AD CS 2008 - What happens when you have two or more certificates that can encrypt files? Which one gets used?
thanks,
craig
craig,
as far understand, can identify certificate used encryption by checking hash referenced in user profile under hkcu\software\microsoft\windows nt\currentversion\efs\currentkeys (you can regenerate it, if desired, via cypher /k - or set manually based on hash of appropriate certificate stored in personal certificate store). i'm not aware of mechanism can apply in order specify different one...
note it's user's private key - rather certificate - relevant point of view of efs (in particular, far decryption concerned)...
hth
marcin
Windows Server > Directory Services
Comments
Post a Comment