Re: NTFS encryption on second drive inaccesible

From: Roger Abell (mvpNOSPAM@asu.edu)
Date: 06/04/02


From: "Roger Abell" <mvpNOSPAM@asu.edu>
Date: Mon, 3 Jun 2002 23:31:50 -0700


That is nice Robert, but we still believe there should be
1. warning when starting to use EFS with XP
2. very brief step-by-step on doing EFS safely with XP

--
Roger Abell
MVP (Windows Platform)  Associate Expert
The Expert Zone - www.microsoft.com/windowsxp/expertzone
"Robert Gu [MS]" <robertg@online.microsoft.com> wrote in message
news:O$N$EV0CCHA.1964@tkmsftngp02...
> .NET server will let you do "cipher /x" to backup your current EFS cert +
> keys. You can also use the "rundll32" to backup the EFS certs+ keys with
the
> .NET server. The Add User UI will also let you backup the certs + keys.
> Check out that when .NET RC1 is availalbe.
>
> --
> This posting is provided "AS IS" with no warranties, and confers no
rights.
>
> Robert Gu [MS Security Developer]
> "Patty MacDuffie" <pattymacduffie@SENDSPAMHERE.attbi.com> wrote in message
> news:#9E7yM0CCHA.2172@tkmsftngp04...
> I heartily concur, Bill.
> --
> Patty MacDuffie
> Windows XP MVP
>
> "Bill Sanderson" <bill_NoSpamSanderson@msn.com> wrote in message
> news:#4lHjrcCCHA.1904@tkmsftngp04...
> > What I would like to see is some warning wording in any publicity
articles
> > about the feature, for example:
> >
> >
>
http://www.microsoft.com/windowsxp/pro/using/howto/security/encryptdata.asp
> >
> > To my mind, such an article must contain a warning up front, and a link
> > somewhere in the body to a clearly delineated procedure for saving the
> > certificate and private key.  I realize that this process is quite
> different
> > in a domain than on a standalone XP Pro workstation, but it's the folks
> with
> > the standalone XP Pro workstations who really need the help.
> >
> > Speaking of which--does anyone have such a link?--this would surely be
> > useful, and I find the process rather difficult to find in Help and
> Support,
> > let alone give a reference to in a newsgroup message.
> >
> > "Roger Abell" <mvpNOSPAM@asu.edu> wrote in message
> > news:OSxE9yTCCHA.2464@tkmsftngp05...
> > > The most recent I have heard is that the changes suggested to
> > > effect an unavoidable "caution notice" to first users all have
> > > difficulties in implementing them now, after the fact, without
> > > causing conflict in other areas.
> > >
> > > So, folks should read the info that has been made available
> > > in the MS XP website on using EFS in XP.
> > >
> > > --
> > > Roger Abell
> > > MVP (Windows Platform)  Associate Expert
> > > The Expert Zone - www.microsoft.com/windowsxp/expertzone
> > >
> > > "Patty MacDuffie" <pattymacduffie@SENDSPAMHERE.attbi.com> wrote in
> message
> > > news:OysQiDSCCHA.1436@tkmsftngp04...
> > > It has been suggested to them by several MVPs numerous times, and is
> being
> > > looked into.  I don't know if they'll be able to get a fix into XP or
> not
> > > though.  It will certainly be in the next OS.
> > > --
> > > Patty MacDuffie
> > > Windows XP MVP
> > >
> > > "Rod" <fake@fake.com> wrote in message
> > news:e0IXsHLCCHA.1064@tkmsftngp04...
> > > > This problem seems to come up often, maybe Microsoft should include
> more
> > > > warnings before attempting EFS.
> > > >
> > > > "Roger Abell" <mvpNOSPAM@asu.edu> wrote in message
> > > > news:O#UQ6NKCCHA.2072@tkmsftngp02...
> > > > > Load the previously saved cert/key, or restore the old system
> > > > > from backup and log in with the account and password as it
> > > > > existed at time of backup - or - say good bye to the files.
> > > > >
> > > > > --
> > > > > Roger Abell
> > > > > MVP (Windows Platform)  Associate Expert
> > > > > The Expert Zone - www.microsoft.com/windowsxp/expertzone
> > > > >
> > > > > "Rod" <fake@fake.com> wrote in message
> > > > news:uKkEcPFCCHA.1692@tkmsftngp05...
> > > > > > There is no way of decrypting the data unless you backed up the
> key.
> > > > > >
> > > > > > "Chris" <avatexjoel@aol.com> wrote in message
> > > > > > news:8cfa01c20840$26b48890$a5e62ecf@tkmsftngxa07...
> > > > > > > I moved my "MYDOCUMENTS" folder to another hard drive to
> > > > > > > protect my data. It worked however when my system drive
> > > > > > > crashed and I had to install XP prof on another drive I
> > > > > > > can nolonger access mydocuments. I encryted them and the
> > > > > > > apparently the encryption keys are lost. Does anyone know
> > > > > > > of anyway to recover this data? I know the original
> > > > > > > passwords for the administrator, but I cannot find the
> > > > > > > backup of the encryption keys. Any advice would be
> > > > > > > appreciated.
> > > > > >
> > > > > >
> > > > >
> > > > >
> > > >
> > > >
> > >
> > >
> > >
> >
> >
>
>


Relevant Pages

  • Re: NTFS encryption on second drive inaccesible
    ... :) Not being a network or EFS guru myself, I have to admit I could barely follow a word of what Robert wa saying. ... > The Expert Zone - www.microsoft.com/windowsxp/expertzone ... >> keys. ...
    (microsoft.public.windowsxp.security_admin)
  • RE: Protecting sensitive files on a Windows file server
    ... Protecting sensitive files on a Windows file server ... Recovery keys aren't a problem. ... I don't care what your encryption program ... EFS only works on NTFS partitions. ...
    (Security-Basics)
  • Re: decrypt files after lost pub/priv keys - possible?
    ... We've even had 3rd party reviews of our EFS code - ... Win2k used DES for its symmetric encryption. ... the symmetric keys would have been AES 256 - ...
    (microsoft.public.win2000.security)
  • RE: Protecting sensitive files on a Windows file server
    ... In EFS, it takes me 5 minutes to remove the recovery key from the ... Protecting sensitive files on a Windows file server ... You have to have backup keys in case the original ...
    (Security-Basics)
  • Re: XP EFS (decrypting)
    ... You have backed up your EFS cert + keys, you can restore that cert + ... If you still have your profiles on the disk and no EFS ... the EFS encryption scheme. ...
    (microsoft.public.windowsxp.security_admin)