Re: Encrypted files got me crazy!!!!!!!

From: Shain Wray (shainw_at_microsoft.com)
Date: 12/03/03


Date: Wed, 03 Dec 2003 03:46:02 GMT

Hello Dan,

I have a few questions in regards to your problem -

1. You said you moved them and then certified the files were there. Just
to make sure, did you move them and then check right away or is it possible
you waited a couple of days? I want to make sure no other changes were
made to the system in between moving them and checking them. The following
KB could be your problem if you had uninstalled SP1 on Windows XP -

329741 EFS Files Appear Corrupted When You Open Them
http://support.microsoft.com/?id=329741

2. You state you see the following in the Security tab -

S-1-5-21-1614895754-920026266-500........ ??????????? This I don't know
what is

This is the Local Administrator account. Have you logged in as the local
admin and tried to view these files?

3. Can you encrypt other files at this point and view them correctly? It
is possible that the DLL's that handle the cryptography have been
corrupted. Try registering the following files and/or restoring them from
SP1, the Winxp CD or the listed updates, depending on what you have
currently installed -

Crypt32.dll
Cryptdlg.dll
Cryptnet.dll
Cryptsvc.dll

The following hotfix is the most recent for Crypt32.dll and Cryptnet.dll
after SP1 -

329433 A Revoked Certificate Is Selected If a Certification Authority in the
http://support.microsoft.com/?id=329433

And the following items are post SP1 also but are older than the above KB
and only updates Crypt32.dll -

821248 Contents of the CRL Distribution Points Field of a Digital
Certificate
http://support.microsoft.com/?id=821248

329115 MS02-050: Certificate Validation Flaw Might Permit Identity Spoofing
http://support.microsoft.com/?id=329115

4. Since the Encryption tag is not checked, the file system does not
consider these encrypted files. It looks like the issue is with the header
information on the data and we may not be able to recover it. Do you have
a backup or a previous restore point that you could go back to?

Best regards,

--
Shain Wray
Microsoft PSS Security Team
This posting is provided "AS IS" with no warranties and confers no rights.
Please reply to the newsgroup so that others may benefit.  Thanks!


Relevant Pages

  • Re: Auto Enrollment not working for one DC
    ... I was already aware of the post SP1 problem with the CERTSVC_DCOM_ACCESS ... Certificate Services: Effects of security enhancements to the DCOM protocol ...
    (microsoft.public.windows.server.active_directory)
  • Re: DTExec slow
    ... It was actually this way before SP1 as well. ... The thing is that when you execute a package, CryptoAPI, on behalf of the SSIS service, attempts to go out to the internet to check a certificate revocation list. ...
    (microsoft.public.sqlserver.dts)
  • RE: Cannot use Outlook after SP1 install
    ... Thank you for posting to the SBS Newsgroup. ... Retaining the original certificate is covered in the SP1 Premium Readme ... Microsoft CSS Online Newsgroup Support ...
    (microsoft.public.windows.server.sbs)
  • RE: Obtaining Digital Certificate
    ... Windows Server 2003 Certificate Services provides enrollment and ... Windows Server 2003 SP1 introduces enhanced default security ... you may have to update these security settings to ... Microsoft CSS Online Newsgroup Support ...
    (microsoft.public.windows.server.sbs)
  • Re: Domain Controller Certificate Renewal
    ... I have recently upgraded both to SP1. ... > that is not the CA started to show AutoEnrollment errors in the event log. ... > I have found the DC certificate template on the server that is the CA. ... just add the Domain Controllers group to the ...
    (microsoft.public.windows.server.security)