Encryption Confusion - Accessed denied - Yes, I Googled HELP PLEASE



Hi people, Boy did I do the wrong thing...XP Pro SR2:

I got curious about file/folder encryption so I did a little reading at
http://support.microsoft.com/kb/223316/en-us before attempting it.

Started to encrypt My Documents folder per the above kb article and then
canceled (turned chicken-I kept remembering the posts from unfortunate souls
who tried encryption and realized I needed to learn more before proceeding).
Noticed that some of the file/folder names were now "green" in color.
Assuming they were encrypted, I did the steps for decrypting the My
Documents folder. The folders' names now appeared in "black" text. I assumed
ALL (including files in the folders) had been decrypted.

Exported the cert with its private key to a CD, JUST IN CASE, and "removed"
the cert from the Personal window in Internet Explorer (because I read this
protects the encrypted files from physical theft of the computer).

Got brave (I mean stupid) again and tried encrypting the My Docs folder, but
again canceled.

THEN, I noticed that certain FILES were still encrypted so I attempted to
decrypt them by importing the cert from the CD. My file decryption attempts
on the individual files failed. I tried decrypting them from the folder
level but this had no effect. I see there are now TWO nearly identical certs
in the Personal window (each has a different serial number). Apparently, my
second attempt at encryption created another certificate(?). And how did the
original cert get listed again even though I "removed" it? :-/

I "viewed" the original cert for clues to what I was doing wrong and read:
"This CA Root Certificate is not trusted, etc." So, thinking I needed to put
it in the trusted cert area, I imported it there, too. Still could not
decrypt the files and now have two certs in the Personal and one in the
Trusted area.

Followed the instructions here http://www3.telus.net/dandemar/encrypt.htm to
take ownership. Turned off file sharing so I could see the security tab,
etc. Several attempts. I am still unable to decrypt the files. And not only
are there 3 certs, but now I have three names in the name list? Because
there are so many certs and names everywhere, I am thoroughly confused.
(aargh!)

Tried going back-in-time (I love this) to a restoration point, but that
didn't work, (of course). Undid the restoration and am back where I was (in
the present). :-)

Have spent hours on this. Just want to get my system back to where it was
before I added all this stuff to it. Can someone *please* tell me how to
clean up this mess? If you need more detailed info, please let me know.
Thanks for reading this!
--
Summer (no valid email)


.



Relevant Pages

  • dual password for file/folder encryption
    ... ideally no two passwords would decrypt the same contents. ... I am looking for encryption software. ... into that folder is automatically encrypted. ... set the master password on the folder (which should filter down to the ...
    (Security-Basics)
  • Re: Windows 2000 encrypted files
    ... Microsoft MVP (Windows, Security) ... > Settings\folder and copyed the Windows 2000 My ... and turn off file encryption it gives me an ... > error saying that it cannot decrypt any of the files. ...
    (microsoft.public.windowsxp.security_admin)
  • Re: All Files are Read-Only
    ... checkbox" If there is a check mark and the box is grayed out, the folder ... If you're trying to decrypt through the UI, ... > MS MVP (Windows Platform), MCSE, MCDBA ... >> thought I had undone the encryption, ...
    (microsoft.public.windowsxp.security_admin)
  • Re: Microsoft EFS
    ... Few questions on EFS. ... You can copy the folder regardless of the file system. ... keys that were used for the initial encryption, ... decrypt is tied to my password) when I change my password. ...
    (microsoft.public.security)
  • Meridian Prolog Manager Username and Plain Text Password Disclosure
    ... This is being released without Meridian or CERT approval. ... Meridian has been dragging their feet and has shown no good intent ... "No Encryption" databases passes every password in plain text as it is ... characters the first returned hash (16 HEX characters after a standard ...
    (Bugtraq)