Re: bug with efs on server 2003



sigh....

"Goldorak-Go" <GoldorakGo@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message news:1485A423-A2A9-4C5F-A50C-9ABB947BD752@xxxxxxxxxxxxxxxx
Hi Brian Komar!!!

Thank you for your response, but I 'm still thinking that something is going
wrong.
nope.

EFS use the public key to encrypt the FEK and the FEK encrypts the efs file.
EFS automatically obtains the user’s public key from the user’s X.509
version 3 file encryption certificate.
EFS never need the private key to encrypt data.
The private key is only needed to decrypt the FEK and then the efs file.

So far, so true.


So if I export and delete the private key that is stored localy, and if I
let the corresponding certificate in place on this server then I must be able
to encrypt using the public key of this certificate.
And this is what is going wrong in my case.
Nope, it also checks that you have the private key to be able to decrypt the file.
You cannot open the file without the private key.


Because the existing certificate is not used. In fact another certificate
and its private key is generated when I put a new file in the encrypted
folder.

Yep, expected behavior.

Most of all, I tried the same procedure on a XP workstation and everything
is going well like I expected and I tried this several times.
But with my Windows server 2003 this is not the same.

You are going down a non-supported path. Do not delete the private key.

anybody has an idea ???



.



Relevant Pages

  • EFS Trouble - External Drive
    ... I exported my EFS certificate AND private key from machine A and successfully imported it onto machine B. I can see the certificate AND private key of machine A in machine B's certificate store. ... Now, when I encrypt files on the USB drive using machine A, machine B cannot read them. ... I have spent more than three hours reading every technet article regarding EFS as well as other people's problems posted on various boards and in this group. ...
    (microsoft.public.windowsxp.security_admin)
  • RE: EFS Trouble - External Drive
    ... successfully imported it onto machine B. I can see the certificate AND ... private key of machine A in machine B's certificate store. ... Now, when I encrypt files on the USB drive using machine A, machine B ... regarding EFS as well as other people's problems posted on various ...
    (microsoft.public.windowsxp.security_admin)
  • Re: Certificates, Keys, Mobile Users, Intended Usage
    ... Option that you think about uses self signed EFS certificates. ... Better then exporting user's private key as backup is to setup DRA (Data ... there is no EFS certificate and it will generate a new one. ... Mobile computer users benefit from encrypting sensitive ...
    (microsoft.public.win2000.security)
  • Re: Entourage mail and PGP/GPG?
    ... > You can digitally sign messages and encrypt them using CA. ... > using a certificate for each recipient. ... > recipient uses this certificate to verify which private key was ...
    (microsoft.public.mac.office.entourage)
  • Re: Encrypting Messages
    ... and private key situation, ... You encrypt a messages using SOMEONE ELSE's public key. ... > person that can decrypt that message is the one that has the matching ... > Use the public key from your certificate. ...
    (microsoft.public.outlook)