Tech Tips / Windows XP / Security


Designate a DRA and recover encrypted files

Bookmark and Share
By default, Windows XP Professional stand-alone PCs don't have a data recovery agent (DRA).

In order to recover users' files, you'll need to create a DRA. However, you must first have a recovery certificate.

Follow these steps to create a DRA certificate:

  1. Log on as an administrator.
  2. In the command prompt, type cipher.exe /r:filename.
  3. Type the password at the prompt. This will create a new DRA certificate and the
    private key.

After obtaining the certificate, follow these steps to designate a DRA:

  1. Log on as an administrator or user who will become the DRA.
  2. Open the Local Security Policy snap-in from the Administrative Tools folder.
  3. Expand Public Key Policies.
  4. Right-click Encrypting File System and select Add Data Recovery Agent, which
    will start the Add Recovery Agent Wizard.
  5. In the Wizard browser, import the .cer file that was created with the cipher utility.
    This will designate the DRA.

Be sure to place the certificate and private key that was created with the cipher utility in a safe place. Don't leave them on the hard drive, because anyone who obtains them can decrypt the files that were created since the DRA designation.

Note: The DRA can only recover files that are encrypted after its designation. Files created before the DRA are unrecoverable.

Contact Us | Advertise | Authors | Subject Index | RSS Feeds

Copyright ©2009 Setup32.com