Re: Using EFS on a server shared drive



Hi

Windows XP performs revocation checking on all certificates for other users
when they're added to an encrypted file. For performance reasons, users that
hold a private key are not checked for revocation. However, certificates
that do not contain a CDP (Certificate Revocation List Distribution Point)
extension (such as those from some 3rd party CAs) will not be validated for
revocation status.

Check for more info:
http://www.microsoft.com/windowsxp/using/security/expert/sharefilesefs.mspx


--
I hop that helps

Good Luck
Jorge Silva
MCSA
Systems Administrator





"blankmonkey" <blankmonkey@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:4964C667-5D51-48C4-AD09-398737683BD6@xxxxxxxxxxxxxxxx

I want multiple users to share an encrypted file on a File server using
W2k3. I can get this to work fine, but with one major problem. After the
file is created, the person to be added has to log onto the server to
export
their key, so that others can add them to the allowed keys to un-encrypt.
Obviously, i do not want my users logging into the server via RD or
console,
and there may be 100's of users. Is this the way it is supposed to
funtion?
how do i export my key that is on the server, from my workstation?


.



Relevant Pages

  • Re: Using EFS on a server shared drive
    ... Encrypting File System in Windows XP and Windows Server 2003 ... Windows XP performs revocation checking on all certificates for other ... I want multiple users to share an encrypted file on a File server using ...
    (microsoft.public.windows.server.active_directory)
  • Re: Using EFS on a server shared drive
    ... userA maps drive to server, ... I have imported a key at the local workstation, and it fails, because the ... Windows XP performs revocation checking on all certificates for other ... I want multiple users to share an encrypted file on a File server using ...
    (microsoft.public.windows.server.active_directory)
  • Re: [Full-Disclosure] PGP vs. certificate from Verisign
    ... PGP vs. certificate from Verisign ... > that IE had no way of checking the revocation status, ... "The certificates could be used to sign programs, ActiveX controls, Office ... current Certificate Revocation List (CRL). ...
    (Full-Disclosure)
  • Re: David Cross article
    ... checkbox etc. Drag the now encrypted file to the shared folder. ... same thing happens) in the Certificates (current ... When I go back as U1 to probe the file, I find that U1 has unlimiyed access ... >> Roger Abell ...
    (microsoft.public.windowsxp.security_admin)
  • Re: Recovering EFS from a Backup
    ... when I go to an encrypted file as a stand ... alone user, logging into the stand alone ... I went into the MMC, Certificates, ... >> I tried logging on the local account, ...
    (microsoft.public.windowsxp.security_admin)