{"id":184,"date":"2016-01-19T11:00:08","date_gmt":"2016-01-19T11:00:08","guid":{"rendered":"http:\/\/www.pkipartner.support\/?page_id=184"},"modified":"2016-03-29T10:41:29","modified_gmt":"2016-03-29T10:41:29","slug":"uc-privatekeymissing-when-running-enable-exchangecertificate","status":"publish","type":"page","link":"https:\/\/pkipartner.com\/support\/uc-privatekeymissing-when-running-enable-exchangecertificate\/","title":{"rendered":"UC &#8211; PrivateKeyMissing when running Enable-ExchangeCertificate"},"content":{"rendered":"<h1>PrivateKeyMissing when running Enable-ExchangeCertificate<\/h1>\n<p><strong>Enable-ExchangeCertificate : The certificate with thumbprint XXXXXXXXX was found but is not valid for use with Exchange Server<\/strong><strong><br \/>\n(reason: PrivateKeyMissing).<br \/>\nAt line:1 char:27<br \/>\n+ Enable-ExchangeCertificate -Thumbprint XXXXXXXXX -Services &#8220;IIS&#8221;<\/strong><\/p>\n<p>The above error can as a result of multiple reasons. CSR was created with IIS and attempted to be installed through the Exchange Management Shell (EMS), CSR was created in EMS on another Exchange Server, a damaged certificate, or Windows simply &#8220;forgets&#8221; where it placed the PrivateKey for the certificate. It doesn&#8217;t happen all the time, but sometimes the error can be a nuisance.<\/p>\n<p><strong>Option #1:<\/strong>\u00a0Repair Damaged Certificate (Windows Server 2003\/2008)<\/p>\n<ol>\n<li>Open MMC and add the Certificate Snap-In for the Local Computer account.<\/li>\n<\/ol>\n<p>&nbsp;<\/p>\n<ol>\n<li>Double-Click on the recently imported certificate.<\/li>\n<\/ol>\n<p><strong>Note:<\/strong>\u00a0In Windows Server 2008 it will be the certificate missing the golden key beside it.<\/p>\n<ol>\n<li>Select the Details tab.<\/li>\n<\/ol>\n<p>&nbsp;<\/p>\n<ol>\n<li>Click on the Serial Number field and copy that string.<\/li>\n<\/ol>\n<p><strong>Note:<\/strong>\u00a0You may use CTRL+C, but not right-click and copy.<\/p>\n<ol>\n<li>Open up a command prompt session. (cmd.exe aka DOS Prompt)<\/li>\n<\/ol>\n<p>&nbsp;<\/p>\n<ol>\n<li>Type:\u00a0<strong>certutil -repairstore my &#8220;SerialNumber&#8221;<\/strong>\u00a0(SerialNumber is that which was copied down in step 4.)<\/li>\n<\/ol>\n<p>&nbsp;<\/p>\n<ol>\n<li>After running the above command, go back to the MMC and Right-Click\u00a0<strong>Certificates<\/strong>\u00a0and select\u00a0<strong>Refresh<\/strong>\u00a0(or hit F5 in the MMC)<\/li>\n<\/ol>\n<p>&nbsp;<\/p>\n<ol>\n<li>Double-Click on the problem certificate. At the bottom of this window (General tab) it should state: &#8220;<strong>You have a private key that corresponds to this certificate.<\/strong>&#8220;<\/li>\n<\/ol>\n<p><strong>Note:<\/strong><strong>\u00a0<\/strong>In Windows Server 2008 there will be a golden key to the left of the certificate, so there is no need to double-click the certificate.<\/p>\n<ol>\n<li>Now that the Private Key is attached to the certificate, please proceed to enable Exchange Services via\u00a0<a href=\"http:\/\/www.pkipartner.com\/support\/uc-assigningenable-additional-services-on-an-existing-ucc\/\">Enable-ExchangeCertificate<\/a>.<\/li>\n<\/ol>\n<p><strong>Option #2:<\/strong>\u00a0Remove and Re-Install Certificate (Windows Server 2003\/2008)<\/p>\n<ol>\n<li>Verify the certificate doesn&#8217;t have it&#8217;s private key.<br \/>\nIn the MMC and double-click the recently imported certificate. (Be sure that you&#8217;re using the Certificate Snap-In for the Local Computer account!)<\/li>\n<\/ol>\n<p><strong>Note:<\/strong>\u00a0In Windows Server 2008 it will be the certificate missing the golden key beside it.<\/p>\n<ol>\n<li>Right-Click on the certificate and click\u00a0<strong>Delete<\/strong>.<\/li>\n<\/ol>\n<p>&nbsp;<\/p>\n<ol>\n<li><a href=\"http:\/\/www.pkipartner.com\/support\/install-installing-a-certificate-on-exchange-2007-powershell\/\">Re-install<\/a><a href=\"http:\/\/pkipartner.files.wordpress.com\/2014\/03\/exchange-2007-power-shell.pdf\">\u00a0<\/a>the Certificate<\/li>\n<\/ol>\n<p>&nbsp;<\/p>\n<p>If any of the above does not work, please contact Microsoft.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>PrivateKeyMissing when running Enable-ExchangeCertificate Enable-ExchangeCertificate : The certificate with thumbprint XXXXXXXXX was found but is not valid for use with Exchange Server (reason: PrivateKeyMissing). At line:1 char:27 + Enable-ExchangeCertificate -Thumbprint XXXXXXXXX -Services &#8220;IIS&#8221; The above error can as a result of multiple reasons. CSR was created with IIS and attempted\u2026<\/p>\n<p> <a class=\"continue-reading-link\" href=\"https:\/\/pkipartner.com\/support\/uc-privatekeymissing-when-running-enable-exchangecertificate\/\"><span>Continue reading<\/span><i class=\"crycon-right-dir\"><\/i><\/a> <\/p>\n","protected":false},"author":1,"featured_media":0,"parent":0,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"","meta":{"footnotes":""},"_links":{"self":[{"href":"https:\/\/pkipartner.com\/support\/wp-json\/wp\/v2\/pages\/184"}],"collection":[{"href":"https:\/\/pkipartner.com\/support\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/pkipartner.com\/support\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/pkipartner.com\/support\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/pkipartner.com\/support\/wp-json\/wp\/v2\/comments?post=184"}],"version-history":[{"count":3,"href":"https:\/\/pkipartner.com\/support\/wp-json\/wp\/v2\/pages\/184\/revisions"}],"predecessor-version":[{"id":784,"href":"https:\/\/pkipartner.com\/support\/wp-json\/wp\/v2\/pages\/184\/revisions\/784"}],"wp:attachment":[{"href":"https:\/\/pkipartner.com\/support\/wp-json\/wp\/v2\/media?parent=184"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}