EFS Recovery Agent

From: Steven Bellamy (nospam_at_nospam.com)
Date: 02/20/04


Date: Fri, 20 Feb 2004 16:05:12 -0000

Hi,

I am having a problem trying to decrypt information using a Recovery Agent.

We're running a W2K Adv Server SP3 in mixed mode.

I have setup EFS using a GPO for the domain. I have specified 3 user
accounts to be Recovery Agents for the domain, all of which are part of the
admin group.
I used the Wizard to add or create the RA's, I did not import any
certificates.

When I use efsinfo /u /r on an encrypted file, I get the following info.

test.txt: Encrypted
  Users who can decrypt:
    ABCDOMAIN\user (user(user@abcdomain.com))
  Recovery Agents:
    Unknown (RA1(ra1@abcdomain.com))
    Unknown (RA2(ra2@abcdomain.com))
    Unknown (RA3(ra3@abcdomain.com))

Does anyone know why the RA's have a domain of Unknown?
Is this possibly why I can't decrypt a file on a PC that has a recovery
agent certificate installed?

Thanks for your help!



Relevant Pages

  • Re: Multiple Data Recovery Agents in EFS for Win2000
    ... recovery agents can only be configured on local machine. ... be decrypted by the recovery agents shown by efsinfo. ... > delliot, delliot2, and administrator. ... > Users who can decrypt: ...
    (microsoft.public.win2000.security)
  • Re: Decrypting an encrypted file
    ... The Recovery Agent needs to be designated in advance. ... You need your key to decrypt the data. ... > create keys, add Recovery Agents etc. and throw the file away? ...
    (microsoft.public.windowsxp.security_admin)
  • Re: encrypted windows 2000 folder problem.
    ... This is the return when I run efsinfo /r /u /c ... ebook: Encrypted ... Users who can decrypt: ... Recovery Agents: ...
    (microsoft.public.win2000.security)