Re: can't recover encrypted files on efs
From: Roger Abell [MVP] (mvpNOSPAM@asu.edu)
Date: 06/22/02
- Next message: Richard Garrett: "Re: Encryption and 'File settings and transfer wizard'"
- Previous message: dion noe: "lost windows xp pro product key"
- In reply to: Brent: "can't recover encrypted files on efs"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
From: "Roger Abell [MVP]" <mvpNOSPAM@asu.edu> Date: Sat, 22 Jun 2002 00:16:36 -0700
A recovery agent cannot decrypt an EFS file until
the .pfx which contains the decryption key has been
imported. It sounds like you did not import the .pfx
into foo's certificates (logged in as foo).
I have had no need for your step where you import
foo's .cer as a Trusted Root CA, and frankly, the
step does not make sense to me.
-- Roger Abell MS MVP (Windows Platform), MCSE, MCDBA Associate Expert - Windows XP ExpertZone http://www.microsoft.com/windowsxp/expertzone "Brent" <brent_midwood@hotmail.com> wrote in message news:1147201c2198b$7ae6f4a0$3aef2ecf@TKMSFTNGXA09... > I am trying to learn about the recovery agent feature of > EFS on XP Pro, but I can't seem to make it work. > > Here is the scenario. > > 1. User "foo" is a limited user. Logged in as "foo", I > use "cipher /r" to create a .cer file. > 2. I log in as Admin and import foo's .cer to the Trusted > Root Certification Authorities folder using the > Certificate Snapin for the computer. > 3. Still logged in as Admin, I then use the "Add a > Recovery Agent" wizard from the Local Security Policy app > to import foo's .cer file and supposedly make foo a > recovery agent. > 4. Still logged in as Admin, I then encrypt a file in a > public directory and make sure that foo has NTFS > permissions to fully control the encrypted file. > 5. I log in as "foo" and try to decrypt the file that was > encrypted by "admin", but I can't... > > What did I do wrong? I thought I had set up "foo" as a > recovery agent correctly before having "admin" encrypt the > file. So shouldn't "foo" be able to decrypt the file? > > Any insight would be appreciated. > > Thanks. > brent_midwood@hotmail.com >
- Next message: Richard Garrett: "Re: Encryption and 'File settings and transfer wizard'"
- Previous message: dion noe: "lost windows xp pro product key"
- In reply to: Brent: "can't recover encrypted files on efs"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Relevant Pages
|