Click here to get back home

Creating CA and self-signed cert for EFS recovery

 HomeNewsGroups | Search | About
 microsoft.public.windows.server.security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content
Subject Author Date
Creating CA and self-signed cert for EFS recovery Bill Hobson 07-19-2007
Get Chitika Premium
Posted by Bill Hobson on July 19, 2007, 10:10 am
Please log in for more thread options
Sigh! When trying to discover a Step-by-Step (even in the so called
Step-by-Step section of Technet) method of setting up a simple (oxymoron?)
configuration of a CA and self-signed certificate for the sole purpose of
being able to recover EFS encrypted files and folders, I struck out.

Can anyone point me to some material on how to set this up? Our environment
is Windows 2003 servers (will make DC a CA for this purpose) and all
machines with EFS will belong to the domain where the CA exists.



Posted by Steve Riley [MSFT] on July 21, 2007, 11:15 pm
Please log in for more thread options
Have these files already been encrypted by EFS? If so, then setting up a CA
after-the-fact won't give you the ability recover those files. They'd have
to be decrypted then re-encrypted after you get the CA set up and all
clients switched over to using the EFS certificates it issues.

Or, if you're looking to deploy EFS the right way before users begin
encrypting anything, allow me to point you to the recently-released Data
Encryption Toolkit for Mobile PCs. The guidance and tool here will make EFS
much easier for you.

http://www.microsoft.com/technet/security/guidance/clientsecurity/dataencryption/default.mspx

Steve Riley
steve.riley@microsoft.com
http://blogs.technet.com/steriley



> Sigh! When trying to discover a Step-by-Step (even in the so called
> Step-by-Step section of Technet) method of setting up a simple (oxymoron?)
> configuration of a CA and self-signed certificate for the sole purpose of
> being able to recover EFS encrypted files and folders, I struck out.
>
> Can anyone point me to some material on how to set this up? Our
> environment is Windows 2003 servers (will make DC a CA for this purpose)
> and all machines with EFS will belong to the domain where the CA exists.
>

Posted by Bill Hobson on July 23, 2007, 10:16 am
Please log in for more thread options
Exactly what I was looking for. I am setting this up before deploying EFS
(read your book, Steve! Protect Your Windows Network).

Thanks for the very enlightening post!

> Have these files already been encrypted by EFS? If so, then setting up a
> CA after-the-fact won't give you the ability recover those files. They'd
> have to be decrypted then re-encrypted after you get the CA set up and all
> clients switched over to using the EFS certificates it issues.
>
> Or, if you're looking to deploy EFS the right way before users begin
> encrypting anything, allow me to point you to the recently-released Data
> Encryption Toolkit for Mobile PCs. The guidance and tool here will make
> EFS much easier for you.
>
>
http://www.microsoft.com/technet/security/guidance/clientsecurity/dataencryption/default.mspx
>
> Steve Riley
> steve.riley@microsoft.com
> http://blogs.technet.com/steriley
>
>
>
>> Sigh! When trying to discover a Step-by-Step (even in the so called
>> Step-by-Step section of Technet) method of setting up a simple
>> (oxymoron?) configuration of a CA and self-signed certificate for the
>> sole purpose of being able to recover EFS encrypted files and folders, I
>> struck out.
>>
>> Can anyone point me to some material on how to set this up? Our
>> environment is Windows 2003 servers (will make DC a CA for this purpose)
>> and all machines with EFS will belong to the domain where the CA exists.
>>



Posted by Steve Riley [MSFT] on July 23, 2007, 9:52 pm
Please log in for more thread options
Cool! And thanks for picking up the book :)

Steve Riley
steve.riley@microsoft.com
http://blogs.technet.com/steriley


> Exactly what I was looking for. I am setting this up before deploying EFS
> (read your book, Steve! Protect Your Windows Network).
>
> Thanks for the very enlightening post!
>
>> Have these files already been encrypted by EFS? If so, then setting up a
>> CA after-the-fact won't give you the ability recover those files. They'd
>> have to be decrypted then re-encrypted after you get the CA set up and
>> all clients switched over to using the EFS certificates it issues.
>>
>> Or, if you're looking to deploy EFS the right way before users begin
>> encrypting anything, allow me to point you to the recently-released Data
>> Encryption Toolkit for Mobile PCs. The guidance and tool here will make
>> EFS much easier for you.
>>
>>
http://www.microsoft.com/technet/security/guidance/clientsecurity/dataencryption/default.mspx
>>
>> Steve Riley
>> steve.riley@microsoft.com
>> http://blogs.technet.com/steriley
>>
>>
>>
>>> Sigh! When trying to discover a Step-by-Step (even in the so called
>>> Step-by-Step section of Technet) method of setting up a simple
>>> (oxymoron?) configuration of a CA and self-signed certificate for the
>>> sole purpose of being able to recover EFS encrypted files and folders, I
>>> struck out.
>>>
>>> Can anyone point me to some material on how to set this up? Our
>>> environment is Windows 2003 servers (will make DC a CA for this purpose)
>>> and all machines with EFS will belong to the domain where the CA exists.
>>>
>
>

Similar ThreadsPosted
2K3 Cert Svcs gives invalid policy error on OpenSSL gen'd cert req June 4, 2007, 1:56 pm
Requesting Code signing cert from cert services November 4, 2005, 12:11 pm
Creating our own certificate February 12, 2006, 10:30 am
Creating Certificate December 16, 2006, 9:16 am
creating shares that are actually writeable July 26, 2005, 11:09 am
Creating domain trusts September 23, 2006, 2:12 am
FTP site on ADC creating problems!!!! June 21, 2008, 11:49 am
Help Needed in Creating Login banner March 1, 2007, 1:03 pm
Is it possible to .PFX file when creating/issuing a certificate July 5, 2007, 12:04 pm
Creating and verifying Domain trust programatically July 5, 2005, 7:09 pm

Our other projects:

Art Dolls, Fairies and Mermaids - Sunnyfaces.net

Roy's Linux, Programming and Search Engines messages

1-Script XML SitemapXML Sitemap