Solved

Configuring Encryption on Windows XP in a Windows 2000 Domain Environment

Posted on 2006-07-21
9
466 Views
Last Modified: 2010-05-18
Hi,

There is a problem one of our clients are experiencing and I want to see if I can help them out.  To achieve this, I need to set up file encryption on one of our computers in the domain.  I don't have any experience in this area for our local network.

We are running a Windows 2000 domain with Windows XP clients.  I first tried right clicking the file >> properties >> Encrypt contents to secure data.  This gives me the following error:

"Recovery policy configured for this system contains invalid recovery certificate".

After doing some research, I found that I need to have a recovery agent configured.  In the local policies there is one certificate under "Public Key Policies/Encrypting File System which is Administrator and in the "Intended Purposes" field it says "File Recovery".  I assume this is a local file recovery certificate and since I am in a domain, I must import a Domain level certificate.  I hope I am on the right track to this point.

Here is where I am stuck in the fact that I want to be very cautious about what I do.  Obviously, I do not want to do anything harm anything on our network.  What do I need to do from here?  Do I export a domain certificate and import it locally?  I also tried "Browse Directory", selected Enterprise Admin, Domain Admin and my user object (with god privilages) and received this error message - "The selected user has no certificates suitable for Encryption File System Recovery and cannot be added as a recovery agent."  

In doing some testing in various areas such a trying to create a certificate, I received errors such as "...there is no certificate authority...".  I bypassed those and went on to other testing but thought that may be useful to note that.

My overall goal is simply to set up 1 domain client system with encryption.    

Thanks in advance for the help!!!!

Best Regards,

Karl
0
Comment
Question by:karlkawano
  • 4
9 Comments
 
LVL 13

Accepted Solution

by:
haim96 earned 250 total points
ID: 17155327
0
 
LVL 10

Assisted Solution

by:Walter Padrón
Walter Padrón earned 250 total points
ID: 17155837
Hi karlkawano,

This is a 5 parts article on using EFS.

Windows XP Pro: Using File Encryption
http://www.practicalpc.co.uk/computing/windows/xpencrypt1.htm

cheers,
Walter
0
 

Author Comment

by:karlkawano
ID: 17155838
Hi,

I did view that KB article.  I also viewed this one:

Best Practices for the Encrypting File System - http://support.microsoft.com/kb/223316/EN-US/

My understanding of the problem is that by default Windows XP Recovery agent is disabled.  You have to add a authorize "Recovery Agent Certificate"  to enable it and allow the encryption to happen.  How and where do I export or create this certificate?

Thanks,

Karl
 






0
Gigs: Get Your Project Delivered by an Expert

Select from freelancers specializing in everything from database administration to programming, who have proven themselves as experts in their field. Hire the best, collaborate easily, pay securely and get projects done right.

 

Author Comment

by:karlkawano
ID: 17155850
Walter,

Just saw your post.  I'll try it now and let you know how it goes.


Thanks,

Karl
0
 

Author Comment

by:karlkawano
ID: 17156671
Hi Walter,

I followed the procedures and was able to successfully create a recover agent and import it.  I was sure it was going to work - until I tried it.  Same error when encrypting:

"Recovery policy configured for this system contains invalid recovery certificate".

When I look the the cermgr under Certificates-Current User >> Personal >> Certificates I see 2 certificates.  One has intended purposes "Encrypting File System" and the other "File Recovery" (I assume the one we just created).

So what is the next step?  One noticable item that stands out in my mind is that he started off with step 1 as just encrypting a folder without first creating the recovery agent.  I read somewhere that the first time you try to encrypt a file it creates the cert file encryption cert.  Does this mean that since it didn't work for me initially that there is some other underlying issue?

Thanks for the help,

Karl
0
 

Author Comment

by:karlkawano
ID: 17156689
One other note,

When I try to open any of the certificates, the cert has a red X and says:

"This CA Root certificate is not trusted.  To enable trust, install this certificate in the Trusted Root Certification Authorities store"

Hope this gives some sort of clue.

Thanks Again,

Karl
0

Featured Post

Gigs: Get Your Project Delivered by an Expert

Select from freelancers specializing in everything from database administration to programming, who have proven themselves as experts in their field. Hire the best, collaborate easily, pay securely and get projects done right.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

In a recent article here at Experts Exchange (http://www.experts-exchange.com/articles/18880/PaperPort-14-in-Windows-10-A-First-Look.html), I discussed my nine-month sandbox testing of the Windows 10 Technical Preview, specifically with respect to r…
In this article we will discuss all things related to StageFright bug, the most vulnerable bug of android devices.
This is used to tweak the memory usage for your computer, it is used for servers more so than workstations but just be careful editing registry settings as it may cause irreversible results. I hold no responsibility for anything you do to the regist…
Hi friends,  in this video  I'll show you how new windows 10 user can learn the using of windows 10. Thank you.

776 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question