Creating CA and self-signed cert for EFS recovery



Sigh! When trying to discover a Step-by-Step (even in the so called
Step-by-Step section of Technet) method of setting up a simple (oxymoron?)
configuration of a CA and self-signed certificate for the sole purpose of
being able to recover EFS encrypted files and folders, I struck out.

Can anyone point me to some material on how to set this up? Our environment
is Windows 2003 servers (will make DC a CA for this purpose) and all
machines with EFS will belong to the domain where the CA exists.


.