Re: An EFS encryption question.



Last question Brian,

The only white paper I found on the MS website talks about security in general, or about the BitLocker feature which I don't have (I have Vista Business).

Can I get a link to that EFS white paper that you mentioned ?

Regards,

Peter

==========================
"Brian Komar" <brian.komar@xxxxxxxxxxxxxxxxx> wrote in message news:%23Eyk8%23UNJHA.5232@xxxxxxxxxxxxxxxxxxxxxxx
Inline...

Good afternoon Brian,

You raised a good point. Does this mean that the burglar who stole my computer and broke into my account could still read the files, simply because Windows will always make a new certificate ?
No. They would need access to the removed certificate's private key to open previous files


There is no registry change that can stop this automatic generation?
No. You need to read the whitepaper on how EFS works.
You could prevent the creation of self-signed EFS, but the client would still either request a Basic EFS certificate or autoenroll another certificate.



About those smart card readers you mentioned. Where can I get a simple one at a reasonable price ?
You need three things:
1) Smart card
2) Smart card reader
3) Middleware/mini-driver
Google is your friend. Search for Gemalto

Thanks for your time and input, Brian.

Peter


.



Relevant Pages

  • RE: Relative Security Provided by Cached Domain Credentials?
    ... So when a user logs on the w2k terminal using a smartcard + pin no (rather ... If it does then EFS ... profile currently logged on for the private certificate. ...
    (Focus-Microsoft)
  • RE: Relative Security Provided by Cached Domain Credentials?
    ... certificates assigned to them, with each certificate having a set number ... smart card management tools which provide private key archival for smart ... AND the cert is also valid for EFS, they likely would be able to do ... What you probably could get to work for local file encryption, ...
    (Focus-Microsoft)
  • Re: EFS Disabling
    ... >> I had to reinstall XP on a computer and so I copied my EFS ... They have the same account names ... > You must have exported your EFS security certificate (onto a floppy ... > claiming that if you included your profile in your backups that there ...
    (microsoft.public.security)
  • Re: EFS Errors
    ... Disabling DFS can disrupt your Group Policy propagation which may be causing ... your EFS errors if you have changed your Recovery Agent Certificate. ... I am able to encrypt on the server but noone is able to encrypt ...
    (microsoft.public.security)
  • Re: How to decrypt EFS-protected restored files?
    ... It is my understanding that some backup programs do not backup efs files ... I export my EFS certificate to a floppy. ... > describes the steps in restoring EFS-protected files, the order of importing ...
    (microsoft.public.security)