Encrypted Data Recovery Agents

Encrypted Data Recovery Agents

Secure Home | Search | About
 Microsoft Applications Security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
Encrypted Data Recovery Agents Bob A 08-25-2006
Posted by =?Utf-8?B?Qm9iIEE=?= on August 25, 2006, 3:17 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
Good Day. I have a Win2K AD domain controller with an expired Administrator
certificate under the Domain Security Policy Encrypted Data Recovery Agents.
I want to encrypt some files, but can't with an expired recovery agent
certificate. How do I renew this certificate? Is there a "How to:" article
with the step-by-step procedures? Google serch and technet search didn't
yeild much.

Thanks in advance,

- Bob

Posted by Steven L Umbach on August 25, 2006, 7:07 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
Do you have a Certificate Authority on your network? If you do you can
request a new one from it while logged on as a domain level administrator.
Otherwise you can use an XP Pro computer and use cipher to create a RA. Then
you can import the .cer file created into the Group Policy where you have
the EFS RA configured. The .cer file is not sensitive but the .pfx file is
as it contains the private key used for decryption and you need to provide a
password for it. You want to keep the RA .pfx file on a secure computer or
copy it to external media and keep in a couple safe places. Even if you
leave it on a secure computer keep a couple of copies in safe places and do
NOT forget the password. The article below explains what you need to know
for XP Pro but in your case you want to import the RA certificate into the
domain level Group Policy that is configured to use it which may be Domain
Security Policy.

Steve

http://support.microsoft.com/kb/887414

> Good Day. I have a Win2K AD domain controller with an expired
> Administrator
> certificate under the Domain Security Policy Encrypted Data Recovery
> Agents.
> I want to encrypt some files, but can't with an expired recovery agent
> certificate. How do I renew this certificate? Is there a "How to:" article
> with the step-by-step procedures? Google serch and technet search didn't
> yeild much.
>
> Thanks in advance,
>
> - Bob



Similar ThreadsPosted
Using ISP webspace to store Encrypted sensitive data. Comments ?? November 6, 2007, 6:16 pm
System Crash and Data Recovery August 14, 2007, 9:53 pm
decrypting email in pst file with efs data recovery certificate??? October 21, 2007, 9:11 pm
Recovery policy contains invalid recovery cert July 28, 2006, 12:59 pm
Re: what does the "Microsoft data access" "remote data services" add-in do? October 18, 2007, 3:17 am
what does the "Microsoft data access" "remote data services" add-in do? October 17, 2007, 5:40 am
Password encrypted for FTP transfer August 29, 2005, 11:39 am
How to Copy EFS(encrypted) Files.... December 5, 2005, 1:45 pm
Cannot decrypt about 5% of encrypted files March 29, 2007, 10:22 am
Access encrypted files September 8, 2007, 11:56 am

The site map in XML format XML site map

Contact Us | Privacy Policy