1.PARMLIB(-
    SLS1511I LKEYINFO)')
    SLS4639I LKEYDEF COMMAND IS NO LONGER SUPPORTED

    Hi;
    Is it related with Configuring and Managing SMC? If yes review:
    http://docs.oracle.com/cd/E21395_02/en/E28330_02/E28330_02.pdf
    Regard
    Helios

  • I recently bought a MacBook Air.  I migrated the info from my old MacBook to the new Air.  None of my contacts migrated.  I still have them on my old Macbook, Ipad and iPhone.  How do I get them to the new Air?

    I recently bought a MacBook Air.  I migrated the info from my old MacBook to the new Air.  None of my contacts migrated.  I still have them on my old Macbook, Ipad and iPhone.  How do I get them to the new Air?

    You can copy the iWeb application from the desktop machine to your new MBA.  But if it's iWeb 2 it won't work with Mavericks or Mt. Lion. Also  copy the Domain.sites file from the desktop to your MBA as that's the file with your webstite files in it.
    Happy New Year

  • HT4796 have migrated the info from old pc to mac, but cant access it, and ideas?

    i have migrated the info from my old PC, but cannot access it, any advice please?

    Do this from the system preferences window.
    Click on Users&Groups.
    Click on the padlock (bottom left) to unlock it if it's not unlocked.
    Then highlight the account in the left pane that you want to remove...
    and then click on the MINUS symbol on the bottom left of that window.
    Just make sure when you delete an account, that you're currently NOT LOGGED INTO that account, or it's not going to work.
    Feel free to chose the delete home-folder option when it prompts you.

  • Problem while migrating the extensions from one instance to the other.

    Hi,
    We are using kintana workbench to migrate the objects from one instance to the other. But after migrating From Instance1 to Intance2 it ws fine. Working properly in Instance2. But when the same package is migrated to Instance3, all are migrated successfully and log files are showing proerly. But when i access the pages in Instance3, I am getting the errors on the page above like this:
    ViewObject attribute is null; ViewUsageName: (ScorecardSummaryVO1); RegionItem: (LastUpdateLogin)
    Can some let me know what could be the problem.
    Thanks.

    user555006,
    Error shows that LastUpdateLogin item on the page has no proper VO attribute attached. Hence it seems that the MDS data is not updated properly. Upload the page again and test.
    --Shiv                                                                                                                                                                                                                                                                                                                                                                                                                       

  • Migrate the email from Blackberry to outlook

    Hi
    I use the pop3 email service to receiving the email on my BB, I would like to migrate the email from my BB to my outlook (pst file). I have installed the desktop software, but the intellisync can't choose the email for sync. Is there any way can achieve it ? Thanks

    BIS doesnt actually download email from your POP3 account, it will still exist on the server so just setup the POP3 account in outlook and download the email directly. If you still wish to keep the email on your blackberry ensure you tick the option "leave mail on server" in the account options in Outlook. 

  • How to migrate the data from DEC RDB 5.1 to Oracle 11g

    Hi,
    As part of my project, we need to migrate the data from DEC RDB 5.1 present on Alpha server with VMS 6.1 OS into Oracle 11g. The size of the data in DEC RDB is around 40 GB.
    Could you please suggest various ways of getting this done in easy and simpler way?
    Thanks in advance.

    Hello,
    when Oracle bought Rdb from Digital Equipment Corporation (DEC) in 1994, the name of the product changed from DEC Rdb to Oracle Rdb. Meanwhile the actual version of Rdb is 7.2, so you are on a VERY old version. And that excludes the suggestions from the mentioned note to use a database link from Oracle RDBMS to Rdb, that is simply not possible with that old version of Rdb.
    But Rdb 5.1 knew already the Rdb Management Utility (RMU) - I just checked that with Rdb 4.1 which is even older.
    There are two commands that are helpful for your task.
    RMU/EXTRACT - that writes the metadata into a file. That output helps you to build a script to create all the objects in your target database.
    RMU/UNLOAD - that writes the data of each table into a formatted file (one file per table). That output can be used by the SQL*Loader to load your data into the target database.
    You can read all details about these commands in the online help on your Alpha. At first, issue the HELP command and look in the output list whether it lists a command RMU or RMU51. Then run that command:
    $ help rmu /extract
    and
    $ help rmu /unload
    Replace rmu by rmu51 if the help command shows you that rmu51 exists but not rmu.
    There is one caveat. Do you use blobs in your Rdb database? If you don't know that, create an the output with RMU/EXTRACT and search the output file for the string LIST OF BYTE VARYING. If there are none then you have no blobs. If you have some you need to take more care of them, they can't be unloaded into a formatted file, that must happen programmatical. If you have such fields then let me know, then I'll tell you how to get them out of your Rdb database.
    Best regards
    Wolfgang
    P.S.: For Rdb related questions it is better to ask in our Communities at https://communities.oracle.com/portal/server.pt/community/rdb_product_family_on_openvms . That forum is watched by Rdb Support and Development.

  • How to migrate the Workbooks from BW3.1 to BI7

    Dear Team,
    How to Migrate the workbooks from Bw3.1 to BI7. We have recently upgraded to BI7. What are necessary steps and necessary cares needs to take for this.
    Best Regards,
    SG

    Migration is manual. When you open up a 3.x component in a 2004s tool in migrates it. There is no automatic migration available
    Rolling out the New SAP NetWeaver 2004s BI Frontend Tools
    Migrating Advanced BEx Analyzer Workbooks - What VBA is Supported?
    Hope it Helps
    Chetan
    @CP..

  • How do I migrate the passwords from secured pdfs/their profiles to a new computer and new version of

    how do I migrate the passwords from secured pdfs/their profiles to a new computer and new version of acrobat?  I lost one computer that had standard 9, went to new computer, then upgraded to XI.  All my password profiles are not coming through.  How do I get them back?

    There is also a program called Senuti that I used when I had a PC crash with all my iTunes stuff on it:
    www.fadingred.com/Senuti

  • Migrating a website from 2008 R2 to 2012 ( iis 8.5)

    Hi Need help with the following scenario.
    I need to move the entire website from 2008 R2 to new 2012 server, please find the details below.
    Web site number : 1
    Current Server 2008 R2 ( iis 7.5)
    Destination : 2012 ( iis 8.5 ) 
    Is there any migration tool available for the same  ?

    Hi Joshy,
    I agree with Tim. You should post the question in IIS forum. I believe we will get a better assistance there. There is the URL of IIS forum:
    http://forums.iis.net/
    I also find two simialr threads from IIS forum. It seems that you can use
    IIS Easy MIgration Tool to migrate. Please refer to and check if can help you.
    IIS 7.5 to 8.5
    How to upgrade from IIS 7.5 (Server 2008R2) to IIS 8.5 (server 2012r2)
    Best regards,
    Justin Gu
    Please remember to mark the replies as answers if they help and unmark them if they provide no help. If you have feedback for TechNet Support, contact [email protected]

  • Migrate folders from 2008 to 2012

    Export this key from registry
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\LanmanServer\Shares
    https://support.microsoft.com/en-us/kb/125996
    * should still work in 2008 and 2012

    Anyone know if there is a way to migrate file shares from a Windows 2008 DC to a Windows 2012 DC?  I am using robocopy and the NTFS permissions come with it but I am wondering if there is a way to get the permissions of the share over as well so I do not have to recreate those?
    This topic first appeared in the Spiceworks Community

  • How to migrate the computers from SCCM 2007 to SCCM 2012

    Hello,
    Could anyone tell me how to mirgrate the computers present in SCCM 2007 to SCCM 2012.
    Does the "collection migration" job migrate the computers or devices present in the collection? I tried this but computers were not migrated.
    Should we again discover the computers in SCCM 2012?
    Thanks,
    SreehariG

    There is no migration job in CM12 that will migrate CM07 clients. You need to install CM12 agent on your CM07 client in order to migrate them. During the installation the existing CM07 client will be uninstalled. You can use any supported
    client deployment methods to migrate to your new CM12 environment. More information here:
    http://social.technet.microsoft.com/Forums/en-US/configmanagermigration/thread/71175a47-22fe-4284-871c-834c0c999075

  • DHCP Mirgation from 2008 to 2012

    Hi,
    I am migrating DHCP server 2008 to 2012
    Environment. Please let me know the Best practice of migration.
    I have configured DHCP failover in Windows 2008 R2
    Environment.
    Any help would be very grateful.
    Thankx & Regards,
    DD6

    Hi,
    This type of question is already running in technet portal.
    http://social.technet.microsoft.com/Forums/en-US/fed16caa-fb53-4037-a578-5f8dfc61e4e3/dhcp-failover-migrate-dhcp-server-to-another-machine?forum=winservergen
    Process of Migration DHCP Server 2008R2 to Windows 2012
    • Firstly, you can disable the DHCP role in Windows Server 2008 R2. However, if the Windows Server 2012 is down, the clients cannot renew their IP lease duration and obtain IP address.
    Therefore, it is recommended to leave the DHCP role in Windows Server 2008 R2 and deploy high availability. Windows Server 2012 brings the new feature: DHCP failover. However it requires both DHCP Servers are Windows Server 2012. Consider another Server
    is Windows Server 2008 R2, we have to choose one of the following:
    >> DHCP in a Windows failover cluster. This option places the DHCP server in a cluster with an additional server configured with the DHCP service that assumes the load if the primary DHCP server fails. The clustering deployment option uses a single
    shared storage. This makes the storage a single point of failure, and requires additional investment in redundancy for storage. In addition, clustering involves relatively complex setup and maintenance.
    >> Split scope DHCP. Split scope DHCP uses two independent DHCP servers that share responsibility for a scope. Typically 70% of the addresses in the scope are assigned to the primary server and the remaining 30% are assigned to the backup server.
    If clients cannot reach the primary server then they can get an IP configuration from the secondary server. Split scope deployment does not provide IP address continuity and is unusable in scenarios where the scope is already running at high utilization of
    address space, which is very common with Internet Protocol version 4 (IPv4).
    More references:
    Step-by-Step: Configure DHCP for Failover (Windows
    Server 2012)
    How
    to configure split-scope using wizard
    DHCP
    Step-by-Step Guide: Demonstrate DHCP Split Scope with Delay on a Secondary Server in a Test Lab
    DHCP
    Step-by-Step Guide: Demonstrate DHCP Failover – Clustering in a Test Lab
    If you need snap shot of migration then follow these links.
    http://blogs.technet.com/b/canitpro/archive/2013/04/29/step-by-step-migration-of-dhcp-from-windows-server-2003-to-windows-server-2012.aspx
    http://www.mehrban.net/migrating-dhcp-from-windows-2008-to-windows-2012
    Deepak Kotian. MCP, MCTS, MCITP Exchange 2010 Ent. Administrator Disclaimer: Please take a moment to "Vote as Helpful" and/or "Mark as Answer", where applicable. This helps the community, keeps the forums tidy, and recognizes useful
    contributions. Thanks! All the opinions expressed here is mine. This posting is provided "AS IS" with no warranties or guarantees and confers no rights.

Maybe you are looking for

  • Hyper-V 2012 R2 On Static IP?

    I have a hyper-v server that has its own static ip address and I want to be able to remotely manage it from a windows 8.1 system. Is this possible? There on different networks and not a part of a domain. thnx

  • I'm in deep trouble and tears with 10.6.5, Pse help

    Have a big job to finish on my iMac, my primary machine. Was running just fine on 10.6.4 but installed 10.6.5 downloaded off the normal software update, so I can update my iPad when OS4.2 comes out. The installation appeared to go fine. Machine resta

  • Random clunk/click sound...

    I know this has been brought up before, but those accounts have been when the user "tilts" their computer. Not my case. I can tilt my computer right now and no sound. I have a new MacBook Pro Intel Core i7 and when I am using it there will be a rando

  • BAPI_MATERIAL_MAINTAINDATA_RT update gross weight for generic article

    Hi, I want to update the gross weight (MARM-BRGEW) for a generic article and it's variants. Sometimes, the new gross weight is not propagate to all the article related variants when I'm using BAPI BAPI_MATERIAL_MAINTAINDATA_RT ?? In the structure hea

  • How do you break a RAID 1 created in Disk Utility and retain data?

    Good Morning all !! Quick subject question.  Background:  I have 2-3 TB of important data that i use only rarely.  I purchased two 4TB external drives.  I could not use a 2 drive raid enclosure because of the fan noise in the studio.   I selected 800