Re: Creating CA and self-signed cert for EFS recovery



Have these files already been encrypted by EFS? If so, then setting up a CA after-the-fact won't give you the ability recover those files. They'd have to be decrypted then re-encrypted after you get the CA set up and all clients switched over to using the EFS certificates it issues.

Or, if you're looking to deploy EFS the right way before users begin encrypting anything, allow me to point you to the recently-released Data Encryption Toolkit for Mobile PCs. The guidance and tool here will make EFS much easier for you.

http://www.microsoft.com/technet/security/guidance/clientsecurity/dataencryption/default.mspx

Steve Riley
steve.riley@xxxxxxxxxxxxx
http://blogs.technet.com/steriley



"Bill Hobson" <Ih8spamwjh2@xxxxxxxxxxxxxx> wrote in message news:uHuFj6gyHHA.1484@xxxxxxxxxxxxxxxxxxxxxxx
Sigh! When trying to discover a Step-by-Step (even in the so called Step-by-Step section of Technet) method of setting up a simple (oxymoron?) configuration of a CA and self-signed certificate for the sole purpose of being able to recover EFS encrypted files and folders, I struck out.

Can anyone point me to some material on how to set this up? Our environment is Windows 2003 servers (will make DC a CA for this purpose) and all machines with EFS will belong to the domain where the CA exists.

.



Relevant Pages

  • Re: Encryption Across Network File Shares
    ... the user should be able to decrypt and work on the EFS files. ... for Delegation" and the user that is encrypting/decrypting will have to be ... certificate/private key into your domain account, by encrypting a file ...
    (microsoft.public.windowsxp.security_admin)
  • Re: Encryption Across Network File Shares
    ... The computer with the share that you want to contain EFS files and the ... certificate/private key into your domain account, by encrypting a file while ... "Rick Blake" wrote in message ...
    (microsoft.public.windowsxp.security_admin)
  • Re: EFS Certificate Needed
    ... Backup and save on non-degrading media the EFS DRA .pfx file ... Foe sure I will follow "Windows Recommendations". ... that recovery agent will only have ... Best practices for the Encrypting File System ...
    (microsoft.public.security)
  • Re: EFS Certificate Issue
    ... It's most useful for EFS certs when users have roaming profiles. ... user's Personal cert store, ... >> Keys are stored in a user's profile. ... >> generate) another keypair when encrypting a file. ...
    (microsoft.public.win2000.security)
  • Re: What _does_ EFS stand for?
    ... EFS = Encrypting File System ... > space required to back up the entire disc so having done ...
    (microsoft.public.windowsxp.security_admin)