Re: DRA is Decrypting Files when it shouldn't be!!!



So what did you exactly do? Create a user, encrypt some files, remove the
user' EFS certificate private key, create an RA, and not be able to decrypt
files as RA or did you use your current configuration where the RA could
decrypt user's files, remove user's EFS certificate private key, and RA can
no longer decrypt files?? Did you look to see if RA had more then one RA
certificate?? --- Steve


"DJ" <DJ@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:C7D62C3E-C1AA-46A1-93E1-D66DE97010B5@xxxxxxxxxxxxxxxx
> Steve, I did what you said (below) and "exported" & "deleted" the user's
> private key and now it's acting correctly. Why is this?
>
> I don't understand, please explain.
>
> Thanks, DJ
>
> "Steven L Umbach" wrote:
>
>> Hmm. Have you tried that first exporting/deleting the user's private key
>> before creating the RA to see what happens or rebooting the computer
>> before
>> you created the RA with cipher /R with the user's private key still on
>> the
>> computer? XP is supposed to flush EFS cache at logoff. Did you remove
>> any
>> old RA from the RA user certificate store via mmc snapin for certificates
>> and then logoff as the RA? You can use efsinfo to see what RAs are
>> included
>> in a user's EFS file and examine the certificate thumbprint to see
>> exactly
>> what RA certificate is being used if there are more than one available.
>> You
>> might also want to post in the Microsoft.public.security.crypto
>> wsgroup. --- Steve
>>
>>
>> "DJ" <DJ@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
>> news:583E06D2-2DEA-4BCE-AE5A-6B2590CD52A6@xxxxxxxxxxxxxxxx
>> >I setup a brand new XP install. Setup a new local user named Joe and
>> >logged
>> > in as Joe . Created a new directory and encrypted 200 files in this
>> > directory.
>> >
>> > Logged off and and logged in as Administrator. Created a DRA (ex:
>> > Cipher
>> > /r:Filename, imported certificate and private key into the local
>> > certificate
>> > store, Ran gpedit.msc and added DRA.). After this, I tried to unencrypt
>> > the
>> > directory while logged in as Administrator and it let me!!! Why is
>> > this?
>> > It
>> > shouldn't allow me to decrypt 200 files that were encrypted before a
>> > DRA
>> > was
>> > created.
>> >
>> > I don't get this crap. Many articles state that you have to create the
>> > DRA
>> > before encrypting the files so that the DRA can decrypt them. If you
>> > don't
>> > then, you need to run cipher /u to update the encrypted files so that
>> > the
>> > newly created DRA will work with older encrypted files.
>> >
>> > In my case, I created the DRA after the files were already encrypted
>> > and
>> > "never" ran a cipher /u. Does anybody know what could cause this?
>> >
>> > Thanks, DJ
>>
>>
>>


.



Relevant Pages

  • Re: Entourage mail and PGP/GPG?
    ... > You can digitally sign messages and encrypt them using CA. ... > using a certificate for each recipient. ... > recipient uses this certificate to verify which private key was ...
    (microsoft.public.mac.office.entourage)
  • Re: Encrypting Messages
    ... and private key situation, ... You encrypt a messages using SOMEONE ELSE's public key. ... > person that can decrypt that message is the one that has the matching ... > Use the public key from your certificate. ...
    (microsoft.public.outlook)
  • Re: CryptAcquireContext returns NTE_BAD_KEY_STATE?
    ... There is also a routine to check whether there is a certificate in the ... > The Microsoft software CSPs encrypt the private keys using DPAPI ... >> that is supposed to create a new server certificate with a private key). ...
    (microsoft.public.platformsdk.security)
  • Re: Need some information about certificates
    ... receiver uses your public key to verify the signature but for encryption you ... use an entities public key to encrypt the data and then the recipient uses ... their private key to decrypt the data. ... certificate installed on the server running my application. ...
    (microsoft.public.windows.server.security)
  • Re: SSL questions
    ... The question of compromised certificate ... if you have the private key from the server's ... > knew about the session when the session was set up, ... > symmetric keys used to encrypt and decrypt all the messages. ...
    (sci.crypt)