PC Review


Reply
Thread Tools Rate Thread

can't recover encrypted data

 
 
bk
Guest
Posts: n/a
 
      7th Jan 2004
Can't access encrypted data after restoring lost
certificates. This is a real disaster--there must be
something simple that I've overlooked. Followed every
instruction set I could find with same results. Any
suggestions?
 
Reply With Quote
 
 
 
 
Drew Cooper [MSFT]
Guest
Posts: n/a
 
      7th Jan 2004
Do you have a more detailed version of the story for us? What kind of
encryption - EFS? Why did you need to import certificates? What happened
to the old ones? Were they just the certificates (.cer files) or did they
also have private keys (.pfx files)?
--
Drew Cooper [MSFT]
This posting is provided "AS IS" with no warranties, and confers no rights.


"bk" <(E-Mail Removed)> wrote in message
news:00cd01c3d4de$169a6030$(E-Mail Removed)...
> Can't access encrypted data after restoring lost
> certificates. This is a real disaster--there must be
> something simple that I've overlooked. Followed every
> instruction set I could find with same results. Any
> suggestions?



 
Reply With Quote
 
=?Utf-8?B?Yms=?=
Guest
Posts: n/a
 
      8th Jan 2004
I forgot to decrypt before reinstalling XP. I've read and re-read all info I can find on EFS and it appears to me that with a personal certificate, .pfx containing both public and private keys, I should be able to read old data even though the SID with which the data were encrypted no longer exists. Else, how would one be able to USE data on another computer as suggested in XP Inside Out, pp. 496? Perhaps I misinterpret the passages--if they mean access data on the original platform with the original account (SID) then I'm buggered. I thought that if I backed up my certificates I would be able to recover from a mistake like this. I imported the old certificate into my personal store as directed and then every other store just to cover all bases.

Is my old premise right or wrong? Can you recover old data with only a (.pfx) certificate--all old account info gone?
 
Reply With Quote
 
Drew Cooper [MSFT]
Guest
Posts: n/a
 
      8th Jan 2004
Correct . EFS is orthogonal to ACLs. With the .pfx of the user's EFS cert
and key (EFS side of the story) and the ability to "take ownership" (ACL
side of the story), you would be able to decrypt the files.
--
Drew Cooper [MSFT]
This posting is provided "AS IS" with no warranties, and confers no rights.


"bk" <(E-Mail Removed)> wrote in message
news:4FC8B634-50F7-41F1-A499-(E-Mail Removed)...
> I forgot to decrypt before reinstalling XP. I've read and re-read all

info I can find on EFS and it appears to me that with a personal
certificate, .pfx containing both public and private keys, I should be able
to read old data even though the SID with which the data were encrypted no
longer exists. Else, how would one be able to USE data on another computer
as suggested in XP Inside Out, pp. 496? Perhaps I misinterpret the
passages--if they mean access data on the original platform with the
original account (SID) then I'm buggered. I thought that if I backed up my
certificates I would be able to recover from a mistake like this. I
imported the old certificate into my personal store as directed and then
every other store just to cover all bases.
>
> Is my old premise right or wrong? Can you recover old data with only a

(.pfx) certificate--all old account info gone?


 
Reply With Quote
 
bk
Guest
Posts: n/a
 
      9th Jan 2004
Appreciate your insights.

>-----Original Message-----
>Correct . EFS is orthogonal to ACLs. With the .pfx of

the user's EFS cert
>and key (EFS side of the story) and the ability to "take

ownership" (ACL
>side of the story), you would be able to decrypt the

files.
>--
>Drew Cooper [MSFT]
>This posting is provided "AS IS" with no warranties, and

confers no rights.
>
>
>"bk" <(E-Mail Removed)> wrote in

message
>news:4FC8B634-50F7-41F1-A499-(E-Mail Removed)...
>> I forgot to decrypt before reinstalling XP. I've read

and re-read all
>info I can find on EFS and it appears to me that with a

personal
>certificate, .pfx containing both public and private

keys, I should be able
>to read old data even though the SID with which the data

were encrypted no
>longer exists. Else, how would one be able to USE data

on another computer
>as suggested in XP Inside Out, pp. 496? Perhaps I

misinterpret the
>passages--if they mean access data on the original

platform with the
>original account (SID) then I'm buggered. I thought that

if I backed up my
>certificates I would be able to recover from a mistake

like this. I
>imported the old certificate into my personal store as

directed and then
>every other store just to cover all bases.
>>
>> Is my old premise right or wrong? Can you recover old

data with only a
>(.pfx) certificate--all old account info gone?
>
>
>.
>

 
Reply With Quote
 
 
 
Reply

Thread Tools
Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Recover Encrypted Data puru Microsoft Windows 2000 Advanced Server 1 2nd Nov 2008 08:08 PM
How to recover from encrypted data Gillies Windows XP General 1 23rd Nov 2005 03:22 PM
can't recover encrypted data bk Windows XP General 0 7th Jan 2004 05:43 AM
Recover encrypted data Hooman Windows XP General 2 10th Nov 2003 03:34 PM
Recover encrypted data Hooman Windows XP Accessibility 1 9th Nov 2003 05:38 PM


Features
 

Advertising
 

Newsgroups
 


All times are GMT +1. The time now is 11:48 AM.