Monday, 30 December 2024

Check Certificate KeySpec Value

 

The following is an example: certutil –v –store my. This command dumps the certificate information to the screen.


The following are the meanings of the various KeySpec values:


Keyspec valueMeansRecommended AD FS use
0The certificate is a CNG certSSL certificate only
1For a legacy CAPI (non-CNG) cert, the key can be used for signing and decryptionSSL, token signing, token decrypting, service communication certificates
2For a legacy CAPI (non-CNG) cert, the key can be used only for signingnot recommended