Go Premium for a chance to win a PS4. Enter to Win


Configuring Encryption on Windows XP in a Windows 2000 Domain Environment

Posted on 2006-07-21
Medium Priority
Last Modified: 2010-05-18

There is a problem one of our clients are experiencing and I want to see if I can help them out.  To achieve this, I need to set up file encryption on one of our computers in the domain.  I don't have any experience in this area for our local network.

We are running a Windows 2000 domain with Windows XP clients.  I first tried right clicking the file >> properties >> Encrypt contents to secure data.  This gives me the following error:

"Recovery policy configured for this system contains invalid recovery certificate".

After doing some research, I found that I need to have a recovery agent configured.  In the local policies there is one certificate under "Public Key Policies/Encrypting File System which is Administrator and in the "Intended Purposes" field it says "File Recovery".  I assume this is a local file recovery certificate and since I am in a domain, I must import a Domain level certificate.  I hope I am on the right track to this point.

Here is where I am stuck in the fact that I want to be very cautious about what I do.  Obviously, I do not want to do anything harm anything on our network.  What do I need to do from here?  Do I export a domain certificate and import it locally?  I also tried "Browse Directory", selected Enterprise Admin, Domain Admin and my user object (with god privilages) and received this error message - "The selected user has no certificates suitable for Encryption File System Recovery and cannot be added as a recovery agent."  

In doing some testing in various areas such a trying to create a certificate, I received errors such as "...there is no certificate authority...".  I bypassed those and went on to other testing but thought that may be useful to note that.

My overall goal is simply to set up 1 domain client system with encryption.    

Thanks in advance for the help!!!!

Best Regards,

Question by:karlkawano
  • 4
LVL 13

Accepted Solution

haim96 earned 1000 total points
ID: 17155327
LVL 10

Assisted Solution

by:Walter Padrón
Walter Padrón earned 1000 total points
ID: 17155837
Hi karlkawano,

This is a 5 parts article on using EFS.

Windows XP Pro: Using File Encryption


Author Comment

ID: 17155838

I did view that KB article.  I also viewed this one:

Best Practices for the Encrypting File System - http://support.microsoft.com/kb/223316/EN-US/

My understanding of the problem is that by default Windows XP Recovery agent is disabled.  You have to add a authorize "Recovery Agent Certificate"  to enable it and allow the encryption to happen.  How and where do I export or create this certificate?



What does it mean to be "Always On"?

Is your cloud always on? With an Always On cloud you won't have to worry about downtime for maintenance or software application code updates, ensuring that your bottom line isn't affected.


Author Comment

ID: 17155850

Just saw your post.  I'll try it now and let you know how it goes.



Author Comment

ID: 17156671
Hi Walter,

I followed the procedures and was able to successfully create a recover agent and import it.  I was sure it was going to work - until I tried it.  Same error when encrypting:

"Recovery policy configured for this system contains invalid recovery certificate".

When I look the the cermgr under Certificates-Current User >> Personal >> Certificates I see 2 certificates.  One has intended purposes "Encrypting File System" and the other "File Recovery" (I assume the one we just created).

So what is the next step?  One noticable item that stands out in my mind is that he started off with step 1 as just encrypting a folder without first creating the recovery agent.  I read somewhere that the first time you try to encrypt a file it creates the cert file encryption cert.  Does this mean that since it didn't work for me initially that there is some other underlying issue?

Thanks for the help,


Author Comment

ID: 17156689
One other note,

When I try to open any of the certificates, the cert has a red X and says:

"This CA Root certificate is not trusted.  To enable trust, install this certificate in the Trusted Root Certification Authorities store"

Hope this gives some sort of clue.

Thanks Again,


Featured Post

Hire Technology Freelancers with Gigs

Work with freelancers specializing in everything from database administration to programming, who have proven themselves as experts in their field. Hire the best, collaborate easily, pay securely, and get projects done right.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Just about everyone has an old PC laying around.  Ask anyone in the IT industry, whether they are a professional or play in it as a hobby.  From outdated Desktops to cheap "throwaway" laptops, they are all around and not as hard to "fix up" as you m…
Windows 10 is here and for most admins this means frustration and challenges getting that first working Windows 10 image. As in my previous sysprep articles, I've put together a simple help guide to get you through this process. The aim is to achiev…
This is used to tweak the memory usage for your computer, it is used for servers more so than workstations but just be careful editing registry settings as it may cause irreversible results. I hold no responsibility for anything you do to the regist…
Hi friends,  in this video  I'll show you how new windows 10 user can learn the using of windows 10. Thank you.

885 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question