smarties11 Posted January 4, 2016 Posted January 4, 2016 Hi All, We use offline files here on Windows 7 so that our users can work on their documents at home and then sync when they are back in school. We have a particular user who has worked on around 30 documents over the holidays, and then when she has come in today she cannot sync the changes to the system - all modified files fail sync, and give the error 'access is denied' I suspected it may be an EFS issue; I've looked in our CA and can see that her Basic EFS certificate expired on 15/12/2015. A new certificate was issued today 04/01/2016. I've checked that both of these certificates exist in her personal store in Certificate Manager and they do. When I try to open any of the files modified since the old certificate expired, it says 'Access is Denied'. I can't even copy them to another location (I thought if I could get these on to another machine I could try installing the certificates and see if I could access this way). If I try and create a new file on her area, this also fails. So it seems that there is some sort of issue with her old certificate expiring - despite it having renewed successfully. Any ideas - this user will lose hours of work if I cannot solve - all help appreciated. Thanks, Smarties
sted Posted January 4, 2016 Posted January 4, 2016 can you open/edit the docs if you disconnect it from the network (ie make it think its at "home" rather than school) and is it worth rolling back the clock to before the cert expired while offline?
smarties11 Posted January 4, 2016 Author Posted January 4, 2016 No, if I disconnect the network, as if I was 'at home' it still doesn't allow me to open the files. I was also just thinking about the clock. I think my next plan is to delete the new certificate from the personal store and turn back the system clock. If I can at least get access to those 30 files I can copy them off manually and then just do an offline file reset. Thinking logically, the system would have been unable to encrypt those files with the users EFS certificate, once it had expired. So the system must 'fall back' to a default certificate / encryption method? The files are there, they're obviously encrypted and I just need to work out how they were encrypted in order to unencrypt them.
smarties11 Posted January 4, 2016 Author Posted January 4, 2016 Rolling the clock back / removing new certificate hasn't worked.
smarties11 Posted January 4, 2016 Author Posted January 4, 2016 Just to report back - thankfully this is now resolved! I remembered I had a copy of the domain DRA private certificate saved on the network. I connected the hard drive of the machine in question to my own computer - imported the DRA private key - and then once I had given myself permissions to the offline files folder (\windows\csc) - I was able to decrypt and open the files. PHEW! I guess I could have just imported this private key into the users personal store and then removed once successfully synced but wanted to be in full control of the process. I can only assume that, in a situation where the client can't renew the EFS certificate due to not being connected to the network, and the certificate expires - the client then only encrypts using the DRA key? Hope this helps someone else in this situation!
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now