How to Copy EFS(encrypted) Files....

How to Copy EFS(encrypted) Files....

Secure Home | Search | About
 Microsoft Applications Security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
How to Copy EFS(encrypted) Files.... kea 12-05-2005
Posted by =?Utf-8?B?a2Vh?= on December 5, 2005, 1:45 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
Hi All,
In my environment EFS has just been rolled out. I do not have the back
office specifics, but need to be able to copy data from one machine to
another in an efficient manner. We have a mechanism to export and import cert.
1. Drive to drive data is copied and efs maintain. But on laptops this means
taking drives out of machines and we do not want to do that.
2. It seems that if you copy the files to a location that is on the machines
bus, or a local drive EFS is maintained.
3. We have tried other methods including backup and restore solutions and
winzip. All are much slower that a direct copy of course.

SO is there any other way to copy EFS file from one user machine to another
and maintain the encrytion over a crossover cable or peer-to-peer copy?

Thanks.

Posted by Miha Pihler [MVP] on December 5, 2005, 2:33 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
Not sure what solution you are looking for, but for the copy operation to be
sucessful the file must be decrypted first (this is how EFS works and
protects data -- anything else would be sort of security bypass and would
beat the purpose of EFS).
This means that user must have private keys corresponding to the private key
that encrypted the files. Once the files are copied to the other computer
(they are copied over the network _unencrypted_) they are again encrypted on
the end server if the folder where you are copying them has encrypt
attribute set... This could again cause some problems since the files must
be encrypted with same keys as before they were copied or user will fail to
access the content of the files...

Also you mentioned that you have a way to export the keys. Think about
this -- especially how keys are protected in this case? Aren't you lowering
the level of security by doing this?

The only really "good" solution that I see here is backup and restore using
software that knows how to "deal" with EFS encrypted files (e.g. ntbackup).
In this case user doing the backup and restore operation doesn't need to
decrypt the files first and encrypt them once the files are copied. The only
permission that user needs in this case is backup permission. Also -- files
are encrypted even when copied over the network.

--
Mike
Microsoft MVP - Windows Security

> Hi All,
> In my environment EFS has just been rolled out. I do not have the back
> office specifics, but need to be able to copy data from one machine to
> another in an efficient manner. We have a mechanism to export and import
> cert.
> 1. Drive to drive data is copied and efs maintain. But on laptops this
> means
> taking drives out of machines and we do not want to do that.
> 2. It seems that if you copy the files to a location that is on the
> machines
> bus, or a local drive EFS is maintained.
> 3. We have tried other methods including backup and restore solutions and
> winzip. All are much slower that a direct copy of course.
>
> SO is there any other way to copy EFS file from one user machine to
> another
> and maintain the encrytion over a crossover cable or peer-to-peer copy?
>
> Thanks.



Similar ThreadsPosted
Cannot decrypt about 5% of encrypted files March 29, 2007, 10:22 am
Access encrypted files September 8, 2007, 11:56 am
Copy protection of files on Server November 7, 2005, 3:56 pm
Can not open encrypted files (EFS) (Urgent, please help) April 8, 2006, 6:14 am
EFS File Copy Decrypts files. How can this be avoided? January 3, 2006, 4:06 pm
Recovering encrypted files after reinstalling Windows August 19, 2006, 1:44 am
Permission to Copy Files to Server Folder But Not Edit Them July 1, 2006, 9:26 pm
How to give multiple users access to encrypted files. June 26, 2006, 6:22 pm
Protecting CD copy June 16, 2005, 2:43 pm
copy protection July 8, 2005, 2:44 am

The site map in XML format XML site map

Contact Us | Privacy Policy