Re: Can not open encrypted files (EFS) (Urgent, please help)



Actually, it sounds as if you at some point changed the password of
the account via a reset, without use of the old password. At that time
access to the old EFS purposed cert became broken, and so, at the
next use of EFS a new cert was generated.
If you do have an export of the old cert, you could try clearing out
the new and/or useless certs and importing the old. You could test
importing the old first using a freshly defined account into which you
would import the cert.
As an alternative, if the cause is a password reset, then if you can
remember the old password, changing back to it may make the old
cert again functional (if you clear the new that by what you have said
is now there out of the way)
"persiancity" <persiancity@xxxxxxxxx> wrote in message
news:1144491250.014253.208030@xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
Hi there,

Please find My problem described here:


http://groups.google.com/group/comp.os.ms-windows.misc/browse_thread/...



At final, I find that I have to replace my Windows XP's account
Certificate with an old one, If I can assign a correct Certificate to
encrypted file then I guess that I am able to decrypt it, I have the
old cert. but:


I opened 'certmgr.msc' in MMC. In the "Personal\Certificates" and
"Trusted People\Certificates" I have TWO Certificates named 'ABC'. One
of them have the correct thumbprint (I am very happy that it exists!),
and another have a new thumbprint and as I see the 'Valid Date' started



from the what date I got the problem.


So, I export both Certificates into a safe place. Then I delete new
Certificate and re-login to the account, it create a new one with a new



new thumbprint instead of using the old Certificate that I guess (I am
sure) slove my problem.


I right-click on the new created Certificate icon and select:
All Tasks -> Renew Certificate with New Key


I am sure it's what I need but I got this message: "The wizard cannot
be started because it failed to contact the active directory."


The message title named "Certificate Renewal Wizard", I have not seen
it yet but I guess it'll let me to import old (CORRECT) certificate key



for new certificate. I am not sure that WinXP have Active Directory
installed, and can not find any option in Add/Remove too.


I need a way to renew an auto-created Certificate with an old one or
replace it for my account. Wizard didn't work to do it! :-|


Please tell me how I can replace/renew a Certificate in Windows XP.


Mehdi



.



Relevant Pages

  • Re: Security problem with Entourage 2004 & digital signature
    ... To be honest I've not played with those popups much. ... Unless you have the certificate that signed your cert somewhere (and maybe ... Do you have Entourage set to include your cert in the message? ... I've got two mail accounts, and have a key pair for each account. ...
    (microsoft.public.mac.office.entourage)
  • Re: IIS 6 Directory Services Mapping ACL Problems
    ... It would appear that you can not delegate Certificate based credentials. ... IIS does not have the user's password, so it can't just logon to the remote ... file server as the user directly. ... Lastly - if you want to see what account is being used to access the remote ...
    (microsoft.public.inetserver.iis.security)
  • Re: How do I deal with "Password Synchronization is not supported"
    ... It just means that you need to select a local account (an account local to ... You can not allocate an SSL Certificate to a single folder. ... and then click Default Web Site. ... In the Anonymous User Account dialog box, ...
    (microsoft.public.inetserver.iis.security)
  • Re: EFS recovery problem
    ... this seems to break efs as it does not update the locking ... some files are missing - for each cert in mmc, ... >especially now since my account name is Dave for some reason. ... export the Dave User certificate ...
    (microsoft.public.windowsxp.security_admin)
  • Re: Protecting Directories
    ... If you do, then only your account, and an optionally ... If you select to use EFS, then you should be certain that you ... For this your machine needs a smart card ... an issueing authority for the certificate on the card. ...
    (microsoft.public.windowsxp.security_admin)