Re: Backing up Encryption Certificate

From: Roger Abell [MVP] (mvpNOSPAM@asu.edu)
Date: 07/09/02


From: "Roger Abell [MVP]" <mvpNOSPAM@asu.edu>
Date: Tue, 9 Jul 2002 06:56:44 -0700


EFS certificates are exported, imported, and removed
by use of the Certificates MMC snapin.
Designation of an EFS recovery agent in the local
policy is only one part of defining a recovery agent that
is able to decrypt files. The .pfx also needs to be imported
by the DRA account using the Certificates snapin.

--
Roger Abell
MS MVP (Windows Platform), MCSE, MCDBA
Associate Expert - Windows XP ExpertZone
http://www.microsoft.com/windowsxp/expertzone
"Dave" <w123456@hotmail.com> wrote in message
news:145dc01c2274c$0267ccb0$36ef2ecf@tkmsftngxa12...
> How do I back up the encryption certificates in XP Pro?
> I have gone to Local Sec Settings/Public Key Policies,
> but I see no Recovery Agents there.
> When I run the wizard to designate user(s) as Recovery
> Agents it is looking for .cer files.
> How do I do this?
> Thanks.


Relevant Pages

  • Re: EFS Recovery Agents
    ... This happens if the Encrypting File System recovery policy implemented on this computer contains one or more EFS recovery agent certificates that have expired. ...
    (microsoft.public.windowsxp.general)
  • Re: EFS (Encrypting File System) - Unable to define Recovery Agent
    ... > I have recently just installed Win XP Pro. ... > setting up a recovery agent and/or to export the existing default recovery ... > I attempted to use certificates snap in to create a recovery ... to create the DRA cert and key - best done while logged in as ...
    (microsoft.public.windowsxp.security_admin)
  • Re: Certificate Templates - Should I delete any?
    ... > We are planning to deploy EFS. ... Delete alle other Templates from this folder. ... > automatically begin to issue certificates to workstations & domain ... Enroll the "recovery agent" and later deltete this template from policy ...
    (microsoft.public.win2000.security)
  • Re: EFS Recovery Agents
    ... implemented on this computer contains one or more EFS recovery agent certificates that have expired. ... Either renew the existing certificates or generate new certificates for the EFS recovery agents and reapply the recovery agent policy with those certificates. ... How To Encrypt a Folder in Windows XP ... How To Remove File Encryption in Windows XP ...
    (microsoft.public.windowsxp.general)
  • Re: ENCRYPTED DATA RECOVERY
    ... The certificates can not be recreated. ... The Recovery Agent needs to be designated beforehand. ... If it is an Ownership issue and not an encryption issue, ... I had made the decision to do a clean install of XP on ...
    (microsoft.public.windowsxp.security_admin)

Quantcast