Site icon EfmSoft

What does HRESULT 0x8009400B (CERTSRV_E_NO_VALID_KRA) mean?

 
Previous Next
CERTSRV_E_KEY_ARCHIVAL_NOT_CONFIGURED CERTSRV_E_BAD_REQUEST_KEY_ARCHIVAL

CERTSRV_E_NO_VALID_KRA

CERTSRV_E_NO_VALID_KRA (0x8009400B) means that Active Directory Certificate Services could not archive the requested private key because the certification authority could not verify one or more configured Key Recovery Agent (KRA) certificates.

Where the failure is

The CA uses KRA public keys when archiving an enrolled private key. The KRA private key does not need to be present on the CA for archival; it is held by the recovery agent and is needed later to decrypt recovered key material. Therefore, this HRESULT should first be investigated as a CA/KRA certificate-validation and configuration problem.

What to check

  • The KRA certificates currently configured on the CA and the certificate hashes recorded in the CA configuration.
  • Validity, chain trust, revocation status, and the Key Recovery Agent usage of each configured KRA certificate.
  • Whether a KRA certificate was renewed, replaced, expired, or removed without updating the CA configuration.
  • The CertificationAuthority and enrollment events for the exact request that failed key archival.

Recovery

Configure the CA with valid KRA certificates that it can verify, then repeat enrollment with key archival enabled. Do not confuse this with CERTSRV_E_KEY_ARCHIVAL_NOT_CONFIGURED, which means key archival itself is not configured, or with CERTSRV_E_BAD_REQUEST_KEY_ARCHIVAL, which indicates malformed archived-key data in the request.

Technical references


Looking for a different code? Search another status or error code.

Exit mobile version