Re: EFS (Encrypting File System) - Unable to define Recovery Agent

From: Roger Abell [MVP] (mvpNOSPAM@asu.edu)
Date: 02/27/03


From: "Roger Abell [MVP]" <mvpNOSPAM@asu.edu>
Date: Thu, 27 Feb 2003 00:17:10 -0700


"Scott Beattie" <scottbeattie@comcast.net> wrote in message news:uc4YfAX3CHA.1896@TK2MSFTNGP10.phx.gbl...
> I was able to generate the certificate and the private key using the cipher
> /r. I then added the certificate to group policy as indicated. I also ran
> cipher /u so that the one existing encrypted text file would get the new
> recovery agent (administrator) listed as a valid recovery agent for the
> file. The file was encrypted by a user other than the administrator. If I
> log on as administrator with the intent to recover the encyrted file from
> the other user - and then I import the certificate and the private key and
> then attempt to manipulate the encrypted file in any way - I am told "access
> denied". I have even tried backing up the file using the backup utility and
> restoring it as a different file name in a different folder - I still cannot
> access it. What step am I missing to recover this file?

Not sure. The backup/restore and also the use of /u
both seem to rule out NTFS permission issue.
Did you say to not prompt when used when given the
choice while importing the pfx ? That is the only
choice that works - selecting to be prompted results
in inability to decrypt.
 

-- 
Roger 
> "Roger Abell [MVP]" <mvpNOSPAM@asu.edu> wrote in message
> news:#YQFkDW3CHA.2576@TK2MSFTNGP11.phx.gbl...
> That is cipher /r one uses for this
> 
> --
> Roger
> 
> "Peter Clark" <clark@hushmail.com> wrote in message
> news:043401c2dd3c$487b1f80$a101280a@phx.gbl...
> > its hidden away :-(
> >
> > cmd -> c:\>cipher /?
> >
> > read about the parameter /w
> >
> > create a new encryption key
> >
> > then add group policy for the local machine in mmc
> >
> > goto: console root\local computer policy\computer
> > configuration\windows settings\security settings\public key
> > policies\encrypting file system\
> >
> > right click and add the .cer file you just created.
> >
> > n.b - i think this is the correct way - it worked for me
> > anyhow, but check first.
> 
> 


Relevant Pages

  • Re: Recovery Agent fails to recover Encrypted Data
    ... >> EFS Recovery Certificate for a user, ... >> Recovery Agent. ... also encrypt a file with ordinary user, ... it is the holder of the *private key* that can open the file as ...
    (microsoft.public.win2000.security)
  • Re: recovery agent keys/certs
    ... If you want to be especially secure you can run "cipher /w" after you ... delete the .pfx file and empty the recycle bin. ... After the new recovery agent is in place in group policy have every user ... > Choose the 'Automatically Select The Certificate Store ...
    (microsoft.public.windowsxp.security_admin)
  • Re: Key Recovery and Decryption
    ... If you did not back up your private key before you re-installed, ... I had the encryption key backed up on ... > and designating a Data Recovery Agent. ... > to install the Administrator's Data Recovery Certificate ...
    (microsoft.public.windowsxp.security_admin)
  • Key Recovery and Decryption
    ... I had the encryption key backed up on ... and designating a Data Recovery Agent. ... to install the Administrator's Data Recovery Certificate ... corresponding private key but if I try to export this ...
    (microsoft.public.windowsxp.security_admin)
  • Re: Recovery Agent certificate
    ... > Create a DRA cert using cipher /r ... >> to add a Recovery Agent to my computer Encryption File System ... >> Importing the certificate into the various "Root Trust" list etc makes ...
    (microsoft.public.windowsxp.security_admin)