Re: Ruined Domains and EFS recovery

From: Steven Umbach (n9rou_at_comcast.com)
Date: 09/08/03


Date: Mon, 08 Sep 2003 02:08:50 GMT


Users should still be able to decrypt their files with their own EFS key,
however to answer your question - yes a Recovery Agent or a user can and should
export their certificate AND private key to a place of safe keeping. When you
export your private key, you are also given the option to password protect the
file. See links below. --- Steve

http://support.microsoft.com/default.aspx?scid=kb;EN-US;223316
http://support.microsoft.com/default.aspx?scid=kb;EN-US;241201

"myrt webb" <myrtwebb@centurytel.net> wrote in message
news:392901c3758e$e3cc03b0$a001280a@phx.gbl...
> A recent post talked about how someone's domain controller
> was ruined by a virus and they had to reformat and
> reinstall which of means that the old domain is gone.
> Apparently a full backup was not available.
>
> Problem occurs with users who have encrypted files on the
> defunct DC and now cannot get to their encrypted files
> because the old domain does not exist.
>
> As a preventative can a recovery agent place their EFS
> recovery certificate on a disk and store it someplace.
> Then use that disk to import the certificate and open the
> encypted files that have been restored to a seperate
> computer?
>
> Is there a better way to do it?(other than full backups of
> DC's)
>
> Interesting problem.



Relevant Pages

  • Re: How to add a domain user as a Data Recovery Agent
    ... Policy settings or contacting a domain controller. ... Recovery Agent certificate and when you examined the certificate are the ...
    (microsoft.public.windows.server.security)
  • Re: How to add a domain user as a Data Recovery Agent
    ... Recovery Agent certificate and when you examined the certificate are the ... I'm trying to figure out how to add a non-privileged, domain user account ... I add the users as data recovery agents. ...
    (microsoft.public.windows.server.security)
  • RE: Recovery agent for EFS, how can i get it done PLEASE HELP
    ... enterprise admins still cant request cert everytime i request i get this ... The certificate cannot be installed because of one or more of the following ... >> Recovery and cannot be added as a recovery agent. ...
    (microsoft.public.windows.server.active_directory)
  • Re: How to add a domain user as a Data Recovery Agent
    ... Did you verify that the certificate issued to the user is indeed a Recovery ... I'm trying to figure out how to add a non-privileged, domain user account ... sure that the EFS Recovery Agent certificate template is published by my ...
    (microsoft.public.windows.server.security)
  • Re: decrypting a file question
    ... I seem to have all profiles. ... > profile of the user account that encrypted the file and the Recovery Agent ... The EFS or Recovery Agent ... > certificate needs to show that "you have the private key that corresponds ...
    (microsoft.public.win2000.security)

Quantcast