Sitecore 9安装遇CRYPT_E_NOT_FOUND错误,关联的SIF配置项是什么?
Let’s break down the common causes and the key configuration variables/preconditions tied to this CRYPT_E_NOT_FOUND error during your Sitecore 9 installation with SIF 1.2.0 and Sitecore Fundamentals 1.1.0. This error almost always relates to missing or misconfigured SSL certificates that the installer expects to create or reference for your Sitecore instance.
Key Configuration Variables to Verify
These variables control how SIF handles SSL certificates during the binding setup:
SSLCertThumbprint: This is the critical variable that tells SIF which certificate to use for SSL bindings. If you’re using the development thumbprint workflow (like your log mentions), SIF is supposed to auto-generate a self-signed certificate, but if this variable is manually set to a thumbprint that doesn’t exist in your local certificate store, you’ll getCRYPT_E_NOT_FOUND.- Ensure you haven’t hardcoded an invalid thumbprint in your SIF parameters file. For development environments, leave this blank or use the
CreateCertificateparameter to let SIF generate it.
- Ensure you haven’t hardcoded an invalid thumbprint in your SIF parameters file. For development environments, leave this blank or use the
CreateCertificate: When set to$true, SIF will generate a self-signed SSL certificate and store its thumbprint inSSLCertThumbprint. If this is set to$false, you must provide a valid existing thumbprint inSSLCertThumbprint.CertStoreLocation: This defines where SIF looks for the certificate (usuallyCert:\LocalMachine\My). Double-check that the certificate (if manually provided) exists in this exact store, and that the installer has permissions to access it.SiteName: Your log referencesC:\inetpub\wwwroot\siteName\App_Data—make sure theSiteNamevariable matches the IIS site you’re targeting, as SIF uses this to associate the SSL binding correctly.
Critical SIF Preconditions to Check
Before re-running the installation, confirm these prerequisites are met:
- PowerShell Execution Policy: Ensure it’s set to
RemoteSigned(runSet-ExecutionPolicy RemoteSigned -Scope CurrentUseras admin) so SIF scripts can run properly. - Certificate Permissions: If you’re using an existing certificate, the user running the SIF installer must have read access to the private key of the certificate in the
LocalMachine\Mystore. You can set this via the Certificate Manager (certlm.msc):- Right-click the certificate > All Tasks > Manage Private Keys > Add your user account and grant Read permissions.
- Sitecore Fundamentals Compatibility: You’re using Sitecore Fundamentals 1.1.0 with SIF 1.2.0—this is a compatible pair, but make sure you’ve installed the Fundamentals module correctly (run
Get-Module -Name SitecoreFundamentals -ListAvailableto verify). - IIS Features: Ensure the IIS Hostable Web Core and IIS Management Scripts and Tools features are installed (these are required for SSL binding operations).
- Clean Previous Attempts: If this is a retry, delete any partially created certificates (from
Cert:\LocalMachine\My) and IIS sites, then clear the SIF cache by removing theSitecoreInstallFrameworkfolder inC:\Program Files\WindowsPowerShell\Modules.
Quick Troubleshooting Check
To confirm if the expected certificate exists in your store, run this PowerShell command (replace your-site-name with the actual site name from your parameters):
Get-ChildItem -Path Cert:\LocalMachine\My | Where-Object { $_.Subject -match "CN=your-site-name" }
If no results come back, SIF either failed to generate the certificate or you’re referencing a non-existent one.
内容的提问来源于stack exchange,提问作者K. Dean

