Question about failed root CA and EFS

Question about failed root CA and EFS

Secure Home | Search | About
 Microsoft Applications Security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
Question about failed root CA and EFS Graham 07-18-2007
Posted by =?Utf-8?B?R3JhaGFt?= on July 18, 2007, 8:26 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
Enterprise Root CA on Windows Server 2003 Std - hard drive was removed from
the server and stored in a locked cabinet.

Just over two years ago, a certificate was created, which apparently allowed
EFS in our domain. Last week, the certificate expired, and we stopped being
able to set the encrypted flag on folders. We now see the message, "Recovery
policy configured for this system contains invalid recovery certificate." All
the KB docs says to renew the certificate, or issue a new one.

We plugged in the hard drive from above, only to discover that it has
failed, so we cannot renew this particular cert or revive the Root CA. I
suppose we could create a new Root CA and issue a new one. The admin who
originally set up the Root CA is no longer here, and we have no documentation
about the certificates that it issued and what they were supposed to do. We
have no other CAs. Being able to recover previously encrypted documents is
not an issue.

My question is, can we just delete the cert from the domain and revert to
the default settings of no cert for EFS?

Thanks,

Similar ThreadsPosted
Question about pkiview.msc Root Certificate Expiring February 15, 2008, 4:16 am
Offline Root CA: Easy question on step 'Specify CRL distribution points' (newbie, please help) January 23, 2007, 5:51 pm
Clients no longer pick up the Root CA as a trusted root authority June 6, 2006, 6:59 pm
Convert Enterprise Root CA to Standalone Root CA and create new Subordinate CAs March 19, 2008, 1:45 am
Migrating from single enterprise root CA to different root CA May 11, 2007, 6:43 am
firewall question and windows installer/spyware question September 24, 2006, 8:48 am
Failed updates downloaded February 26, 2007, 5:04 am
Windows Defender failed to initialize?? January 1, 2007, 5:40 am
Failed to open the Group Policy Object September 12, 2005, 7:31 am
How to clear the Certificate Services "failed requests" log March 16, 2006, 1:56 pm

The site map in XML format XML site map

Contact Us | Privacy Policy