Re: Recovering Encrypted File on WIndows XP workstation

From: Roger Abell (mvpNOSpam_at_asu.edu)
Date: 01/26/05


Date: Tue, 25 Jan 2005 18:49:06 -0700

Let us assume that the XP was joined to the domain when the
file was encrypted, and that we are speaking of a file encrypted
by EFS.

Just what is it that you exported when you
"exported the administrator file recovery certificate"
You should have a pfx file that you used for the import that
contained both the EFS cert and the private key, and when
you were exporting it you should have seen that it had stated
use for EFS data recovery. You need the private key to be
able to decrypt - the cert is for encrypting.

One thing you could instead do, here stated in the safest form,
is to use NTbackup at the XP to package up the encrypted file,
and then unpack this (restore) onto a machine where you can
log in with the DRA (the account where you exported the EFS
recovery cert).

-- 
Roger Abell
Microsoft MVP (Windows  Security)
MCSE (W2k3,W2k,Nt4)  MCDBA
"Chad Guiney" <ChadGuiney@discussions.microsoft.com> wrote in message
news:4E019A44-C020-460F-AC8F-A817A4BFB072@microsoft.com...
> I have a user that encrypted a file on the desktop and the user acct has
been
> deleted off the server. The user no longer works here and I need to
recover
> the file. I have exported the administrator file recovery certificate and
> imported it on the workstation in question. However it does not let me
> decrypt the file. I dont have a PKI or CA setup on the domain. I have
looked
> for articles on the web but what I have read is not working. From what I
read
> I should be able to log on to the workstation as the domain admin and
decrypt
> the file but nothing is working. Is there any way to recover the file? any
> help would be greatly appreciated!!
>
> Thanks
> Chad


Relevant Pages

  • Re: Getting back my encrypted directory
    ... Take Ownership of a File or Folder in Windows XP ... > If you start to use NTFS Encrypting File System (EFS), ... > Q241201 How to Back Up Your Encrypting File System Private Key ... > Q242296 How to Restore an EFS Private Key for Encrypted Data Recovery ...
    (microsoft.public.windowsxp.security_admin)
  • Re: Encryption Across Network File Shares
    ... the user should be able to decrypt and work on the EFS files. ... for Delegation" and the user that is encrypting/decrypting will have to be ... certificate/private key into your domain account, by encrypting a file ...
    (microsoft.public.windowsxp.security_admin)
  • Re: Encryption Across Network File Shares
    ... The computer with the share that you want to contain EFS files and the ... certificate/private key into your domain account, by encrypting a file while ... "Rick Blake" wrote in message ...
    (microsoft.public.windowsxp.security_admin)
  • Re: EFS Certificate Needed
    ... Backup and save on non-degrading media the EFS DRA .pfx file ... Foe sure I will follow "Windows Recommendations". ... that recovery agent will only have ... Best practices for the Encrypting File System ...
    (microsoft.public.security)
  • Re: EFS Certificate Issue
    ... It's most useful for EFS certs when users have roaming profiles. ... user's Personal cert store, ... >> Keys are stored in a user's profile. ... >> generate) another keypair when encrypting a file. ...
    (microsoft.public.win2000.security)

Loading