XP Certificates & System Restore

  • Thread starter Thread starter West
  • Start date Start date
W

West

Greetings!
I'm really having a problem finding a solution...... (that's almost an
aximoron)
I suppose sending a problem report could be sent. Anyway....there are a
few problems (sometimes more than at othertimes over the past few weeks....)
This began after intalling the Cumulative Security Update XPSP2 (KB8334707)
http://www.microsoft.com/technet/security/bulletin/ms04-038.mspx

Problem: caused corruption of Power User Account - decryption of files,
acknowledgment of privilage settings - limited Administrators rights -
lockout - System Restore was unable to complete the task. MMC Security
Policy snap-in restricts access from Administrator group account

SIDEBAR: it also should be noted several program intallations & upgrades to
VGA drivers were implimented within a 24 hr period of the update which used
up allocated space for sytem restore.There was mention in an article about
allowing 24hrs for the changes to propogate and take effect. .


Attempted fixes:
At this point I don't know enough about this archectecture to say I'm not
causing more harm than good; and finding myself right back where I started
from.lol

ATI Multimedia could not uninstall "access denied" NT AUTHORITY shut down my
system.????
Created Security Policy from default templet in MMC
Manually set permissions for users on %sysroot%/drivers/etc,
Desktop, mailstore, current user/Temp files "access denied" and several
programs.
Installed and Imported .pks .cer (could not migrate in MMC to Computer
(local) or selected user -"access is denied" resides in current user)
Also had to create a new pagefile on a different drive to meet system min.
requirements for ATI upgrade version 9.1
Mozilla browsers needed to be reinstalled - can only use default profiles.
BTW posting Reply to Sender in NNTP in OE6 causes the default browser to
load home page?


Cannot remove Internet Explorer and Outlook Express from add remove programs
Cannot create a Recovery Agent,or issue session certificates in IIS
The system also lost my passwords for each account and I was only able to
recover from Administrator Domain Controlers start up
..bak file was deleted by system restore

Questions:
How do I preserve a restore set which sytem restore won't overwrite?
Does a pagefile have to exist on the same drive as the OS?
How do I regain permission to use MY Cert to decrypt encryped files?
(the thumbprint matches although it is RSA 1024 bits and read this could be
a problem - not the standard 128bits)

References:
http://support.microsoft.com/default.aspx?scid=kb;en-us;318027
http://securityadmin.info
http://www.microsoft.com/technet/community/columns/5min/default.mspx
http://support.microsoft.com/default.aspx?scid=kb;en-us;243026
http://www.microsoft.com/technet/prodtechnol/winxppro/maintain/default.mspx
and in Help and Support using and managing certificates
also installed Support Tools -which are now gone after the last system
restore.

Any suggestions other than reformatting C ?
I still would like to one day decrypt the data ( backed up private key and
Information Exchange key) What steps do I take to get access?
Steps I have taken re:
http://www.microsoft.com/technet/prodtechnol/winxppro/maintain/certenrl.mspx
http://www.microsoft.com/technet/prodtechnol/winxppro/maintain/certenrl.mspx#ECAA

Thanks in advance

West
 
Found the solution!!!
& picked up a couple of great resources along the way
Thanks goes out ot the MVP's who support this newsgroup ( Iwouldn't have
found it without your advice!)
I guess it's a good thing when someone finds his own way... too much
information!!!

Resources to help with security related issues:
Of coarse..... http://aumha.org/
http://support.microsoft.com/newsgroups/default.aspx
http://support.microsoft.com/?kbid=228930
http://www.microsoft.com/technet/community/columns/5min/default.mspx
http://securityadmin.info/faq.asp#contents
http://www.microsoft.com/windows/reskits/default.asp
http://www.microsoft.com/technet/security/tools/mbsaqa.mspx
http://www.microsoft.com/technet/security/tools/stkintro.mspx
http://msdn.microsoft.com/library/default.asp?url=/library/en-us/dnanchor/html/psdktoolsanchor.asp
http://www.microsoft.com/technet/scriptcenter/default.mspx

West
http://trak.to/more

PS. The last thing I wanted to face was lossing all those hours customizing
my PC and the encryped files.
Believe it or not the solution was simily to change the account type to the
administrators group - re-enable the active directory - load the default
templet for the Security Policy snap-in for MMC scan the system with
Microsoft's Baseline Security Configuration Analyzer - follow the directions
on how to correct the errors -and finally uncheck the read only atributes to
the selected encrypted files.
 
Back
Top