EFS Recovery Agent Creation Question.

EFS Recovery Agent Creation Question.

Secure Home | Search | About
 Microsoft Applications Security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
EFS Recovery Agent Creation Question. Mark 11-01-2006
Posted by =?Utf-8?B?TWFyaw==?= on November 1, 2006, 5:32 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
All,
I am in the final steps of implementing EFS into Active directory. I
have created my CA server, configured my EFS recover template, but that
leaves me with one question. When I request an EFS recovery certificate, the
computer name is displayed in the summary page during the certificate request
wizard. Does it matter which computer I create the recovery agent’s
certificate upon as long as the computer is a member of the domain? Or does
it need to be a certain computer in the domain such as a DC?

Thanks for your help in this.

Mark


Posted by Brian Komar [MVP] on November 1, 2006, 11:06 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
Mark@discussions.microsoft.com says...
> All,
> I am in the final steps of implementing EFS into Active directory. I=
=20
> have created my CA server, configured my EFS recover template, but that=
=20
> leaves me with one question. When I request an EFS recovery certificate,=
the=20
> computer name is displayed in the summary page during the certificate req=
uest=20
> wizard. Does it matter which computer I create the recovery agent=E2=A4=
=3D3Fs=20
> certificate upon as long as the computer is a member of the domain? Or do=
es=20
> it need to be a certain computer in the domain such as a DC?
>=20
> Thanks for your help in this.
>=20
> Mark
>=20
>=20
It really does not matter where you request the certificate. Just make=20
sure that you export:
- The certificate in base64 or DER encoding to add to the Recovery Agent=20
policy (preferably at each domain)
- The certificate in a PKCS#12 format and saved to media such as a CD to=20
allow import for recovery procedures

Brian

Similar ThreadsPosted
EFS files without recovery agent September 12, 2006, 10:42 am
RE: EFS files without recovery agent September 14, 2006, 5:08 am
problem with EFS Recovery agent December 10, 2007, 4:03 pm
Creating a recovery agent on local computer January 12, 2006, 9:40 pm
Recovery policy contains invalid recovery cert July 28, 2006, 12:59 pm
Share Creation Event ID May 23, 2006, 10:25 am
Audit the Creation of a Directory February 7, 2007, 3:48 pm
Is there any SPNEGO/GSSAPI token creation API? August 9, 2005, 9:29 pm
disable dump file creation January 12, 2006, 2:53 am
disable dump file creation January 12, 2006, 2:55 am

The site map in XML format XML site map

Contact Us | Privacy Policy