打开APP
userphoto
未登录

开通VIP,畅享免费电子书等14项超值服

开通VIP
Third-party certification authority support for encrypting file system

Third-party certification authority support for encrypting file system

Article ID: 273856 - View products that this article applies to.
System TipThis article applies to a different version of Windows than the one you are using. Content in this article may not be relevant to you. Visit the Windows XP Solution Center
This article was previously published under Q273856

On This Page

SUMMARY

This article describes how Microsoft Windows 2000 supports third-party Certification Authorities (CAs) that issue Encrypting File System (EFS) certificates and EFS Recovery Agent certificates.

Overview

The rules for forming the certificate are:
  • Key Usage = Key Encipherment
  • EKU = File Recovery(1.3.6.1.4.1.311.10.3.4.1)
As stated in the "EFS Certificate" section, the third-party CA may provide Microsoft clients with Web enrollment pages to enroll for the certificates, or the third-party CA may export the certificate and the associated private key into a file that can be imported into a Microsoft client.

After it is created, the certificate can be imported by using the Recovery Agent Wizard.

During file recovery, both the file recovery certificate and the private key must be imported into the system that is used to recover the files according to the following guidelines:
  • Keys must be stored in the Microsoft RSABase CSP.
  • The Key Info property on the certificate must point to this key in the RSABase CSP. The provider name should be "Microsoft Base Cryptographic Provider v1.0."
You can use Certificate Import in the Certificate MMC snap-in to import the certificate and private key. IMPORTANT: The rules that are outlined in this article were validated by Microsoft by configuring a leading, third-party certification authority product to issue EFS and EFS Recovery Agent certificates. The EFS test team tested encryption and recovery by using these certificates.
本站仅提供存储服务,所有内容均由用户发布,如发现有害或侵权内容,请点击举报
打开APP,阅读全文并永久保存 查看更多类似文章
猜你喜欢
类似文章
【热】打开小程序,算一算2024你的财运
Windows 7 BitLocker 实战 – Xiwang''''s TechNet Blog
文件夹名变绿,解密,图示NTFS加密文件解
codeigniter Message: mkdir(): Invalid path Filename: drivers/Session_files_driver.php
求助delphi实现ssl验证客户端证书
Download Wise Data Recovery Software Full Crack Al...
Advanced EFS Data Recovery破解EFS加密
更多类似文章 >>
生活服务
热点新闻
分享 收藏 导长图 关注 下载文章
绑定账号成功
后续可登录账号畅享VIP特权!
如果VIP功能使用有故障,
可点击这里联系客服!

联系客服