Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations Westi on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

A different kind of EFS problem

Status
Not open for further replies.

mattkizerian

Technical User
Apr 10, 2002
4
US
I'm having problems getting access to my EFS encrypted files. This, however, is different than most of the threads I've seen. Here's the scoop:

Apple iTunes tosted my Win2000 box. I tried repairing, etc. witht the CD to no avail. I then read something suggesting to do a repair install so as to keep my file system intact.

So, I got my system back, BUT none of my files (encrypted in My Documents) will decrypt. All of my user profiles are just as I left them; I didn't have to set up any new users or anything, so I assume my Admin SID didn't change during the reinstall.

To make things even more weird, I used CIPHER in the My Docs directory and several (but not all) of the directories decrypted. When I tried it with files, only "older" files would decrypt. It seems that I can decrypt files and directories that were saved up to 2-3 months after I got my system. After that, nada.

This is the first time I've had any problems with Win2k. I've never had to reinstall/restore/repair and I've used the Admin account for most of my stuff (that's not very smart, I know...)

I did notice that there are two Admin certificates for File Recovery in the Current User Personal Store, and one for Encrypt File System. They all have different dates, but are within a week of one another and date back to when I originally got my system. One of these File Recovery certs is also found in the Encrypted Data Recovery Certificates under Public Key Policies in Local Security Settings.

Does anyone have any clues? This is mainly my wife's computer and, needless to say with 2.5 years worth of data "tosted" I'm in the dog house BIG time on this one.
 
To answer my own post, it turned out to be a service pack issue. Installing SP-2 (128-bit encryption) fixed the problem. That's apparently why there were 2 keys (a 52-bit and a 128-bit) and why only the older files would decrypt.
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top