Specify that the private key will be imported as non-extractable. This means it will not be able to export from the keychain.
NOTE: This setting only applies to new auto-enrollment private key, it will not change those auto-enrolled private keys that are already imported to keychain.
Registry Hive | HKEY_CURRENT_USER |
Registry Path | Software\Policies\Centrify\CentrifyDC\Settings\Mac\Security\PublicKeyPolicies |
Value Name | PrivateKeyExtractable |
Value Type | REG_SZ |
Enabled Value | NO |
Disabled Value | YES |