{"id":167291,"date":"2017-08-02T22:06:19","date_gmt":"2017-08-02T15:06:19","guid":{"rendered":"https:\/\/www.icez.net\/blog\/?p=167291"},"modified":"2017-08-02T22:06:19","modified_gmt":"2017-08-02T15:06:19","slug":"ms-exchange-cryptographicexception-invalid-provider-type-specified","status":"publish","type":"post","link":"https:\/\/www.icez.net\/blog\/167291\/ms-exchange-cryptographicexception-invalid-provider-type-specified","title":{"rendered":"0226 | MS Exchange : CryptographicException: Invalid provider type specified"},"content":{"rendered":"<p>There&#8217;s issue when installing\/renewing a certificate to MS Exchange.<\/p>\n<blockquote>\n<p>System.Security.Cryptography.CryptographicException: Invalid provider type specified<\/p>\n<\/blockquote>\n<p>This is the explaination (reference: MS Technet > exchange server 2013 > <a href=\"https:\/\/social.technet.microsoft.com\/Forums\/ie\/en-US\/a9efd351-032d-47d1-8b68-2ad00f11bcc8\/unable-to-access-ecpowa?forum=exchangesvrdeploy\">Unable to access ECP\/OWA<\/a>)<\/p>\n<blockquote>\n<p>The basic problem is that the Exchange code cannot properly handle X.509 certificates signed with the new and mighty Microsoft Software Key Storage Provider (which is kind of funny)<\/p>\n<\/blockquote>\n<p>To fix this, do the following step:<\/p>\n<ol>\n<li>Export the certificate as &#8216;pfx&#8217; file then remove it from the certificate store.<\/li>\n<li>Open &#8216;Exchange Management Shell&#8217;<\/li>\n<li>Type command <code>certutil -csp \"Microsoft RSA SChannel Cryptographic Provider\" -importpfx c:\\path\\to\\certificate.pfx<\/code> note to change &#8216;c:\\path\\to\\certificate.pfx&#8217; to the path of your certificate exported from step 1.<\/li>\n<li>Type <code>certutil -store my<\/code>, (see sample output below) Check if the &#8216;Provider = &#8216; line is &#8216;Microsoft RSA SChannel Cryptographic Provider&#8217;. Copy the hash after &#8216;Cert Hash(sha1):&#8217;<\/li>\n<li>Enable the certificate for Exchange. Type <code>Enable-ExchangeCertificate -thumbprint \"00 11 22 33 44 55 66 77 88 99 aa bb cc dd ee ff 01 23 45 67\" -Services \"iis,pop,imap,smtp\"<\/code><\/li>\n<li>Restart IIS.<\/li>\n<\/ol>\n<pre>Serial Number: ************\nIssuer: CN=WMSvc-***\n NotBefore: 12\/24\/2014 7:18 PM\n NotAfter: 12\/21\/2024 7:18 PM\nSubject: CN=WMSvc-***\nSignature matches Public Key\nRoot Certificate: Subject matches Issuer\nCert Hash(sha1): 00 11 22 33 44 55 66 77 88 99 aa bb cc dd ee ff 01 23 45 67\n  Key Container = WMSvc Certificate Key Container\n  Unique container name: *******************************************\n  Provider = Microsoft RSA SChannel Cryptographic Provider\nEncryption test passed<\/pre>\n","protected":false},"excerpt":{"rendered":"<p>There&#8217;s issue when installing\/renewing a certificate to MS Exchange. System.Security.Cryptography.CryptographicException: Invalid provider type specified This is the explaination (reference: MS Technet > exchange server 2013 > Unable to access ECP\/OWA) The basic problem is that the Exchange code cannot properly handle X.509 certificates signed with the new and mighty Microsoft Software Key Storage Provider (which [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[5698],"tags":[8249],"class_list":["post-167291","post","type-post","status-publish","format-standard","hentry","category-windows-server","tag-exchange-server"],"_links":{"self":[{"href":"https:\/\/www.icez.net\/blog\/wp-json\/wp\/v2\/posts\/167291","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.icez.net\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.icez.net\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.icez.net\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.icez.net\/blog\/wp-json\/wp\/v2\/comments?post=167291"}],"version-history":[{"count":1,"href":"https:\/\/www.icez.net\/blog\/wp-json\/wp\/v2\/posts\/167291\/revisions"}],"predecessor-version":[{"id":167292,"href":"https:\/\/www.icez.net\/blog\/wp-json\/wp\/v2\/posts\/167291\/revisions\/167292"}],"wp:attachment":[{"href":"https:\/\/www.icez.net\/blog\/wp-json\/wp\/v2\/media?parent=167291"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.icez.net\/blog\/wp-json\/wp\/v2\/categories?post=167291"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.icez.net\/blog\/wp-json\/wp\/v2\/tags?post=167291"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}