PKI, External CA, EFS ?

Discussion in 'Security Software' started by Donald Welker, Oct 30, 2003.

  1. The following assume Windows 2000, XP, or 2003, but AD may or may not be

    1. Is it possible to set up a certificate issued by an external CA to be
    used for EFS encryption?

    2. Is it possible to set up a certificate issued by an external CA to act as
    an EFS recovery agent, or must all recovery agents be created in Windows?

    3. Assuming the answer to 1 is no, what processes or products exist to
    encrypt files and folders using externally-issued certificates that are
    located in the user's Windows certificate store?

    Don Welker
    Donald Welker, Oct 30, 2003
  2. 1. yes.

    2. yes, you can use a third party CA

    3. just install a valid third party cert and it should work automatically


    Third-Party Certificate Authority Support for Encrypting File System
    David Cross [MS], Oct 31, 2003
  3. Thanks David, that's good info.

    I would also like to flag MSKB Article 331333 for those with XP in NT4

    Unfortunately my CA doesn't implement the correct usage extensions so I
    guess I don't have a "valid third part cert" -- at least now I know what's

    Donald Welker, Oct 31, 2003
