AD CS 2008 - What happens when you have two or more certificates that can encrypt files? Which one gets used?


in ad cs 2008 if have 2 or more certificates can same thing, such efs (encrypting file system) and a user (client authentication, secure email, encrypting file system) certificate available certificate used file encryption?  both used, can specify 1 use?  how work , best practices dealing this?

thanks,
craig

craig,

as far understand, can identify certificate used encryption by checking hash referenced in user profile under hkcu\software\microsoft\windows nt\currentversion\efs\currentkeys (you can regenerate it, if desired, via cypher /k - or set manually based on hash of appropriate certificate stored in personal certificate store). i'm not aware of mechanism can apply in order specify different one...

note it's user's private key - rather certificate - relevant point of view of efs (in particular, far decryption concerned)...

hth
marcin



Windows Server  >  Directory Services



Comments

Popular posts from this blog

WIMMount (HSM) causing cluster storage to go redirected (2012r2 DC)

Failed to delete the test record dcdiag-test-record in zone test.com

Azure MFA with Azure AD and RDS