Re: EFS File Copy Decrypts files. How can this be avoided?



XCOPY /G will force the move of encrypted files to location that may not
support encryption. Miha is correct that the file must be decrypted for
travel across the wire. If your issue was with security in transit then
WEBDAV would be a viable solution since WEBDAV supports the use of SSL all
content would be encrypted on the wire. However from what I have read, your
only issue is the latency produced by the decryption and re-encryption of the
files. Unfortunately the only way you are going to avoid this is via a
imaging software such as Ghost. Using Ghost you can image the data and
restore fully encrypted. However as Miha mentioned, you will need to make
sure that the user's key is transfered over to the destination machine. If it
is not, then they will be denied access. Using the Cipher /R command you can
generate a .pfx file of the users certificate on the source machine and
import it on to the destination machine thus allowing access. Either way you
are looking at additional overhead.

Good Luck!
--
David Davis [MCSE, CCNA, Security +]



"Miha Pihler [MVP]" wrote:

> When copying over the network is it just slow -- or it doesn't work at all?
> I am not sure from your last post? If it doesn't work at all -- how does it
> fail? What is end result?
>
> One big difference in this case is that when copying to e.g. external drive
> (e.g. USB) it is still same computer that holds the keys -- so the operation
> is quite simple...
> When copying over the network -- the end server needs to have the keys too
> to be able to encrypt the file in your name (and the computer must be
> "trusted for delegation") ...
>
> --
> Mike
> Microsoft MVP - Windows Security
>
> "Talon" <Talon@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
> news:673EF130-80F5-4ACF-AAB5-6FA0C89394AB@xxxxxxxxxxxxxxxx
> > >:)
> > I have performed extensive testing on this. I can copy an encrytped file
> > from Laptop#1 to a drive popped out of a laptop#2 that has encyrption as
> > well(Not folders but files) in a USB Bay or Drive bay.
> > The mass file copies move just as fast as prior to efs. This is not true
> > if
> > I perform the same over the network, or via crossover connectivity.
> > The text on this may not be accurate or up to date.
> > Again...
> > I have two laptops both supporting encryption with private keys and such.
> > Folders are NOT set to encrypt, its actually a policy and app that is
> > performing the EFS.
> > Copying to the drive in a USB Drive enclosure works, Copying to the drive
> > in
> > a Selectbay works.
> > Copying over network or Crossover connectivyt doesnt.
> > I challenge you all to try it.
> >
> >
> >
>
>
>
.



Relevant Pages

  • Help ! newbie question about Asymmetric encrypt ?
    ... symmetric encryption. ... So we use the PGP utilities of Network Associates to be the asymmetric ... in .net using AsymmetricXXX classes can make the asymmetric encryption ... about the existing keys (or other keys get from other CA server -- not only ...
    (microsoft.public.dotnet.security)
  • Re: making a copy of encrypted data cd
    ... That is NOT what encryption does. ... That the file is encrypted is irrelevant to copying it. ... I just assumed that data disk was encrypted. ... prevent you from copying the CDs. ...
    (microsoft.public.windowsxp.general)
  • Re: making a copy of encrypted data cd
    ... Nothing prevent anyone from copying a file regardless of whatever arrangement of bytes are contained within. ... Encryption means that someone without the key cannot *use* the contents of that file. ... that doesn't prevent you from copying the CDs. ... Maybe they have a utility to determine the features of your optical drives to determine the likelihood that you can make backup copies of the copy-protected CDs. ...
    (microsoft.public.windowsxp.general)
  • Re: HTWWW probably wont be in Blu-Ray and HD-DVD
    ... encryption, copying a DVD is legal in several circumstances ("Fair ... -- Col. Ralph Albertazzie ...
    (rec.arts.movies.tech)
  • RE: file can be read only, can not copy and paste or move
    ... what is the solution to block the user from copying the file? ... has any file protection such as encryption? ... "fabius" wrote: ...
    (microsoft.public.windowsxp.customize)