Creating a recovery agent on local computer

Creating a recovery agent on local computer

Secure Home | Search | About
 Microsoft Applications Security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
Creating a recovery agent on local computer Nick Savoiu 01-12-2006
Posted by Nick Savoiu on January 12, 2006, 9:40 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
Hi,

I'm trying to create a recovery agent on my XP laptop.

I followed the instructions at

http://www.microsoft.com/windows2000/en/advanced/help/default.asp?url=/windows2000/en/advanced/help/encrypt_to_add_recovery_agent.htmIt's
not for WinXP but it seems to work. However when I get to the partwhere I should
select a recovery agent I need to browse for a certificate(I'm not on a domain,
therefore no active directory).How do I create this certificate in the first
place?Thanks,Nick


Posted by Nick Savoiu on January 12, 2006, 9:42 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
The link got messed up

http://www.microsoft.com/windows2000/en/advanced/help/default.asp?url=/windows2000/en/advanced/help/encrypt_to_add_recovery_agent.htm


Nick


> Hi,
>
> I'm trying to create a recovery agent on my XP laptop.
>
> I followed the instructions at
>
>
http://www.microsoft.com/windows2000/en/advanced/help/default.asp?url=/windows2000/en/advanced/help/encrypt_to_add_recovery_agent.htmIt's
> not for WinXP but it seems to work. However when I get to the partwhere I
> should select a recovery agent I need to browse for a certificate(I'm not
> on a domain, therefore no active directory).How do I create this
> certificate in the first place?Thanks,Nick
>



Posted by Roger Abell [MVP] on January 12, 2006, 9:51 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
cipher /r
may be used to create the cert

Then add this in local policy

If you want the DRA to be able to decrypt without having to
import the cert then log in with the DRA account and add the
DRA cert to its certificates (otherwise then may be done only
when decrypting in needed). In XP when this is imported one
may get the option of being prompted when use happens. Is so,
you must select to not get prompted.

Finally, save the cert file on non-degrading external media,
store safely, and do not forget the password.

> Hi,
>
> I'm trying to create a recovery agent on my XP laptop.
>
> I followed the instructions at
>
>
http://www.microsoft.com/windows2000/en/advanced/help/default.asp?url=/windows2000/en/advanced/help/encrypt_to_add_recovery_agent.htmIt's
> not for WinXP but it seems to work. However when I get to the partwhere I
> should select a recovery agent I need to browse for a certificate(I'm not
> on a domain, therefore no active directory).How do I create this
> certificate in the first place?Thanks,Nick
>



Posted by Steven L Umbach on January 12, 2006, 9:58 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
On XP Pro use the cipher /R command which will generate a .cer file that
contains only the certificate/public key and a .pfx file that contains the
certificate/private key. The .cer file is the one you want to import/add as
a Recovery Agent. Use cipher /? to find syntax on the cipher command. Be
sure to backup your user/RA EFS private key to a password protected .pfx
files and store in offline media somewhere safe. You might want to select
the option for delete of the private key for the RA when you export it and
keep it only off of the computer. --- Steve

http://support.microsoft.com/default.aspx?scid=kb;EN-US;223316 --- EFS
best practices.

> Hi,
>
> I'm trying to create a recovery agent on my XP laptop.
>
> I followed the instructions at
>
>
http://www.microsoft.com/windows2000/en/advanced/help/default.asp?url=/windows2000/en/advanced/help/encrypt_to_add_recovery_agent.htmIt's
> not for WinXP but it seems to work. However when I get to the partwhere I
> should select a recovery agent I need to browse for a certificate(I'm not
> on a domain, therefore no active directory).How do I create this
> certificate in the first place?Thanks,Nick
>



Similar ThreadsPosted
EFS files without recovery agent September 12, 2006, 10:42 am
RE: EFS files without recovery agent September 14, 2006, 5:08 am
problem with EFS Recovery agent December 10, 2007, 4:03 pm
EFS Recovery Agent Creation Question. November 1, 2006, 5:32 pm
Computer Hacker is illegally creating a new logon on my computer November 10, 2007, 9:32 pm
Creating local user account from ASP.NET (C#) April 24, 2007, 8:02 am
Copying local policy from one computer to another (No AD) March 17, 2006, 3:29 pm
Create a local group on a different computer November 9, 2007, 10:21 am
Recovery policy contains invalid recovery cert July 28, 2006, 12:59 pm
Isa 2004 and the Dpm 2006 agent December 26, 2005, 12:04 pm

The site map in XML format XML site map

Contact Us | Privacy Policy