RE: Encrypting files on Windows XP: No Way

From: Pat Hoffer [MSFT] (pathoff_at_online.microsoft.com)
Date: 07/12/05


Date: Mon, 11 Jul 2005 15:28:03 -0700

It sounds like the File Recovery certificate that is installed in your
domain's EFS policy may have expired. You can see that certificate by
running rsop.msc on your WXP laptop and then expanding the Computer
Configuration policy all the way to the Encrypting File System node. (You
must be an admin on the machine to see this.) When you get to the node, open
the certificate in the right pane and check the validity dates.

This might help:
http://www.microsoft.com/windows2000/en/advanced/help/default.asp?url=/windows2000/en/advanced/help/sag_seconceptsunefs.htm
Click on "Data recovery."

Thanks.
Pat

-- 
This posting is provided "AS IS" with no warranties, and confers no rights.
"Wim" wrote:
> Hello,
> 
> Hope u can help me with this one. Until recently I could encrypt files on my 
> laptop (part of a Domain).
> My password didn't change.
> I could decrypt al my earlier encrypted fiels, but when I want to encrypt a 
> file i get:
> The "Recovery policy configured for this system contains invalid recovery 
> certificate"
> 
> I don't know where to look now....the workstation itself? The 
> Domaincontroller/AD (W2000) and hope someone's got very good tips for 
> me.......
> 
> Kind regards,
> 
> 
> Wim
> 


Relevant Pages

  • Re: Can no longer encrypt files
    ... The recovery policy as seen by the XP machine is bad. ... > and recovery agent's certificate. ... > This was working fine until the account password expired and was changed. ...
    (microsoft.public.windowsxp.security_admin)
  • Re: Expired Recovery Agent EFS Cert
    ... > one their Group Policy refreshes to show a valid certificate. ... > gpupdate on the XP pro computers to speed up the propagation of Group ... >> the Recovery Agent at the domain level policy. ...
    (microsoft.public.win2000.security)
  • Re: problems with creating a Recovery Agent
    ... in local security policy you indicate that there is a recovery ... > via a router, but not running active directory (that I know of, I don't ... > personal certificate, even get as far as exporting it to a .cer file, then ...
    (microsoft.public.windowsxp.security_admin)
  • EFS precautions
    ... I am a bit concerned about the recovery policy, ... Data Recovery Agent certificate to a floppy (well I think that it's the DRA ...
    (microsoft.public.windowsxp.security_admin)
  • Re: The message must contain a wsa:To header
    ... My client app is not generating a trace file. ... the client is not applying the WSE policy at all because of an ... at ApplicationMessagingWS.Dispatch(String messageType, String ... look for a certificate with this subject name in the certificate store ...
    (microsoft.public.dotnet.framework.webservices.enhancements)