PC Review


Reply
Thread Tools Rate Thread

Access denied to encrypted files after reinstalling XP Pro

 
 
=?Utf-8?B?a2lrbw==?=
Guest
Posts: n/a
 
      10th Sep 2007
Hi,

I need help. I could not access to my D drive (encrypted data) after
reinstalling XP Pro (in C drive). I did not touched D drive at all. I went
thru some of the posts here and tried the various method suggested i.e.
taking ownership, permission - but to no avail. Kept getting "access denied".
Now I'm sitting here helplessly, staring at all my files trying to figure out
how not to lose them. Can someone help me pls?

Thanks,

Kiko.
 
Reply With Quote
 
 
 
 
Malke
Guest
Posts: n/a
 
      10th Sep 2007
kiko wrote:
> Hi,
>
> I need help. I could not access to my D drive (encrypted data) after
> reinstalling XP Pro (in C drive). I did not touched D drive at all. I went
> thru some of the posts here and tried the various method suggested i.e.
> taking ownership, permission - but to no avail. Kept getting "access denied".
> Now I'm sitting here helplessly, staring at all my files trying to figure out
> how not to lose them. Can someone help me pls?


If you really, really encrypted the data using EFS and neglected to back
up your keys, the data is lost. You might contact Elcomsoft to see if
their program can help but I'm not optimistic about it.

http://tinyurl.com/6l6xx - MS information about EFS (Encryption)
http://www.elcomsoft.com/aefsdr.html - Encrypted files retrieval application

http://www3.telus.net/dandemar/encrypt.htm - encryption info
http://www.beginningtoseethelight.org/efsrecovery/ - more encryption info


Malke
--
Elephant Boy Computers
www.elephantboycomputers.com
"Don't Panic!"
MS-MVP Windows - Shell/User
 
Reply With Quote
 
Patrick Keenan
Guest
Posts: n/a
 
      10th Sep 2007
"kiko" <(E-Mail Removed)> wrote in message
news:188D716E-D4DF-48AE-9B6E-(E-Mail Removed)...
> Hi,
>
> I need help. I could not access to my D drive (encrypted data) after
> reinstalling XP Pro (in C drive). I did not touched D drive at all. I went
> thru some of the posts here and tried the various method suggested i.e.
> taking ownership, permission - but to no avail. Kept getting "access
> denied".
> Now I'm sitting here helplessly, staring at all my files trying to figure
> out
> how not to lose them. Can someone help me pls?
>
> Thanks,
>
> Kiko.


The encryption scheme in XP is tied to your account credentials, not to the
data or XP permissions. These credentials are more than the username and
password.

The last step of encryption, unfortunately neglected by many, is backing up
the account credentials.

Following a reinstall, or any of the events that damage or alter the account
credentials (such as changing the password from outside the account), the
credentials are simply re-imported, and then you can take ownership of the
files and decrypt them.

If you did not perform this last step, or cannot find the backup floppies,
or they have failed, there is no happy ending here. The data can be
considered permanently inaccessible.

Microsoft did a really good job at making strong encryption easily
accessible, but didn't do quite as good a job at making clear what the
implications of all the steps are.

-pk


 
Reply With Quote
 
=?Utf-8?B?a2lrbw==?=
Guest
Posts: n/a
 
      10th Sep 2007
I was able to decrypt the folder. Is this a good thing? Also if I have the
key how do I use it?

"Patrick Keenan" wrote:

> "kiko" <(E-Mail Removed)> wrote in message
> news:188D716E-D4DF-48AE-9B6E-(E-Mail Removed)...
> > Hi,
> >
> > I need help. I could not access to my D drive (encrypted data) after
> > reinstalling XP Pro (in C drive). I did not touched D drive at all. I went
> > thru some of the posts here and tried the various method suggested i.e.
> > taking ownership, permission - but to no avail. Kept getting "access
> > denied".
> > Now I'm sitting here helplessly, staring at all my files trying to figure
> > out
> > how not to lose them. Can someone help me pls?
> >
> > Thanks,
> >
> > Kiko.

>
> The encryption scheme in XP is tied to your account credentials, not to the
> data or XP permissions. These credentials are more than the username and
> password.
>
> The last step of encryption, unfortunately neglected by many, is backing up
> the account credentials.
>
> Following a reinstall, or any of the events that damage or alter the account
> credentials (such as changing the password from outside the account), the
> credentials are simply re-imported, and then you can take ownership of the
> files and decrypt them.
>
> If you did not perform this last step, or cannot find the backup floppies,
> or they have failed, there is no happy ending here. The data can be
> considered permanently inaccessible.
>
> Microsoft did a really good job at making strong encryption easily
> accessible, but didn't do quite as good a job at making clear what the
> implications of all the steps are.
>
> -pk
>
>
>

 
Reply With Quote
 
Patrick Keenan
Guest
Posts: n/a
 
      10th Sep 2007
"kiko" <(E-Mail Removed)> wrote in message
news:76A26F7A-FBFC-4717-93FD-(E-Mail Removed)...
>I was able to decrypt the folder.


I'll note that gaining access through taking ownership is not the same as
decryption. You may have set the files to private, which is *not at all*
the same as encrypting them.

> Is this a good thing?


If you needed the data, decrypting it or gaining access is definitely a good
thing. You're done.

Be sure that you do have tested backups of the account credentials if you
are using encryption. You may also wish to make safety copies of backups
without encryption, stored in a very secure location (for example a bank
safety deposit box).

A copy of the exported credentials should also be stored in a secure offsite
location. If they were exported to floppy, you might want to use one of
the floppy imaging programs available and burn that image to CD, to guard
against the degradation of floppies.

> Also if I have the
> key how do I use it?


The key is the exported account credentials, which you have obviously now
imported if you had actually invoked encryption; this means you know how to
use it.

It sounds like you may have set them to private rather than actually
encrypting them with EFS.

Again, setting the files to private *does not encrypt them*. The contents
of the files are available to anyone with a smattering of knowledge and
access to your PC for half an hour.

If you do really need the encryption, and there are indeed circumstances
where it is highly appropriate, be sure that you fully understand how the
encryption utilities work and how you can be sure that you can recover the
files should the system be damaged in any way.

"Best practices for the Encrypting File System"

http://support.microsoft.com/kb/223316/EN-US/



HTH
-pk


>
> "Patrick Keenan" wrote:
>
>> "kiko" <(E-Mail Removed)> wrote in message
>> news:188D716E-D4DF-48AE-9B6E-(E-Mail Removed)...
>> > Hi,
>> >
>> > I need help. I could not access to my D drive (encrypted data) after
>> > reinstalling XP Pro (in C drive). I did not touched D drive at all. I
>> > went
>> > thru some of the posts here and tried the various method suggested i.e.
>> > taking ownership, permission - but to no avail. Kept getting "access
>> > denied".
>> > Now I'm sitting here helplessly, staring at all my files trying to
>> > figure
>> > out
>> > how not to lose them. Can someone help me pls?
>> >
>> > Thanks,
>> >
>> > Kiko.

>>
>> The encryption scheme in XP is tied to your account credentials, not to
>> the
>> data or XP permissions. These credentials are more than the username and
>> password.
>>
>> The last step of encryption, unfortunately neglected by many, is backing
>> up
>> the account credentials.
>>
>> Following a reinstall, or any of the events that damage or alter the
>> account
>> credentials (such as changing the password from outside the account), the
>> credentials are simply re-imported, and then you can take ownership of
>> the
>> files and decrypt them.
>>
>> If you did not perform this last step, or cannot find the backup
>> floppies,
>> or they have failed, there is no happy ending here. The data can be
>> considered permanently inaccessible.
>>
>> Microsoft did a really good job at making strong encryption easily
>> accessible, but didn't do quite as good a job at making clear what the
>> implications of all the steps are.
>>
>> -pk
>>
>>
>>



 
Reply With Quote
 
=?Utf-8?B?a2lrbw==?=
Guest
Posts: n/a
 
      10th Sep 2007
> The key is the exported account credentials, which you have obviously now
> imported if you had actually invoked encryption; this means you know how to
> use it.


I was able to decrypt the folder but not the files in it. :-(
How do I use the key?

Which media is a better back up? USB thumb drive or CD?

If those data are really gone, I guess I will have to reinstall again. They
are taking too much space (50GB). What should I take note of if I want to
encrypt my data?

Thanks again for your help. =)

> Be sure that you do have tested backups of the account credentials if you
> are using encryption. You may also wish to make safety copies of backups
> without encryption, stored in a very secure location (for example a bank
> safety deposit box).
>
> A copy of the exported credentials should also be stored in a secure offsite
> location. If they were exported to floppy, you might want to use one of
> the floppy imaging programs available and burn that image to CD, to guard
> against the degradation of floppies.


> If you do really need the encryption, and there are indeed circumstances
> where it is highly appropriate, be sure that you fully understand how the
> encryption utilities work and how you can be sure that you can recover the
> files should the system be damaged in any way.

 
Reply With Quote
 
Patrick Keenan
Guest
Posts: n/a
 
      10th Sep 2007
"kiko" <(E-Mail Removed)> wrote in message
news:411535A6-8DFD-4205-863E-(E-Mail Removed)...
>> The key is the exported account credentials, which you have obviously
>> now
>> imported if you had actually invoked encryption; this means you know how
>> to
>> use it.

>
> I was able to decrypt the folder but not the files in it. :-(
> How do I use the key?


You have to first have the key - which is the exported credentials (or
"certificates"). You can't get these after a reinstall; they died with the
original account. If you don't have it now, you can't get it back.

To import the certificates, go to start, run, type "certmgr.msc ". Go to
Action, All Tasks, Import.

Then you should be able to access the encrypted files.

> Which media is a better back up? USB thumb drive or CD?


USB drives are known to fail suddenly (I have half a dozen failed ones in my
desk drawer). So, while they are very useful, they are for data transport
and not for storage of critical data.

Use CDs and DVDs for longer-term storage. Make more than one copy and don't
keep them all in the same place.

Many people use a set of five DVDs, marked with days of the week, and swap
them daily for daily backups.

Regularly make an extra copy and store them offsite. This is important to
account for recovery from things like fires.

> If those data are really gone, I guess I will have to reinstall again.


Reinstalling will not change this in any way.


> They
> are taking too much space (50GB). What should I take note of if I want to
> encrypt my data?


You must be sure that you fully understand and take all the steps so that
the data is both protected and recoverable. And *test* the backups on
another system or account to be sure that you can in fact regain access to
the encrypted data before relying on them, and until you are satisfied that
the data is recoverable, keep an unencrypted copy.

Again, to test, use an account or system that can't decrypt the data.
Import the certificates and verify that you can then decrypt the data.

Be sure to store a tested copy of the certificates at another secure site.

HTH
-pk


>
> Thanks again for your help. =)
>
>> Be sure that you do have tested backups of the account credentials if you
>> are using encryption. You may also wish to make safety copies of
>> backups
>> without encryption, stored in a very secure location (for example a bank
>> safety deposit box).
>>
>> A copy of the exported credentials should also be stored in a secure
>> offsite
>> location. If they were exported to floppy, you might want to use one of
>> the floppy imaging programs available and burn that image to CD, to guard
>> against the degradation of floppies.

>
>> If you do really need the encryption, and there are indeed circumstances
>> where it is highly appropriate, be sure that you fully understand how the
>> encryption utilities work and how you can be sure that you can recover
>> the
>> files should the system be damaged in any way.



 
Reply With Quote
 
=?Utf-8?B?a2lrbw==?=
Guest
Posts: n/a
 
      17th Sep 2007
> The last step of encryption, unfortunately neglected by many, is backing up
> the account credentials.
>
> Following a reinstall, or any of the events that damage or alter the account
> credentials (such as changing the password from outside the account), the
> credentials are simply re-imported, and then you can take ownership of the
> files and decrypt them.


May I know how exactly do I do that?
 
Reply With Quote
 
John Wunderlich
Guest
Posts: n/a
 
      17th Sep 2007
=?Utf-8?B?a2lrbw==?= <(E-Mail Removed)> wrote in
news:1ED7A63E-0DCF-4805-A2AE-(E-Mail Removed):

>> The last step of encryption, unfortunately neglected by many, is
>> backing up the account credentials.
>>
>> Following a reinstall, or any of the events that damage or alter
>> the account credentials (such as changing the password from
>> outside the account), the credentials are simply re-imported, and
>> then you can take ownership of the files and decrypt them.

>
> May I know how exactly do I do that?
>


It's documented here, near the bottom:

"Best practices for the Encrypting File System"
<http://support.microsoft.com/kb/223316/en-us>

Importing is just the opposite of exporting.

HTH,
John

 
Reply With Quote
 
=?Utf-8?B?a2lrbw==?=
Guest
Posts: n/a
 
      18th Sep 2007
Thanks a lot, John.
 
Reply With Quote
 
 
 
Reply

Thread Tools
Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Re: EFS Encrypted files coming up as Access Denied Patrick Keenan Windows XP Help 0 12th Oct 2009 01:46 AM
Re: EFS Encrypted files coming up as Access Denied Al Windows XP Help 0 10th Oct 2009 08:08 PM
Re: EFS Encrypted files coming up as Access Denied David H. Lipman Windows XP Help 0 10th Oct 2009 03:19 PM
Denied access to encrypted files on my old HD. Weston Windows Vista Administration 1 23rd Feb 2008 09:08 PM
Access denied when accessing encrypted files =?Utf-8?B?UmFjaGVsIEwgQ2hpcG1hbg==?= Windows XP Security 3 1st Apr 2005 08:31 PM


Features
 

Advertising
 

Newsgroups
 


All times are GMT +1. The time now is 07:25 PM.