Windows EFS problem



Hi all.
I used to share a USB key between my home PC (Win 2003 Server) and my
work PC (Win XP, joined to a domain).

To protect my data, I encrypt them via the EFS that is implemented into
the NTFS filesystem.

To do this I have exported the EFS certificate from my work PC to my
home PC and until some days ago all worked fine.

So I had my home PC able to open the encrypted files that I created at
work on the USB key.

But the company upgraded XP to Seven, and now I have no longer access to
any encrypted file from my home PC.

I have checked and it seems that Seven has generated another EFS
certificate, so I exported it (including the private key) and imported
it to 2003 (my home PC).

But,... still I do not have access to any file.

I do have exported the private key related to this certificate but,...
Win 2003 continues to deny the access to the encrypted files.

Does anyone know what I have to check to enlighten this problem?

BTW: if I import this new certificate to a *new* installation of Windows
(I have done this experiment via a virtual machine) all work flawlessly,
and I can open all the encrypted files.

Really, I believe I'm missing something... but what?

Thanks in advance.

Mauro.
.



Relevant Pages

  • RE: Deleting the certificate does not stop decryption!
    ... Domains have the default EFS recovery policy (a File Recovery ... EFS certificate. ... EFS keeps your private key in cache until you log off. ... As for moving encrypted files between standalone machines, ...
    (microsoft.public.windowsxp.security_admin)
  • Re: PKI & EFS
    ... certificate services. ... On one system I logged in with UserA and requested an EFS ... Encrypting File System in Windows XP and Windows Server 2003 ... up in which I noticed I can copy encrypted files to. ...
    (microsoft.public.windows.server.security)
  • Re: Windows XP Pro amd NTFS encryption
    ... If the certificate was expired or archived, it won't show up in the default ... left pane of the certificates snapin, right click, then go to View->Options. ... I would guess that you imported an expired EFS cert/key pair. ... you should be able to access your old encrypted files. ...
    (microsoft.public.windowsxp.security_admin)
  • Giving a device access to EFS (Encrypting File System)
    ... I am developing an application that uses encrypted files which are ... rights to access EFS encrypted files. ... certificate and private key inorder to read the contents of EFS ...
    (microsoft.public.windows.server.security)
  • RE: Import certificate to "All users"
    ... originally the certificate was placed on one USB key and it was enough ... certificate would contain the username but if stored in the computer store ... certs have no functional purpose at all in the computer store, ...
    (microsoft.public.windows.server.security)