Solved

EFS over the network - authenticating 2 different ways

Posted on 2006-11-03
3
237 Views
Last Modified: 2013-12-04
So I have a weird issue.  We have a server located in a DMZ that is a drop server for files from our clients.  We have two different accounts (local to the server) that we use to log in and retrieve these files.  These accounts each have a locally encrypted directory (EFS) with a share off of it.
Both accounts are local admins on the box.

When we log in (map a drive) with account A to its share, no problem, send/receive files.

When we log in (map a drive) with account B to its share, I can see the files, but I can not cut or paste to it.

Since EFS over the network only works with Kerberos, it seems to me that I'm authenticating with kerberos for account A, but account B is defaulting to NTLM.  This is from any workstation.  Anyone have any ideas?

Greg
0
Comment
Question by:gherzog
  • 2
3 Comments
 
LVL 38

Expert Comment

by:Rich Rumble
ID: 17874379
EFS can use either NTLM/LM or kerb, we may need more information about what OS's your running...
 http://www.microsoft.com/technet/prodtechnol/winxppro/deploy/cryptfs.mspx#EME (see the last bullet point below)
When copying an encrypted file:
•      If using Windows 2000 and the target server is running Microsoft® Windows NT Server 4.0, the file will be silently decrypted and copied to the server. If using Windows XP or Windows Server 2003, the user will be warned and prompted to allow the decryption operation.
•      If the target server is running Windows 2000 or Windows Server 2003, and the machine account of the server is trusted for delegation in the Active Directory, the file will be silently decrypted and copied to the server where it will be re-encrypted using a local profile and encryption key.
Note The file is transmitted on the network between the client and the server in an unprotected format. If this file contains confidential information, care should be given to ensure that the network connection also provides secure transmission of the data. Such network data protection might include IP Security (IPSec).
•      If the target server is running Windows 2000 or Windows Server 2003 and the machine account of the server is not trusted for delegation in the Active Directory, or the server is in a workgroup or a Windows NT 4.0 domain, the file will not be copied and the user will receive an "access denied" error message.
The "access denied" error message is returned to applications from the NTFS file system in order to ensure compatibility with existing applications. The use of an alternate or more descriptive error message would cause many applications to fail or behave erratically.

The Windows XP Professional client contains some enhancements in the area of copying encrypted files. Both the shell interface and the command-line now support an option to allow or disallow file decryption. When an encrypted file is copied to a target location that does not allow remote encryption, the user will be prompted with a dialog box that allows a choice of whether or not to decrypt the file.
=========================
I assume account A is a domain account and account B is a work group account? Try copying the recovery agent key to the workgroup pc.
http://support.microsoft.com/kb/887414
http://support.microsoft.com/kb/241201
-rich
0
 
LVL 1

Author Comment

by:gherzog
ID: 17890796
The server is running Windows 2003.  It is not configured for delegation in Active Directory, nor is the account that works fine.  Both accounts are local accounts, not domain.

I think my logic on binding NTLM vs Kerberos is sketchy. that makes no sense. If i can connect and use the one account (obviously kerberos), it's not going to bind via NTLM based on a different set of user credentials. The binding should be all workstation based. So now I'm trying to figure out what the possible differences might be between these two accounts that would cause this behavior.

Greg
0
 
LVL 38

Accepted Solution

by:
Rich Rumble earned 500 total points
ID: 17891514
Do both accounts have equal access to their folders, via NTFS permissions, and are both listed as RA's  and or Decryptors for their respective folders?
http://support.microsoft.com/kb/243026 http://www.microsoft.com/downloads/details.aspx?FamilyID=9c70306d-0ef3-4b0c-ab61-81da208f5c47&displaylang=en
C:\>efsinfo efs-test.txt /U /R   (/s will do subdirectories)
C:\
efs-test.txt: Encrypted
  Users who can decrypt:
    domain\user (user(user@domain.ad))
  Recovery Agents:
    user\Administrator (Administrator)
-rich
0

Featured Post

Highfive Gives IT Their Time Back

Highfive is so simple that setting up every meeting room takes just minutes and every employee will be able to start or join a call from any room with ease. Never be called into a meeting just to get it started again. This is how video conferencing should work!

Join & Write a Comment

No security measures warrant 100% as a "silver bullet". The truth is we also cannot assume anything but a defensive and vigilance posture. Adopt no trust by default and reveal in assumption. Only assume anonymity or invisibility in the reverse. Safe…
Article by: btan
The intent is not to repeat what many has know about Ransomware but more to join its dots of what is it, who are the victims, why it exists, when and how we respond on infection. Lastly, sum up in a glance to share such information with more to help…
Illustrator's Shape Builder tool will let you combine shapes visually and interactively. This video shows the Mac version, but the tool works the same way in Windows. To follow along with this video, you can draw your own shapes or download the file…
This demo shows you how to set up the containerized NetScaler CPX with NetScaler Management and Analytics System in a non-routable Mesos/Marathon environment for use with Micro-Services applications.

743 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

11 Experts available now in Live!

Get 1:1 Help Now