Problem with EFS...

From: Chris (ehathgepiurhe@REMOVETHIS.yahoo.com)
Date: 03/17/03


From: Chris <ehathgepiurhe@REMOVETHIS.yahoo.com>
Date: Mon, 17 Mar 2003 14:27:40 +1000


Hi,

I was having a problem with decrypting files using EFS on WIndows XP
that I was hoping someone may be able to help me with. Specifically, I
cannot use a DRA to decrypt them. These are the steps I followed (all
on a stand-alone, non networked PC):
1. Created the user account that I wanted to be the DRA (& added them
to the Administrators group)
2. Logged on as that user
3. Opened up a command prompt, & typed "cipher /r:efscert"
4. This created the efscert.cer & efscert.pfx files
5. I logged out of this user, & logged back in as my account (with
Admin rights)
6. I then went into MMC & opened up Certificates (My User Account). I
then opened up the Certificates - Current User-Personal-Certificates
folder
7. I then imported the .pfx file that I created for the DRA account
8. I then went into MMC & opened up Local Computer Policy-Computer
Configuration-Windows Settings-Security Settings-Public Key
Policies-Encrypting File System
9. I then added the .cer I created for the DRA account
10. I exited from MMC & encrypted a plain text file as a test
11. I logged out of my account, & logged back in as the DRA account
12. When I tried to open the encrypted file, the message given was
"Cannot open the {location & filename} file. Make sure a disk is in
the drive you specified" (the file was on the hard drive, not a floppy
disk), & when I right clicked on it & tried to remove the tick
specifying that it was encrypted, I got "An error occurred applying
attributes to the file {location & filename}. Access is denied")
13. I then logged out of the DRA account & logged back in as myself. I
was able to access the text file fine, & to remove the encryption (& I
checked the details tab - the DRA account was listed as the "Data
Recovery Agents for this file as defined by Recovery Policy")
Can anyone tell me what I've missed? The strange thing is that before
I had to format my drive & reinstall XP from scratch. I had EFS & the
DRA working fine, & as far as I can remember, I used the exact same
steps.

Thanks,

CM



Relevant Pages

  • Re: NTFS File Encryption Question
    ... >>> know it is tied to the SID of the user account in question. ... >NTFS file encryption is not for the faint of heart. ... Well, as I said at the outset, I'm no expert in EFS. ...
    (microsoft.public.windowsxp.general)
  • Encrypted files problem
    ... The network is not using any sort of encryption on the server and we have not assign any DRA account on the netwok. ... the users is member of a domain and he used his domain account to encrypt the files. ...
    (microsoft.public.win2000.file_system)