Re: Encrypting the Offline Files cache

From: Helmuth Snoeijen (HelmuthSnoeijen_at_discussions.microsoft.com)
Date: 12/28/04


Date: Tue, 28 Dec 2004 05:45:10 -0800

Hello Tim,

Thanks for your reply. But I'm still puzzled.

When the Offline Files cache is encrypted there should be at least a self
signed user certitficate (for EFS) in the local certificate store on the
client, or not?

In my case there was no certificate. Can I therefore make the conclusion
that nothing is encrypted on the client (including the Offline Files cache)?

Thanks,

Helmuth

"Tim Springston [MSFT]" wrote:

> The user interface in the on the client is the best way to check. The UI
> has logic to decide whether the "encrypt" option is available (unencrypted)
> or not an option (unsupported client or already encrypted on a supported
> client configuration).
>
> Encryption of the cached items for client side caching is done within the
> cached items database, so it will not display as encrypted as other file
> system objects would (like an encrypted Word doc) even if it is encrypted.
>
> If you have a need to prove that the items are encrypted for a security
> audit, please contact Microsoft Product Support Services and we can help.
> You should not be charged for this incident if that is all you need.
>
> Please repost if you have any additional questions or concerns.
> --
>
> Tim Springston
> Microsoft Corporation
>
> This posting is provided "AS IS" with no warranties, and confers no rights.
> "Helmuth Snoeijen" <HelmuthSnoeijen@discussions.microsoft.com> wrote in
> message news:F41BE611-7C0F-4EC3-A789-422BB93DEF93@microsoft.com...
> > I've the following situation:
> > - Active Directory W2K3, using OU's and GPO's for controlling settings on
> > the clients
> > - Windows XP SP2 clients (laptops)
> > - "My Documents' is redirected to the users' homeshare and made offline
> > available
> > - The Offline Files cache encryption is enabled using a GPO setting
> > - EFS is enabled for users using default Domain GPO
> > - The domain administrator is the default data recovery agent
> >
> > Question:
> > How can I check if the CSC (cache) directory is encrypted (automatically)
> > on
> > the client?
> >
> > Additional info:
> > - I've used the EFSINFO resource kit tool to check if the CSC is
> > encrypted.
> > It says "not encrypted".
> > - When I display the attributes belonging to the CSC directory, there is
> > no
> > "E" attribute for encrypted.
> > - There is no user certificate on the client, which I think should be
> > present.
> >
> > What is going wrong here.
> >
> > Thanx in advance..
> >
> >
>
>
>



Relevant Pages

  • RE: Cannot decrypt files encrypted using Crypto API on a different
    ... previous message which uses the recipien't public key.) ... KEK (key encryption key) to protect the session key. ... embedded into your client app and server code). ... but what is the point to encrypt the data if ANYBODY can decrypt it (since ...
    (microsoft.public.platformsdk.security)
  • Re: username and Password sent as clear text strings
    ... encryption of the traffic. ... SSL is used. ... client, it would seem like too much hassle for a low possibility hack. ... This is how all web applications on the planet work today by design. ...
    (Pen-Test)
  • Re: username and Password sent as clear text strings
    ... encryption of the traffic. ... SSL is used. ... client, it would seem like too much hassle for a low possibility hack. ... This is how all web applications on the planet work today by design. ...
    (Pen-Test)
  • Re: XP wireless questions ...setting encryption
    ... I never use the Linksys software for drivers. ... 802.1x authentication is only used with WPA encryption. ... wireless network. ... The manufacturers client program ...
    (alt.internet.wireless)
  • Re: recovering encrypted files with encryption key via network cli
    ... I can disable simple file sharing on the client, which is XP pro and get ... In XP Pro ... that I can do a clean reinstall of windows on the faulty system. ... EFS encryption option) on the hard disk of the faulty system. ...
    (microsoft.public.windowsxp.help_and_support)