How can I export a certificate from MMC as a PFX file?

July 2, 2021


How can I export a certificate from MMC as a PFX file? – Super User

Stack Exchange Network

Stack Exchange network consists of 177 Q&A communities including Stack Overflow, the largest, most trusted online community for developers to learn, share their knowledge, and build their careers.

Visit Stack Exchange

  1. 0
  2. +0
  3. Log in Sign up

Super User is a question and answer site for computer enthusiasts and power users. It only takes a minute to sign up.

Sign up to join this community

Anybody can ask a question

Anybody can answer

The best answers are voted up and rise to the top

Asked 4 years, 11 months ago

Viewed 72k times

I’m in the process of trying to change the KeySpec property of a code signing certificate from Comodo by following this guide. The guide mentions importing your certificate file into MMC and then exporting it again later. However, I don’t seem to have the option to export as a PFX file. I already have a PFX file; I can import it successfully, but when I go to export the option is greyed out / disabled.

pfx disabled

What do I need to do to enable this export option?

asked Jul 8 ’16 at 21:42

soapergemsoapergem

1,31688 gold badges2424 silver badges4040 bronze badges

The Certificates snap-in really doesn’t like to export PFX certificates, but PowerShell is happy to. You can use the Export-PfxCertificate cmdlet.

  1. Go to the certificates pseudo-drive by typing cd cert: at the PowerShell prompt.
  2. Type cd CurrentUser or cd LocalMachine as appropriate for where the certificate is. You may need to launch PowerShell as admin to export a machine certificate.
  3. cd into the appropriate store (a dir may help). The Personal store in MMC is called My here.
  4. Use dir to identify which ID corresponds to the certificate you want.
  5. Type this command to export it as a PFX with a password:

    Export-PfxCertificate -Cert .LONGSTRINGOFHEX -FilePath ‘C:pathtooutfile.pfx’ -Password (ConvertTo-SecureString -String ‘password’ -AsPlainText -Force)

    LONGSTRINGOFHEX should be replaced with your certificate’s ID. Fortunately, you can use tab completion on that.

Once that command executes, you have a PFX certificate protected with the password you supplied. PowerShell refuses to export the certificate’s private key without a password, and the password can’t be blank. Nevertheless, your PFX is out.

answered Jul 11 ’16 at 19:04

Ben NBen N

36.9k1616 gold badges124124 silver badges168168 bronze badges

11

My problem was that I had created the CSR file on one machine and then tried to create the pfx file on another (Windows 10 had done an update overnight and locked me out of the first machine). Both the CSR and the pfx file need to be created on the same machine.

answered Jun 22 ’20 at 14:51

If you import a cert into the WebHosting store, you can’t export the private key. Move it to Personal store, and you will be able to export as PFX. I was able to do this in Windows 2012R2 without having to go to the command line and use Export-PfxCertificate (which is a pain as I couldn’t figure out the certificate’s ID to save my life).

answered Jul 30 ’19 at 22:01

MC9000MC9000

14711 gold badge11 silver badge77 bronze badges

2

Export the .P7B file once. And then go back and try exporting the certificate again. The .PFX export get enabled the next time.

answered Jul 19 ’19 at 16:30

2 Highly active question. Earn 10 reputation (not counting the association bonus) in order to answer this question. The reputation requirement helps protect this question from spam and non-answer activity. {};’)}catch(a){return!0}}function o(){return’undefined’!=typeof googletag&&!!googletag.apiReady}function p(){o()||(googletag={cmd:l(B)})}function q(){var a=document.createElement(‘div’);a.className=’adsbox’,a.id=’clc-abd’,a.style.position=’absolute’,a.style.pointerEvents=’none’,a.innerHTML=’ ‘,document.body.appendChild(a)}function r(){return Object.keys(F.ids).filter(function(a){return’clc-cpa’!=a})}function s(a){var b=a.split(‘_’)[0],c=F.ids[b],d=F.slots[c];’function’==typeof d&&(d=d(b));return{path:’/’+C+’/’+E+’/’+c+’/’+D,sizes:d,zone:c}}function t(a){try{Array.isArray(clc.dfp.slotsRenderedEvents)||(clc.dfp.slotsRenderedEvents=[]),clc.dfp.slotsRenderedEvents.push(a);var b=a.slot.getSlotElementId(),c=[];b||c.push(‘id=0’);var d=document.getElementById(b);if(!b||d?d.hasAttribute(‘data-clc-stalled’)&&c.push(‘st=1’):c.push(‘el=0’),0!==c.length)return void G(c.join(‘&’));var e=s(b),f=e.zone;if(clc.collapse&&clc.collapse[f]&&a.isEmpty)return h(d),void d.setAttribute(‘data-clc-ready’,’true’);if(-1!==y.dh.indexOf(a.lineItemId))h(d);else if(a.lineItemId){d.setAttribute(‘data-clc-prefilled’,’true’);var j=d.parentElement;if(j.classList.contains(‘js-zone-container’)){g(j);var k=j.querySelectorAll(‘.js-report-ad-button-container’),l=k[0];switch(l.style.height=’24px’,b){case’dfp-tlb’:case’dfp-tag’:{j.classList.add(‘mb8′);break}case’dfp-mlb’:case’dfp-smlb’:case’dfp-bmlb’:{j.classList.add(‘my8′);break}case’dfp-isb’:{j.classList.add(‘mt24′);break}case’dfp-m-aq’:{j.classList.add(‘my12’),j.classList.add(‘mx-auto’);break}default:}i(j),i(d)}else i(d);if(‘dfp-msb’==b){var m=document.getElementById(‘hireme’);h(m)}}d.setAttribute(‘data-clc-ready’,’true’)}catch(a){var n=document.querySelector(‘#dfp-tsb, #dfp-isb, #clc-tsb’);n&&n.setAttribute(‘data-clc-ready’,’true’),G(‘e=1’)}}function u(a,b){‘dfp-isb’===a&&b.setTargeting(‘Sidebar’,[‘Inline’]),’dfp-tsb’===a&&b.setTargeting(‘Sidebar’,[‘Right’]);var c=s(a),d=c.path,e=c.sizes,f=c.zone,g=googletag.defineSlot(d,e,a);g.addService(b),!1;var h=a.split(‘_’);if(‘clc-cpa’==h[0]&&h[1]){var i=h[1];g.setTargeting(‘talent-company-id’,i)}}function v(b){var c=a.dfp&&a.dfp.targeting||{};’SystemDefault’===c.ProductVariant&&(window.matchMedia&&window.matchMedia(‘(prefers-color-scheme: dark)’).matches?c.ProductVariant=’Dark’:c.ProductVariant=’Light’),Object.keys(c).forEach(function(a){b.setTargeting(a,c[a])})}function w(a){var g=a.map(b).filter(e);return{eligible:g.filter(f).filter(d),ineligible:g.filter(c)}}function x(b){void 0===b&&(b=r());var c=[‘dfp-mlb’,’dfp-smlb’];if(!o())return p(),void googletag.cmd.push(function(){return x(b)});var d=w(b),e=d.eligible,f=d.ineligible;if(e.forEach(function(a){g(a)}),f.forEach(h),0!==e.length){y.abd&&q();var i=googletag.pubads().getSlots(),j=i.filter(function(a){return 0c.indexOf(a.id)}),m=e.filter(function(a){return!!y.ll&&0<=c.indexOf(a.id)});l.forEach(function(a){u(a.id,k),a.setAttribute('data-dfp-zone','true')}),googletag.enableServices(),l.forEach(function(a){googletag.display(a.id)}),y.ll&&(k.enableLazyLoad({fetchMarginPercent:0,renderMarginPercent:0}),m.forEach(function(a){u(a.id,k),a.setAttribute('data-clc-prefilled','true')}),m.forEach(function(a){googletag.display(a.id)}))}}var y=function(a){for(var b=[],c=1;c Super User works best with JavaScript enabled

Your privacy

By clicking “Accept all cookies”, you agree Stack Exchange can store cookies on your device and disclose information in accordance with our Cookie Policy.

 

Source