Re: troubleshooting shared EFS on Windows XP
From: dpapas665 (dpapas665_at_yahoo.com)
Date: 06/23/05
- Next message: David Hahn: "Re: Windows Firewall"
- Previous message: Northstar Ambulance: "Printer installation rights.....Please"
- In reply to: Pat Hoffer [MSFT]: "RE: troubleshooting shared EFS on Windows XP"
- Next in thread: Pat Hoffer [MSFT]: "Re: troubleshooting shared EFS on Windows XP"
- Reply: Pat Hoffer [MSFT]: "Re: troubleshooting shared EFS on Windows XP"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Date: 23 Jun 2005 09:20:37 -0700
OK, I logged locally into the machine and imported my cert (including
private key) to the remote machine and turned on "trust computer for
delegation" in AD. Thus far, that solved the problem in that, if a file
is encrypted, both users can decrypt it when logged lcoally into that
machine. However, I found I was still unable to remotely encrypt or
decrypt it. Trying to decrypt, got "access denied". Trying to encrypt,
got the error: "the requested operation requires delegation to be
enabled on the machine".
So, the remaining problem looks to be the "trust computer for
delegation". I checked the userAccountControl field for the computer
account in ADSIEdit to see if the setting had taken, and it appears to
have the value (528834) required as specified by MS KB# 305144, and the
user account doesn't have the "account is sensitive and cannot be
delegated" property set. So, at this point I'm not sure why the remote
machine won't impersonate the user as pointed out in the article you
referred me to:
Remote EFS operatons in a file share environment
6. EFS must impersonate the user to obtain access to the necessary
public or private key. This requires the following:
1. The computer must be a domain member in a domain that uses
Kerberos authentication because impersonation relies on Kerberos
authentication and delegation.
2. The computer must be trusted for delegation.
3. The user must be logged on with a domain account that can be
delegated.
Thanks again,
-D.
- Next message: David Hahn: "Re: Windows Firewall"
- Previous message: Northstar Ambulance: "Printer installation rights.....Please"
- In reply to: Pat Hoffer [MSFT]: "RE: troubleshooting shared EFS on Windows XP"
- Next in thread: Pat Hoffer [MSFT]: "Re: troubleshooting shared EFS on Windows XP"
- Reply: Pat Hoffer [MSFT]: "Re: troubleshooting shared EFS on Windows XP"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Relevant Pages
|