• Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 992
  • Last Modified:

BartPE and EFS

I am looking for a way to build a BartPE image that will allow me to import a users EFS certificates so that I can decrypt and recover their files. Thanks!
0
jbyrd1981
Asked:
jbyrd1981
  • 2
  • 2
2 Solutions
 
slam69Commented:
Hi,

This isnt possible for the very reason that you wouldnt want to buold an image that included an individuals EFS certificate otherwise each time you install the image the certfifcate would be included great if you only have one user but if your deploying to lots of users then teh certficate could get wrongly used.

id recommend always making sure the efs is done as a standalone task
0
 
jbyrd1981Author Commented:
Another option I have been researching is using windows backup utility to copy the users profile. From what I understand it will copy the files even if encrypted with EFS. This way I can put in the BartPE disk into the computer with the bad drive, copy the users profile to an external location, then move that data to a new machine and import their certs. I have tried using a nt5backup plugin for Bart but have not been able to get it to work correctly. Any ideas??
0
 
slam69Commented:
Hmm interesting idea and have to be honest its not something I have tried I just know you cant put an EFS certificate onto PE.

Does sound feasible what you are looking into does the back up complete at the least if so i would recommend setting up a network storage area for admins only of your EFS cert backups and backing up the data, then in the event of driver failure you restore the backup of teh encrypted files and pull the necessary certificate out your storage area?

Tyhats a method i have seen employed before
0
 
jbyrd1981Author Commented:
I got it to work! All EFS files were copied and I put the users profile on another machine and it came back up great. Once their certs were available they had access to all the files EFS'd on the bad drive. I could never get the plugin for nt5backup to work for BartPE so I just used the one on the drive that I was recovering data from, it is in the c:\Windows\System32 folder. There are some errors initially but I found that if you disable volume shadow copy it works flawlessly and copies the users profile including EFS files to an extermal drive I had hooked up. Thanks for all the help though!
0

Featured Post

Cyber Threats to Small Businesses (Part 2)

The evolving cybersecurity landscape presents SMBs with a host of new threats to their clients, their data, and their bottom line. In part 2 of this blog series, learn three quick processes Webroot’s CISO, Gary Hayslip, recommends to help small businesses beat modern threats.

  • 2
  • 2
Tackle projects and never again get stuck behind a technical roadblock.
Join Now