Re: Recovery Agent cannot recover encrypted files



Richard R wrote:
Just to recap the steps are now:

1. Created user efs_recovery and added to administrators group 2. Logged in as user and ran cipher /r:cert.pfx 3. In "Local Security Policy" Went to the "public key Policies/EFS" section and ran the "Add data recovery Agent" wizard. Added the cert i created using the cipher command which added the efs_recovery user as a recovery agent. 4.*NEW* Opened "Certificates (Local Computer)\Personal" in the MMC Certificates snap in and imported the pfx file created in step2.
4. Logged onto the server as USER2 who is also an administrator. Went to some random folder and encrypted the folder and it's contents. When i go to "Properties/Advanced/Details" the user i created (efs_recovery) is in the list of Recovery Agents. 5. Log in as efs_recovery and go to the folder that i previously encrypted. "Properties/Advanced" and untick the "Encrypt contents to secure data" checkbox.

It should have worked.

Remember, when you use /r:cert.pfx, your two files will be named: cert.pfx.pfx and cert.pfx.cer

Just so you don't confuse them when you import cert.pfx.pfx in your new step, the file dialog that comes up when you import has a filter on *.cer by default.

The new step doesn't need to be the new number 4, you just need to do it before you execute step 5.
.



Relevant Pages

  • Re: unable to perform "perfmon" on a remote Windows XP Pro
    ... I verified that the remote registry service is running on that XP Pro ... As far as the user rights in Local Security Policy, ... the XP that's having the problem the administrators group and the domain ...
    (microsoft.public.win2000.security)
  • Re: Admin equivalent group
    ... Or you can have freedom. ... -- RAH ... Administrators group can do. ... Local Security Policy and matching things up there, ...
    (microsoft.public.windowsxp.security_admin)
  • Admin equivalent group
    ... In Windows XP Pro, in Computer Management, I created a new Group called 'Onyx Remote Users'. ... I want this group to be able to do WHATEVER the Administrators group can do. ... There must be a quick, simple way to do this other than going into Local Security Policy and matching things up there, assigning security on folders, etc. ...
    (microsoft.public.windowsxp.security_admin)

Quantcast