Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations strongm on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

EFS Problem 2

Status
Not open for further replies.

joearmitage

IS-IT--Management
Aug 2, 2001
33
GB
Hi,
This is a classic. I encrypted one of my folders using properties-advanced-encrypt, and promptly forgot about it. Later (problem not related) I needed to re-install w2k on the other partition because I just couldn't access the pc. When I then tried to open files in my encrypted folder I couldn't, and the system wouldn't allow me to untick the encrypted box. Is there any way I can get access back to the encrypted files?
Thanks in advance.

Joe
 
Basically, no. When files are encrypted under NTFS EFS, only the user who encrypted the file, and an authorised Data Recovery Agent (usually the Administrator) are able to recover the file.

If you have wiped those users from the system (as you would have to in a fresh install) your ability to recover the encrypted file depends on your having backed up the Encryption Certificates before wiping them... I suspect that you havnt done this.

The only chance you might have is if the machine was part of a Win2000 Domain - the Data Recovery Agent in that case may still exist on the network.

Otherwise, the encryption will be 'statistically infeasible' (read: impossible) to break. Sorry to give you the bad news.

The moral of the story, I guess, is if you use EFS, back up the encryption keys to a floppy and put it somewhere VERY safe.

Hope this helps

Terry-Lee Blay
MCP, A+, Net+, Server+, APS, IBM Thinkpads/Portables
webwarrior@angelfire.com
 
Thanks Tels - it is bad news but I've learned a big lesson from it

Joe
 
That link above gives all the details on how to back up EFS recovery keys, etc, so if you have a look at that I'm sure you'll feel a whole lot more confident about using EFS in the future.

Sorry I couldn't help more.

Best Regards

Terry-Lee Blay
MCP, A+, Net+, Server+, APS, IBM Thinkpads/Portables
webwarrior@angelfire.com
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top