GPO propagates certificate to Trusted People instead of Personal folder

Auntiejack 201 Reputation points
2021-01-14T00:04:12.417+00:00

Hi,

I have a GPO which pushes a certificate to specific users. In the GP Management Editor, the certificate is located at 'User Configuration / Policies / Windows Settings / Security Settings / Public Key Policies / Trusted People'. I got it working after this advice - thanks FanFan https://learn.microsoft.com/answers/answers/228765/view.html

However, GP pushes the certificate to the client machine Certificate Store under 'Certificates - Current User / Trusted People'. This doesn't get picked up by SQL Server to decrypt the columns, because the default location for master key certificates is 'Certificates - Current User / Personal'.

Can I force the GP to push the certificate to the 'Personal' folder instead of 'Trusted People'? Or can I change the location for SQL Server master key certificates?

Thanks,

Jack

Windows
Windows
A family of Microsoft operating systems that run across personal computers, tablets, laptops, phones, internet of things devices, self-contained mixed reality headsets, large collaboration screens, and other devices.
5,427 questions
SQL Server
SQL Server
A family of Microsoft relational database management and analysis systems for e-commerce, line-of-business, and data warehousing solutions.
13,865 questions
0 comments No comments
{count} votes

Accepted answer
  1. Fan Fan 15,336 Reputation points Microsoft Vendor
    2021-01-14T03:36:55.153+00:00

    Hi,

    For the GPO part, based on my research , there is not such a setting to push the certificate to the 'Personal' folder instead of 'Trusted People"
    But a logon script and schedule task can be considered to do this.
    Following link for your reference:
    https://jasonpearce.com/2012/02/02/import-pfx-certificate-via-group-policy-preferences/(Third-party link)
    This response contains a third-party link. We provide this link for easy reference. Microsoft cannot guarantee the validity of any information and content in this link.
    Best Regards,

    0 comments No comments

1 additional answer

Sort by: Most helpful
  1. Auntiejack 201 Reputation points
    2021-01-14T03:55:52.03+00:00

    Thanks FanFan, checking out the link. That may be the way to go.
    Jack

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.