The Notebook Review forums were hosted by TechTarget, who shut down them down on January 31, 2022. This static read-only archive was pulled by NBR forum users between January 20 and January 31, 2022, in an effort to make sure that the valuable technical information that had been posted on the forums is preserved. For current discussions, many NBR forum users moved over to NotebookTalk.net after the shutdown.

Recovery of EFS encryption settings

Discussion in 'Dell Latitude, Vostro, and Precision' started by duschnouk, Feb 16, 2009.

Thread Status:
Not open for further replies.
  1. duschnouk

    duschnouk Notebook Enthusiast

    Reputations:
    0
    Messages:
    24
    Likes Received:
    1
    Trophy Points:
    5
    Following a swap of hard drive between two E4300 (asked by the dell support...), the TPM and encrypting settings have been erased.

    In order to retrieve the functionality and access to encrypted files, I did the following:

    - System restauration at a date before the fatal swapping of hard drive

    - Bios reset of the tpm and reinstallation of all the tpm software

    -Restauration of the tpm setting which I saved the day I first set the TPM after finishing the install wizard (keyarchive.xml) via the Embassy Security Center/Archive and Restore

    - Restauration of the efs key which I saved the day I first set the EFS at the end of the install with the wizard (pfx file) and application of the certificate of the saved pfx via the Secure EFS Wizard (so option "choose an EFS certificate" and then I enable "EFS TPM Certificate" of my pfx file)

    The result I have now is the following :

    -If I type in the DOS command "cipher /y" I can see that the serial number of my EFS certificate is effectively the one I created in december, and if I encrypt a file, the file is using this certificate.

    - In internet explorer/options/content/Certificate I can see that under "personal" my EFS TPM Certificate of december,with the right serial number is there, and if I double click, it is said that I have the private key of this certificate

    - But now,if I want to have access to the files I created before I have my tpm system crashed, despite that with the dos command "cipher /C" my files are effectively encrypted with that same EFS TPM certificate with the same serial number, the access is always refused, despite i have ownership on these files.

    So what can I do??? Thanks for your help.
     
  2. aehrlich

    aehrlich Newbie

    Reputations:
    0
    Messages:
    4
    Likes Received:
    0
    Trophy Points:
    5
    Are there any good documents about TPM+EFS?
    Had you created a "generic" (i.e. irrelevant to TPM) recovery agent or exported the encryption keys beforehand?
    And what is the "/y" switch of cipher? At least XPP doesn't have it (while there is "/u", for example...).
     
  3. duschnouk

    duschnouk Notebook Enthusiast

    Reputations:
    0
    Messages:
    24
    Likes Received:
    1
    Trophy Points:
    5
    I exported beforehand the EFS setting and TPM setting as requested by the wizards. But of course it doesn't work.
    Dell support is lost with these TPM and EFS stuff - so anyway I'm on the way to delete all - I have not lost many things anyway, but it is the occasion to see that if you have a problem with your tpm it is impossible to recover the data, even if you saved the keys. Obviously, the software shipped by Dell (from Wave corp) do not work.
     
Loading...
Thread Status:
Not open for further replies.

Share This Page