Re: Recovering EFS from a Backup

From: Pat Hoffer [MSFT] (pathoff_at_online.microsoft.com)
Date: 01/18/05


Date: Mon, 17 Jan 2005 15:09:05 -0800

You said that you opened MMC > Certificates > Personal > Certificates and saw
a certificate associated with your domain existence. If you are truly logged
on as the "local user" that you were when you encrypted the files on the
standalone machine, you would not see a domain certificate in this store.
(BTW: The Personal store is the MY store.)

If you encrypted the files as Machine01/Mike Go, you must log in as
Machine01/Mike Go in order to decrypt them. Don't log on as
<UserDomain>\Mike Go. (You don't have to disconnect from the domain in order
to log in with your local machine username.) Hope that helps.

Thanks.
Pat

"Mike Go" wrote:

> Sorry for the delay on the response,
>
> You asked about error messages, when I go to an encrypted file as a stand
> alone user, logging into the stand alone (not connected to the domain)
> machine01, I right click Properties>Advanced> UNCHECK Encrypt this file, all
> goes well until I Apply then I get the "Error Applying Attributes, an error
> occurred applying attributes to the file: File name, access is denied"
>
> The thumbprints for my certificate as well as the response from EFSinfo.exe
> is the same. However my thumbprint as a domain user is different.
>
> When I run efsinfo on an encrypted file I get
>
> Filename.txt: Encrypted
> Users who can decrypt:
> Machine01\Mike Go (Mike Go(Mike Go@SONY))
>
> Machine01 is the local machine
> Mike Go is my user name
> Not sure what @SONY represents, other than an earlier existance
>
> Also, could you expalin, MY Store? I went into the MMC, Certificates,
> Personal, Certificates, and there appears two certificates, one with a
> thumbnail from my previous life, and one with a thumbnail associated with my
> domain existance.
>
> These also appear in the Trusted People > Certificates. Both note that there
> are private keys associated with them. Where would I located these?
>
> Any help is appreciated.
>
> THX!,
> Mikego
>
> "Shreeniwas Kelkar [MSFT]" wrote:
>
> > Why do you mean by "could not decrypt". Can you be more specific and
> > describe the exact steps you are trying, the error you get, etc.
> >
> > Also, can you see your EFS certificate in the MY store. Does is have a
> > private key associated with it?
> >
> > --
> > Shreeniwas Kelkar [MSFT]
> >
> > This posting is provided "AS IS" with no warranties, and confers no rights.
> >
> >
> > "Mike Go" <MikeGo@discussions.microsoft.com> wrote in message
> > news:EC1E3972-DD2A-4847-84CE-6CD05E16BE30@microsoft.com...
> > > Jan,
> > > I tried logging on the local account, but could not decrypt. Not sure why.
> > > Mikego
> > >
> > > "Jan Peter Stotz" wrote:
> > >
> > >> Mike Go schrieb:
> > >>
> > >> > Stung by EFS!
> > >> > Can anyone help me recover my EFS files... I was a stand alone machine
> > >> > when
> > >> > I encrypted, I didn't create a recovery agent (bad, bad, bad) and then
> > >> > I
> > >> > joined a domain.
> > >>
> > >> That should not be a problem with EFS. Use your local account instead of
> > >> your new domain account and everything should be fine.
> > >>
> > >> Jan
> > >>
> >
> >
> >



Relevant Pages

  • Re: Active Directory User Object certificate store to personal certificate store
    ... Active Directory doesn't store private keys. ... the keys and certificates are stored in the user profile - you can ... > Is there a way to move AD published certs to from the Active Directory ... I can see the certs in the AD User Object cert store for ...
    (microsoft.public.windows.server.security)
  • RE: EAP-TLS Client enrollment recovery.
    ... the private keys are not restored when you ... only restore the certificates. ... store in order to extract certificates and keys from it and then putting them ...
    (microsoft.public.platformsdk.security)
  • Re: Shared Certificate Store in Active Directory
    ... There is no need to store IPSEC certs in the AD for IPSEC, ... > Active Directory so you can make Certificates and their ... > Certificates rather than Kerberos? ...
    (microsoft.public.win2000.security)
  • Re: Microsoft CA not installing trusted root path in local computer store
    ... > I installed a standalone root CA, I use it to validate vpn l2tp/IPSec> conections, the problem is that when I try to install the root ... > certification path for the CA in the client machine > using the web page, it is installed in te user certificates store, and> not in the local computer certificates store. ...
    (microsoft.public.win2000.security)
  • Re: Using smartcard as certificate store
    ... It allows the user to perform secure operations like web ... we want to put the certificates we acquire when browsing ... You should still not need to store certificates from arbitrary websites ... that isn't a smartcard but is treated by CAPI as though it were one"! ...
    (microsoft.public.platformsdk.security)

Quantcast