How to backup the recovery key
To backup the local administrator's private
key:
(The following is from Microsoft)
WARNING:
After you export the private key to a disk, store the disk in a secure place. If
someone gains access to your EFS private key, he or she can gain access to your
encrypted data.
- Log on to your computer using the local Administrator
account.
NOTE: You must use the built-in Administrator
account, not just an account with Administrator privileges.
- Click Start, click Run, type secpol.msc, and
then click OK.
- Click the plus sign (+) next to Public Key Policies to expand this item.
- Click the Encrypted Data
Recovery Agents category.
- In the right-hand pane, a certificate that is issued
to "Administrator" with an intended purpose of "file recovery" is displayed.
Right-click this item, and then click All tasks >
export.
- Click Next.
- Ensure the Yes, export the
private key option is selected, and then click Next.
- In the Export File Format
dialog box, if you want to remove the private key associated with the
Administrator account, click to select the Delete the
private key if the export is successful check box.
- Click Next.
- Type and confirm a password to secure the exported
key, and then click Next.
-
You are prompted to save the certificate and the
private key to a file. You should back up the file to a disk or removable
media device, and then store the backup in a location where physical security
of the backup is ensured. Type an appropriate file name, and then click
Next.
-
When the
Completing the
Certificate Export Wizard
dialog box is displayed, verify the options that
you selected, and then click
Finish
.
- When the The export was
successful dialog box is displayed, click OK.
- You must restart your computer to complete the
removal of the private key.