Cancel
Disclaimer
This page is only available in English and was created using Entrust official Release Notes.
Welcome to Entrust Certificate Agent for Windows.
If you currently use Entrust Entelligence Security Provider for Windows, uninstall it before installing Entrust Certificate Agent for Windows.
This section describes fixes, changes, and feature enhancements that have been introduced in Entrust Certificate Agent 11.0.15 for Windows. Numbers in parenthesis are for internal tracking purposes.
Original CSP: eToken Base Cryptographic Provider (for SafeNet 5110)
Changed KSP: SafeNet Smart Card Key Storage Provider
The Invalid OCSPCacche.sst file caused Microsoft Outlook to exit unexpectedly (PKI-42563)
This section describes fixes, changes, and feature enhancements that have been introduced in Entrust Certificate Agent 11.0.14 for Windows. Numbers in parenthesis are for internal tracking purposes.
Entrust Certificate Agent for Windows failed to identify a domain controller when sending an auto-enrollment request to the Auto-enrollment Service (PKI-42221)
In Entrust Administration Services, the Auto-enrollment Service (AES) provides automatic enrollment of Entrust digital IDs or individual X.509 certificates to users, computers, and domain controllers. Entrust Certificate Agent for Windows can send auto-enrollment requests to AES for users, computers, and domain controllers. In AES, you can configure the default certificate types issued to users, machines, and domain controllers when processing an auto-enrollment request. AES will assign a default certificate type if the request sent by the auto-enrollment client does not match any client request settings configured in AES.
Previously when Entrust Certificate Agent for Windows sent an auto-enrollment request for a domain controller to AES, Entrust Certificate Agent for Windows would fail to identify the end entity as a domain controller. This issue caused AES to issue the default certificate type for machines for the account instead of the default certificate type for domain controllers. This issue is fixed in this release.
This section describes fixes, changes, and feature enhancements that have been introduced in Entrust Certificate Agent 11.0.13 for Windows. Numbers in parenthesis are for internal tracking purposes.
Previously when Entrust Certificate Agent for Windows checked for digital ID updates, it did not use the certificate definition policy to verify the status of the CMP signing certificate. This issue caused Entrust Certificate Agent for Windows to incorrectly display the CMP signing certificate as being in a valid state, even when it was due for renewal. This issue is fixed in this release. Entrust Certificate Agent for Windows now checks that the certificate definition policy is now applied during update checks, allowing Entrust Certificate Agent for Windows to correctly identify and display the renewal state of the CMP signing certificate.
Ability to use a PIN Unblocking Key to reset the PIN of a PIV smart card that does not have an Entrust Applet (PKI-41129)
This release adds the ability for Entrust Certificate Agent for Windows to use a PIN Unblocking Key to reset the PIN of a PIV smart card that does not have an Entrust Applet installed. Users must contact the administrator to obtain the PIN Unblocking Key. To reset the PIN, a user must select Reset Entrust Smart Card PIN from the Entrust Certificate Agent for Windows menu in the system tray. Reset PIN is performed locally without connecting to the server.
An Entrust smart card that has the Entrust Applet installed has the PIN rules. If the smart card does not have the Entrust Applet installed, the PIN rules can configured in the Windows registry. The PIN rules are based on the factory-defined PIN rules for third-party smart cards.
The following PIN rules can be configured in the Windows registry:
Key: HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Entrust\ECAW
Value Type: REG_DWORD
Registry settings:
Value Name: PIVPINPolicyMinLen
Minimum length of the PIN value:1 to 8 (default 6)
Value Name: PIVPINPolicyMaxLen
Maximum length of PIN value:1 to 8 (default 8)
Value Name: PIVPINPolicyDigit
Decimal values in PIN: ALLOWED, NOT ALLOWED, REQUIRED (default ALLOWED)
Value Name: PIVPINPolicyUpper
Uppercase values in PIN: ALLOWED, NOT ALLOWED, REQUIRED (default NOT ALLOWED)
Value Name: PIVPINPolicyLower
Lowercase values in PIN: ALLOWED, NOT ALLOWED, REQUIRED (default NOT ALLOWED)
Value Name: PIVPINPolicySpecial
Special characters in PIN: ALLOWED, NOT ALLOWED, REQUIRED (default NOT ALLOWED)
Cache stores were not updated when verifying a certificate’s revocation status (PKI-41104)
Previously, Entrust Certificate Agent for Windows would not update the cache stores as expected when verifying a certificate’s revocation status, but only when starting a new process. This issue is fixed in this release.
The serial number and reader name of the smart card is now displayed with resetting a smart card PIN (PKI-41103)
Starting in this release, when resetting the PIN of a smart card, Entrust Certificate Agent for Windows will display the reader name and serial number of the smart card. The reader name and serial number will be displayed on the Reset Entrust Smart Card PIN dialog box and the success message.
Ability to download CA certificates based on the user’s certificate AIA extension and install them into the Microsoft certificate store (PKI-41054, PKI-40991, PKI-40985)
Starting in this release, Entrust Certificate Agent for Windows can download CA certificates based on the AuthorityInfoAccess (AIA) extension in the user’s certificate and install them into the Microsoft certificate store. Microsoft will prompt the user with a dialog box for permission to add the certificate. To support this feature, this release introduces the following new registry settings.
The following setting controls whether to download CA certificates based on the user’s certificate AIA extension when the certificate chain is incomplete.
Registry Path: HKEY_LOCAL_MACHINE\<ECAW_registry_location>
Value Name: EnableDownloadCACertFollowAIA
Value Type: REG_DWORD
Value Data: 0 or 1
Value 0 (default): Do not download CA certificates.
Value 1: Download CA certificates.
The following setting specifies the retry interval (in minutes) for downloading CA certificates after a failed attempt.
Registry Path: HKEY_LOCAL_MACHINE\<ECAW_registry_location>
Value Name: ProblemAIACacheInterval
Value Type: REG_DWORD
Value Data: number of minutes (default 60)
When a download fails, Entrust Certificate Agent for Windows logs the failure under the following setting:
Registry Path: HKEY_CURRENT_USER\SOFTWARE\Entrust\ECAW\ProblemAIACache
Value Name: Location to put failure information
Value Type: REG_SZ
Value Data: failure details
For more information about these settings, see the Entrust Certificate Agent for Windows Administration Guide.
DLL and EXE files signed with an updated code-signing certificate (PKI-41042, PKI-40971)
All DLL and EXE files in Entrust Certificate Agent for Windows are signed with a code-signing certificate. The previous code-signing certificate expired in March 12, 2025. Some environments do not allow DLL files or EXE files that are signed by an expired certificate. This release signs all DLL and EXE files in Entrust Certificate Agent for Windows with an updated code-signing certificate. The updated code-signing certificate expires on January 28, 2028.
Attention: To update all DLL and EXE files, you must perform a full installation. Patch installations do not update all DLL and EXE files.
Wrong log message written during CNG enrollment when ECDHKeyAgreementAlg setting was not specified in the directory (PKI-40992)
During CNG enrollment, the wrong log message would be written when the setting ECDHKeyAgreementAlg was not specified in the registry. This issue is fixed in this release.
Entrust Certificate Agent for Windows failed to archive a certificate causing Entrust Certificate Agent for Outlook to select the wrong certificate when encrypting an email message (PKI-40806)
Previously, Entrust Certificate Agent for Windows could fail to archive a certificate contained in desktop profile (EPF file), causing Entrust Certificate Agent for Outlook to select the wrong certificate and fail to encrypt an email message. This issue is fixed in this release
Entrust Certificate Agent did not support some alternate elliptic curve names for the same OID used for signatures or encryption (PKI-40214)
In Entrust Certificate Authority Administration, the following user policy attributes specify the algorithms generated by client applications for client-generated user keys:
For elliptic curve algorithms, the algorithms can be entered as EC-<curve>. Some elliptic curves may have multiple names. For example, elliptic curve OID 1.2.840.10045.3.1.7 has the names P-256 and ansix9p256r1. Previously, if the algorithm specified in these policy attributes was an elliptic curve, Entrust Certificate Agent for Windows required the value to be specified as the EC-P-<curve> name. This issue is fixed in this release.
Key Access Service did not work with Entrust Certificate Authority with algorithm enforcement enabled (PKI-39085)
Previously, if a user’s Certification Authority (CA) was Entrust Certificate Authority with algorithm enforcement enabled for Common Criteria compliance, then the Key Access Service in Entrust Certificate Agent for Windows did not work. This issue is fixed in this release.
This section describes fixes, changes, and feature enhancements that have been introduced in Entrust Certificate Agent 11.0.12 for Windows. Numbers in parenthesis are for internal tracking purposes.
Event logs for Entrust Computer Digital ID and Entrust Windows Service Digital ID snap-ins could not be refreshed after too many logs (PKI-40772)
Previously, when the Entrust Computer Digital ID and Entrust Windows Service Digital ID snap-ins contained too many event logs, refreshing the dialog box would fail to refresh to event logs. This issue was observed after reaching 100 event logs. This issue is fixed in this release.
Automatic recovery requests could be sent for manually-enrolled digital IDs (PKI-40652)
Entrust Certificate Agent for Windows can automatically enroll or recover digital IDs for users and computers. Automatic enrollment and recovery is performed with Entrust Administration Services through the Auto-enrollment Service. Previously if a digital ID was enrolled manually, Entrust Certificate Agent would attempt to perform an automatic recovery if manually-enrolled digital ID was in the Key Recovery state. This issue is fixed in this release. Entrust Certificate Agent for Windows will no longer attempt an automatic recovery for a digital ID that was enrolled manually. If a manually-enrolled digital ID is in the Key Recovery state, Entrust Certificate Agent for Windows will notify the user to manually recover the digital ID.
Entrust Certificate Agent for Windows failed to automatically enroll a user with the Auto-enrollment Service in a Hosted Deployment (PKI-40483)
In Entrust Administration Services, the Auto-enrollment Service (AES) provides automatic enrollment of Entrust digital IDs or individual X.509 certificates to users or computers. Auto-enrollment clients such as Entrust Certificate Agent for Windows send the auto-enrollment request to the Auto-enrollment Service. Previously if AES was installed as a Hosted Deployment, Entrust Certificate Agent for Windows failed to automatically enroll a user. This issue is fixed in this release.
This section describes fixes, changes, and feature enhancements that have been introduced in Entrust Certificate Agent 11.0.11 for Windows. Numbers in parenthesis are for internal tracking purposes.
Updated cJSON components to prevent potential security vulnerability (PKI-40038)
Entrust Certificate Agent for Windows includes some cJSON components. This release updates the CJSON components to release 1.7.18 to prevent potential security vulnerability CVE-2024-31755.
Could not encrypt files using Personal Encryption Groups (PKI-40033, PKI-39680)
Previously, attempting to encrypt files using a Personal Encryption Group would result in errors. If you ignored the errors and encrypted the file, users in the Personal Encrpytion Group could not decrypt the file. This issue is fixed in this release.
Personal Encryption Groups could fail to import certificates for users if multiple certificates had the same subject name but different issuers (PKI-40027)
Previously, when a user had multiple certificates with the same subject DN but different issuers (such as cn=Sample User,ou=Example CA,o=Example,c=US and cn=Sample User,ou=Test CA,o=Example,c=US), Personal Encryption Groups could fail to import all the certificates for the user. This issue is fixed in this release.
Entrust snap-ins in the Microsoft Management Console would sometimes not work properly when enrolling a computer or service for a digital ID (PKI-39483)
Previously when enrolling a Windows computer or service for a digital ID, the Entrust snap-ins in the Microsoft Management Console (MMC) would sometimes not work properly. The snap-in could stop working or skip the dialog box that prompts you for the activation codes. This issue is fixed in this release.
Product version of language packs displayed in the About Entrust dialog box and the Add/Remove Programs dialog box could be different (PKI-39040)
Previously, the product version of language packs that was displayed in the Entrust Certificate Agent for Windows About Entrust dialog box could be different from the version displayed in the Add/Remove Programs dialog box in the Windows Control Panel. This issue is fixed in this release.
Missing verification certificate error could occur after Entrust Certificate Agent for Windows upgraded an EPF user from V1 to V2 (PKI-32919)
When a V1 user logs in to Entrust Certificate Agent for Windows with an EPF file, Entrust Certificate Agent for Windows upgrades the user’s digital ID from V1 to V2. After upgrading the user’s digital ID to V2, Entrust Certificate Agent for Window could display an error that the user was missing a verification certificate. This issue is fixed in this release.
This section describes fixes, changes, and feature enhancements that have been introduced in Entrust Certificate Agent 11.0.10 for Windows. Numbers in parenthesis are for internal tracking purposes.
The Key Access Service attempted to create a certificate for an EPF user during a key recovery (PKI-38856)
The Key Access Service is used when the user’s digital ID is stored on a smart card. Previously, when recovering a user’s keys to an EPF file, the Key Access Service would attempt to create a certificate. This issue is fixed in this release.
Ability to specify the ECDH key agreement algorithm to support Entrust Certificate Authority with algorithm enforcement enabled (PKI-38672)
This release introduces the following new registry setting that specifies the ECDH key agreement algorithm to use for CMP communications.
Key: <ECAW_registry_location>\PKI\<DN_of_CA>
Value Name: ECDHKeyAgreementAlg
Value Type: REG_SZ
Value Data: One of the following algorithms:
This setting specifies the algorithm used to derive MAC keys for protecting CMP messages. The default value is ECDH-X963SHA1KDF.
If the CA is Entrust Certificate Authority 10.1.x or later with algorithm enforcement enabled (the advanced setting EnforceAllowedCryptoAlgs=enabled), set the value to ECDH-X963SHA256KDF. Otherwise, set the value to ECDH-X963SHA1KDF.
XML log format was not readable (PKI-38246)
Previously, the XML log format produced by Entrust Certificate Agent for Windows was not readable by some applications such as Microsoft Excel. This issue is fixed in this release.
Selecting ‘Disable Enhanced Logout’ in the configuration utility did not disable enhanced logout (PKI-38204)
Previously when selecting the Disable Enhanced Logout option in the Entrust Certificate Agent Installer Configuration Utility, enhanced logout was still enabled after installing Entrust Certificate Agent for Windows. This issue occurred because the associated DisableEnhancedLogout registry setting was not created at the correct location in the Windows registry. (The setting was created in the Windows registry under <ECAW_registry_location> instead of <ECAW_registry_location>\EELS.) This issue is fixed in Entrust Certificate Agent Installer Configuration Utility 11.0.10.
Note: When upgrading from a pre-11.0.10 release, the Entrust Certificate Agent for Windows patch installer can move the registry setting to the correct location, but only when installed using administrative privileges. See Known issues and limitations.
The current signing key on a smart card got marked as archived if the certificate type was updated (PKI-38195)
Previously if a user’s certificates were stored on a smart card and then an administrator changed the user’s certificate type, the current signing key on the smart card would get marked as archived when Entrust Certificate Authority for Windows checked for certificate updates. This issue is fixed in this release.
The Key Access Service process could stop working if two smart cards using the same key storage provider were inserted (PKI-38084)
Previously, if two smart cards that used the same key storage provider were inserted, the Key Access Service (KAS) process could stop working. This issue is fixed in this release.
Revocation checking with an OCSP server could fail (PKI-38081)
Previously, revocation checking with an OCSP server could fail. This issue is fixed in this release.
Entrust Certificate Agent for Windows failed to connect to Roaming Server if Roaming Server was using a non-default port (PKI-37380, PKI-37196)
Previously if Entrust Authority Roaming Server was using a non-default port number, Entrust Certificate Agent for Windows would fail to connect to Roaming Server. This issue is fixed in this release.
Personal Encryption Groups did not import the correct certificates for some users (PKI-37177)
Previously, Personal Encryption Groups could fail to import the correct certificates for some users. This issue could occur if multiple certificates had the same subject name but different issuer names. This issue is fixed in this release. Personal Encrpytion Groups can now import certificates for the same user from different issuing CAs.
Could not decrypt a file after upgrading from Entrust Entelligence Security Provider (PKI-37037)
Previously when upgrading from Entrust Entelligence Security Provider, you may have been unable to decrypt a file. A message could appear stating that your digital ID name could not be found and the Entrust Security Store Login dialog box would not have the previously-used digital ID selected. This issue could occur if Security Provider for Windows or Security Provider for Outlook was installed, a message or file was encrypted, then Security Provider was uninstalled.
This issue occurred because the list of most recently-used security stores were not migrated from the old Security Provider registry location to the new Entrust Certificate Agent for Windows registry location. This issue is fixed in this release. Starting in this release, the Entrust Certificate Agent for Windows will migrate some existing Security Provider registry settings to the new Entrust Certificate Agent for Windows registry location.
Entrust Certificate Agent for Windows installer would create some registry settings with no value (PKI-36972)
Previously, installing Entrust Certificate Agent for Windows would create the following registry settings under Computer\HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Entrust\ECAW with no value set:
These settings are not used by Entrust Certificate Agent for Windows. Starting in this release, these registry settings are not created by the installer.
Reduced number of output files when the registry setting LogBinaryDetails is 1 (PKI-36971)
When the Entrust Certificate Agent for Windows registry setting LogBinaryDetails is 1, Entrust Certificate Agent for Windows writes the certificate, certificate chain, or CRL context to a ZIP file in the user’s local data folder. Starting in this release to reduce the number of output files, only context for certificates, certificate chains, and CRLs that are managed by CAs in the Entrust Certificate Agent for Windows registry will be output to files. For certificate output files, the serial number of the certificate will be used as a suffix in the output file name instead of a temporary file name created by the Microsoft API.
Some options in the Entrust Certificate Agent Installer Configuration Utility were not being set correctly in the Windows registry (PKI-36947)
Previously, if you selected the following options in the Entrust Certificate Agent Installer Configuration Utility, the associated registry settings were not set correctly.
IgnoreEntrustSecurityStoreUpdateUntilLogin)EffectOfLoginOnWaitingUpdate)SkipUpdateAfterEntrustSecurityStoreLogin)This issue is fixed in this release. Seleting these options in the configuration utility will now correctly set the associated registry settings when installing Entrust Certificate Agent for Windows.
MAC algorithm changes to support Entrust Certificate Authority with algorithm enforcement enabled (PKI-34461)
The CMP messages in a key management request to the CA are protected using a MAC (message authentication code) algorithm. This release introduces the following new registry settings that control the MAC algorithm used for key management requests. For more information about these settings, see the Entrust Certificate Agent for Windows Administration Guide.
Key: <ECAW_registry_location>\PKI\<DN_of_CA>
Value Name: ProtocolMacAlg
Value Type: REG_SZ
Value Data: One of the following algorithms:
This setting specifies the MAC algorithm used to protect a CMP request to create or recover a digital ID. The default value is HMAC-SHA1.
The value must be one of the algorithms specified by policy CMPMACwhiteList in the CA.
For Security Manager 8.3.x or earlier, set the value to HMAC-SHA1.
For Entrust Certificate Authority 10.1.x or later with algorithm enforcement enabled (the advanced setting EnforceAllowedCryptoAlgs=enabled), do not set the value to HMAC-SHA1.
Key: <ECAW_registry_location>\PKI\<DN_of_CA>
Value Name: CertHashProtocolMacAlg
Value Type: REG_SZ
Value Data: One of the following algorithms:
This setting specifies the MAC algorithm used to protect a CMP request to update a digital ID. The default value is HMAC-SHA1.
If the CA is Entrust Certificate Authority 10.1.x or later with algorithm enforcement enabled (the advanced setting EnforceAllowedCryptoAlgs=enabled), set the value to HMAC-SHA256. Otherwise, set the value to HMAC-SHA1.
Support for encrypting Entrust security stores with AES algorithms (PKI-33601)
Starting in this release, Entrust Certificate Agent for Windows supports encrypting Entrust security stores with AES-CBC-256 and AES-GCM-256. The registry setting EPFEncryptionAlgorithm now supports the following new values:
For more information about the EPFEncryptionAlgorithm registry setting, see the Entrust Certificate Agent for Windows Administration Guide.
This section describes fixes, changes, and feature enhancements that have been introduced in Entrust Certificate Agent 11.0.1 for Windows. Numbers in parenthesis are for internal tracking purposes.
Entrust Certificate Explorer did not search the directory with the correct searchbase order (PKI-36745)
In the Windows registry settings for Entrust Certificate Agent for Windows, the SearchBaseOrder registry setting specifies one or more searchbases. When searching for certificates in the directory, the Entrust Certificate Explorer component is supposed to search the directory using the searchbase order defined by the SearchBaseOrder registry setting. Previously when searching the directory for certificates, the Entrust Certificate Explorer component did not follow the correct searchbase order. The Entrust Certificate Explorer component would search the first directory searchbase listed, but then search each directory searchbase in the reverse order. This issue is fixed in this release.
Security Provider for Windows keys were added to the Windows registry when starting Entrust Certificate Agent for Windows (PKI-36710)
Previously when starting Entrust Certificate Agent for Windows, some Security Provider for Windows keys were added to the Windows registry. This issue is fixed in this release.
Certificate validation slowed because the Entrust CA Certificate Finder did not save the last search time when cross-certificates and link certificates were downloaded successfully (PKI-36598)
Previously, the Entrust CA Certificate Finder did not save the last search time in the Windows registry when cross-certificates and link certificates were downloaded successfully. The last search time was saved only when the download failed. This issue caused LDAP access traffic to slow down certificate validation when performing some operations. Starting in this release, the Entrust CA Certificate Finder will save the last search time whenever cross-certificates and link certificates are downloaded successfully or not.
OCSP Revocation Provider could cause some slowness when visiting HTTPS sites in some Web browsers (PKI-36511)
When opening HTTPS sites in some Web browsers such as Microsoft Edge, the OCSP Revocation Provider in Entrust Certificate Agent for Windows would trigger. The browser can create multiple threads to attach to the provider. Previously, the OCSP cache file was opened when a thread was attached, sometimes causing some slowness. Starting in this release to improve performance, the OCSP cache file is opened when the process is attached.
Entrust Certificate Agent for Windows could stop working when updating a digital ID if the certificates contained large serial numbers (PKI-36478, PKI-36475)
Previously when updating digital ID, Entrust Certificate Agent for Windows could stop working if the certificates contained large serial numbers. This issue is fixed in this release.
Entrust Certificate Agent for Windows could incorrectly recognize a contact reader as a contactless reader when encoding a smart card (PKI-36363)
When encoding a smart card with a contact reader, Entrust Certificate Agent for Windows may display a dialog box informing the user to remove and re-insert the smart card into the reader. This dialog box is expected. Previously when encoding a smart card with a contact reader, Entrust Certificate Agent for Windows could incorrectly recognize the reader as a contactless reader. This issue could cause Entrust Certificate Agent to not recognize the smart card being re-inserted. This issue is fixed in this release.
Entrust Certificate Agent for Windows failed to decrypt a file from a network folder if the user entered trailing spaces to a local folder for the decrypt location (PKI-36352)
When decrypting a file from a network location, Entrust Certificate Agent for Windows will prompt the user to provide a local folder for the decrypted file. If the user entered trailing spaces to the local folder, the decrypt operation would fail. This issue is fixed in this release. Entrust Certificate Agent will now remove trailing spaces from the provided local folder before decrypting the file.
Could not open some Microsoft files after decrypting them with Entrust Certificate Agent for Windows (PKI-36316)
Previously, after decrypting some Microsoft Office files (such as Microsoft Excel files) with Entrust Certificate Agent for Windows, you could not open the decrypted files. This issue is fixed in this release.
Entrust Certificate Agent for Windows could not access the online help hosted by Entrust (PKI-36264)
Previously, Entrust Certificate Agent for Windows could not access the online help that was hosted by Entrust. This issue is fixed in this release.
Ability to automatically log an Entrust security store out of a CAPI application (PKI-36250)
Users can log in to a CAPI application using their Entrust security store. Previously, the Entrust security store would remain logged in to the CAPI application. This patch adds the ability for Security Provider to automatically log an Entrust security store out of a CAPI application. This ability is controlled by the following new Windows registry settings:
Key: ECAW_registry_location
Name: LogoutOnCapiAppTimeout
Value Type: REG_DWORD
Value Data: 0, or 1 to 28800
This setting controls how long an Entrust security store can be logged in to a CAPI application before timing out.
0 (default) – The Entrust security store will not time out from the CAPI application.
1 to 28800 – The number of seconds that the Entrust security store can remain logged in to a CAPI application before timing out.
If the timeout occurs while the security store is still logged in to the CAPI application, Entrust Certificate Agent will lock the security store. If the CAPI application shuts down or releases its acquired context before the timeout, the security store will be locked and then logged out unless another CAPI application acquired another context.
If the value is greater than 0, Entrust Certificate Agent will monitor all CAPI applications unless one of the following registry settings defined:
Key: ECAW_registry_location
Name: LogoutOnCapiAppEnabledList
Value Type: REG_MULTI_SZ
Value Data: List of applications
This setting specifies a list of specific application processes that Entrust Certificate Agent will monitor.
Key: ESP_registry_location
Name: LogoutOnCapiAppDisabledList
Value Type: REG_MULTI_SZ
Value Data: List of applications
This setting specifies a list of application processes that Entrust Certificate Agent will ignore (not monitor).
For more information about these registry settings, see the Entrust Certificate Agent for Windows Administration Guide.
Roaming Windows accounts could fail to decrypt files (PKI-36249)
Some Entrust Certificate Agent for Windows users may use a computer shared with multiple other users. These users may log in to different computers and their Windows account information is roaming. Windows account roaming is handled by Microsoft Windows, not Entrust Certificate Agent for Windows.
When a Windows account roams to another computer, some Entrust Certificate Agent entries in the Windows registry may be deleted. In Entrust Certificate Agent, the Key Access Service (KAS) feature require the following Windows registry key:
Computer\HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\MY\PhysicalStores\Entrust KAS Certificate
If this key is deleted by the Windows roaming feature, then a user will not be able to use the Key Access Service feature to decrypt old files.
Starting in this release, the Key Access Service engine in Entrust Certificate Agent (eekas.exe) has been enhanced to detect the presence of this Windows registry key at startup, and will add the key if required.
Smart card monitoring enhancements to supported Yubico smart cards (PKI-36248)
By default when using a smart card, certificates on the smart card are imported to the personal certificate store. Entrust Certificate Agent includes a feature that controls whether the certificates are removed from the personal certificate store when the smart card is removed. This feature is controlled by the Windows registry setting EnableSmartCardCertificateRemoval (see the Entrust Certificate Agent for Windows Administration Guide for details).
Previously, when the registry setting EnableSmartCardCertificateRemoval=1, certificates were not removed from the personal certificate store when a Yubico smart card was removed. This feature worked with other supported smart cards. This issue is fixed in this release. Entrust Certificate Agent’s monitoring of smart cards has been enhanced in this release.
Enhancements to prevent smart card synchronization issues (PKI-36247)
Some Entrust Certificate Agent users may use multiple computers. These users may have performed a digital ID recovery on one computer and when logging in to another computer, the Digital ID Monitor may try to update the digital ID because of old certificates in the personal store.
If these users are using the Key Access Service (KAS) to decrypt older files, the CAPI application could try to use an old certificate that was left on the computer. Windows will then prompt the user to insert a smart card since the system does not have access to the key anymore.
To prevent these synchronization issues, Entrust Certificate Agent will list the distinguished names (DNs) and certificate serial numbers found on the smart card. Entrust Certificate Agent will then look on the computer for certificates in the personal store and the Intermediate CA store, and will remove certificates that have the same DN but with a serial number not found on the smart card.
Entrust Certificate Agent will now remove smart card-based certificates from other users during startup (PKI-36246)
Some Entrust Certificate Agent users may use a computer shared with multiple other users. These users may log in to different computers and their Windows account information is roaming. Windows account roaming is handled by Microsoft Windows, not Entrust Certificate Agent.
If a file is encrypted for multiple users, a CAPI application may attempt to decrypt a file with another user’s certificate. The application may prompt the user to insert the smart card associated with the other user’s certificate. To prevent this issue, during startup, Entrust Certificate Agent find all Profile IDs associated with verification certificates found on inserted smart cards. Entrust Certificate Agent will then remove all smart card-based certificates from the personal store and Intermediate CA store which are associated with a non-listed Profile ID.
Improved handling of connections to Roaming Server (PKI-36185)
When a user logs in to a roaming profile, Entrust Certificate Agent for Windows connects to Entrust Authority Roaming Server. Previously when attempting to connect to Roaming Server, Entrust Certificate Agent could make multiple connection attempts to Roaming Server if the first attempt failed. Multiple failed connection attempts could make Entrust Certificate Agent appear unresponsive.
Starting in this release, Entrust Certificate Agent attempts to connect to Roaming Server only once. This release also introduces the following new Windows registry setting that controls how long Entrust Certificate Agent will wait to connect with Roaming Server before timing out:
Key: The PKI registry key associated with the Roaming Server.
Name: RoamingServerConnectionTimeout
Value Type: REG_DWORD
Value Data: 0, or 1 to 30
0 (default) – Entrust Certificate Agent for Windows will use the default timeout defined by Windows.
1 to 30 – The number of seconds that Entrust Certificate Agent for Windows will wait to connect with Roaming Server before timing out.
Support for SID certificate extensions in the Entrust Certificate Explorer (PKI-36095)
In Entrust Certificate Agent for Windows, the Entrust Certificate Explorer allows users to view certificates. This release enhances the Entrust Certificate Explorer to add support for Security Identifier (SID) extensions in user certificates, so that these extensions are formatted properly when viewed in the Entrust Certificate Explorer.
Support for Microsoft Windows 11 Update 22H2 (PKI-35988)
Starting in this release, Entrust Certificate Agent for Windows is supported on Microsoft Windows 11 Update 22H2.
Entrust Certificate Agent 11.0 for Windows contains the following changes. Numbers in parenthesis are for internal tracking purposes.
Support for Windows 11 (PKI-32106, PKI-32106)
This version of Entrust Certificate Agent (including Entrust Password Decryption) adds Windows 11 and Windows Server 2022 to the list of supported platforms.
Product name changes
The following product names have been changed:
| Previous product name | New product name |
|---|---|
| Entrust Entelligence Security Provider for Windows | Entrust Certificate Agent for Windows |
| Entrust Entelligence Security Provider for Outlook | Entrust Certificate Agent for Outlook |
| Entrust Entelligence Secure Desktop for Macintosh | Entrust Certificate Agent for the macOS |
| Entrust Authority Security Manager | Entrust Certificate Authority |
| Entrust Authority Administration Services | Entrust Administration Services |
| Entrust Authority Roaming Server | Entrust Roaming Server |
| Entrust IdentityGuard | Entrust Identity Enterprise |
Certificate Agent supports using TLS 1.2 with Entrust Certificate Authority Proxy 7.0 (PKI-34329)
This version of Entrust Certificate Agent for Windows supports using TLS 1.2 for communication with Entrust Certificate Authority Proxy 7.0.
Certificate Agent supports using TLS 1.2 with Entrust Roaming Server 9.0 (PKI-33017)
This version of Entrust Certificate Agent for Windows supports using TLS 1.2 for communication with Entrust Roaming Server 9.0.
Certificate Agent supports using AES-128 with Entrust Roaming Server (PKI-34337)
This version of Entrust Certificate Agent for Windows supports using AES-128 for communication with Entrust Roaming Server.
Updated cipher suite (PKI-24496)
This version of Entrust Certificate Agent for Windows adds the TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 cipher suite for use when communicating with compatible applications.
Users can choose not to hide their certificate store password as they enter it (PKI-23260)
Users can choose not to hide their certificate store password as they type it into the Entrust Certificate Agent for Windows login window. Users are able to see and check the password as they type it in.
Improvements to the ecautil troubleshooting utility (PKI-24952)
The ecautil utility now includes additional switches allowing users to dump service certificates to the zip file created for troubleshooting.
Logging level selection added to the Entrust Certificate Agent menu (PKI-33468)
Log level can now be controlled from the Entrust Certificate Agent menu rather than just using a registry setting. This feature is available by default but can be turned off or on using the registry setting DisableUpdateRequestFromUsers.
Note: Disabling this feature also disables logging service configuration changes for the ecautil troubleshooting utility.
Ability to display and delete expired or archived certificates from the Local Machine store (PKI-22255, PKI-22898)
The Entrust Computer Digital ID snap-in now displays expired and archived certificates allowing the user to delete them from the Local Machine store.
The Entrust certificate store is now saved immediately after performing key management by default (PKI-22154)
The default value for the SaveEPFOnKeyManagement setting has been changed from 0 to 1. This setting determines whether or not Entrust Certificate Agent for Windows saves the Entrust certificate store immediately after performing key management. Entrust Certificate Agent for Windows now saves the certificate store by default.
Administrators can add network cloud folders to those controlled by PreventNetworkFileDecrypt (PKI-32897)
This release adds a registry setting allowing Administrators to specify the network cloud folders that will be controlled by the registry setting PreventNetworkFileDecrypt.
Key: <ecaw_registry_location>
Value Name: FileDecryptionCloudFolders
Value Type: Multi-String Value
Description: Administrators can specify multiple network cloud folders. Entrust Certificate Agent for Windows treats these folders as if they are on network drive. Use this registry setting with the setting PreventNetworkFileDecrypt to determine whether or not Certificate Agent can decrypt files directly on a network cloud folder.
Note: Certificate Agent automatically lists the folder path associated to Microsoft One-Drive. You do not need to include the Microsoft One-Drive folder in FileDecryptionCloudFolders list.
Improved certificate chain validation performance (PKI-35255)
By default Certificate Agent for Windows now ignores expired certificates when importing CA certificates into the CAPI store. This improves Security Provider’s performance when using certificate chain validation. This behavior is controlled by the registry setting CheckCertValidTime.
Certificate Agent for Windows response to the client authentication request during LDAP connection can be disabled (PKI-35499)
By default Certificate Agent for Windows responds to an LDAP request for client authentication during connection. This registry setting allows the administrator to disable this behavior.
Note: This registry setting is added to the registry key associated with the directory.
Registry Key : The key associated with the directory
Name : LDAPDisableClientAuth
Value Type : REG_DWORD
Value Data : 0 or 1
0 (default)- Certificate Agent for Windows does not disable client authentication for the LDAP connection.
1 – Certificate Agent for Windows disables client authentication for the LDAP connection.
The following issues have been fixed in this release. Numbers in parenthesis are for internal tracking purposes.
In some instances keys were not updated for PIV cards (PKI-840)
Under some circumstances keys were not updated as expected for users with PIV cards. This issue has been resolved.
Intermittent errors due to an issue building an accepted certification path (PKI-35151, PKI-35172)
Some customers experienced an intermittent error due to an issue building an accepted certification path. Entrust Certificate Agent 11.0 includes a fix for this issue.
Context sensitivity issue with locally installed help (PKI-23181, PKI-22972)
Context sensitivity did not work if Entrust Certificate Agent Help was installed locally or on a file server. This issue has been fixed.
Certificate Agent experienced a delay when encrypting files (PKI-34637)
Certificate Agent experienced a delay if there were a large number of expired intermediate certificates in users’ certificate stores as a revocation check was performed on current and expired intermediate certificates. To avoid this delay add the following registry setting:
Key: <ecaw_registry_location>
Value Name: NoRevocationCheckForExpiredCert
Value Type: REG_DWORD
Value Data: 0 or 1
0: Certificate Agent Revocation Provider performs a revocation check for expired certificates.
1 (Default): Certificate Agent Revocation Provider does not perform a revocation check for expired certificates. The revocation provider returns the error code CRYPT_E_NO_REVOCATION_CHECK. The revocation check is passed to the next revocation provider in the revocation provider list.
The following features have been discontinued in this release. Numbers in parenthesis are for internal tracking purposes.
CardMS features removed (PKI-35422, PKI-31462)
Starting in this release, the Card Management System (CardMS) feature has been removed from Entrust Certificate Agent for Windows. All DLL files and log files for the CardMS feature will no longer be installed, and the CardMS registry settings are no longer supported. Entrust Certificate Agent for Windows will no longer manage any digital ID that is currently owned by a Card Management System. The Entrust Certificate Agent Installer Configuration Utility 11.0 does not have a CardMS tab, and will not accept any CardMS-related registry settings
Copyright 2026 Entrust. All rights reserved.
Entrust and the Hexagon Logo are trademarks, registered trademarks and/or services marks of Entrust Corporation in the U.S. and/or other countries. All other brand or product names are the property of their respective owners. Because we are continuously improving our products and services, Entrust Corporation reserves the right to change specifications without prior notice.
Export and/or import of cryptographic products may be restricted by various regulations in various countries. Export and/or import permits may be required.