Re: EFS/NTFS

From: redrum (redrum@hotmail.com)
Date: 06/04/02


From: "redrum" <redrum@hotmail.com>
Date: Mon, 3 Jun 2002 23:03:33 -0700


So basically you're saying that I might as well start
freeing some space for new content coz I'm never gettin'
back my files?
I somehow expected this because I did a lot of
constructive fooling around trying to recreate the same
SID, accounts, certificates and basically anything
(however foolish) but it was all in vain.
By the way, it *is* a standalone and no I didn't back
anything up.
I think the SID would have been the key here since the
entire accounts folders and certificates are intact.
Well at least I'm learning new things. Thanks.
 
>-----Original Message-----
>Is you XP a DC member or a standalone machine?
Standalone XP has no recovery
>policy by default. You will not be able to decrypt the
files just using the
>admin account.
>
>If the PC is a standalone PC, unless you have backed up
your EFS cert +
>keys, you would not be able to get back your EFS files
without brutal force
>the keys.
>
>Your EFS private keys are protected by a master key.
That key is protected
>by your password and your SID. When you reinstall the
OS, your SID is
>changed. Even though you think you use the same account
name and password,
>they are not the same to the OS.
>
>--
>This posting is provided "AS IS" with no warranties, and
confers no rights.
>
>Robert Gu [MS Security Developer]



Relevant Pages

  • RE: SIDS show instead of user names
    ... I'd like to make sure the sid can be resolved at the same time you see SID ... As far as the accounts being deleted in AD, ... Go to Capture --> Networks to choose the correct network card by ...
    (microsoft.public.win2000.active_directory)
  • RE: ADMT - SID History Issues, Cannot access resources in old domain
    ... the permission to access the old resource. ... Since OldDomain\User1 is a built-in group we cannot use ADMT to migrate it. ... we are able to use Security Translation Wizard with a SID ... on all the Windows 2000 computers with different user accounts. ...
    (microsoft.public.windows.server.migration)
  • RE: SIDS show instead of user names
    ... name is always followed by the SID. ... As far as the accounts being deleted in AD, ... Go to Capture --> Networks to choose the correct network card by ...
    (microsoft.public.win2000.active_directory)
  • Re: Website Access for Internet User to Manage Their Content
    ... Yes, if the machine is a standalone machine, it has it's own user ... You can define local users, ... Is their a user table for a standalone ... > Iunderstand how to add and manage user accounts in AD for a Windows 2003 ...
    (microsoft.public.inetserver.iis.security)
  • Re: NT4 Client in W2K3 AD migrated / SID
    ... the Windows shell calls the LookupAccountSid function to contact ... Can you add accounts from the old domain or the new ... But the next time I check the ACL ... |>>are display as SID not as account names. ...
    (microsoft.public.windows.server.migration)