DRA and EFS

  • Thread starter Thread starter Guest
  • Start date Start date
G

Guest

Hi, enabled EFS on our XP portables, together with the DRA functionality which is integrated with the Active Directory and the group policies
We generated a DRA certificate using the Microsoft Certificate Server and noticed that the validity period is only 1 year, we tried to change this but this seams to be not possible or does anybody have a proven method to change the validity period of a DRA certificate
Another question is: what happens with the DRA functionality if the DRA certificate expires, will we still be able to decrypt the data, even if the DRA certificate has expired
Thanks
Steven
 
The validity period is determined when the certificate is issued.

You will be able to decrypt but not encrypt when the DRA cert expires.
Actually that's also true for user's encryption certs - the expired ones can
still be used to decrypt, but not encrypt.
--
Drew Cooper [MSFT]
This posting is provided "AS IS" with no warranties, and confers no rights.


SAX said:
Hi, enabled EFS on our XP portables, together with the DRA functionality
which is integrated with the Active Directory and the group policies.
We generated a DRA certificate using the Microsoft Certificate Server and
noticed that the validity period is only 1 year, we tried to change this but
this seams to be not possible or does anybody have a proven method to change
the validity period of a DRA certificate.
Another question is: what happens with the DRA functionality if the DRA
certificate expires, will we still be able to decrypt the data, even if the
DRA certificate has expired?
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Back
Top