Re: EFS and Delegation
From: Guillaume (Guillaume_at_discussions.microsoft.com)
Date: 06/10/05
- Next message: Steven L Umbach: "Re: EFS and Delegation"
- Previous message: Steven L Umbach: "Re: Remote Desktop MITM Concerns"
- In reply to: Steven L Umbach: "Re: EFS and Delegation"
- Next in thread: Steven L Umbach: "Re: EFS and Delegation"
- Reply: Steven L Umbach: "Re: EFS and Delegation"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Date: Fri, 10 Jun 2005 10:25:01 -0700
Response inline.
"Steven L Umbach" wrote:
> I have never tried that myself as a way to prevent a user from creating EFS
> files on a share and I wonder if the changes have not been replicated to all
> the necessary domain controllers or the information is being cached on the
> server or once the user has the certificate on the server disabling his
> account to not be able to be trusted for delegation does no longer matter.
Only one DC in the domain , one CA, and stations (everything tested on
Virtual Server).
> What you might try is to create a test user that has his account configured
> so that it can not be trusted for delegation right off the bat and then see
> if that new test user can encrypt a file via EFS on the server share. If
> that works try deleting an existing user profile on the server for a user
> and then have them try to encrypt a file via EFS on the share. The user
> profile is where the EFS certificate/private key is located. --- Steve
>
Let me develop on the test:
- created a share directly on the DC
- created two user accounts from scratch: user1 with "sensitive account..."
cleared, one with "sensitive account..." cleared
- both accounts retrieved EFS v2 Certificates through auto-enrollment
- did NOT copy profiles to the DC
- acces the share from a station, logged on as user1, then user2
- each time, I was able to create a file and encrypt it remotely. Of course,
as profiles were not copied to the server, this one created the profiles
locally, and auto-emitted EFS certificates (basic EFS v1 cetificates that are
the only one that can be emitted when needed are disabled on the CA), which
is perfectly OK as it's supposed to behave this way.
So the problem is really that no matter your clear or check the box "account
is sensitive...", you can still encrypt/decrypt on the server as long as this
one has EFS permitted. If you dont't have any profile on the server, it will
create one for you and generate the needed certificate/private key.
You solutions to disable EFS directly on the server works vey well btw.
Guillaume.
- Next message: Steven L Umbach: "Re: EFS and Delegation"
- Previous message: Steven L Umbach: "Re: Remote Desktop MITM Concerns"
- In reply to: Steven L Umbach: "Re: EFS and Delegation"
- Next in thread: Steven L Umbach: "Re: EFS and Delegation"
- Reply: Steven L Umbach: "Re: EFS and Delegation"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Relevant Pages
|