EFS and recovery agents after migrating to Active Directory

From: company (sbalaji@dontspam.bindview.com)
Date: 03/18/02


From: "company" <sbalaji@dontspam.bindview.com>
Date: Mon, 18 Mar 2002 09:57:38 -0600

I had some files encrypted on a W2K machine that was part of a NT4.0 domain
structure. The account used to encrypt was a domain user account that has
local admin
priveleges. Recently I migrated that account to a AD domain and a new
account was
created. When I log back in to the box with the old account, I was not able
to
decrypt the file. The private key portion of the certificate is not found
and only the
certificate is there. EFSINFO /R /U /C lists the recovery agent as the
Active directory domain
admin with a thumbprint. But if the AD domain admin logs in to the box and
tried it still gives
access denied. Next we tried the recovery steps as highlighted by support
articles and here
and it still is not working.

My question is where do I find the DRA's private key (on which box) and how
do I find one that matches the thumbprint of this DRA (as reported by
EFSINFO cmd)?

Thanks in Advance
/s



Relevant Pages

  • Re: Encrypted File System
    ... admin,but still he would be the default recovery agent within the ... all the regular tasks/backups and use the domain admin just for ... the new account with minimal admin rights could just perform regular ... perform maintainance tasks. ...
    (microsoft.public.windows.server.sbs)
  • Re: Incoming E-Mail - cant create contact in OU
    ... central admin pool different than the web app. ... that account a little (if the web app is compromised or something, ... So I started with giving the app pool account domain admins permissions then ...
    (microsoft.public.sharepoint.windowsservices)
  • Re: Security Breach in AD! Help!
    ... > about 5 minutes the user was removed from the built in admin group. ... > changed the default domain policy, the default domain controller policy, ... >> auditing of account logon for success and failure and account management ... >> success and failure in Domain Controller Security Policy. ...
    (microsoft.public.win2000.security)
  • Re: cant verify disk
    ... She went to DU, and when she pressed "verify disk", it asked her user ... Disk Utility has required an administrator name and password for certain ... This is clearly a task which requires admin privileges, ... seriously mucked up with her user account settings in the NetInfo ...
    (comp.sys.mac.system)
  • Re: Wscript within VBA
    ... One box is running VBA code,. ... One box is a domain controller, or has an account trusted to manipulate AD ... >> It posts a form to an ASP page, ... >> Since what you want to do sounds like it will require admin privileges, ...
    (microsoft.public.vb.database)