Skip to content

Get‑CertificatePrivateKeySecurityDescriptor

raandree edited this page Sep 6, 2026 · 1 revision

SYNOPSIS

Gets the DACL descriptor for a supported certificate private key.

SYNTAX

Certificate (Default)

Get-CertificatePrivateKeySecurityDescriptor -Certificate <X509Certificate2> -ProviderName <String>
 -KeyName <String> [<CommonParameters>]

Key

Get-CertificatePrivateKeySecurityDescriptor -ProviderName <String> -KeyName <String> -KeyScope <String>
 [<CommonParameters>]

DESCRIPTION

Inspects a persisted RSA private-key DACL in the Microsoft Software Key Storage Provider. The key is addressed either through an exact caller-owned X.509 certificate plus the expected CNG provider and key name, or, when no certificate is available, through the provider, key name, and key scope alone. It never exports or serializes private-key material.

EXAMPLES

EXAMPLE 1

$certificate = Get-Item 'Cert:\LocalMachine\My\0123456789ABCDEF'
Get-CertificatePrivateKeySecurityDescriptor `
    -Certificate $certificate `
    -ProviderName 'Microsoft Software Key Storage Provider' `
    -KeyName 'WorkloadKey'

Gets only the DACL descriptor for the exact supported CNG key.

EXAMPLE 2

Get-CertificatePrivateKeySecurityDescriptor `
    -ProviderName 'Microsoft Software Key Storage Provider' `
    -KeyName 'WorkloadKey' `
    -KeyScope Machine

Gets the same descriptor without a certificate, which is how a portability record and a desired-state resource address the key.

PARAMETERS

-Certificate

An exact X509Certificate2 object with the private key to inspect. The command does not dispose the caller-owned certificate.

Type: X509Certificate2
Parameter Sets: Certificate
Aliases:

Required: True
Position: Named
Default value: None
Accept pipeline input: True (ByValue)
Accept wildcard characters: False

-KeyName

The exact expected persisted CNG key name. The command verifies it against the key selected by Certificate before reading the descriptor.

Type: String
Parameter Sets: (All)
Aliases:

Required: True
Position: Named
Default value: None
Accept pipeline input: False
Accept wildcard characters: False

-KeyScope

Selects the machine or current-user key store when the key is addressed without a certificate.

Type: String
Parameter Sets: Key
Aliases:

Required: True
Position: Named
Default value: None
Accept pipeline input: False
Accept wildcard characters: False

-ProviderName

The exact expected CNG provider. This increment accepts only Microsoft Software Key Storage Provider.

Type: String
Parameter Sets: (All)
Aliases:

Required: True
Position: Named
Default value: None
Accept pipeline input: False
Accept wildcard characters: False

CommonParameters

This cmdlet supports the common parameters: -Debug, -ErrorAction, -ErrorVariable, -InformationAction, -InformationVariable, -OutVariable, -OutBuffer, -PipelineVariable, -Verbose, -WarningAction, and -WarningVariable. For more information, see about_CommonParameters.

INPUTS

System.Security.Cryptography.X509Certificates.X509Certificate2

OUTPUTS

WindowsAccessControl.CertificatePrivateKeySecurityDescriptor

NOTES

RELATED LINKS

Home

Commands

DSC resources

Clone this wiki locally