Re: Expired Recovery Agent EFS Cert
- From: "Steven L Umbach" <n9rou@xxxxxxxxxxxxxxxxxxxxxxxxxx>
- Date: Wed, 7 Dec 2005 23:24:50 -0600
Once you add the new certificate to the Group Policy where the EFS RA is
specified then the users on the computers should be able to use EFS again
one their Group Policy refreshes to show a valid certificate. You can run
gpupdate on the XP pro computers to speed up the propagation of Group Policy
otherwise it should take approximately 90 minutes for computers already
online. You can run rsop.msc on an XP Pro computer to see if the change has
propagated. Be sure to export a copy of the new RA certificate AND private
key to a password protected .pfx file on external media for safe
eping. --- Steve
"Jeffrey" <noemail@xxxxxxxxx> wrote in message
news:uUGhhf0%23FHA.2520@xxxxxxxxxxxxxxxxxxxxxxx
>
> I am on a Windows 2000 domain where the Administrator account is set as
> the Recovery Agent at the domain level policy. The certificate recently
> expired for that account and some XP machines can no longer encrypt files
> or folders. When doing so they receive this error:
>
> "Recovery policy configured for this system contains invalid recovery
> certificate."
>
> I have done some looking, but I am still a little foggy on what steps I
> need to do to replace that certificate with a current one. It looks like
> I can run cipher /r to generate a recovery cert on an XP machine, import
> it into the Administrator's account using the Certificates MMC and then
> re-add Administrator to the policy as a recovery agent. After that it
> appears I can run cipher /u to update on the client machine to update it
> with the new info. Is that correct? Any steps or details I am leaving
> out?
>
> Thanks!
> Jeffrey
.
- Follow-Ups:
- Re: Expired Recovery Agent EFS Cert
- From: Roger Abell [MVP]
- Re: Expired Recovery Agent EFS Cert
- References:
- Expired Recovery Agent EFS Cert
- From: Jeffrey
- Expired Recovery Agent EFS Cert
- Prev by Date: Re: Delegation Account Unlock to Users
- Next by Date: Re: Identifying Service Accounts
- Previous by thread: Expired Recovery Agent EFS Cert
- Next by thread: Re: Expired Recovery Agent EFS Cert
- Index(es):
Relevant Pages
|
|