Previous Topic: Use a Server Certificate You Generate from a Third-Party Root Certificate

Next Topic: Changing CA Access Control Service Account Settings

Password-Protected Server Certificates

You can configure CA Access Control to use a password-protected server certificate; if you do, CA Access Control uses a specified password to protect the private key for the server certificate. CA Access Control stores the password in the crypto.dat file in the ACInstallDir/Data/crypto directory, where ACInstallDir is the directory in which you installed CA Access Control. The crypto.dat file is hidden, encrypted, read-only, and protected by CA Access Control. If CA Access Control is stopped, only the superuser can access the password.

If you create a password-protected server certificate, sechkey does not encrypt the certificate. If you create a server certificate that is not password-protected, sechkey encrypts the certificate using AES256 and the CA Access Control encryption key.