Cant decrypt w/admin acct

From: Joakim (anonymous_at_discussions.microsoft.com)
Date: 03/02/04


Date: Tue, 2 Mar 2004 11:52:58 -0800

Look at this site
http://www.elcomsoft.com/aefsdr.html

>-----Original Message-----
>Hello,
>
>Have no idea what happend. I have about 60 MSWord
>documents that at some point in time I applied the encrypt
>attribute to. Well I went to open one and it wont let me.
>I get the error that "User does not have access
>privledges." I did check to see I had access to it, and I
>show full priciledges. Heck I was the creator. Now I only
>have this account and the default admin account on this
>computer (Windows 2000 Professional as a standalone). I
>used this account to encypt them. I tried using the admin
>account since I read that it is the defualt Recovery
>Agent, but when I tried I get an error that simply
>says "Access Denied". I checked the certificates and they
>are valid and still in effect and the Recovery Agent Cert
>was still listed in the Trusted Certs folder in MMC.
>
>I also ran "efsinfo /r" on the folder and files and it
>says:
>Recovery Agents:
> Unknown (OU= EFS File Encryption Certificate, L=EFS,
>CN=Dwayne ******** (* =My last name)
>
>I Ran it with the /c option and got the following:
>Users Who Can Decrypt:
>Unknown (OU= EFS File Encryption Certificate, L=EFS,
>CN=Dwayne ******** (My last name)
>Certificate Thumbprint: FCD9 44C3 2B33 7650 07FC F5F7 6042
>221A 1294 28C6
>
>OK does anyone know what the heck happened and how come I
>cant decrypt these files now or even with the Admin
>account??? I havent deleted any accounts or anything so
>there shouldnt have been any keys deleted or whatever.
>Trying to understand this the best that I can with what I
>have read today about how this works. I was under the
>impression I should be able to recover the files with the
>Admin account since it is supposed to be a default
>Recovery Agent. Well hope someone can help me out here.
>Hopefully I provided enough info here on what I have done
>so far. Thank you
>
>Dwayne
>
>
>.
>



Relevant Pages

  • Cant decrypt w/admin acct
    ... have this account and the default admin account on this ... are valid and still in effect and the Recovery Agent Cert ... Unknown (OU= EFS File Encryption Certificate, L=EFS, ... Admin account since it is supposed to be a default ...
    (microsoft.public.win2000.security)
  • Re: How good is Comodo Internet Security?
    ... Admin account + web browser + LUA token ... admin account opposed of running as iam now, which is JUST PURE admin level? ... While LUA gives added security, ... payload delivered by a buffer overrun (assuming the app was allowed to ...
    (comp.security.firewalls)
  • Re: domain admin account impersontating
    ... i guees that the bottom line is that the domain admin account can be ... with the same username and password. ... Starting with Windows XP this became less simple, ...
    (microsoft.public.windows.server.security)
  • RE: runas issue
    ... to Power Users per new company policy,so then only one local built-in admin ... user account was at one time an admin account and was changed to power user. ...
    (microsoft.public.windowsxp.perform_maintain)
  • RE: Decrypt File
    ... "accidentally" reinstalled the machine without saving the recovery agent. ... in properties for the encrypted data re-assign the new local admin account ... Senior Consultant (Directory Services Security) ... domain controllers) reinstalls of any single domain controller. ...
    (Security-Basics)

Loading