How to decrypt EFS-protected restored files?

From: *Vanguard* (no-email_at_reply-to-newsgroup.invalid)
Date: 05/08/04


Date: Fri, 7 May 2004 20:25:43 -0500

I had a directory configured to use EFS (so anything put under it got
encrypted). I export my EFS certificate to a floppy. My system crashed and
a disk image wouldn't work (because of changes in the hardware). However, I
could still use the ImageExplorer that comes with DriveImage to peruse the
contents of the image files to extract files out of them. So I've tried the
following:

- Extracted the files from disk image. Cannot view them because of the EFS
protection. Imported the EFS certificate used when the files got encrypted.
It was imported under the Personal store for certificates. Could not open
the files.

- Deleted the EFS certificate and re-imported it but this time left the
option selected to have Windows XP automatically determine under which
certificate store to place the certificate. It imported it to the Trusted
People certificate store. Still couldn't access the encrypted files.

- Figuring that EFS had not yet been implemented on my new install and that
maybe the imported EFS certificate would not get exercised until EFS was
used, I right-clicked on a folder and had it encrypted. Then I copied the
files to under this directory figuring that the certificate might also have
to be imported before moving the files into an EFS-protected directory.
Still cannot access the file contents.

I've read several KB articles and the included help but it really never
describes the steps in restoring EFS-protected files, the order of importing
the EFS certificate (before or after the files have been restored to the new
instance of Windows), or if importing the EFS certificate after restoring
the files (or before) would allow access to them (or if I also need to
actually implement EFS to have it utilize the imported certificate). I see
mention of how use EFS, export certificates, manage them, import them, and
some vague inferences in using them against encrypted files but no real
instructions. After a few hours, I've exhausted what I could come up for a
procedure to decrypt these files. Any ideas?

--
____________________________________________________________
*** Post replies to newsgroup.  Share with others.
*** Email: domain = ".com" and append "=NEWS=" to Subject.
____________________________________________________________
-- 
____________________________________________________________
*** Post replies to newsgroup.  Share with others.
*** Email: domain = ".com" and append "=NEWS=" to Subject.
____________________________________________________________


Relevant Pages

  • How to decrypt EFS-protected restored files?
    ... Imported the EFS certificate used when the files got encrypted. ... describes the steps in restoring EFS-protected files, the order of importing ...
    (microsoft.public.windowsxp.general)
  • How to decrypt EFS-protected restored files?
    ... Imported the EFS certificate used when the files got encrypted. ... describes the steps in restoring EFS-protected files, the order of importing ...
    (microsoft.public.security)
  • Re: How to decrypt EFS-protected restored files?
    ... I export my EFS certificate to a floppy. ... or if importing the EFS certificate after restoring ...
    (alt.computer.security)
  • Re: An EFS encryption question.
    ... Does this mean that the burglar who stole my computer and broke into my account could still read the files, simply because Windows will always make a new certificate? ... You could prevent the creation of self-signed EFS, but the client would still either request a Basic EFS certificate or autoenroll another certificate. ... all newly encrypted files will use the new default EFS key ...
    (microsoft.public.windows.vista.security)
  • Re: Encrypted Files
    ... >>To update the meta data (EFS certificates and recovery> certificates on the ... >>certificate thumbnail, which is used to encrypt the file ... >>efsinfo /y will display your current EFS certificate. ...
    (microsoft.public.windowsxp.security_admin)