EFS DRA and the like!

Discussion in 'MCDST' started by dales, Sep 16, 2006.

  1. dales

    dales Terabyte Poster

    2,005
    51
    142
    Hi all,

    quick question for you about the pfx file and requirements for EFS recovery.

    Say for example 2 computers in workgroup computer 1 has a DRA and EFS set up correctly, certificates backed up to whatever removeable media you feel like. user on computer 1 trashes their certificate, by having their password renamed by the administrator.

    The recovery will take place on computer 2, which imports a copy of the encrypted data. My question is when you go to add the certificates safetly stored on your removable media to computer 2 do you need to add the public key to the local security policy as well as importing the PFX file (which as I understand it has both pulic and private keys in anyway), or can you just install the pfx file and access the data.

    cant really find the info I needed in any of the books i've got here, went into town especially to pick up some mcdst books today but the massive book shop in my local town didnt have any!!!!! Oh well at least I can get one from amazon!:biggrin
     
    Certifications: vExpert 2014+2015+2016,VCP-DT,CCE-V, CCE-AD, CCP-AD, CCEE, CCAA XenApp, CCA Netscaler, XenApp 6.5, XenDesktop 5 & Xenserver 6,VCP3+5,VTSP,MCSA MCDST MCP A+ ITIL F
    WIP: Nothing
  2. dales

    dales Terabyte Poster

    2,005
    51
    142
    actually thinking about it, is the purpose to the certificate in the local security policy only to add that key to any encrypted file that is created on that machine, thus creating the dra get out clause????
     
    Certifications: vExpert 2014+2015+2016,VCP-DT,CCE-V, CCE-AD, CCP-AD, CCEE, CCAA XenApp, CCA Netscaler, XenApp 6.5, XenDesktop 5 & Xenserver 6,VCP3+5,VTSP,MCSA MCDST MCP A+ ITIL F
    WIP: Nothing
  3. Bluerinse
    Honorary Member

    Bluerinse Exabyte Poster

    8,878
    181
    256
    Dales I am not sure as EFS is slightly different in XP and I studied Windows 2000.

    Why don't you test it out? Hands on practice will always reap more rewards than just reading - then come back and tell us the answer :)
     
    Certifications: C&G Electronics - MCSA (W2K) MCSE (W2K)
  4. dales

    dales Terabyte Poster

    2,005
    51
    142
    been playing with it for a while, took me a while to figure it out, but in retrospect it was my stupidity that stopped me seeing the bigger picture.

    Anyway what I've figured out so far I think, is that you create the DRA first and add the .Cer file into the security policy, that in turn writes the certificate number to any files/folders you encrypt from that point on.

    Went to do my 271 in wokingham on monday, i'd been i'll all that weekend and still wasnt feeling great so travelled all the way there only to be told that their site had failed and they were'nt running any exams that day, The receptionist cheerily went onto say that she had 10 other people comming in and they we not going to be able to do it either. (dont know why they didnt phone us in the morning to say, cause my closest test centre is 15 miles through hellish traffic blackspots):twisted:

    And I was all psyched up for it and everything!
     
    Certifications: vExpert 2014+2015+2016,VCP-DT,CCE-V, CCE-AD, CCP-AD, CCEE, CCAA XenApp, CCA Netscaler, XenApp 6.5, XenDesktop 5 & Xenserver 6,VCP3+5,VTSP,MCSA MCDST MCP A+ ITIL F
    WIP: Nothing

Share This Page

Loading...
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.