EFS recovery problem

  • Thread starter Thread starter Sergiy Oliynyk
  • Start date Start date
S

Sergiy Oliynyk

Have serious trouble with decryption of user files on notebook.
OS is Windows XP sp1 and host is in Domain (Windows 2000 Server).
Once client notebook was reinstalled, so all private keys were lost... there
no backup.

Standart "Administrator" account is designated as default recovery agent for
domain, and i see him as RA in encrypted file properties. That's all fine
except a fact that "Administrator" was deleted from AD...
I made new account "RecoveryAdmin" with domain administrator privileges, and
designated it as RA for default domain policy. As a result - all new files
are encrypted with "RecoveryAdmin" as RA in their properties. But not old
ones!!!

Is there a way to assign new RA for old files?

Thank You!
 
Thank you, David!
That helped!

David Cross said:
The new RA will only be updated on files once those files, have been opened,
modified or touched by a script to apply the new DRA cert to them. you
should run cupher.exe /u to update all files to the new DRA.

http://www.microsoft.com/technet/prodtechnol/winxppro/deploy/cryptfs.mspx


--


David B. Cross [MS]

--
This posting is provided "AS IS" with no warranties, and confers no rights.

http://support.microsoft.com

Sergiy Oliynyk said:
Have serious trouble with decryption of user files on notebook.
OS is Windows XP sp1 and host is in Domain (Windows 2000 Server).
Once client notebook was reinstalled, so all private keys were lost... there
no backup.

Standart "Administrator" account is designated as default recovery agent for
domain, and i see him as RA in encrypted file properties. That's all fine
except a fact that "Administrator" was deleted from AD...
I made new account "RecoveryAdmin" with domain administrator privileges, and
designated it as RA for default domain policy. As a result - all new files
are encrypted with "RecoveryAdmin" as RA in their properties. But not old
ones!!!

Is there a way to assign new RA for old files?

Thank You!
 
Back
Top