Re: Cant create keypair for EFS DRA

From: Brian Komar (bkomar@komarconsulting.com)
Date: 08/14/02


From: Brian Komar <bkomar@komarconsulting.com>
Date: Tue, 13 Aug 2002 21:34:47 -0500


In article <09d201c2418c$1c8fd3d0$a5e62ecf@tkmsftngxa07>, junkmail2
@lukaschuk.com says...
>
> This server does not have Certificate Server installed
> but I didnt think thats a requirement. EFS encryption
> certificates are generated OK and EFS is functioning. I
> just cant generate key pair to define recovery agents.
>
>
You will have to install an Enterprise CA on the network that will issue
the EFS Recovery Agent certificates. Change the permissions on the
certificate template to allow the desired user account Read and Enroll
permissions.

If you have Windows XP clients on the network, you can use the cipher
command to generate a new EFS recovery agent certificate by running
CIPHER /R.

This command generates an EFS recovery agent key and certificate, then
writes them to a .PFX file (containing certificate and private key) and
a .CER file (containing only the certificate).

You can then add the /CER file tot he EFS recovery policy for the domain
by importing the certificate from a file. For recovery, you can import
the PFX file into any user account that is performing the EFS recovery.

For more information on EFS and EFS recovery, please see:

http://www.microsoft.com/windowsxp/pro/techinfo/administration/recovery/

HTH,
Brian



Relevant Pages

  • RE: Relative Security Provided by Cached Domain Credentials?
    ... So when a user logs on the w2k terminal using a smartcard + pin no (rather ... If it does then EFS ... profile currently logged on for the private certificate. ...
    (Focus-Microsoft)
  • RE: Relative Security Provided by Cached Domain Credentials?
    ... certificates assigned to them, with each certificate having a set number ... smart card management tools which provide private key archival for smart ... AND the cert is also valid for EFS, they likely would be able to do ... What you probably could get to work for local file encryption, ...
    (Focus-Microsoft)
  • Re: EFS Disabling
    ... >> I had to reinstall XP on a computer and so I copied my EFS ... They have the same account names ... > You must have exported your EFS security certificate (onto a floppy ... > claiming that if you included your profile in your backups that there ...
    (microsoft.public.security)
  • Re: EFS Errors
    ... Disabling DFS can disrupt your Group Policy propagation which may be causing ... your EFS errors if you have changed your Recovery Agent Certificate. ... I am able to encrypt on the server but noone is able to encrypt ...
    (microsoft.public.security)
  • Re: How to decrypt EFS-protected restored files?
    ... It is my understanding that some backup programs do not backup efs files ... I export my EFS certificate to a floppy. ... > describes the steps in restoring EFS-protected files, the order of importing ...
    (microsoft.public.security)