Decryption not working...have certificate

S

Scott

Hi,

I have a couple XP SP1 laptops that are used for travel. I
encrypted the entire user's profile so anything they saved
to their My Documents folder or Desktop would
automatically become encrypted. After they returned from
their trip and logged back onto our network their desktop
links and all documents that were encrypted will not
decrypt or open. I cannot change the encryption attribute
even though the original EFS certificate still exists.
While on travel the users were logging on with cached
network credentials. Any ideas?
Thanks.
 
R

Roger Abell

Scott said:
Hi,

I have a couple XP SP1 laptops that are used for travel. I
encrypted the entire user's profile so anything they saved
to their My Documents folder or Desktop would
automatically become encrypted. After they returned from
their trip and logged back onto our network their desktop
links and all documents that were encrypted will not
decrypt or open. I cannot change the encryption attribute
even though the original EFS certificate still exists.
While on travel the users were logging on with cached
network credentials. Any ideas?
Thanks.

Was their password changed ?
You should be able to import the cert/key into a
new account and have access to the files. Does
this actually work ?
 
G

Guest

-----Original Message-----


Was their password changed ?
You should be able to import the cert/key into a
new account and have access to the files. Does
this actually work ?

--
Roger Abell
Microsoft MVP (Windows Server System: Security)
MCSE (W2k3,W2k,Nt4) MCDBA


.
Passwords were not changed. I am able to decrypt other
user files and even folders of the users in question. But
nothing with the files.
 
R

Roger Abell [MVP]

Scott,

As they can access some but not all of their EFS files,
you should examine the thumbprints on the files using
the efsinfo.exe tool that installs as part of the support tools.
You may find that the accounts encrypted files for the first
time on the machine when it was disconnected from the
network, and so the on-demand EFS certificate that was
created was stored into the cached profile.
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top