Re: EFS encrypted files

Tech-Archive recommends: Repair Windows Errors & Optimize Windows Performance



Are you part of a domain?
In Windows XP and beyond, the user's RSA private key is backed up
using an offline public key whose matching private key is stored in
one of two places: the password reset disk (if Windows XP is not a
member of a domain) or in the Active Directory (if Windows XP is a
member of a domain).

Files encrypted with EFS can only be decrypted by using the RSA
private key(s) matching the previously-used public key(s). The stored
copy of the user's private key is ultimately protected by the user's
logon password. Accessing encrypted files from outside Windows with
other operating systems (Linux, for example, or even another instance
of Windows) is not possible -- not least of which because there is
currently no third party EFS component driver. Further, using special
tools to reset the user's login password will render it impossible to
decrypt the user's private key and thus useless for gaining access to
the user's encrypted files.


excelsior
.



Relevant Pages

  • Re: ssh : password against keys
    ... If someone manages to get in my windows Box, ... >keep a copy of the password protecting the private key file in memory so ... because the attacker now has "unlimited ... you could have key for connecting ...
    (comp.os.linux.security)
  • Lost EFS Recovery Key for local admin
    ... local Administrator's recovery private key that is generated with the ... recovery certificae when the administrator first logs on. ... Backing up then deleteing the Administrator profile, and letting Windows ...
    (microsoft.public.win2000.security)
  • Re: EFS
    ... You can export private key from user's profile (if the key was marked as ... Much better solution to your problem would be use of Windows Rights ... However, if this USB device ... >> key on smart card. ...
    (microsoft.public.windows.server.general)
  • Re: SignCode.exe gives an error
    ... on a Windows 2000 or Windows 98 machine? ... double check that you are using the correct certificate associated ... with that private key, which is what this error message usually indicates. ... "Sergey Michalev" wrote in message ...
    (microsoft.public.platformsdk.security)