T33-2026: BIOVIA Vault Server 2026: Correct Certificate Store for PFX Files
Update to documentation for BIOVIA Vault Server 2026
Program
BIOVIA Vault Server 2026
Operating System
Microsoft Windows Server versions supported by BIOVIA Vault Server 2026
Description
Appendix E of the BIOVIA Vault Server 2026 Installation Guide contains a section titled "Importing a SSL Certificate PFX File into the Trusted Root Store." The procedure directs administrators to select a .PFX file, mark the private key as exportable, and place the certificate in the Trusted Root Certification Authorities store.
Later in the same appendix, the signing-certificate procedure identifies Certificates - Local Computer\Personal\Certificates as the default certificate location. These instructions assign two different stores to certificates that contain or use private keys.
A PFX (PKCS #12) file normally packages an identity certificate with its associated private key. The Trusted Root Certification Authorities store represents trusted public root/CA certificates. Keeping identity keys separate from trust anchors makes access control, certificate selection, renewal, and compromise recovery clearer and safer.
Documentation discrepancy
| Guidance | Certificate store |
| 2026 PFX import procedure | Trusted Root Certification Authorities |
| 2026 signing-certificate procedure | Local Computer\Personal\Certificates (default) |
| Correct placement | PFX/private key: Personal; public root CA: Trusted Root; public intermediate CA: Intermediate Certification Authorities |
Resolution
BIOVIA QA verified that the Vault Server .pfx file should be installed in Local Computer\Personal\Certificates. The BIOVIA Vault Server 2027 Installation Guide has been corrected. Customers installing or replacing certificates in Vault Server 2026 should use the corrected procedure below.
Corrected procedure for Vault Server 2026
- Launch Microsoft Certificates for Local Computer by running certlm.msc with appropriate administrative privileges.
- Open Personal > Certificates, select All Tasks > Import, and select the Vault Server .PFX file.
- Enter the PFX password. Mark the private key as exportable only when an approved key backup or rotation procedure requires it.
- Place the certificate in Local Computer\Personal\Certificates and complete the import.
- Confirm that the imported certificate has the expected subject, validity period, certificate chain, and associated private key.
- Continue the Vault Server certificate configuration and verify that the intended certificate is used by the applicable Vault services and HTTPS endpoint.
- Import only the required public root CA certificate into Trusted Root Certification Authorities. Import public intermediate CA certificates into Intermediate Certification Authorities when required by the certificate chain.
Security and operational considerations
- Trust scope: A certificate in Trusted Root can be treated as an implicit trust anchor, which can create broader trust than intended.
- Private-key exposure: Importing an exportable private key into a broadly used trust store can increase the risk of unauthorized export or use.
- Certificate selection: Mixing trust anchors with service identities can make chain building and application certificate selection less predictable.
- Lifecycle management: Separating public trust anchors from identity private keys simplifies renewal, rotation, removal, audit, and compromise response.
Standards context
The corrected placement aligns with the separation of trust anchors from operational identity keys described in established PKI and key-management guidance. RFC 5280 describes the trust-anchor model; RFC 7292 defines PKCS #12 as a personal-information exchange format that can transport private keys; and NIST SP 800-57 Part 1 Rev. 5 emphasizes private-key protection, least privilege, role separation, and recoverable key lifecycles. FIPS 140-2 and FIPS 140-3 address cryptographic-module protection of sensitive security parameters; they do not, by themselves, prescribe a specific Windows certificate-store path.
References
- BIOVIA Vault Server 2026 Installation Guide, Appendix E: PFX import and signing-certificate topics.
- BIOVIA Vault Server 2027 Installation Guide: corrected PFX certificate-store guidance.
- RFC 5280, Internet X.509 Public Key Infrastructure Certificate and Certificate Revocation List (CRL) Profile.
- RFC 7292, PKCS #12: Personal Information Exchange Syntax v1.1.
- NIST Special Publication 800-57 Part 1 Revision 5, Recommendation for Key Management.
- FIPS PUB 140-2 and FIPS PUB 140-3, Security Requirements for Cryptographic Modules.
How to contact BIOVIA Support
If you have any questions, please contact BIOVIA Support.
Need Assistance?
Our support team is here to help you make the most of our software. Whether you have a question, encounter an issue, or need guidance, we've got your back.