Re: Recovery Agent configured in GPO, but cannot see it in Encrypt



Hi Steven !

Thank you for your tips....

gpresult says, all policies applied successfully,
especially the EFS Recovery Policy
I checked the certificates twice, they are made out of a EFS Recovery Template

i created a file and encrypted it 4 mins. ago, no RA is defined....

is there a possibility to reset the efs portion of windows xp that it
reloads gpo settings ?

We now have several users, who need their files recovered.....
bad situation

regards
daniel


"Steven L Umbach" wrote:

Did running rsop.msc on that computer show the RA was defined by the domain
GPO?? Possibly the file was encrypted before a RA was configured and has not
been access since. Try opening the file to see if a RA shows after closing
it or creating a new EFS file to see what shows. If that all fails then
maybe there is a problem with GP applying to the computer. Usually that will
show as userenv errors/warning in the application log. The support tool
gpresult can also show what Group Policies are being applied to the computer
and the last time they were applied. The certificates that you added to the
domain GP need to be RA certificates when you view them. --- Steve


"daniel_theracer" <danieltheracer@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in
message news:5F0CAF64-F585-49CB-8389-B26F961ABF74@xxxxxxxxxxxxxxxx
Hi Steve !

Sorry, for misunderstood,

the domain group policy is defined, autoenrollment enabled, two accounts
entered as recovery agents..

on the client all group policies are applied, but in the details of an efs
encrypted file i still cannot see any RA ....
regards
Daniel

"Steven L Umbach" wrote:

Just because you can not see it in Local Security Policy does not mean
that
it is not enabled as that just means there is nothing defined in Local
Security Policy. Run rsop.msc on a computer to see if it shows configured
via your domain Group Policy and you can also examine the properties of
an
EFS file in properties/advanced - details [or use efsinfo] to see if a RA
is
associated with the EFS file. --- Steve


"daniel_theracer" <danieltheracer@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in
message news:A30710BB-1198-42D2-9CDA-59BCE01944CD@xxxxxxxxxxxxxxxx
Hi ms folks !

I'm a bit stressed, my users work with their efs certificates and do a
lot
encrypting.
I now discovered, that if i look to encryption details of a file, there
is
no RA displayed.
But i configured two accounts as RA 's

What can i do ?

Domain Policy is defined, configured.
when i look the the local security policy of a domain computer i cannot
see
anything
= "no policy defined"

Pls. help !
thank you very much
Daniel






.



Relevant Pages

  • Re: Recovery Agent configured in GPO, but cannot see it in Encrypt
    ... The other thing I would look at is to make sure your RA certificates are not ... rsop.msc but does not use them when EFS files are created. ... configuration/windows settings/security settings/public key ... the domain group policy is defined, autoenrollment enabled, two ...
    (microsoft.public.windowsxp.security_admin)
  • Re: Recovery Agent configured in GPO, but cannot see it in Encrypt
    ... details as that rsop.msc shows the computer displays the RA, the certificates ... EFS enabled, ... Group Policy settings can be forced to refresh ... because of domain Group Policy configuration you may have a problem with DNS ...
    (microsoft.public.windowsxp.security_admin)
  • Re: EFS files without recovery agent
    ... Someone before me has configured EFS policy in "Default Domain GPO". ... "EFS GPO" where I created Recovery agent with proper certificate. ...
    (microsoft.public.security)
  • Re: Recovery Agent configured in GPO, but cannot see it in Encrypt
    ... On the computer where you created the EFS files that do not show a RA try ... Policy that has the RAs configured which should be all computers if done at ... because of domain Group Policy configuration you may have a problem with DNS ...
    (microsoft.public.windowsxp.security_admin)
  • RE: Credential Roaming + EFS - how to cleanup user certificates ?
    ... Reason being that 25 certificates existed for that user which was too much ... we found that almost all users have multiple EFS ... Credential roaming is enabled and EFS is used for Offline files for all ... We are wondering if the EFS certificate template settings are correct. ...
    (microsoft.public.security)