EFS AND RECOVERY AGENTS
WinXPTalk.com Forum Index WinXPTalk.com
Forums for Windows XP users.
 
 FAQFAQ   MemberlistMemberlist     RegisterRegister 
 ProfileProfile   Log in to check your private messagesLog in to check your private messages   Log inLog in 
 
Google
 
Web winxptalk.com
EFS AND RECOVERY AGENTS

 
Post new topic   Reply to topic    WinXPTalk.com Forum Index -> Security
Author Message
Chris
Guest





Posted: Tue Dec 21, 2004 10:05 pm    Post subject: EFS AND RECOVERY AGENTS Reply with quote

Hi All,

I am reading the book "Windows XP Inside Out" by MS Press. I am at the
chapter that talks about using EFS in a workgroup setting. It states that
when creating the data recovery certificate using "cipher /r:filename", it
warns that the resulting .pfx and .cer files should be removed and stored
externally because these files allow anyone to become a recovery agent.

The next stage of the process is to import the .pfx file to the users
certificate store using certificate manager, then import the .cer file into
Local Security Settings (secpol.msc). That user is now a data recovery
agent. The way I understand it, is that these same files are used to
designate any further recovery agents in exactly the same way.

My query is when using EFS in XP Pro in a workgroup, and you want to
designate more than one user to become a recovery agent, are their recovery
agent certificates the same?

Any help with this query would be appreciated.

Cheers - Chris
Back to top
Dusko Savatovic
Guest





Posted: Tue Dec 21, 2004 10:33 pm    Post subject: Re: EFS AND RECOVERY AGENTS Reply with quote

I'll try to give you a simple explanations, so I apologize if it's too
simple.

It goes like this:

1. Ana encrypts file and wants that Bob and Cathy can recover her file. Ana
encrypts file with FEK (File encryption key).

2. Ana makes two additional copies of FEK.
Imagine that these keys are real metal keys.

3. Ana drops these keys in Bob's and Cathy's mailbox.
Imagine it is real metal mailbox.

4. Bob opens his mailbox with his own key. Bob retreives FEK and reads Ana's
file.

5. Cathy opens her mailbox with her own key. Cathy retreives FEK and reads
Ana's file.

That's all

Dusko Savatovic
Back to top
 
Post new topic   Reply to topic    WinXPTalk.com Forum Index -> Security All times are GMT
Page 1 of 1

 
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum


Office Forums Access Forums Windows Server Exchange Server Help
New Topics Powered by phpBB