Click here to get back home

EFS on shared file server

 HomeNewsGroups | Search | About
 microsoft.public.windows.server.security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content
Subject Author Date
EFS on shared file server Lorenzo Soncini 05-23-2008
Posted by Lorenzo Soncini on May 23, 2008, 3:08 am
Please log in for more thread options
Hi,
I need to use EFS on a shared folder of my file server. For grant access to
many people to the file in folder I have created many EFS Recovery Agent.
All work fine if I use a local file system, but on the file sever only the
user who have encrypted the file can access to it and not the EFS Recovery
agent.

Other question:
Is possible store the User Certificate for EFS on AD so if one user logon on
different computer can always access encrypeted file?

The scenario:
In a company the Human Resource Office (HR) need EFS for the reservation of
sensitive information about employees. But all the employees of the HRO need
to access this information. Is not applicable the solution to manually add
all user on the property of EFS in all encrypted file.

Thanks
Lorenzo Soncini


Posted by S. Pidgorny on May 23, 2008, 6:17 am
Please log in for more thread options
EFS is for protecting local information. In your scenario, the file gets
decrypted on the file server and sent to the client in clear, with no
guarrantee of any protection whatsoever (unless everybody in HR is using
Bitlocker). And because you're creating many recovery agents, the secrecy
deteriorates while you have to manage recovery agents etcetera. Correct me
if I'm incorrect but IT people also will have access to the information or
the backup sets.

I would concentrate on protecting local access to the server console and
maintaining the share ACLs.

Side note: MS guidelines for sharing access to EFS are in the
http://support.microsoft.com/kb/308991 (equally applies to Windows Server
2003)


--
Svyatoslav Pidgorny, MS MVP - Security, MCSE
-= F1 is the key =-

* http://sl.mvps.org * http://msmvps.com/blogs/sp *


> Hi,
> I need to use EFS on a shared folder of my file server. For grant access
> to many people to the file in folder I have created many EFS Recovery
> Agent.
> All work fine if I use a local file system, but on the file sever only the
> user who have encrypted the file can access to it and not the EFS Recovery
> agent.
>
> Other question:
> Is possible store the User Certificate for EFS on AD so if one user logon
> on different computer can always access encrypeted file?
>
> The scenario:
> In a company the Human Resource Office (HR) need EFS for the reservation
> of sensitive information about employees. But all the employees of the HRO
> need to access this information. Is not applicable the solution to
> manually add all user on the property of EFS in all encrypted file.
>
> Thanks
> Lorenzo Soncini



Posted by Lorenzo Soncini on May 23, 2008, 11:39 am
Please log in for more thread options
You tell me all corect thing. I have readed and know the official
solution....but I have many file and do the work manually is an hard work.
I think my is tipacally working scenario.

The only usable solution is use the Recovery Agent.
If someone have other solutions....

Lorenzo Soncini

> EFS is for protecting local information. In your scenario, the file gets
> decrypted on the file server and sent to the client in clear, with no
> guarrantee of any protection whatsoever (unless everybody in HR is using
> Bitlocker). And because you're creating many recovery agents, the secrecy
> deteriorates while you have to manage recovery agents etcetera. Correct me
> if I'm incorrect but IT people also will have access to the information or
> the backup sets.
>
> I would concentrate on protecting local access to the server console and
> maintaining the share ACLs.
>
> Side note: MS guidelines for sharing access to EFS are in the
> http://support.microsoft.com/kb/308991 (equally applies to Windows Server
> 2003)
>
>
> --
> Svyatoslav Pidgorny, MS MVP - Security, MCSE
> -= F1 is the key =-
>
> * http://sl.mvps.org * http://msmvps.com/blogs/sp *
>
>
>> Hi,
>> I need to use EFS on a shared folder of my file server. For grant access
>> to many people to the file in folder I have created many EFS Recovery
>> Agent.
>> All work fine if I use a local file system, but on the file sever only
>> the user who have encrypted the file can access to it and not the EFS
>> Recovery agent.
>>
>> Other question:
>> Is possible store the User Certificate for EFS on AD so if one user logon
>> on different computer can always access encrypeted file?
>>
>> The scenario:
>> In a company the Human Resource Office (HR) need EFS for the reservation
>> of sensitive information about employees. But all the employees of the
>> HRO need to access this information. Is not applicable the solution to
>> manually add all user on the property of EFS in all encrypted file.
>>
>> Thanks
>> Lorenzo Soncini
>
>

Posted by Brian Komar \(MVP\) on May 23, 2008, 1:06 pm
Please log in for more thread options
EFS is not designed for your solution.
It is user based, not group based.
GIving the recovery agent certificate and private key to users is about the
worst/stupidest (seriously, give away the ability to open *any* EFS
encrypted files!!!!) idea I have seen in some time.
Now, with Windows Vista and WIndows Server 2008, the behavior of EFS
changes.
You may be able to use remote EFS in this scenario with Credential Roaming
SErvices.
But you would still have to individually add users and their certificates.
Brian

> You tell me all corect thing. I have readed and know the official
> solution....but I have many file and do the work manually is an hard work.
> I think my is tipacally working scenario.
>
> The only usable solution is use the Recovery Agent.
> If someone have other solutions....
>
> Lorenzo Soncini
>
>> EFS is for protecting local information. In your scenario, the file gets
>> decrypted on the file server and sent to the client in clear, with no
>> guarrantee of any protection whatsoever (unless everybody in HR is using
>> Bitlocker). And because you're creating many recovery agents, the secrecy
>> deteriorates while you have to manage recovery agents etcetera. Correct
>> me if I'm incorrect but IT people also will have access to the
>> information or the backup sets.
>>
>> I would concentrate on protecting local access to the server console and
>> maintaining the share ACLs.
>>
>> Side note: MS guidelines for sharing access to EFS are in the
>> http://support.microsoft.com/kb/308991 (equally applies to Windows Server
>> 2003)
>>
>>
>> --
>> Svyatoslav Pidgorny, MS MVP - Security, MCSE
>> -= F1 is the key =-
>>
>> * http://sl.mvps.org * http://msmvps.com/blogs/sp *
>>
>>
>>> Hi,
>>> I need to use EFS on a shared folder of my file server. For grant access
>>> to many people to the file in folder I have created many EFS Recovery
>>> Agent.
>>> All work fine if I use a local file system, but on the file sever only
>>> the user who have encrypted the file can access to it and not the EFS
>>> Recovery agent.
>>>
>>> Other question:
>>> Is possible store the User Certificate for EFS on AD so if one user
>>> logon on different computer can always access encrypeted file?
>>>
>>> The scenario:
>>> In a company the Human Resource Office (HR) need EFS for the reservation
>>> of sensitive information about employees. But all the employees of the
>>> HRO need to access this information. Is not applicable the solution to
>>> manually add all user on the property of EFS in all encrypted file.
>>>
>>> Thanks
>>> Lorenzo Soncini
>>
>>


Posted by Lorenzo Soncini on May 24, 2008, 4:33 am
Please log in for more thread options
There is some solution (not manually solutions) to share encripted file to
some users?
Thanks
Lorenzo

> EFS is not designed for your solution.
> It is user based, not group based.
> GIving the recovery agent certificate and private key to users is about
> the worst/stupidest (seriously, give away the ability to open *any* EFS
> encrypted files!!!!) idea I have seen in some time.
> Now, with Windows Vista and WIndows Server 2008, the behavior of EFS
> changes.
> You may be able to use remote EFS in this scenario with Credential Roaming
> SErvices.
> But you would still have to individually add users and their certificates.
> Brian
>
>> You tell me all corect thing. I have readed and know the official
>> solution....but I have many file and do the work manually is an hard
>> work.
>> I think my is tipacally working scenario.
>>
>> The only usable solution is use the Recovery Agent.
>> If someone have other solutions....
>>
>> Lorenzo Soncini
>>
>>> EFS is for protecting local information. In your scenario, the file gets
>>> decrypted on the file server and sent to the client in clear, with no
>>> guarrantee of any protection whatsoever (unless everybody in HR is using
>>> Bitlocker). And because you're creating many recovery agents, the
>>> secrecy deteriorates while you have to manage recovery agents etcetera.
>>> Correct me if I'm incorrect but IT people also will have access to the
>>> information or the backup sets.
>>>
>>> I would concentrate on protecting local access to the server console and
>>> maintaining the share ACLs.
>>>
>>> Side note: MS guidelines for sharing access to EFS are in the
>>> http://support.microsoft.com/kb/308991 (equally applies to Windows
>>> Server 2003)
>>>
>>>
>>> --
>>> Svyatoslav Pidgorny, MS MVP - Security, MCSE
>>> -= F1 is the key =-
>>>
>>> * http://sl.mvps.org * http://msmvps.com/blogs/sp *
>>>
>>>
>>>> Hi,
>>>> I need to use EFS on a shared folder of my file server. For grant
>>>> access to many people to the file in folder I have created many EFS
>>>> Recovery Agent.
>>>> All work fine if I use a local file system, but on the file sever only
>>>> the user who have encrypted the file can access to it and not the EFS
>>>> Recovery agent.
>>>>
>>>> Other question:
>>>> Is possible store the User Certificate for EFS on AD so if one user
>>>> logon on different computer can always access encrypeted file?
>>>>
>>>> The scenario:
>>>> In a company the Human Resource Office (HR) need EFS for the
>>>> reservation of sensitive information about employees. But all the
>>>> employees of the HRO need to access this information. Is not applicable
>>>> the solution to manually add all user on the property of EFS in all
>>>> encrypted file.
>>>>
>>>> Thanks
>>>> Lorenzo Soncini
>>>
>>>
>

Similar ThreadsPosted
Shared SSL on my WIn 2003 Server November 2, 2007, 9:23 am
File Access Audit on File Server June 20, 2007, 4:59 pm
File Log on Domain Server November 23, 2005, 12:35 am
File Server Permissions - Best Practices August 10, 2006, 4:56 am
Firewall For File Sharing in Server December 28, 2006, 2:54 am
file server move from win2000 to win2003 April 24, 2008, 9:50 pm
File Access Auditing on Exchange 2003 Server June 28, 2005, 4:01 am
Bizarre File Security Issue in Win2003 server January 12, 2006, 9:50 am
W2K3 Server File Deletion From Windows Service August 11, 2006, 4:20 pm
Moving server 2003 CA database file location November 6, 2006, 3:35 pm

Our other projects:

Art Dolls, Fairies and Mermaids - Sunnyfaces.net

Roy's Linux, Programming and Search Engines messages

1-Script XML SitemapXML Sitemap