Re: Encryption



On Tue, 8 May 2007 13:06:02 +0800, Richard wrote:

Hi

I am having some difficulties with efs. I am still working on the issue
(previous thread with same title).

I am now trying an ecrypted file within the same domain. I encrypted a file
'encrypttest.txt' on A and copied it to a shared directory. I went to
another computer B, tried to open it, access denied.

Then I exported the cert/key from 'A' to the shared directory and installed
it to 'B'. Tried to open the file but couldn't open it.

What could I be doing wrong?

Any help appreciated. Many thanks in advance.

Richard

The problem is that you are you do not understand how EFS works when you
encrypt files on a server. I recommend that you read the whitepaper on EFS
available at:
http://www.microsoft.com/technet/prodtechnol/winxppro/deploy/cryptfs.mspx

Check out the section titled: "File Sharing on Remote Servers"

The basic issue is that you are working with the certificates at the
clients when the certificates being used are at the server.

Brian
.



Relevant Pages

  • Re: EFS/DRA
    ... In AD U/C I am able to see certificates in the "Published Certificates" Tab. ... would be better to go with Roaming Profiles. ... If you do not have roaming profiles, and you want to roam EFS credentials, I ... To make things easier, let's say that the file is stored on a "server", ...
    (microsoft.public.security)
  • Re: Using EFS for laptops in a domain
    ... to avoid EFS on the server except for some very specialized uses. ... but then I couldn't set or clear the encryption ... I'll give the folder disabling ...
    (microsoft.public.windowsxp.security_admin)
  • Re: Folder Redirection Data Encryption
    ... >First the remote server must be trusted for delegation ... >certificate/private key or import your existing one into ... >encrypt a file on it creating a EFS certificate/private ...
    (microsoft.public.win2000.networking)
  • Re: Folder Redirection Data Encryption
    ... user profile on that server and either encrypt a file there to generate a encryption ... encrypt a file on it creating a EFS certificate/private key in that profile. ...
    (microsoft.public.win2000.networking)
  • Re: EFS - Zusammenfassung und neue Fragen
    ... Ein herzliches Hallo an alle EFS Spezialisten! ... aufgrund der Transparenz von EFS hat Alles was im Benutzerkontext läuft Zugriff auf die verschlüsselten Informationen ... werden die Zertifikate nicht automatisch oder manuell verlängert, so wird mal eben auf selbst signierte Zertifikate umgestellt und was das zur Folge hat, spreche ich gar nicht erst an... ...
    (microsoft.public.de.german.windows.server.active_directory)