Server that issued EFS certificates going offline


hi guys,

not security, have issue.  our original domain controller root ca @ 1 time(i know bad) and efs certificates issued users(with dra well) , working correctly.  since did make new root ca server , keeping offline , using 2 other subordinate issuing ca servers.  need replace original domain controller have few questions.  happen users efs files when root ca issued certificate goes offline? happens efs files encrypted when efs certificate expires? 

any quick tips appreciated.

thanks,

dan
dan heim


hi dan,

you mentioned users issued efs certificate can encrypt files. planning replace domain controller , new ca.

users still able decrypt files still have efs certificate in personal store private key. till time have the certificate , access private keys , have no issues in decrypting files.
the private key stored in user profile , protected dpapi component which uses user's credentials protect store containing private keys. so, make sure not change user passwords may cause isssues.

however if user certificate expires won't able encrypt any more files, neither able edit or modify existing ones.
you able decrypt 'previously encrypted files' though.

you might want take @ article -- http://technet.microsoft.com/en-us/library/bb457065.aspx

since moving new pki architecture, recommend new certificates users issued new ca.

here article provides detailed information efs -- http://technet.microsoft.com/en-us/library/cc700811.aspx

please revert if have queries.

thanks,
nitin


Windows Server  >  Security



Comments

Popular posts from this blog

Error: 0x80073701 when trying to add Print Services Role in Windows 2012 Standard

Disconnecting from a Windows Server 2012 R2 file sharing session on a Windows 7,8,10 machine

Event ID 64,77,1008 Certificates Events Windows Server 2008, 2008R2