Encrypting File System |
As mentioned earlier in this chapter, it is recommended that you remove private keys for recovery agent accounts from the computers by exporting the keys to removable media and then putting the keys in locked storage. This should be done with the default recovery keys before any changes are made to recovery policy.
The Certificate Export wizard accomplishes this purpose. This wizard is available through the Certificates console (a Microsoft Management Console
If you are securing the recovery key for a stand-alone computer, log on as Administrator. The EFS recovery agent certificate is contained in the personal certificate store for the Administrator account.
If you are securing the recovery key for a domain, log on as Administrator on the initial domain controller created for the domain. The EFS recovery agent certificate is contained in the personal certificate store for the Administrator account of the first domain controller installed for the domain.
Use the Certificate Export wizard to export the certificate and private key to a removable medium. For information about how to export a certificate and its private key, see Certificates Help, and see "Windows 2000 Certificate Services and Public Key Infrastructure" in this book.
To delete the private key from the computer, you must select the Delete the private key if the export is successful check box on the Export File Format page of the wizard. When you have completed the wizard, the private key is deleted from the computer and the recovery agent certificate and private key resides in a .pfx file in the folder or drive that you have specified. Now you need to protect the .pfx file by putting it into secure storage.
To protect a .pfx file
You then can use the Certificates console to import the .pfx file to a recovery computer and perform recovery operations. After recovering encrypted files, secure the private key again.
An alternative to securing the private key on removable storage media is to use physically secured stand-alone computers for recovery operations and leave the private key for recovery on the computer. You then log on to the recovery agent account and use the secure computer for data recovery only. It is important, however, that you keep a backup of the certificate and private key so you can restore them to the recovery computer if necessary. You can use the Certificate Export wizard to create a backup of the recovery agent certificate and private key, but make sure the Delete the private key if the export is successful check box is cleared before completing the wizard. You cannot use the computer for recovery if the private key is deleted.
You can also store the recovery agent certificate and private key on a smart card. You must map the smart card certificate to the designated recovery account by using the certificate mapping feature of the Active Directory Users and Computers console (a Microsoft Management Console