Re: EFS Certificate  Self Signed Vs. User Cert

Re: EFS Certificate Self Signed Vs. User Cert

Secure Home | Search | About
 Microsoft Applications Security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
Re: EFS Certificate Self Signed Vs. User Cert Brian Komar 05-26-2005
Posted by Brian Komar on May 26, 2005, 12:28 am
If you were  Registered and logged in, you could reply and use other advanced thread options
Griff@discussions.microsoft.com says...
> I have setup my PKI and was able to designate a Recovery Agent through the
> domain policy. When the users Encrypt on there local workstations they use
> the User cert that I issued them. When they encrypt on the network it uses a
> self signed cert. The RA still works but I would like to have everyone using
> their User cert for EFS. What is the easiest way to make this happen??????
> Thanks in advance for any help....
>
This is the expected behavior. When you encrypt a file on a network
share using CIFS, the server impersonates the user, and performs the
encryption locally in the security context of the user (hence why the
server must be trusted for delegation).

Because the server cannot request a certificate from the CA, the server
generates a self signed certificate.

You can use the local EFS certificate (the one you want) by connecting
to the share by using WebDAV rather than CIFS. You must share the folder
as a Web Folder and then connect using HTTP rather than SMBs.

Brian
--
==
Brian Komar
MVP - Windows - Security
http://www.identit.ca/blogs/brian

Similar ThreadsPosted
Commercial cert vs. Microsoft Certificate Services generated cert June 21, 2007, 4:23 am
Computer cert/User cert 802.x Authentication query August 7, 2007, 5:20 am
MSSOAP refuses to accept self-signed certificate March 30, 2006, 11:43 am
import contact signed certificate and root ca September 28, 2007, 9:36 pm
requesting cert from local CA: "no trusted certificate authorities available" November 6, 2006, 12:58 pm
"No Certificate Templates Could Be Found" Error Message When User Requests Certificate from CA Web Enrollment Pages September 21, 2006, 1:33 pm
Root CA cert expires, I renewed but I'm unable to request new cert March 7, 2006, 3:16 pm
PKI- Renewing user certificate February 21, 2008, 7:45 pm
PKI Question - User Certificate Renewal February 21, 2008, 4:56 pm
Certificate for Smart Card User September 3, 2008, 5:26 am

The site map in XML format XML site map

Contact Us | Privacy Policy