Skip to main content

Are there any types of certificates that are not supported by the Security Token Service?

Suggest edit Updated on September 10, 2021

Yes. The Pega Robotic Automation Security Token Service does not support CNG (Cryptography Next Generation) certificates.

There are two ways to determine if a certificate is a CNG certificate:

  • Do a p/invoke of CertGetCertificateContextProperty, and inspect dwProvType on the returned CertGetCertificateContextProperty.
  • Use the certutil command from the command line to query the certificates.

If the ProviderType (rgProvParam) and KeySpec (dwKeySpec) are zero (0), it is a CNG private key. Here is the format of the command that you would use to list the certificate properties:

certutil -v -store [StoreName]

For example, use the following command:

certutil -v -store my
Note: Use the certutil –store –? command to get Help on the –store command.
Did you find this content helpful? YesNo

100% found this useful

Have a question? Get answers now.

Visit the Collaboration Center to ask questions, engage in discussions, share ideas, and help others.

Ready to crush complexity?

Experience the benefits of Pega Community when you log in.

We'd prefer it if you saw us at our best. is not optimized for Internet Explorer. For the optimal experience, please use:

Close Deprecation Notice
Contact us