Re: Encrypted folder or files

From: David Cross [MS] (dcross_at_online.microsoft.com)
Date: 11/29/04

  • Next message: Jeffrey Altman: "Re: trying WinVerify fail"
    Date: Mon, 29 Nov 2004 05:01:45 -0800
    
    

    Unfortunately, you cannot add a recovery agent after the files were
    encrypted. You need the original private key and certificate for the user
    or DRA:

     http://www.microsoft.com/technet/prodtechnol/winxppro/deploy/cryptfs.mspx

    -- 
    David B. Cross [MS]
    --
    This posting is provided "AS IS" with no warranties, and confers no rights.
    Top Whitepapers:
    Auto-enrollment whitepaper: 
    http://www.microsoft.com/technet/prodtechnol/windowsserver2003/technologies/security/autoenro.mspx
    Best Practices for implementing Windows Server 2003 PKI: 
    http://www.microsoft.com/technet/prodtechnol/windowsserver2003/technologies/security/ws3pkibp.mspx
    Troubleshooting Certificate Status and Revocation whitepaper: 
    http://www.microsoft.com/technet/security/topics/crypto/tshtcrl.mspx
    Windows Server 2003 web enrollment and troubleshooting guide: 
    http://www.microsoft.com/technet/prodtechnol/windowsserver2003/technologies/security/webenroll.mspx
    Windows Server 2003 web enrollment and troubleshooting guide: 
    http://www.microsoft.com/technet/prodtechnol/windowsserver2003/technologies/security/webenroll.mspx
    "Abu Aly" <Abu Aly@discussions.microsoft.com> wrote in message 
    news:D53247CE-8DE9-49FC-8E81-3A6C7371DB56@microsoft.com...
    >I have running Windows Xp professional on my LapTop, and I had aproblem in
    > restoring the operating system. So, I decided to reformat the "C" drive 
    > only
    > which is containing the operating system but I forgot to decrypt two
    > important folders which I stored them in drive "E".
    > Now, I tried a lot to recover those folders and files but I failed, while 
    > I
    > tried many times to generate a certificate + private key to add a recovery
    > agent in (public policy in mmc.exe), but always give me a error message 
    > that
    > the file doesn't contain a proper certificate and private key.
    > Please, can you help me in this important issue to me. 
    

  • Next message: Jeffrey Altman: "Re: trying WinVerify fail"

    Relevant Pages

    • Re: parsing PKCS#7 returnedy by ICertAdmin2::GetArchivedKey in .NET
      ... private key is in the underlying data that was signed, ... MS documentation says key archival blob should have ... > in the recovery blob. ... > the user certificate being recovered, the chain of the signing CA ...
      (microsoft.public.dotnet.security)
    • Re: EFS
      ... You can use the commandline tool cipher.exe. ... new recovery cert and private key. ... > EFS with Certificate Snap-In opend by Administrator ...
      (microsoft.public.windowsxp.security_admin)
    • Re: How can I share encripted files between two user accounts?
      ... If it's dual-boot, the easiest way to ... make this work is to make both users the recovery agents on their machines, ... using the same certificate and private key. ...
      (microsoft.public.windows.server.security)
    • Re: EFS On Drive Works With >1 Computer?
      ... "An alternate procedure would involve physically transporting the recovery ... agent's private key and certificate, ... certificate, decrypting the file or folder, and then deleting the imported ...
      (microsoft.public.windowsxp.security_admin)
    • RE: SIMple SSL question ??
      ... I believe your book is instructing you to keep the private key secure. ... you use the certificate request wizard in IIS to install the cert after it's ... the certificate that's just been installed. ... If an attacker retrievs the SSL certificate, ...
      (microsoft.public.dotnet.security)