Re: About EFS and local certificate that I want to export
- From: "CreateWindow" <createwindow@xxxxxxxxx>
- Date: Sat, 5 May 2007 08:55:11 +1000
Hi Pascal,
EFS does not encrypt over the network as that would expose the data to
network snoops. However if XP_A and B "trust each other for delegation" an
advanced security setting, (and I think the Domain Controller must also
trust the workstations) this can be made to work.
You really need to set up a CA on your AD to manage the certs. plus fully
understand the processes involved. You can read all this on microsoft.com.
Good luck,
CreateWindow
"Pascal" <pascal_t@xxxxxxxxxxxxxxxxxx> wrote in message
news:mn.23907d753190e61a.70874@xxxxxxxxxxxxxxxxxxxxx
Hello,
I have test something but I am not sure that I am right !
I have two computers XP_A and XP_B member of an active directory domain
with no certificate authority.
There are two users : Pascal and Isabelle.
1. Pascal logs on XP_A and encrypt a file with EFS.
2. Pascal exports his certificate through Internet explorer (with or
without the private key, the issue will be the same)
3. Now, on XP_B, an admin install the Pascal certificate on the computer
(in the "Trusted People" store).
4. Isabelle logs on XP_B and encrypts a file with EFS, then she adds the
Pascal certificate to authorize him to access this encrypted file.
5. Pascal is connected to XP_A and opens the encrypted files for which his
certificate is attached on XP_B,but he still has an access denied.
Question : Why Pascal is not able to access this file from the network ?
(From XP_A to XP_B)
More generally, if I export an EFS user certificate from one computer to
another, can I access the encrypted file through the network.
With a certificate authority, I think there will be no problem but I would
like to understand why like this it is not working.
Thank you :)
--
Pascal
.
- Follow-Ups:
- References:
- Prev by Date: Re: Desktop
- Next by Date: Re: Configuring A Mandatory Profile On A Server
- Previous by thread: About EFS and local certificate that I want to export
- Next by thread: Re: About EFS and local certificate that I want to export
- Index(es):
Relevant Pages
|