Windows 10 reached EOS (end of support) on October 14, 2025. If you are on Windows 10, see this article.

Tìm kiếm hỗ trợ

Tránh các lừa đảo về hỗ trợ. Chúng tôi sẽ không bao giờ yêu cầu bạn gọi hoặc nhắn tin đến số điện thoại hoặc chia sẻ thông tin cá nhân. Vui lòng báo cáo hoạt động đáng ngờ bằng cách sử dụng tùy chọn "Báo cáo lạm dụng".

Tìm hiểu thêm
Mở

How to push ".p12" keypairs into a windows domain's accounts

Alax Morgan đã trả lời
White-Gandalf

Hallo, my setup is some server (keycloak) with mTLS needing keypairs just for allowance for the machines in the enterprise. But as far as i know, i need to setup personal keypairs for the users, not just the machines. How do i push a ".p12" keypair into the browsers trust stores? Is there a way via GPOs? As far as i have read the https://firefox-admin-docs.mozilla.org/reference/policies/, there is no support for ".p12" files?

The only way i got told from AI is via a script. If i could just stuff that ".p12" file into some place in the GPO, i would be perfectly happy... (?)

Hallo, my setup is some server (keycloak) with mTLS needing keypairs just for allowance for the machines in the enterprise. But as far as i know, i need to setup personal keypairs for the users, not just the machines. How do i push a ".p12" keypair into the browsers trust stores? Is there a way via GPOs? As far as i have read the https://firefox-admin-docs.mozilla.org/reference/policies/, there is no support for ".p12" files? The only way i got told from AI is via a script. If i could just stuff that ".p12" file into some place in the GPO, i would be perfectly happy... (?)

Tất cả các câu trả lời (3)

I assume the reason for distribution via script is the protection by password, which needs to be delivered for the ingestion of the ".p12" into the trust store of the users firefox, which in turn is protected by the individual master password of the users... But then... then the script should not work as well... I do not understand the process, obviously. Has anybody an explanation?

The scriplet i'm told to use:

certutil -f -user -p "YourExportPasswordHere" -importpfx "MyPersonalStore" "\\server\share\certs\machine-identity.p12"


This seems to discuss the same issue: https://github.com/mozilla/policy-templates/issues/335

Được chỉnh sửa bởi White-Gandalf vào

This was an implementation decision at the time. P12 files typically have other requirements (passwords) that make them not work via policy.

It also would need to show the primary password dialog if a user had one.

I think the key distinction here is between CA certificates and client certificates. Firefox’s Certificates > Install policy is intended for CA certificates and supports DER/PEM, not importing a .p12 bundle containing a user’s private key.

For mTLS, I would avoid distributing the same .p12 private key to every user. Ideally, each user/device should have its own client certificate and private key, preferably issued through your enterprise PKI/MDM or another certificate-enrollment mechanism.

On Windows, GPO can distribute certificates through Public Key Policies, but that is primarily useful for establishing trust and managing certificates in the Windows certificate store. Firefox can then be configured with ImportEnterpriseRoots to trust certificates from the Windows certificate store.

So for your setup, I’d use GPO/PKI for certificate enrollment and trust, rather than trying to place a .p12 file directly into Firefox’s certificate policy. If the private key absolutely must be provisioned, a controlled deployment script or certificate-management/MDM solution would be the safer approach.

Đặt một câu hỏi

Bạn phải đăng nhập vào tài khoản của bạn để trả lời bài viết. Vui lòng bắt đầu một câu hỏi mới, nếu bạn chưa có tài khoản.