Re: File ENcryption Problem Detail

From: Mandy (mmmandy@hotmail.com)
Date: 08/24/02


From: "Mandy" <mmmandy@hotmail.com>
Date: Sat, 24 Aug 2002 09:02:04 +0800


Here is the detail:

A user wants to encrypt a file in a drive, the drive is mapped from a shared
folder on the server. When user tries to encrypt the file, the server is
hang and the user's PC has shown "processing".

There is nothing being modified in the recovery agent. Therefore,

Server- there is one local recovery agent in the local security policy and
one domain recovery agent defined in the domain security policy.
PC - there is one local recovery agent is defined locally and one domain
recovery agent is defined by the domain controller (this domain recovery
agent has the same certificate ID in the domain recovery agent in the
server).

"Mandy" <mmmandy@hotmail.com> ¼¶¼g©ó¶l¥ó
news:#xfCHjwSCHA.3720@tkmsftngp08...
> Robert,
>
> nothing is encrypted on the server or client PC (I have implemented this
> scenario in the testing environment, which has the clean installation of
> server and professional).
>
> I just wonder is it possible to do encrypted on server by client PC?
>
> Mandy
>
> "Robert Gu [MS]" <robertg@online.microsoft.com> ¼¶¼g©ó¶l¥ó
> news:eBiwo0sSCHA.2412@tkmsftngp13...
> > Encryption should not cause hang. Local recovery agent should not affect
> the
> > recovery policy. Is the %temp% on the server marked as encrypted? Can
you
> > provide more detailed repro steps?
> >
> > --
> > This posting is provided "AS IS" with no warranties, and confers no
> rights.
> >
> > Robert Gu [MS Security Developer]
> > "Mandy" <mmmandy@hotmail.com> wrote in message
> > news:#EAbVooSCHA.1880@tkmsftngp13...
> > > Hi everyone,
> > >
> > > Would u please give me a help. Here is the situation.
> > >
> > > Environment:
> > > - Windows 2000 Server promoted to a Domain Controller (Server), and
> domain
> > > computer (PC).
> > > - A shared folder is created on Server such that user can map the
shared
> > > folder as a Drive
> > >
> > > Problem: Domain User using PC encrypts the shared file on Server such
> > that
> > > the server will be hang.
> > >
> > > Resolution has done:
> > > - I have tried this scenario many many times in the testing
environment,
> > but
> > > the same problem occurs.
> > > - I have tried to use roaming profile.
> > > - Domain User accounts are not marked as "sensitive and cannot be
> > delegated"
> > > this is following the instruction from MS White Paper.
> > >
> > > Question: I just wonder how to encrypt a file on a server/domain
> > controller.
> > > Or is it possible?
> > >
> > > After a few tries on the testing environment, it works fine when I
> deleted
> > > the local recovery agent on the sever. Will that be the cause of the
> > > problem?
> > >
> > > Man
> > >
> > >
> >
> >
>
>



Relevant Pages

  • Re: Event ID 6032
    ... I made sure I have the recovery agent "Administrator" certificate installed ... to encrypt, you should just be able to un-click the box to decrypt. ... and import the recovery agent certificate from the server. ...
    (microsoft.public.windows.server.sbs)
  • Re: File ENcryption Problem Detail
    ... Not that it's good policy to use your DCs for file ... If you're logged on to the DC locally, can you encrypt any files? ... We do have Win2K server running EFS here. ... >>> There is nothing being modified in the recovery agent. ...
    (microsoft.public.win2000.security)
  • Re: Event ID 6032
    ... see who is the recovery agent by opening the properties of an encrypted file ... decrypt the files by reversing the process in which you encrypted them. ... to encrypt, you should just be able to un-click the box to decrypt. ... and import the recovery agent certificate from the server. ...
    (microsoft.public.windows.server.sbs)
  • Re: File ENcryption Problem Detail
    ... Will forward this to our testers for a repro. ... We do have Win2K server running EFS here. ... When user tries to encrypt the file, ... > There is nothing being modified in the recovery agent. ...
    (microsoft.public.win2000.security)
  • Re: File ENcryption Problem Detail
    ... Where is the shared folder? ... We do have Win2K server running EFS here. ... >> There is nothing being modified in the recovery agent. ... >> PC - there is one local recovery agent is defined locally and one domain ...
    (microsoft.public.win2000.security)