EFS file sharing with constrained delegation

EFS file sharing with constrained delegation

Secure Home | Search | About

Microsoft Applications Security - Microsoft's general security discussions and announcements 

Bookmark this page:  YahooMyWeb Yahoo!  Google Google  Windows Live Favorites Windows Live  del.icio.us del.icio.us  digg digg  Add to Netscape Netscape
Subject Author Date
EFS file sharing with constrained delegation Ondrej Sevecek 06-18-2009
Posted by Ondrej Sevecek on June 18, 2009, 4:35 am
If you were  Registered and logged in, you could reply and use other advanced thread options
Hello,

would you be please able to give me an authoritative answer whether (and
then how) Windows Server 2008 (domain member) acting as a file server for
EFS encrypted files can use CONSTRAINED delegation to obtain EFS encryption
certificates for users from an enterprise CA?

Currently, it works for me with UNconstrained delegation (the "trust
computer for delegation to any service"), it normally obtaines kerberos
tickets for several services such as CIFS/dc, ProtectedStorage/dc, LDAP/dc,
GC/dc and HOST/ca etc.

But when I switch it to the constrained ("trust computer for delegation to
specified services only - kerberos only") and list the services manually,
the file server then is not willing to delegate to CIFS/dc at all and is
using just anonymous connection which is refused with access denied.

This looks like the file server is generally not able/willing to use
constrained delegation for shared files at all (as tested with ASP
FileSystemObject script which also works only with unconstrained
delegation).

ondrej sevecek
MVP, MCM:DS




Similar ThreadsPosted
file sharing October 19, 2006, 1:14 pm
Windows NT file sharing June 29, 2005, 5:28 pm
File sharing permissions August 16, 2005, 3:36 am
File Sharing and Broadband November 2, 2005, 3:29 am
OneCare Live file sharing January 28, 2006, 7:29 am
Delegate user for file sharing? January 14, 2010, 3:46 am
webserver + file&print sharing enabled June 16, 2005, 4:07 pm
RE: Setting up home file sharing over ethernet June 21, 2006, 10:55 am
Firewall File and Print Sharing Toggles at StartUp September 1, 2009, 8:25 am
Kerberos Delegation July 6, 2005, 2:06 pm

The site map in XML format XML site map

Contact Us | Privacy Policy