Re: which cert?

From: Brian Komar [MVP] (bkomar_at_nospam.identit.ca)
Date: 09/20/05


Date: Tue, 20 Sep 2005 07:06:48 -0500

In article <1127192730.816522.311930@g47g2000cwa.googlegroups.com>,
moley_cruz@yahoo.com.au says...
> i have shared out the encrypted files on computerA on the LAN. next, i
> imported the EFS cert to another computerB. When i try to access the
> shared folder on computerA it says access denied.
> does it means that i can only decrypt the files on computerA only?
>
>
EFS is a different animal when you introduce network sharing. EFS is a
local file encryption technology. Any user that attempts to open the EFS
encrypted file will have to generate a local user profile for the
storage of the EFS encryption certificate and private key. In addition,
the computer account of the server (computerA in your case) must be
trusted for delegation to allow the computer to impersonate your
account.

Unless you start importing and exporting private keys between the
servers, you will be unable to connect to a remote encrypted file (or
implement roaming profiles or DIMS in the future).

I recommend you read up on the basics of EFS. Here are a few
whitepapers:
EFS:
http://www.microsoft.com/WindowsXP/pro/techinfo/administration/recovery/
default.asp
http://www.msdn.microsoft.com/library/default.asp?url=/library/en-
us/dnsecure/html/WinNETSrvr-EncryptedFileSystem.asp

Brian



Relevant Pages

  • Re: File Encryption
    ... EFS, even it has been enabled a year ago on more than 100 computers in our ... >> of all workstations with some encrypted file. ... > - figuring out how to make software inventory report IsEncrypted for a ... Software inventory seems to store file inventory information in ...
    (microsoft.public.sms.admin)
  • EFS Pilot
    ... I'm trying to configure a EFS pilot on our domain. ... We are running Windows ... I'm trying to configure EFS to use a Certificate Authority to allow multiple ... users to have access to a single encrypted file. ...
    (microsoft.public.windows.server.security)
  • Re: Encryption problem with Windows XP
    ... Do you have Windows XP Home or Pro? ... Encrypted File System is available with Windows XP Pro and not ... EFS is very good at what it does and there is no back door. ...
    (microsoft.public.windowsxp.security_admin)
  • Re: Lost Password debacle
    ... If EFS was used with that account the problem already ... a fresh install, but a upgrade/repair overinstall - a fresh ... don't do this if you used the Encrypted File System for any ...
    (microsoft.public.windowsxp.security_admin)