Expired Recovery Agent EFS Cert




I am on a Windows 2000 domain where the Administrator account is set as the Recovery Agent at the domain level policy. The certificate recently expired for that account and some XP machines can no longer encrypt files or folders. When doing so they receive this error:


"Recovery policy configured for this system contains invalid recovery certificate."

I have done some looking, but I am still a little foggy on what steps I need to do to replace that certificate with a current one. It looks like I can run cipher /r to generate a recovery cert on an XP machine, import it into the Administrator's account using the Certificates MMC and then re-add Administrator to the policy as a recovery agent. After that it appears I can run cipher /u to update on the client machine to update it with the new info. Is that correct? Any steps or details I am leaving out?

Thanks!
Jeffrey
.



Relevant Pages

  • Re: Lost EFS Recovery Key for local admin
    ... I found I could get a File Recovery ... the certificate will be there. ... Fixing that allowed the built in Administrator to get a ... Along the way I created separate account called 'recovery' ...
    (microsoft.public.win2000.security)
  • Re: Access Denied after Encrypting Offline Cache
    ... I found that the Default Domain Policy had an expired recovery ... solution will depend on if you have a an Enterprise Certificate Authority ... not allow you to encrypt system files. ...
    (microsoft.public.windowsxp.security_admin)
  • Re: Can no longer encrypt files
    ... The recovery policy as seen by the XP machine is bad. ... > and recovery agent's certificate. ... > This was working fine until the account password expired and was changed. ...
    (microsoft.public.windowsxp.security_admin)
  • Re: How to add a domain user as a Data Recovery Agent
    ... Policy settings or contacting a domain controller. ... Recovery Agent certificate and when you examined the certificate are the ... Administrator account and I've tested the domain admin in regards to ...
    (microsoft.public.windows.server.security)
  • Re: EFS Recovery Agent
    ... It's a failed account lookup. ... Their certificate also needs to be a recovery certificate as ...
    (microsoft.public.win2000.security)