Encrypting File System |
The process for recovering an encrypted file or folder when users have lost their private keys includes the following:
If the administrator has followed the procedure described earlier under "Securing the Recovery Key," the recovery agent account's certificate and public key are offline and securely stored in a .pfx file. To use the certificate on a recovery computer, you must import the certificate into the personal certificate store for the designated recovery account. For more information about importing certificates, see Certificates Help.
After you are done using the certificate for file recovery, delete it from the hard disk. There is no need to export it again because it remains on the removable medium.
Note that in this process the private key for recovery always stays on a designated recovery computer. The recovery agent administrator could bring his or her private key to the owner's computer, but it is not a good security practice to copy a private key on another computer.