Use of separated certificate and private key might be confusing without understanding how parts or CryptoAPI are related one to another. Apparently, CryptSignMessage and friends require private key in order to create a digital signature. It is not a problem when private key resides right in the signing certificate (such as, for example, imported with…