Cannot get EFS recovery agent function to work!

From: kgstrong (kgstrong_at_hotmail.com)
Date: 03/22/05


Date: Tue, 22 Mar 2005 03:06:36 -0800


I'm new to Windows 2000, running Win2k Pro on a stand-alone machine. I
encrypted some files before I knew anything about EFS - now a program
that uses some of the files cannot access them. The files were encrypted
under my "power user" account. The certificate that Win2k used to
encrypt them is enabled for "All Purposes" including Encrypted File
System, and File Recovery. As Administrator, I cannot import this
certificate for the Recovery Agent - says it is not enabled for file
recovery.

My Recovery Agent certificate (issued by Administrator to Administrator,
has a different thumbprint and is for File Recovery only.

Does EFS recovery agent's certificate thumbprint have to match the
certificate the files were encrypted with in order to recover these files?

Ken



Relevant Pages

  • RE: EFS File Share Help
    ... And your roaming profile cannot work properly. ... If user tries to encrypt a remote file/folder stored ... user, and subsequently requests, or generates a self-signed EFS ... The certificate and private key are loaded in a local profile ...
    (microsoft.public.windows.server.sbs)
  • RE: EFS rollout using Active Directory
    ... I just have something to add to the Final Thought regarding laptop users: ... You can implement EFS on systems running Windows 2000 and Windows XP ... Stand-alone workstations generate their own public key certificate that you ... encrypt the contents of their files or folders. ...
    (Focus-Microsoft)
  • Re: How can I share encripted files between two user accounts?
    ... Strong protection on keys doesn't work with EFS. ... Find the EFS recovery cert in the Personal store ... We just pick one of them to encrypt a file - there's no guarantee which one ... "George Valkov" wrote in message ...
    (microsoft.public.windows.server.security)
  • Re: EFS Errors
    ... Disabling DFS can disrupt your Group Policy propagation which may be causing ... your EFS errors if you have changed your Recovery Agent Certificate. ... I am able to encrypt on the server but noone is able to encrypt ...
    (microsoft.public.security)
  • Re: Restoring Encrypted Files
    ... I'm using EFS because of Microsoft recommendation to do so on portable ... clients. ... >> If I encrypt files on an XP Pro client and backup those files using NT ... > corrupted or missing certificate, it is critical that you back up the ...
    (microsoft.public.windows.server.sbs)