Re: EFS

From: Steven L Umbach (n9rou_at_nsattbi.com)
Date: 09/07/03


Date: Sat, 06 Sep 2003 22:49:32 GMT


In a Windows 2000 domain there are two people who can decrypt a file. The
user who created the file and the Recovery Agent. You did not say if you
rebuilt from scratch or was able to restore from a recent backup that
included the System State. The private EFS keys used to decrypt are located
in the user profile and managed through the user certificate mmc snapin .
The Recovery Agent by default is the original administrator account on the
first domain controller for the domain. You can use the efsinfo utility to
find out who can decrypt an EFS encrypted file and view the thumbprint of
the certificate. See links below on how to recover EFS encrypted files and
best practices. --- Steve

http://support.microsoft.com/default.aspx?scid=kb%3Ben-us%3B255742
http://support.microsoft.com/default.aspx?scid=kb;EN-US;223316
http://support.microsoft.com/default.aspx?scid=kb%3Ben-us%3B242296
http://support.microsoft.com/default.aspx?scid=kb%3Ben-us%3B243026

"Shoghi" <smartinezg@msn.com> wrote in message
news:%23oVb57IdDHA.1280@tk2msftngp13.phx.gbl...
> Hi to all!
>
> My problem is as follow, we had recreated (formating system partition)
our
> AD domain due to virus infection, but now a users can not acces her files
> stored in the server becouse she encrypted the files. is there a way solve
> this?, I'm not familiar with file encryptión.
>
>
>



Relevant Pages

  • Re: Encrypting File System
    ... If you do not have back-ups of the original keys, ... Creating a recovery Agent after the fact will not work. ... There is not and there should not be a way to decrypt the data without ...
    (microsoft.public.windowsxp.security_admin)
  • Re: Recovering encrypted files and folders
    ... >decrypt those files are YOUR user key and the recovery key ... >to extract the keys to decrypt your files. ... The second disk was copies of My Documents. ... >> recovery agent, but it didn't work. ...
    (microsoft.public.win2000.security)
  • Re: Encrypting File System Recovery
    ... created a new recovery agent for the administrator account ... which doesn't have the ability to decrypt my files for the ... >> Admin but since I haven't logged on as an Admin due to ...
    (microsoft.public.win2000.security)
  • Re: cant recover encrypted files on efs
    ... A recovery agent cannot decrypt an EFS file until ... into foo's certificates. ... I log in as Admin and import foo's .cer to the Trusted ... I log in as "foo" and try to decrypt the file that was ...
    (microsoft.public.windowsxp.security_admin)