Re: EFS with files on network share

From: Drew Cooper [MSFT] (dcoop_at_online.microsoft.com)
Date: 02/26/04


Date: Wed, 25 Feb 2004 19:53:57 -0800

1. Choose any certificate that has a private key on the target machine. If
your users have roaming profiles, this can be easy. If not, you might be
shuffling certificates around and trying to export certs with their private
keys on the server. It's not pretty.

2. There is a cache, but I'm not sure that's what you're seeing. Are you
sure it's using a completely different cert than the one you picked? You
selected the cert using the UI on XP or Server 2003 or you wrote your own
app?

3. The only time EFS does revocation checking is in the "add user through
the UI" codepath. I guess you are using the UI. If (on the server) you
open the certificate UI for the cert you're trying to add, is there a big
red X of "something's wrong"? How about on the client-side?

#3 is the really disturbing one for me - if your CA's online and the certs
are ok I'm not sure quite what could be going wrong. If everything checks
out but the add user still fails with the revocation error, please let me
know. I'd like to be able to reproduce a problem like that.

-- 
Drew Cooper [MSFT]
This posting is provided "AS IS" with no warranties, and confers no rights.
"Gordon" <gdccyuen@alumni.cuhk.net> wrote in message
news:uPiU9m0%23DHA.2576@tk2msftngp13.phx.gbl...
> Anyone doing file encryption on network share?
>
> I tested using 2 accounts: X and Y, and did have some success. However
> there are a lot of thing I can't understand:
>
> 1. X and Y both have multiple EFS certificates (result of using
> Auto-enrollment from AD integrated CA?), should X choose the most recent
> one or what?
>
> 2. If X want to encrypt the file using another certificate from Y, the
> server refuse and continue to use the previous picked one. Some cache on
> server need to be cleaned?
>
> 3. All of a sudden, X could not add any certificate with an error
> 'Revocation Server is offline'. I try to capture the network traffic but
> found no traffic at all which seems to check anything about certificate
> revocation, any idea?
>
> Gordon


Relevant Pages

  • Re: Web Certificate for IIS Server on SBS Domain
    ... Before your reply, I actually ran across rapidssl myself, and have ordered and installed the free 30-day certificate on my site. ... I explained what you'd told me about putting my existing configuration at risk by installing Cert Services, and he said he didn't know that. ... Again, if you're just needing a cert to install on your web server to provide SSL connectivity for remote users, go with an external third-party provider. ... When you add Certificate Services on an internal network, lots of internal communications will start using pieces provided by the Cert Server instead of the defaults from Server 2003, and when things blow up, they can blow up gloriously. ...
    (microsoft.public.windows.server.sbs)
  • Re: Activesync between Windows Mobile 5 and SBS2003 gives error
    ... If you don't find a cert here that matches the URL for OWA, you need to re-run the CEICW wizard on the SBS box and re-create the self signed cert. ... I exported the certificate straight from the server. ... Treo 700wx running Windows Mobile 5. ...
    (microsoft.public.windows.server.sbs)
  • Re: Terminal Services over a VPN
    ... Create a certificate request and submit it to godaddy in order to obtain a public cert. ... You can use the wizard in IIS Manager for this by creating a new website that matches the above name (on your TS server), right-click and choose properties, directory security tab, server certificate button. ... After the install you can stop or delete the website created above since you don't need it for anything. ...
    (microsoft.public.windows.terminal_services)
  • Re: SBS 2003 Premium and Cert Services
    ... that philosphy got blown out of the equation when SBS included Exchange OWA ... "Small Business Server" which is MS claim as to why the risk of exposing the ... the Certificate Server on another server, ... >> Cert, or you could edit the properties of your Certification Authority to ...
    (microsoft.public.windows.server.sbs)
  • Re: Web Certificate for IIS Server on SBS Domain
    ... and installed the free 30-day certificate on my site. ... instructions to install Certificate Services. ... If I can find a way to issue my own cert without risking my SBS setup, ... > Server instead of the defaults from Server 2003, and when things blow up, ...
    (microsoft.public.windows.server.sbs)