Re: EFS not secure on LAN -- if accurate it is a BUG

From: Herb Martin (news_at_LearnQuick.com)
Date: 07/31/03


Date: Wed, 30 Jul 2003 21:46:32 -0500


> I saw it happen. While I am new to EFS and make mistake
> like everyone else, I tried this several times. Today, I
> was able to export, delete, and import the certificate for
> EFS. It was installed in my Personal store. When the
> certificate was present there anyone who had NTFS
> permission to the folder could see the file's data; when
> the certificate was not there (after a reboot) no-one
> could access the data even if they had access to the
> folder and file. Before a reboot, even without the
> certificate in the store, apparently some kind of cache of
> the certificate was still allowing people to see the data.

Then it's a serious bug -- be sure to report it.

What I understand about the scenario:

    1) Owner of the file accesses the file (over the net)
    2) While (or after) this access OTHERS can with mere
        permissions can read the file while the key is at the server
    3) Reboot clears the key from server -- stops uncertificated access

That's a bug.

Sure you can use NTFS permissions to prevent the access but
the key alone should do that.

What should happen even with permission:
Example: Someone other than the owner (who is also not a
Recover Agent) has Full Control of an encrypted file. Tries
to access that file -- denied as if it were a permission issue.



Relevant Pages

  • Re: SBS2003Premium Certification Authority from HELL!!!
    ... The command-output shows a list of certificate templates that are attached ... Microsoft CSS Online Newsgroup Support ... | Yes all the grey templates have permission issues. ...
    (microsoft.public.windows.server.sbs)
  • Re: SBS2003Premium Certification Authority from HELL!!!
    ... Can I assume that all the permission of this grey template encountered the ... Microsoft CSS Online Newsgroup Support ... | "No certificate templates could be found. ...
    (microsoft.public.windows.server.sbs)
  • Re: Autoenrollment error
    ... I suggest you may refer to the following steps to troubleshoot the ... Certificate Services: Effects of security enhancements to the DCOM ... Domain Users, Domain Computers, and Domain Controllers. ... Certificate you wish to assign permission and click Properties. ...
    (microsoft.public.windows.server.active_directory)
  • Re: The Tragedy of the Commons
    ... No certificate, no sending. ... Each individual host would have its own certificate ... The permission could limit size of enclosures, size of text, etc. ... Initiate communications using a sendor write. ...
    (comp.lang.java.advocacy)
  • Re: WSE 3.0 - Correct placement/setting/permission for x509 certificates
    ... Unable to unwrap a symmetric key using the private key of an X.509 ... read the private key of certificate with subject name ... With this configuration the console app can call the web service and it ... I've gone to the registry and giving permission to ASPNET, Local Service, ...
    (microsoft.public.dotnet.framework.webservices.enhancements)