EFS DRA policy

G

Guest

Our environment is 2000 AD with XP Pro sp2 & 2000 pro clients.
The users that will be encrypting data are XP Pro users and we intend to
move to 2003 AD later this year - currently on test.

We are just beginning to look at encryption and I've noticed that if I open
the administrators personal certificates mmc on a DC, I can see multiple file
recovery certificates. There are 8 certificates in total:
x1 EFS expiring in 2015
x7 File recovery with different expiry dates, one of which expired earlier
this year.

Why are there so many certificates? I thought one was generated
automatically.

Also, if I open the default domain policy, I can see that there is a
certificate for the adminstrator for file recovery but it expired March 2006.
I'm guessing this is the one that is automatically created? If I export
these keys (for backup) I am notified that there is no private key. What
would be the issues if this is deleted and I create another one?

many thanks
 
G

Guest

To update this:

I have looked at kb222022 which bizarely describes a different looking
policy -perhaps it's because I'm using gpmc on an xp pro sp2 pc. Anyway, I
have deleted all the contents out of Comp Config\ Windows Settings\ Security
settings\Public Key Policies\ Encrypting File System and from Propeties
unchecked Allow Users to use EFS...in order to disable EFS until I get it up
and running.
I've created a new OU with an EFS policy and am currently following the step
by step guide (which although is for w2k3 will I'm sure be useful).

I'm still curious about my questions below tho.
Thanks
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top