Re: Decrypt error

From: Marc Frenette (post.reply.only@noemail.com)
Date: 01/31/03


From: "Marc Frenette" <post.reply.only@noemail.com>
Date: Fri, 31 Jan 2003 05:52:21 -0500


The Encrypting File System (EFS) is designed to protect the privacy of
sensitive data. Besides the user who encrypts a file, only a designated
recovery agent personnel can decrypt it. Other system accounts that have
permissions for that file (even the Take Ownership permission)cannot open
the file without the encryptor's private key.

In short, if you didn't encrypt it or wasn't designated as a recovery agent,
you can't touch it.

FYI. I also remember reading somewhere that if you encrypt a file on a
network share, the encryption key gets placed on the workstation that was
used to encrypt the file. If the workstation gets hosed, reformatted or
re-imaged... there goes the key.

Marc

"pvm7" <pvm7@yahoo.com> wrote in message
news:009b01c2c8eb$458a8190$cef82ecf@TK2MSFTNGXA08...
> Hi ,
> Having trouble decryping folders and changing permissions
> to decrypt folder: messege is " a error occured" thought I
> am administrator to the machine.
> Any geeks in this area ??
> thanks
> pvm



Relevant Pages

  • Re: Difficult Encryption Problem
    ... Does EFS encrypt your data using the public key, ... We encrypt your plain text data with various keys - these keys are then ... If you have a recovery agent we also then encrypt the key ring with its ... setting passwords on the local Administrator account it is too risky to ...
    (microsoft.public.windowsxp.security_admin)
  • Re: File/Folder Encryption
    ... You need to designate a Data Recovery Agent for your ... domain - this is a user account that can recover encrypted files in the ... I'm not 100% sure if SBS or Windows Server create a recovery agent by ... create a test directory and encrypt it. ...
    (microsoft.public.windows.server.sbs)
  • Re: Event ID 6032
    ... I made sure I have the recovery agent "Administrator" certificate installed ... to encrypt, you should just be able to un-click the box to decrypt. ... and import the recovery agent certificate from the server. ...
    (microsoft.public.windows.server.sbs)
  • Re: recovery agent keys/certs
    ... To decrypt a file two things are needed a) read permissions ... Create the recovery agent before users encrypt files so that you ... Backing up EFS certificates will allow for later ...
    (microsoft.public.windowsxp.security_admin)
  • RE: Laptop Security - Microsoft EFS
    ... When you use EFS, ... who can also decrypt the respective persons info. ... If the private key for the recovery agent sits on the very computer you are ... trying to protect, then you may as well not encrypt anything, because it's ...
    (Security-Basics)