Click here to get back home

About EFS and local certificate that I want to export

 HomeNewsGroups | Search | About
 microsoft.public.windows.server.security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content
Subject Author Date
About EFS and local certificate that I want to export Pascal 05-04-2007
Posted by Pascal on May 4, 2007, 9:17 am
Please log in for more thread options
Hello,

I have test something but I am not sure that I am right !

I have two computers XP_A and XP_B member of an active directory domain
with no certificate authority.
There are two users : Pascal and Isabelle.

1. Pascal logs on XP_A and encrypt a file with EFS.
2. Pascal exports his certificate through Internet explorer (with or
without the private key, the issue will be the same)
3. Now, on XP_B, an admin install the Pascal certificate on the
computer (in the "Trusted People" store).
4. Isabelle logs on XP_B and encrypts a file with EFS, then she adds
the Pascal certificate to authorize him to access this encrypted file.
5. Pascal is connected to XP_A and opens the encrypted files for which
his certificate is attached on XP_B,but he still has an access denied.

Question : Why Pascal is not able to access this file from the network
? (From XP_A to XP_B)

More generally, if I export an EFS user certificate from one computer
to another, can I access the encrypted file through the network.

With a certificate authority, I think there will be no problem but I
would like to understand why like this it is not working.

Thank you

--
Pascal



Posted by Brian Komar on May 4, 2007, 3:09 pm
Please log in for more thread options
You need to get your head around how EFS works.
EFS is local file encryption (always). When you connect to a server using
SMB connections, the file is transferred to/from the server in the clear.
The encryption/decryption takes place at the server.

In your case, you added the incorrect EFS certificate in step 4. You would
need to add the EFS certificate that Pascal would use *on* computer XP_B.

When Pascal connects over the network to XP_B, the computer account for
XP_B impersonates Pascal, and generates a new EFS certificate for Pascal.

Even with a certificate authority, you would run into the same issue.
I recommend that you investigate Certificate Roaming Service on
microsoft.com

Brian


On Fri, 04 May 2007 15:17:59 +0200, Pascal wrote:

> Hello,
>
> I have test something but I am not sure that I am right !
>
> I have two computers XP_A and XP_B member of an active directory domain
> with no certificate authority.
> There are two users : Pascal and Isabelle.
>
> 1. Pascal logs on XP_A and encrypt a file with EFS.
> 2. Pascal exports his certificate through Internet explorer (with or
> without the private key, the issue will be the same)
> 3. Now, on XP_B, an admin install the Pascal certificate on the
> computer (in the "Trusted People" store).
> 4. Isabelle logs on XP_B and encrypts a file with EFS, then she adds
> the Pascal certificate to authorize him to access this encrypted file.
> 5. Pascal is connected to XP_A and opens the encrypted files for which
> his certificate is attached on XP_B,but he still has an access denied.
>
> Question : Why Pascal is not able to access this file from the network
> ? (From XP_A to XP_B)
>
> More generally, if I export an EFS user certificate from one computer
> to another, can I access the encrypted file through the network.
>
> With a certificate authority, I think there will be no problem but I
> would like to understand why like this it is not working.
>
> Thank you

Posted by Pascal on May 5, 2007, 8:18 am
Please log in for more thread options
> You need to get your head around how EFS works.
> EFS is local file encryption (always). When you connect to a server using
> SMB connections, the file is transferred to/from the server in the clear.
> The encryption/decryption takes place at the server.
>
> In your case, you added the incorrect EFS certificate in step 4. You would
> need to add the EFS certificate that Pascal would use *on* computer XP_B.
>
> When Pascal connects over the network to XP_B, the computer account for
> XP_B impersonates Pascal, and generates a new EFS certificate for Pascal.
>
> Even with a certificate authority, you would run into the same issue.
> I recommend that you investigate Certificate Roaming Service on
> microsoft.com
>
> Brian


Thank you for the information.
I am not sure to understand what you want to say by "You would
need to add the EFS certificate that Pascal would use *on* computer
XP_B."

If I have well understood I should have to enable the "trust computer
for delegation" if I want to be able to access to an encrypted file
over the network ?

--
Pascal



Similar ThreadsPosted
Certificate FQDN example.local domain using example.com certificate October 31, 2006, 7:40 am
export/import .pfx , .cer and "Friendly Name" July 25, 2005, 12:26 pm
Can I export Distribution Lists? February 13, 2006, 8:15 pm
Export IPSec Policies to XML April 25, 2006, 7:03 am
Export Current Settings to Template? March 3, 2007, 11:58 am
Utility to export file, folder, and share permissions July 10, 2006, 7:24 pm
Export IPSec to Plain Text/XML - Readable Format August 10, 2007, 6:54 pm
Automatic certificate enrollment for local system failed August 3, 2006, 10:22 am
Automatic certificate enrollment for local system failed after upgrading member server to domain controller August 25, 2005, 6:11 pm
Is local system account member of local Administrators group? June 21, 2005, 11:33 am

Our other projects:

Art Dolls, Fairies and Mermaids - Sunnyfaces.net

Roy's Linux, Programming and Search Engines messages

1-Script XML SitemapXML Sitemap