Re: Problems setting up the Recovery Agent
- From: "Roger Abell [MVP]" <mvpNoSpam@xxxxxxx>
- Date: Wed, 27 Dec 2006 17:23:10 -0700
OK, let's focus on this step
<quote>
I relog on as the RA, and import the cert of the RA into
this machine and then try to open up the dummy file.
</quote>
I assume the workstation is XP, and that by import the cert
you did mean the private key from the pfx was also imported.
In XP when you do this you are offered to have a prompt
on use, but for decryption to work when importing the key
you must select to just have the key used without prompting.
Did you do it that way ?
"techo crat" <spos4life@xxxxxxxxxxx> wrote in message
news:1167251788.260324.205270@xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
To be more clear on my problem I'll list some other steps/info I didn't
mention.
I installed the Entreprise CA of Microsoft.
I had also given the new Recovery Agent "Modify" rights on the
encrypted file.
After installing the Entreprise CA, I added the Recovery Agent to the
Recovery Policy.
A side note, I also created a recovery policy for the Domain Admin. So
presently the Recovery Agent and the Domain Admin has a Certificate
issued by the CA. But I also kept the self signed Certificate for the
Domain Admin (which was created the first time I logged into the DC)
In the properties of the encrypted file, in the "Data Recovery Agents
For This File As Defined By Recovery Policy:",
I could see the 3 Recovery Agents, mentioned above, for this file.
Even the certificate thumbprint of each RA in the properties of the
encrypted file and in the Group Policy Editor were identical.
So I don't know what is missing.
Thanks for any help.
.
- Follow-Ups:
- Re: Problems setting up the Recovery Agent
- From: techo crat
- Re: Problems setting up the Recovery Agent
- References:
- Problems setting up the Recovery Agent
- From: techo crat
- Re: Problems setting up the Recovery Agent
- From: Roger Abell [MVP]
- Re: Problems setting up the Recovery Agent
- From: techo crat
- Problems setting up the Recovery Agent
- Prev by Date: Re: "Best Practices" Guidelines for New Network Admins
- Next by Date: Re: Windows 2003 Domain Controller (Open Port 593)
- Previous by thread: Re: Problems setting up the Recovery Agent
- Next by thread: Re: Problems setting up the Recovery Agent
- Index(es):
Relevant Pages
|
|