FUCKUP #002: The Service That Worked Without Its Expected Private-Key ACL Entry
The symptom On a Windows Server 2019 host, a service failed after a second cold restore. The service used a manually provisioned certificate with a private key in Local Computer → Personal. The certificate and associated private key had been present for more than six months and had not been intentionally replaced or reprovisioned. The service had been working normally. Investigation of the failed state showed no explicit Read ACL entry for the service account on the private key. Adding that entry made the service work immediately again. ...