hidden hit counter
Welcome to WindowsForumz.com!
FAQFAQ      ProfileProfile    Private MessagesPrivate Messages   Log inLog in

EFS Issue

 
   Windows XP (Home) -> Security Admin RSS
Next:  WIA (Camera wizard)  
Author Message
Mouse4440




Joined: Apr 27, 2005
Posts: 3



(Msg. 1) Posted: Wed Apr 27, 2005 5:07 pm
Post subject: EFS Issue

Recently I used RIS (Remote Installation Service) to reinstall a clients workstation because it had been upgraded and had different versions of Office installed and just generally had issues, but what I didn't know is that the user had Encrypted files on another drive (USB External Hard Drive) so after I reinstalled the OS the Computer account is not the same as before and he can no longer access the files that were on the other drive. I have tried several of the free downloadable recovery packages Advanced EFS recovery and others but have had no luck, the recovery agent displays that no user is able to decrypt the files and the user account has not changed because the user is in a domain. I have tried logging in as local admin, domain admin, but still no luck. anyone know of anything I can do. and no the user didn't export the keys.

 >> Stay informed about: EFS Issue 
Back to top
Login to vote
Jupiter Jones MVP

External


Since: Jun 13, 2004
Posts: 1861



(Msg. 2) Posted: Wed Apr 27, 2005 10:54 pm
Post subject: Re: EFS Issue [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

Was there a Designated Recovery Agent on the domain?
If not, the data is most likely gone for good.

See the bottom of this page for ways to help prevent data loss with EFS in
the future:
<a style='text-decoration: underline;' href="http://www3.telus.net/dandemar/encrypt.htm" target="_blank">http://www3.telus.net/dandemar/encrypt.htm</a>

--
Jupiter Jones [MVP]
<a style='text-decoration: underline;' href="http://www3.telus.net/dandemar" target="_blank">http://www3.telus.net/dandemar</a>
In memory of our dear friend, MVP Alex Nichol
<a style='text-decoration: underline;' href="http://www.dts-l.org" target="_blank">http://www.dts-l.org</a>


"Mouse4440" <UseLinkToEmail.DeleteThis@WindowsForumz.com> wrote in message
news:3_1177687_c7f35c781fba764475392afee945baeb@windowsforumz.com...
 > Recently I used RIS (Remote Installation Service) to reinstall a
 > clients workstation because it had been upgraded and had different
 > versions of Office installed and just generally had issues, but what I
 > didn't know is that the user had Encrypted files on another drive (USB
 > External Hard Drive) so after I reinstalled the OS the Computer
 > account is not the same as before and he can no longer access the
 > files that were on the other drive. I have tried several of the free
 > downloadable recovery packages Advanced EFS recovery and others but
 > have had no luck, the recovery agent displays that no user is able to
 > decrypt the files and the user account has not changed because the
 > user is in a domain. I have tried logging in as local admin, domain
 > admin, but still no luck. anyone know of anything I can do. and no
 > the user didn't export the keys.
 >
 > --
 > Posted using the <a style='text-decoration: underline;' href="http://www.windowsforumz.com" target="_blank">http://www.windowsforumz.com</a> interface, at author's
 > request
 > Articles individually checked for conformance to usenet standards
 > Topic URL:
<font color=purple> > <a style='text-decoration: underline;' href="http://www.windowsforumz.com/Security-Admin-EFS-Issue-ftopict365344.html</font" target="_blank">http://www.windowsforumz.com/Security-Admin-EFS-Issue-ftopict365344.ht...lt;/fon</a>>
 > Visit Topic URL to contact author (reg. req'd). Report abuse:
<font color=purple> > <a style='text-decoration: underline;' href="http://www.windowsforumz.com/eform.php?p=1177687</font" target="_blank">http://www.windowsforumz.com/eform.php?p=1177687</font</a>><!-- ~MESSAGE_AFTER~ -->

 >> Stay informed about: EFS Issue 
Back to top
Login to vote
Mouse4440




Joined: Apr 27, 2005
Posts: 3



(Msg. 3) Posted: Fri Apr 29, 2005 10:01 am
Post subject: Re: EFS Issue [Login to view extended thread Info.]

I'm not sure, I logged in as admin on the local machine and as the domain admin and the windows recovery thing display no recovery agent present. is this something that user had to setup or is an automatic thing?
 >> Stay informed about: EFS Issue 
Back to top
Login to vote
kerry15

External


Since: Jan 27, 2005
Posts: 236



(Msg. 4) Posted: Fri Apr 29, 2005 10:01 am
Post subject: Re: Re: EFS Issue [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

"Mouse4440" <DoNotEmail.DeleteThis@WindowsForumz.com> wrote in message
news:3_1183971_590abcb1375a568d59e74bf288c16868@windowsforumz.com...
 > "Jupiter Jones MVP" wrote:
  > > Was there a Designated Recovery Agent on the domain?
  > > If not, the data is most likely gone for good.
  > >
  > > See the bottom of this page for ways to help prevent data loss
  > > with EFS in
  > > the future:
<font color=green>  > > <a style='text-decoration: underline;' href="http://www3.telus.net/dandemar/encrypt.htm</font" target="_blank">http://www3.telus.net/dandemar/encrypt.htm</font</a>>
  > >
  > > --
  > > Jupiter Jones [MVP]
<font color=green>  > > <a style='text-decoration: underline;' href="http://www3.telus.net/dandemar</font" target="_blank">http://www3.telus.net/dandemar</font</a>>
  > > In memory of our dear friend, MVP Alex Nichol
<font color=green>  > > <a style='text-decoration: underline;' href="http://www.dts-l.org</font" target="_blank">http://www.dts-l.org</font</a>>
  > >
  > >
  > > "Mouse4440" <UseLinkToEmail.DeleteThis@WindowsForumz.com> wrote in
  > > message
  > > news:3_1177687_c7f35c781fba764475392afee945baeb@windowsforumz.com...
   > > > Recently I used RIS (Remote Installation Service) to
  > > reinstall a
   > > > clients workstation because it had been upgraded and had
  > > different
   > > > versions of Office installed and just generally had issues,
  > > but what I
   > > > didn't know is that the user had Encrypted files on another
  > > drive (USB
   > > > External Hard Drive) so after I reinstalled the OS the
  > > Computer
   > > > account is not the same as before and he can no longer
  > > access the
   > > > files that were on the other drive. I have tried several of
  > > the free
   > > > downloadable recovery packages Advanced EFS recovery and
  > > others but
   > > > have had no luck, the recovery agent displays that no user
  > > is able to
   > > > decrypt the files and the user account has not changed
  > > because the
   > > > user is in a domain. I have tried logging in as local admin,
  > > domain
   > > > admin, but still no luck. anyone know of anything I can do.
  > > and no
   > > > the user didn't export the keys.
   > > >
   > > > --
   > > > Posted using the <a style='text-decoration: underline;' href="http://www.windowsforumz.com" target="_blank">http://www.windowsforumz.com</a> interface, at author's
   > > > request
   > > > Articles individually checked for conformance to usenet
  > > standards
   > > > Topic URL:
<font color=brown>   > > > <a style='text-decoration: underline;' href="http://www.windowsforumz.com/Security-Admin-EFS-Issue-ftopict365344.html</font" target="_blank">http://www.windowsforumz.com/Security-Admin-EFS-Issue-ftopict365344.ht...lt;/fon</a>>
   > > > Visit Topic URL to contact author (reg. req'd). Report
  > > abuse:
<font color=brown>   > > > <a style='text-decoration: underline;' href="http://www.windowsforumz.com/eform.php?p=1177687</font" target="_blank">http://www.windowsforumz.com/eform.php?p=1177687</font</a>>
 >
 > I’m not sure, I logged in as admin on the local machine and as the
 > domain admin and the windows recovery thing display no recovery agent
 > present. is this something that user had to setup or is an automatic
 > thing?
 >

With XP you have to setup the recovery agent. Win2k worked differently. If
he was logged on locally when he encrypted the files you are probably out of
luck. If he was logged on as a domain user you will have to figure out if
there is a recovery agent and who it is. Export the recovery key and import
it on the machine with the files on it. You may also have to take ownership
of the files on the USB drive first.

<a style='text-decoration: underline;' href="http://support.microsoft.com/default.aspx?scid=kb;en-us;887414" target="_blank">http://support.microsoft.com/default.aspx?scid=kb;en-us;887414</a>

<a style='text-decoration: underline;' href="http://www.microsoft.com/resources/documentation/Windows/XP/all/reskit/en-us/Default.asp?url=/resources/documentation/windows/xp/all/reskit/en-us/prnb_efs_lnfx.asp" target="_blank">http://www.microsoft.com/resources/documentation/Windows/XP/all/reskit...-us/Def</a>

Kerry<!-- ~MESSAGE_AFTER~ -->
 >> Stay informed about: EFS Issue 
Back to top
Login to vote
Mouse4440




Joined: Apr 27, 2005
Posts: 3



(Msg. 5) Posted: Fri Apr 29, 2005 12:16 pm
Post subject: Re: Re: EFS Issue [Login to view extended thread Info.]

He was a domain user but the key was on the system partition and the data is on another drive, the system partition that had the keys was deleted with the install of Win XP. I logged in as the user and the recovery agent displays no recovery agent present, likewise for the local admin and domain admin. I have not taken ownership though. would I need to do that for the recovery agent.
 >> Stay informed about: EFS Issue 
Back to top
Login to vote
kerry15

External


Since: Jan 27, 2005
Posts: 236



(Msg. 6) Posted: Fri Apr 29, 2005 12:16 pm
Post subject: Re: EFS Issue [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

"Mouse4440" <DoNotEmail.DeleteThis@WindowsForumz.com> wrote in message
news:3_1184166_682e46f0d60f56f2114f32822a76208d@windowsforumz.com...
 > "kerry15" wrote:
  > > "Mouse4440" <DoNotEmail.DeleteThis@WindowsForumz.com> wrote in message
  > > news:3_1183971_590abcb1375a568d59e74bf288c16868@windowsforumz.com...
   > > > "Jupiter Jones MVP" wrote:
  > >  > > Was there a Designated Recovery Agent on the domain?
  > >  > > If not, the data is most likely gone for good.
  > >  > >
  > >  > > See the bottom of this page for ways to help prevent
  > > data loss
  > >  > > with EFS in
  > >  > > the future:
<font color=green>  > >  > > <a style='text-decoration: underline;' href="http://www3.telus.net/dandemar/encrypt.htm</font" target="_blank">http://www3.telus.net/dandemar/encrypt.htm</font</a>>
  > >  > >
  > >  > > --
  > >  > > Jupiter Jones [MVP]
<font color=green>  > >  > > <a style='text-decoration: underline;' href="http://www3.telus.net/dandemar</font" target="_blank">http://www3.telus.net/dandemar</font</a>>
  > >  > > In memory of our dear friend, MVP Alex Nichol
<font color=green>  > >  > > <a style='text-decoration: underline;' href="http://www.dts-l.org</font" target="_blank">http://www.dts-l.org</font</a>>
  > >  > >
  > >  > >
  > >  > > "Mouse4440" <UseLinkToEmail.DeleteThis@WindowsForumz.com>
  > > wrote in
  > >  > > message
  > >  > >
  > > news:3_1177687_c7f35c781fba764475392afee945baeb@windowsforumz.com...
  > >   > > > Recently I used RIS (Remote Installation
  > > Service) to
  > >  > > reinstall a
  > >   > > > clients workstation because it had been
  > > upgraded and had
  > >  > > different
  > >   > > > versions of Office installed and just
  > > generally had issues,
  > >  > > but what I
  > >   > > > didn't know is that the user had Encrypted
  > > files on another
  > >  > > drive (USB
  > >   > > > External Hard Drive) so after I reinstalled
  > > the OS the
  > >  > > Computer
  > >   > > > account is not the same as before and he can
  > > no longer
  > >  > > access the
  > >   > > > files that were on the other drive. I have
  > > tried several of
  > >  > > the free
  > >   > > > downloadable recovery packages Advanced EFS
  > > recovery and
  > >  > > others but
  > >   > > > have had no luck, the recovery agent
  > > displays that no user
  > >  > > is able to
  > >   > > > decrypt the files and the user account has
  > > not changed
  > >  > > because the
  > >   > > > user is in a domain. I have tried logging in
  > > as local admin,
  > >  > > domain
  > >   > > > admin, but still no luck. anyone know of
  > > anything I can do.
  > >  > > and no
  > >   > > > the user didn't export the keys.
  > >   > > >
  > >   > > > --
  > >   > > > Posted using the
  > > <a style='text-decoration: underline;' href="http://www.windowsforumz.com" target="_blank">http://www.windowsforumz.com</a> interface, at author's
  > >   > > > request
  > >   > > > Articles individually checked for
  > > conformance to usenet
  > >  > > standards
  > >   > > > Topic URL:
  > >   > > >
<font color=green>  > > <a style='text-decoration: underline;' href="http://www.windowsforumz.com/Security-Admin-EFS-Issue-ftopict365344.html</font" target="_blank">http://www.windowsforumz.com/Security-Admin-EFS-Issue-ftopict365344.ht...lt;/fon</a>>
  > >   > > > Visit Topic URL to contact author (reg.
  > > req'd). Report
  > >  > > abuse:
  > >   > > >
<font color=green>  > > <a style='text-decoration: underline;' href="http://www.windowsforumz.com/eform.php?p=1177687</font" target="_blank">http://www.windowsforumz.com/eform.php?p=1177687</font</a>>
   > > >
   > > > I’m not sure, I logged in as admin on the local machine and
  > > as the
   > > > domain admin and the windows recovery thing display no
  > > recovery agent
   > > > present. is this something that user had to setup or is an
  > > automatic
   > > > thing?
   > > >
  > >
  > > With XP you have to setup the recovery agent. Win2k worked
  > > differently. If
  > > he was logged on locally when he encrypted the files you are
  > > probably out of
  > > luck. If he was logged on as a domain user you will have to
  > > figure out if
  > > there is a recovery agent and who it is. Export the recovery
  > > key and import
  > > it on the machine with the files on it. You may also have to
  > > take ownership
  > > of the files on the USB drive first.
  > >
<font color=green>  > > <a style='text-decoration: underline;' href="http://support.microsoft.com/default.aspx?scid=kb;en-us;887414</font" target="_blank">http://support.microsoft.com/default.aspx?scid=kb;en-us;887414</font</a>>
  > >
<font color=green>  > > <a style='text-decoration: underline;' href="http://www.microsoft.com/resources/documentation/Windows/XP/all/reskit/en-us/Default.asp?url=/resources/documentation/windows/xp/all/reskit/en-us/prnb_efs_lnfx.asp</font" target="_blank">http://www.microsoft.com/resources/documentation/Windows/XP/all/reskit...-us/Def</a>>
  > >
  > > Kerry
 >
 > He was a domain user but the key was on the system partition and the
 > data is on another drive, the system partition that had the keys was
 > deleted with the install of Win XP. I logged in as the user and the
 > recovery agent displays no recovery agent present, likewise for the
 > local admin and domain admin. I have not taken ownership though.
 > would I need to do that for the recovery agent.

You have to figure out who the DRA is (see my previous links), export their
private certificate and key, then import the certificate and key on the
computer that you are using to decrypt the files. It is common practice to
only use certain secure computers for EFS recovery so that the key cannot be
taken away and data unencrypted off site. If this is the case you would have
to have the files on the recovery computer. You may or may not have to take
ownership first but it wouldn't hurt to do so. EFS can be very tricky. From
what you have described his data is probably gone. You should investigate
the links in my last post and either restrict users from using EFS via group
policy or setup a DRA and store the certificate and key in a safe place. If
you don't this may cause you grief again in the future.

Kerry<!-- ~MESSAGE_AFTER~ -->
 >> Stay informed about: EFS Issue 
Back to top
Login to vote
Display posts from previous:   
Related Topics:
Windows XP update - Jpeg security issue - Hi, I want to protect my PC against this new security issue with Jpeg files. I have XP home, I don't wish to install Service Pack 2 as it changes the operating system significantly. How can I protect my PC against this potential security breach? When...

User account issue - Hi, I have another user with limited account created on my XP pro standalone system. The user was loging on her account fine until she got the following error message: "the security log on this system is full, only an administrator can fix this....

Log On Issue - I hope I have the right forum for this, I recently shut down my computer (XP Pro) I remember seeing an error box indicating something about "hidden windows not responding" The computer shut down, and when I tried to log on a day later, the...

Windows XP SP2 Printing Issue - Hello, We have a Web system running on SQL server. Recently we received several calls from users that installed Windows XP SP2 not able to view/print reports in system from Internet Explorer (where MS-Word does not open with the report showing from..

Automated domain login issue in XP Pro - Many months ago I configured XP Pro for an image-based roll-out in our office. I have recently installed an app. which requires to update itself automatically at random times. I have configd. this s/w in the same way at other XP PCs in our office..
   Windows XP (Home) -> Security Admin All times are: Eastern Time (US & Canada) (change)
Page 1 of 1

 
You can post new topics in this forum
You can reply to topics in this forum
You can edit your posts in this forum
You can delete your posts in this forum
You can vote in polls in this forum

Categories:
  Windows XP
 Win 2000/NT/98/ME
 Windows Vista!


[ Contact us | Terms of Service/Privacy Policy ]