can't recover encrypted data

Posted: 01-07-2004, 05:21 AM
Can't access encrypted data after restoring lost
certificates. This is a real disaster--there must be
something simple that I've overlooked. Followed every
instruction set I could find with same results. Any
suggestions?
Reply With Quote

Responses to "can't recover encrypted data"

Drew Cooper [MSFT]
Guest
Posts: n/a
 
Re: can't recover encrypted data
Posted: 01-07-2004, 11:50 PM
Do you have a more detailed version of the story for us? What kind of
encryption - EFS? Why did you need to import certificates? What happened
to the old ones? Were they just the certificates (.cer files) or did they
also have private keys (.pfx files)?
--
Drew Cooper [MSFT]
This posting is provided "AS IS" with no warranties, and confers no rights.


"bk" <anonymous@discussions.microsoft.com> wrote in message
news:00cd01c3d4de$169a6030$a001280a@phx.gbl...
> Can't access encrypted data after restoring lost
> certificates. This is a real disaster--there must be
> something simple that I've overlooked. Followed every
> instruction set I could find with same results. Any
> suggestions?

Reply With Quote
bk
Guest
Posts: n/a
 
Re: can't recover encrypted data
Posted: 01-08-2004, 09:21 PM
I forgot to decrypt before reinstalling XP. I've read and re-read all info I can find on EFS and it appears to me that with a personal certificate, .pfx containing both public and private keys, I should be able to read old data even though the SID with which the data were encrypted no longer exists. Else, how would one be able to USE data on another computer as suggested in XP Inside Out, pp. 496? Perhaps I misinterpret the passages--if they mean access data on the original platform with the original account (SID) then I'm buggered. I thought that if I backed up my certificates I would be able to recover from a mistake like this. I imported the old certificate into my personal store as directed and then every other store just to cover all bases.

Is my old premise right or wrong? Can you recover old data with only a (.pfx) certificate--all old account info gone?
Reply With Quote
Drew Cooper [MSFT]
Guest
Posts: n/a
 
Re: can't recover encrypted data
Posted: 01-08-2004, 11:59 PM
Correct . EFS is orthogonal to ACLs. With the .pfx of the user's EFS cert
and key (EFS side of the story) and the ability to "take ownership" (ACL
side of the story), you would be able to decrypt the files.
--
Drew Cooper [MSFT]
This posting is provided "AS IS" with no warranties, and confers no rights.


"bk" <anonymous@discussions.microsoft.com> wrote in message
news:4FC8B634-50F7-41F1-A499-DC190A41B4E6@microsoft.com...
> I forgot to decrypt before reinstalling XP. I've read and re-read all
info I can find on EFS and it appears to me that with a personal
certificate, .pfx containing both public and private keys, I should be able
to read old data even though the SID with which the data were encrypted no
longer exists. Else, how would one be able to USE data on another computer
as suggested in XP Inside Out, pp. 496? Perhaps I misinterpret the
passages--if they mean access data on the original platform with the
original account (SID) then I'm buggered. I thought that if I backed up my
certificates I would be able to recover from a mistake like this. I
imported the old certificate into my personal store as directed and then
every other store just to cover all bases.
>
> Is my old premise right or wrong? Can you recover old data with only a
(.pfx) certificate--all old account info gone?


Reply With Quote
bk
Guest
Posts: n/a
 
Re: can't recover encrypted data
Posted: 01-09-2004, 04:44 PM
Appreciate your insights.
>-----Original Message-----
>Correct . EFS is orthogonal to ACLs. With the .pfx of
the user's EFS cert
>and key (EFS side of the story) and the ability to "take
ownership" (ACL
>side of the story), you would be able to decrypt the
files.
>--
>Drew Cooper [MSFT]
>This posting is provided "AS IS" with no warranties, and
confers no rights.
>
>
>"bk" <anonymous@discussions.microsoft.com> wrote in
message
>news:4FC8B634-50F7-41F1-A499-DC190A41B4E6@microsoft.com...
>> I forgot to decrypt before reinstalling XP. I've read
and re-read all
>info I can find on EFS and it appears to me that with a
personal
>certificate, .pfx containing both public and private
keys, I should be able
>to read old data even though the SID with which the data
were encrypted no
>longer exists. Else, how would one be able to USE data
on another computer
>as suggested in XP Inside Out, pp. 496? Perhaps I
misinterpret the
>passages--if they mean access data on the original
platform with the
>original account (SID) then I'm buggered. I thought that
if I backed up my
>certificates I would be able to recover from a mistake
like this. I
>imported the old certificate into my personal store as
directed and then
>every other store just to cover all bases.
>>
>> Is my old premise right or wrong? Can you recover old
data with only a
>(.pfx) certificate--all old account info gone?
>
>
>.
>
Reply With Quote
 
LinkBack Thread Tools Display Modes
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On
Forum Jump


Similar Threads
Thread Thread Starter Forum Replies Last Post
Need to recover encrypted data poxrox Windows NT/2000/XP 0 05-26-2008 03:50 AM
HDD crash, can't log in but need to recover encrypted files Windows XP Performance & Maintenance 1 11-24-2003 07:20 AM
HDD crash, can't log in but need to recover encrypted files Windows XP Hardware 1 11-24-2003 04:56 AM
Recover encrypted data Hooman Windows XP Accessibility 1 11-09-2003 05:38 PM
recover encrypted files Kare Windows XP Accessibility 3 10-26-2003 07:30 PM