Click here to get back home

Smartcard / NTFS Encryption

 HomeNewsGroups | Search | About
 microsoft.public.windows.server.security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content
Subject Author Date
Smartcard / NTFS Encryption Michael Meiners 05-13-2007
Posted by Michael Meiners on May 13, 2007, 7:37 pm
Please log in for more thread options
Hi,

I am trying to store the certificates for NTFS Encryption on the smartcards
of my user. It took me quite long to find a CSP which is capable of doing
so. So far it is working now but now I have some questions regarding NTFS
encryption.

Im am still experimenting around. First I create an encrypted folder, then I
export the encryption certificate and import it into the smartcard and
delete the certificate from the windows store. If I now log off and on I can
only access the encrypted folder if the smartcard is inserted into the
reader. The problem here is that as soon I create a new encrypted folder
windows does not use the existing encryption certificate but generates a new
one. So I would require to have for every encrypted folder a seperate smart
card. Any thoughts how I can optimize this?

As I mentioned above I currently move the windows generated encryption
certificate from the windows store to the card. It would be much more
elegant if I could generate my own certificates and windows uses them for
encryption. I know that the certificate requires the "File System
Encryption" Attribute. In fact some of the certificates I generated do work
fine and other are just ignored by windows. Is there somewhere a document
about the requirements of an encryption certificate available?

Kind Regards
Your M&M


Posted by Brian Komar on May 13, 2007, 11:30 pm
Please log in for more thread options
On Mon, 14 May 2007 01:37:06 +0200, Michael Meiners wrote:

> Hi,
>
> I am trying to store the certificates for NTFS Encryption on the smartcards
> of my user. It took me quite long to find a CSP which is capable of doing
> so. So far it is working now but now I have some questions regarding NTFS
> encryption.
>
> Im am still experimenting around. First I create an encrypted folder, then I
> export the encryption certificate and import it into the smartcard and
> delete the certificate from the windows store. If I now log off and on I can
> only access the encrypted folder if the smartcard is inserted into the
> reader. The problem here is that as soon I create a new encrypted folder
> windows does not use the existing encryption certificate but generates a new
> one. So I would require to have for every encrypted folder a seperate smart
> card. Any thoughts how I can optimize this?
>
> As I mentioned above I currently move the windows generated encryption
> certificate from the windows store to the card. It would be much more
> elegant if I could generate my own certificates and windows uses them for
> encryption. I know that the certificate requires the "File System
> Encryption" Attribute. In fact some of the certificates I generated do work
> fine and other are just ignored by windows. Is there somewhere a document
> about the requirements of an encryption certificate available?
>
> Kind Regards
> Your M&M

Are you using Windows Vista?
Smart card-based EFS certificates is only supported in Vista
Brian

Posted by Michael Meiners on May 14, 2007, 4:13 am
Please log in for more thread options
> Are you using Windows Vista?
> Smart card-based EFS certificates is only supported in Vista
> Brian

Hi Brian,

no, thats not true. It fully depends on the CSP. It took me month to find a
CSP which supports EFS. In fact I tested it with XP and W2k3 (dont have
Vista available yet).

But never mind and thanks a lot - I solved the issues asked in my previous
postings.


Similar ThreadsPosted
Multiple Certs on Smartcard and Windows Smartcard Logon July 8, 2005, 8:01 am
Cannot Logon using Smartcard October 28, 2005, 11:55 pm
Smartcard logon with third-party CA without MS CA May 13, 2006, 2:01 am
Smartcard logon and certification authority December 2, 2005, 4:29 am
Smartcard for multi-factor authentication March 2, 2006, 10:01 am
IAS + user smartcard + workstation certificate July 6, 2007, 9:48 am
AD GetObject fails in ASP page when using smartcard logon June 14, 2005, 6:07 pm
userCertificate in user's entry for smartcard logon February 25, 2007, 1:47 pm
[Q] Kerberos DES encryption April 20, 2007, 6:11 am
Encryption information request September 20, 2006, 3:52 pm

Our other projects:

Art Dolls, Fairies and Mermaids - Sunnyfaces.net

Roy's Linux, Programming and Search Engines messages

1-Script XML SitemapXML Sitemap