Note
Access to this page requires authorization. You can try signing in or changing directories.
Access to this page requires authorization. You can try changing directories.
One key recovery agent (KRA) object instance is created for each installed Cert Server (with a unique common name) during cert server setup. If two CAs were given the same common name during CA setup, they will share a single KRA object instance.
| Entry | Value |
|---|---|
| CN | ms-PKI-Key-Recovery-Agent |
| Ldap-Display-Name | msPKI-Key-Recovery-Agent |
| Update Privilege | An admin installing a CA will need to be able to create a KRA instance in the KRA container. Installed cert servers need to be able to update the userCertificate attribute. |
| Update Frequency | A few certificates will be added at most every few months. |
| Schema-Id-Guid | 26ccf238-a08e-4b86-9a82-a8c9ac7ee5cb |
Implementations
- Windows Server 2003
- Windows Server 2003 R2
- Windows Server 2008
- Windows Server 2008 R2
- Windows Server 2012
Windows Server 2003
| Entry | Value |
|---|---|
| System-Only | False |
| Object-Category | 1 |
| Default-Object-Category | - |
| Governs-Id | 1.2.840.113556.1.5.195 |
| Default-Hiding-Value | 1 |
| Rdn-Att-Id | Common-Name |
| Subclass of | User |
| Possible Superiors | Container |
| Auxiliary Classes | - |
| NT-Security-Descriptor | O:BAG:BAD:S: |
| Default Security Descriptor | D:(A;;RPWPCRCCDCLCLORCWOWDSDDTSW;;;DA)(A;;RPWPCRCCDCLCLORCWOWDSDDTSW;;;SY)(A;;RPLCLORC;;;AU) |
| System-Flags | 0x00000010 |
Windows Server 2003 Attributes
This class contains the following attributes for Windows Server 2003:
Windows Server 2003 R2
| Entry | Value |
|---|---|
| System-Only | False |
| Object-Category | 1 |
| Default-Object-Category | - |
| Governs-Id | 1.2.840.113556.1.5.195 |
| Default-Hiding-Value | 1 |
| Rdn-Att-Id | Common-Name |
| Subclass of | User |
| Possible Superiors | Container |
| Auxiliary Classes | - |
| NT-Security-Descriptor | O:BAG:BAD:S: |
| Default Security Descriptor | D:(A;;RPWPCRCCDCLCLORCWOWDSDDTSW;;;DA)(A;;RPWPCRCCDCLCLORCWOWDSDDTSW;;;SY)(A;;RPLCLORC;;;AU) |
| System-Flags | 0x00000010 |
Windows Server 2003 R2 Attributes
This class contains the following attributes for Windows Server 2003 R2:
Windows Server 2008
| Entry | Value |
|---|---|
| System-Only | False |
| Object-Category | 1 |
| Default-Object-Category | - |
| Governs-Id | 1.2.840.113556.1.5.195 |
| Default-Hiding-Value | 1 |
| Rdn-Att-Id | Common-Name |
| Subclass of | User |
| Possible Superiors | Container |
| Auxiliary Classes | - |
| NT-Security-Descriptor | O:BAG:BAD:S: |
| Default Security Descriptor | D:(A;;RPWPCRCCDCLCLORCWOWDSDDTSW;;;DA)(A;;RPWPCRCCDCLCLORCWOWDSDDTSW;;;SY)(A;;RPLCLORC;;;AU) |
| System-Flags | 0x00000010 |
Windows Server 2008 Attributes
This class contains the following attributes for Windows Server 2008:
Windows Server 2008 R2
| Entry | Value |
|---|---|
| System-Only | False |
| Object-Category | 1 |
| Default-Object-Category | - |
| Governs-Id | 1.2.840.113556.1.5.195 |
| Default-Hiding-Value | 1 |
| Rdn-Att-Id | Common-Name |
| Subclass of | User |
| Possible Superiors | Container |
| Auxiliary Classes | - |
| NT-Security-Descriptor | O:BAG:BAD:S: |
| Default Security Descriptor | D:(A;;RPWPCRCCDCLCLORCWOWDSDDTSW;;;DA)(A;;RPWPCRCCDCLCLORCWOWDSDDTSW;;;SY)(A;;RPLCLORC;;;AU) |
| System-Flags | 0x00000010 |
Windows Server 2008 R2 Attributes
This class contains the following attributes for Windows Server 2008 R2:
Windows Server 2012
| Entry | Value |
|---|---|
| System-Only | False |
| Object-Category | 1 |
| Default-Object-Category | - |
| Governs-Id | 1.2.840.113556.1.5.195 |
| Default-Hiding-Value | 1 |
| Rdn-Att-Id | Common-Name |
| Subclass of | User |
| Possible Superiors | Container |
| Auxiliary Classes | - |
| NT-Security-Descriptor | O:BAG:BAD:S: |
| Default Security Descriptor | D:(A;;RPWPCRCCDCLCLORCWOWDSDDTSW;;;DA)(A;;RPWPCRCCDCLCLORCWOWDSDDTSW;;;SY)(A;;RPLCLORC;;;AU) |
| System-Flags | 0x00000010 |
Windows Server 2012 Attributes
This class contains the following attributes for Windows Server 2012: