Re: EFS issue...somewhat complicated



It sounds like a problem with your EFS private key. Hopefully you made a
backup to external media before this all happened. Try using the mmc snapin
for user certificates and go to the personal/certificates folder to see if
your EFS certificate is there and it shows that the private key is also
present. To really see if the private key is intact try to export it. If you
can not or get some error message then the private key may have become
corrupted and it may be worthwhile to run Check Disk on the computer
selecting the option to automatically fix file system errors. Also check to
see that you have full control permissions to the folder/file.

If the private key is there and can be exported it may not be the correct
private key. You can compare the thumbprint of the certificate to what is
shown in the file properties for the EFS file and they must match or it can
not decrypt the file. If you are unsure of the existence of the private key
download the free limited trial version of the EFS recovery program from
Elcomsoft as it will try to find any EFS private keys and then you must
enter the proper password for the private key to be able to decrypt files
though the trial version will only decrypt small files. --- Steve

http://www.elcomsoft.com/aefsdr.html --- Elcomsoft
http://support.microsoft.com/default.aspx?scid=kb;EN-US;223316

"Roger" <n@xxxxx> wrote in message
news:%23w8zgVuUGHA.328@xxxxxxxxxxxxxxxxxxxxxxx
XP Pro with SP 2 installed. No domain, no recovery agent
Using third party authentication program to sign on to the computer (rohos
welcome). A test of the security in Rohos appears to have corrupted my
user profile.... The test was a forced change (through a different
administrator) of my windows password to confirm that the USB key could
not
log into my account. To regain access to my account, I had to do a second
forced change to reset my password back to normal. The situation I am
trying to fix is as follows:

Issue:

Computer recognizes I have permission to open the encrypted files
(permission) and am listed as authorized to access the file on the
encryption properties screen (I have at least one decryption key), but the
computer is acting as though I am not authorized. It wont decrypt the
file
or allow me to turn off the encryption attribute. I keep getting error
messages that say access denied.

Any suggestions on how to fix this would be appreciated.

Roger


.



Relevant Pages

  • Re: CryptAPI(encryption/decryption)
    ... It seems like you're missing the Base64 decode step when trying to decrypt ... I misspelled the Private Key as Primary Key. ... Is there any variation in the encryption format in openssl compared to ... "Dylan DSilva " wrote: ...
    (microsoft.public.pocketpc.developer)
  • Re: CryptAPI(encryption/decryption)
    ... The openssl encrypted data format is in bigendian ... Is there any way I can import the PEM formated private key to the MS CSP ... I'm decoding the base64 encoded data before trying to decrypt. ... Is there any variation in the encryption format in openssl compared ...
    (microsoft.public.pocketpc.developer)
  • Re: CryptAPI(encryption/decryption)
    ... since symmetric encryption is faster than public key encryption. ... As per your reply I could get the handle of the private key. ... possible for B to decrypt the data using his Private Key. ... The PFX format encrypts the private key with the user supplied password ...
    (microsoft.public.pocketpc.developer)
  • Re: No way to encrypt with private key in C#?
    ... 1)if a file is encrypted with the private key, ... 2)if a file is encrypted with the public key, ... The two ways are usually called encryption and signing, from public to private and back again. ... There is nothing prohibiting an application using RSA to "encrypt" the entire file using the private key and release it, so that everyone that wants to use it must first decrypt it with the public key. ...
    (microsoft.public.dotnet.languages.csharp)
  • Re: DRA is Decrypting Files when it shouldnt be!!!
    ... > EFS is allowing the RA to decrypt 200 files that were encrypted BEFORE an RA ... > encryption to get the RA to decrypt encrypted files. ... the default RA certificate was used. ... certificate and private key only when needed). ...
    (microsoft.public.windowsxp.security_admin)