Re: EFS on shared file server
- From: "Lorenzo Soncini" <lorenzo.soncini@xxxxxxxxxxxxxxxxx>
- Date: Fri, 23 May 2008 17:39:00 +0200
You tell me all corect thing. I have readed and know the official solution....but I have many file and do the work manually is an hard work.
I think my is tipacally working scenario.
The only usable solution is use the Recovery Agent.
If someone have other solutions....
Lorenzo Soncini
"S. Pidgorny <MVP>" <slavickp@xxxxxxxxx> wrote in message news:e#Wjy4LvIHA.1936@xxxxxxxxxxxxxxxxxxxxxxx
EFS is for protecting local information. In your scenario, the file gets decrypted on the file server and sent to the client in clear, with no guarrantee of any protection whatsoever (unless everybody in HR is using Bitlocker). And because you're creating many recovery agents, the secrecy deteriorates while you have to manage recovery agents etcetera. Correct me if I'm incorrect but IT people also will have access to the information or the backup sets..
I would concentrate on protecting local access to the server console and maintaining the share ACLs.
Side note: MS guidelines for sharing access to EFS are in the http://support.microsoft.com/kb/308991 (equally applies to Windows Server 2003)
--
Svyatoslav Pidgorny, MS MVP - Security, MCSE
-= F1 is the key =-
* http://sl.mvps.org * http://msmvps.com/blogs/sp *
"Lorenzo Soncini" <lorenzo.soncini@xxxxxxxxxxxxxxxxx> wrote in message news:%23FQjHPKvIHA.3384@xxxxxxxxxxxxxxxxxxxxxxxHi,
I need to use EFS on a shared folder of my file server. For grant access to many people to the file in folder I have created many EFS Recovery Agent.
All work fine if I use a local file system, but on the file sever only the user who have encrypted the file can access to it and not the EFS Recovery agent.
Other question:
Is possible store the User Certificate for EFS on AD so if one user logon on different computer can always access encrypeted file?
The scenario:
In a company the Human Resource Office (HR) need EFS for the reservation of sensitive information about employees. But all the employees of the HRO need to access this information. Is not applicable the solution to manually add all user on the property of EFS in all encrypted file.
Thanks
Lorenzo Soncini
- Follow-Ups:
- Re: EFS on shared file server
- From: Paul Adare
- Re: EFS on shared file server
- From: Brian Komar \(MVP\)
- Re: EFS on shared file server
- References:
- EFS on shared file server
- From: Lorenzo Soncini
- EFS on shared file server
- Prev by Date: Re: Smart Card Logon RODC
- Next by Date: Re: EFS on shared file server
- Previous by thread: EFS on shared file server
- Next by thread: Re: EFS on shared file server
- Index(es):
Relevant Pages
|
|