Re: cant decrypt files

Tech-Archive recommends: Fix windows errors by optimizing your registry



In news:84CEFCCA-4B3C-47A0-BD27-B66594E33FA9@xxxxxxxxxxxxx,
ckwong19802003@xxxxxxxxx <ckwong19802003@xxxxxxxxx> stated, which I
commented on below:
hi

I have these problem

recovery policy configured for this system contain invalid recovery
certificate.and i suspect the certificate is expired on the domain
controller and it cause these problem.Kindly advise on how to fix
these problem

Did you check the domain's CA for the actual expiration date? Was there a
recovery user configured? By default the domain admin is the recovery
account.

--
Ace
Innovative IT Concepts, Inc (IITCI)
Willow Grove, PA

This posting is provided "AS-IS" with no warranties or guarantees and
confers no rights.

Ace Fekay, MCSE 2003 & 2000, MCSA 2003 & 2000, MCSE+I, MCT, MVP
Microsoft MVP - Directory Services
Microsoft Certified Trainer

Having difficulty reading or finding responses to your post?
Instead of the website you're using, I suggest to use OEx (Outlook Express
or any other newsreader), and configure a news account, pointing to
news.microsoft.com. This is a direct link to the Microsoft Public
Newsgroups. It is FREE and requires NO ISP's Usenet account. OEx allows you
to easily find, track threads, cross-post, sort by date, poster's name,
watched threads or subject.
It's easy:

How to Configure OEx for Internet News
http://support.microsoft.com/?id=171164

Infinite Diversities in Infinite Combinations
Assimilation Imminent. Resistance is Futile
"Very funny Scotty. Now, beam down my clothes."

The only constant in life is change...


.



Relevant Pages

  • Re: How to add a domain user as a Data Recovery Agent
    ... Did you verify that the certificate issued to the user is indeed a Recovery ... I'm trying to figure out how to add a non-privileged, domain user account ... sure that the EFS Recovery Agent certificate template is published by my ...
    (microsoft.public.windows.server.security)
  • Re: Access Denied after Encrypting Offline Cache
    ... solution will depend on if you have a an Enterprise Certificate ... not allow you to encrypt system files. ... a message appears: "Recovery policy configured ... it's only the offline copies that are to be encypted. ...
    (microsoft.public.windowsxp.security_admin)
  • Re: Access Denied after Encrypting Offline Cache
    ... I found that the Default Domain Policy had an expired recovery ... solution will depend on if you have a an Enterprise Certificate Authority ... not allow you to encrypt system files. ...
    (microsoft.public.windowsxp.security_admin)
  • Windows 2003 CA Server and Templates Do not work for EFS!
    ... Requirement is to have an EFS recovery certificate for the domain that has ... Create a policy for users designated as recovery agents by creating a group ...
    (microsoft.public.security)
  • Re: Lost EFS Recovery Key for local admin
    ... I found I could get a File Recovery ... the certificate will be there. ... Fixing that allowed the built in Administrator to get a ... Along the way I created separate account called 'recovery' ...
    (microsoft.public.win2000.security)