Re: ciphered files

From: Michele Tegon (tegon@easy.pc.it)
Date: 09/18/02


From: "Michele Tegon" <tegon@easy.pc.it>
Date: Wed, 18 Sep 2002 22:53:20 +0200

I can't say I'm happy to read this but thank you Torgeir for you detailed
answer.
I'll be more careful in the future.

Just a question... it's too late to attach my laptop to a domain in which I
create a DRA to recover the data, isn't it?

Michele

"Torgeir Bakken" <Torgeir.Bakken-spam@hydro.com> ha scritto nel messaggio
news:3D86248A.14D15CE0@hydro.com...
> Michele Tegon wrote:
>
> > I re-installed the operating system and now I can't access the file that
are
> > ciphered.
> > Any solution?
>
> Hi
>
> If you are not in a domin, and you did not export your encryption keys
before
> the reinstall (or you have a full system state backup), your files are
gone...
>
>
> My view on EFS:
>
> Do not to use encryption (EFS) unless you are in a domain and you know
what you
> are doing. Too much things can go wrong. You will most likely sooner or
later
> loose your data (for good). It is not without reason some people calls EFS
> the "delayed Recycle Bin". Use NTFS permissions instead to protect your
data.
>
> The major problem with EFS is not having as proper backup of the
encryption
> keys, as well not having created a Recovery Agent (with backup of the
recovery
> agents keys). If you don't have this in place before you start encrypting
your
> files, and you need to reinstall you OS of some reason or other, your
files will
>
> not be recoverable. They will effectively be gone forever. Read the links
below,
>
> and understand what they say before you start using encryption.
>
>
> But if you must use EFS, in this link:
>
http://www.microsoft.com/WINDOWSXP/pro/techinfo/administration/recovery/defa
ult.asp
>
> it is described how to create a data recovery agent (DRA), and also gives
> information/links on to how to export keys, e.g.
>
> "Data Recovery on Standalone Machines"
> "Importing and Exporting Data Recovery Agent Keys"
>
>
> Under "Knowledge Base Articles on EFS" you will find e.g.
>
> Q241201 How to Back Up Your Encrypting File System Private Key
> Q259732 EFS Recovery Agent Cannot Export Private Keys
> Q255742 Methods for Recovering Encrypted Data Files
>
>
> Reading Q255742, will give you this as well:
>
> Q241201 HOW TO: Back Up Your Encrypting File System Private Key in Windows
2000
> Q242296 How to Restore an EFS Private Key for Encrypted Data Recovery
>
>
> If your computer is not a member of an AD domain, this part of the
document is
> obligatory reading:
>
> "Using EFS with Standalone Machines or NT 4.0 Domains"
>
>
> --
> torgeir
>
>



Relevant Pages

  • Re: Corrupted Admin Profile
    ... > My view on EFS: ... > Do not to use encryption unless you are in a domain and you know ... as well not having created a Recovery Agent (with backup of the ... > Q241201 How to Back Up Your Encrypting File System Private Key ...
    (microsoft.public.windowsxp.security_admin)
  • RE: Protecting sensitive files on a Windows file server
    ... In EFS, it takes me 5 minutes to remove the recovery key from the ... Protecting sensitive files on a Windows file server ... You have to have backup keys in case the original ...
    (Security-Basics)
  • RE: Protecting sensitive files on a Windows file server
    ... Protecting sensitive files on a Windows file server ... Recovery keys aren't a problem. ... I don't care what your encryption program ... EFS only works on NTFS partitions. ...
    (Security-Basics)
  • Re: Corrupted Admin Profile
    ... > My view on EFS: ... > Do not to use encryption unless you are in a domain and you know ... as well not having created a Recovery Agent (with backup of the ... > Q241201 How to Back Up Your Encrypting File System Private Key ...
    (microsoft.public.windowsxp.security_admin)
  • Re: Built-in encryption questions
    ... keys, but as I said, all the documentation I can find is terribly involved ... > this folder private". ... >> If I get all this sorted out I'll use encryption but want some way to ... I see there are such things as recovery ...
    (microsoft.public.windowsxp.general)