Re: EFS nightmare



In news:%23vhg0VhxKHA.5940@xxxxxxxxxxxxxxxxxxxx,
big country <someone@xxxxxxxxxxxxx> typed:
Hey all I have a WinXP SP2 workstation. It has an external
hard disk that is failing and there are some files that are
encrypted that we cant decrypt. So we cant move the files.
The user is not sure who initially encrypted the files but
the file shows an AD account that is specified as a data
recovery agent for that file. When I went to group policy
on the local machine there was not a EFS policy defined so
I created one with the data recovery account from AD. The
account shows a valid cert so I logged into the pc using
the data recovery account and I still cant decrypt the
file. Any thoughts?

If you can't locate the keys & certs that were used when the
data was encrypted, it's lost for good. Nothing you create now
will allow access to it, period. Hope you have backups if it's
important. MS did one thing right; their encryption structure
is unbeatable without a lot of time and money.
See help & support for EFS for more details; look for
certificate exports.

HTH,

Twayne`


.



Relevant Pages

  • Re: EFS nightmare
    ... EFS policy defined so I created one with the data recovery account ... using the data recovery account and I still cant decrypt the file. ... Backups are the only "backup plan" that has much of any validity when they ... Encryption is made to keep people out. ...
    (microsoft.public.windowsxp.security_admin)
  • Re: Lost pin numbers
    ... >Encryption is one-way encryption because I encrypted them with ... I mean i cant decrypt them, ... >them with TNS C but in the S system I dont have TNS C and have to ... the TNS C compiler and RTL for the S-Series machine. ...
    (comp.sys.tandem)
  • Re: Lost pin numbers
    ... Encryption is one-way encryption because I encrypted them with ... I mean i cant decrypt them, ... them with TNS C but in the S system I dont have TNS C and have to ... compile them with Native compiler. ...
    (comp.sys.tandem)
  • EFS nightmare
    ... failing and there are some files that are encrypted that we cant decrypt. ... When I went to group policy on the local machine there ... was not a EFS policy defined so I created one with the data recovery account ... data recovery account and I still cant decrypt the file. ...
    (microsoft.public.windowsxp.security_admin)