Re: EFS Data Recovery not working as expected



Thank you for your reply. Believe me when I tell you that I have read all
Microsoft and most non-microspft articles on EFS. I have googled "EFS" and
read at least 2 pages worth of searches; nothing explaining the problem I am
having. Probably something trvial, but I cannot figure it out. Essentially, I
have a CA setup as an enterprise CA issuing certificates to users
automatically. a group policy was created with group filtering for specific
machines that we want EFS to be used on regardless of who logs in. A test
user logs in, they get a certificate from CA and DRA listed as agent able to
recover data, NOT domain administrator (microsoft best practice). The
thumbprint for the DRA on the encrypted file matches the thumbprint of the
DRA's file recovery certificate on the certicate server. I log into the CA as
the DRA and export the private key into pfx format. I log into the machine
that I want to recover data for as the DRA, import the private key, try to
decrypt data, access denied. I'm stumped and Microsoft's explanation of using
a DRA is somewhat lacking when it comes to a domain setup

"GreenieLeBrun" wrote:



Leo Cruz wrote:
I've recently setup EFS for an enterprise network and everything is
working great, except decryption. I've created a custom group policy,
setup and enterprise CA, and everything seems to be working well.
When i attempt to recover data as the DRA, i'm getting access denied
and cannot figure out the cause. If this is the correct forum to post
this in, let me know and I'll go through an exhaustive explanation of
the setup. If this is not the correct forum, please let me know where
i should post this. Thanks.

I don't use EFS but you may find some help in the attached links :-

The Encrypting File System
http://www.microsoft.com/technet/security/topics/cryptographyetc/efs.mspx

Best practices for the Encrypting File System
http://support.microsoft.com/kb/223316/en-us

How to back up the recovery agent Encrypting File System (EFS) private key
in Windows Server 2003, in Windows 2000, and in Windows XP
http://support.microsoft.com/kb/241201

How To Encrypt a Folder in Windows XP
http://support.microsoft.com/?id=308989

How To Remove File Encryption in Windows XP
http://support.microsoft.com/?id=308993

How To Encrypt a File in Windows XP
http://support.microsoft.com/?id=307877

HOW TO: Share Access to an Encrypted File in Windows XP
http://support.microsoft.com/?id=308991

Advanced EFS Data recovery
http://www.crackpassword.com/products/prs/mswin/efs/



.



Relevant Pages

  • Re: Encrypted files
    ... Best practices for the Encrypting File System ... How to back up the recovery agent Encrypting File System (EFS) private key ... in Windows Server 2003, in Windows 2000, and in Windows XP ...
    (microsoft.public.windowsxp.help_and_support)
  • Re: a 2nd person can delete a file encrypted by the 1st in EFS,Why?
    ... If efs is built to deny access of an encrypted file to a 2nd ... Set permissions on the file or folder if you want to control who can delete it. ... How to set, view, change, or remove special permissions for files and folders in Windows XP ... Best practices for the Encrypting File System ...
    (microsoft.public.windowsxp.general)
  • Re: Migrating from Mac to Windows
    ... Be careful with EFS (Encrypting File System). ... Encrypting File System in Windows XP and Windows Server 2003 ...
    (microsoft.public.windowsxp.general)
  • Re: Problem mit EFS
    ... Ein simple Suche nach EFS bringt Ergebnisse zu Dokumentation ohne ... Sichern des privaten EFS-Schlüssels für den Wiederherstellungsagenten in Windows Server 2003, ... Dateisystem (Encrypting File System, EFS). ...
    (microsoft.public.de.german.windows.server.active_directory)
  • RE: Re[2]: Encryption on Laptops?
    ... attack that Bart described is indeed possible - but only on Windows 2000 ... I don't see any reason to conclude that EFS is inherently a weak solution. ... to facilitate one-on-one interaction with one of our expert instructors. ... Attend a course taught by an expert instructor with years of in-the-field ...
    (Security-Basics)

Quantcast