Solved

EFS on Windows 2003 domain with a 2008 File Server

Posted on 2013-06-07
1
604 Views
Last Modified: 2013-06-10
I would like to know if it is possible to set up EFS on several shares for a Windows 2008 server, while the domain level is on Windows 2003 Server. I have tried to set it up unsuccessfully for the past couple of days, nut I have not been able to find any supporting info regarding the different versions and implementing EFS. We have several Workstations on Windows 7 and XP.

Regards,
0
Comment
Question by:Synetek
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
1 Comment
 
LVL 64

Accepted Solution

by:
btan earned 500 total points
ID: 39231223
It should be possible.

 You can use EFS to encrypt and decrypt files and folders that are located on NTFS volumes on a remote server if the server is trusted for delegation in Active Directory. To remotely encrypt and decrypt files and folders, your certificate and private key must be stored on the server. The server uses Kerberos delegation to access this information.

E.g.  When files are stored on file shares, all EFS operations occur on the computer on which the files are stored. For example, if a user connects to a network file share and chooses to open a file that he or she previously encrypted, the file is decrypted on the computer on which the file is stored and then transmitted in plaintext over the network to the user’s computer.

Note the "plaintext" over the network. Hence not end to end for remote shares

I am suggesting below to see if helpful on the criteria for Remote EFS file share :
http://technet.microsoft.com/library/bb457116.aspx#EHAA

this is an lengthy forum which seems to be likely what commonly faced in remote shares
http://social.technet.microsoft.com/Forums/en-US/w7itprosecurity/thread/ab0a7538-cede-477f-9b9b-bfccf2ee27fb


Likewise there is EFS troubleshooting (on error msg) if necessary
http://technet.microsoft.com/en-us/library/bb457116.aspx#EBAA
http://technet.microsoft.com/en-us/library/cc700811.aspx#XSLTsection132121120120
0

Featured Post

Has Powershell sent you back into the Stone Age?

If managing Active Directory using Windows Powershell® is making you feel like you stepped back in time, you are not alone.  For nearly 20 years, AD admins around the world have used one tool for day-to-day AD management: Hyena. Discover why.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Restoring deleted objects in Active Directory has been a standard feature in Active Directory for many years, yet some admins may not know what is available.
This article explains how to install and use the NTBackup utility that comes with Windows Server.
This tutorial will show how to configure a new Backup Exec 2012 server and move an existing database to that server with the use of the BEUtility. Install Backup Exec 2012 on the new server and apply all of the latest hotfixes and service packs. The…
With the advent of Windows 10, Microsoft is pushing a Get Windows 10 icon into the notification area (system tray) of qualifying computers. There are many reasons for wanting to remove this icon. This two-part Experts Exchange video Micro Tutorial s…
Suggested Courses

632 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question