分享

Third-party certification authority support for encrypting file system

 梦中家园 2013-04-24

Third-party certification authority support for encrypting file system

Article ID: 273856 - View products that this article applies to.
System TipThis article applies to a different version of Windows than the one you are using. Content in this article may not be relevant to you. Visit the Windows XP Solution Center
This article was previously published under Q273856

On This Page

SUMMARY

This article describes how Microsoft Windows 2000 supports third-party Certification Authorities (CAs) that issue Encrypting File System (EFS) certificates and EFS Recovery Agent certificates.

Overview

The rules for forming the certificate are:
  • Key Usage = Key Encipherment
  • EKU = File Recovery(1.3.6.1.4.1.311.10.3.4.1)
As stated in the "EFS Certificate" section, the third-party CA may provide Microsoft clients with Web enrollment pages to enroll for the certificates, or the third-party CA may export the certificate and the associated private key into a file that can be imported into a Microsoft client.

After it is created, the certificate can be imported by using the Recovery Agent Wizard.

During file recovery, both the file recovery certificate and the private key must be imported into the system that is used to recover the files according to the following guidelines:
  • Keys must be stored in the Microsoft RSABase CSP.
  • The Key Info property on the certificate must point to this key in the RSABase CSP. The provider name should be "Microsoft Base Cryptographic Provider v1.0."
You can use Certificate Import in the Certificate MMC snap-in to import the certificate and private key. IMPORTANT: The rules that are outlined in this article were validated by Microsoft by configuring a leading, third-party certification authority product to issue EFS and EFS Recovery Agent certificates. The EFS test team tested encryption and recovery by using these certificates.

    本站是提供个人知识管理的网络存储空间,所有内容均由用户发布,不代表本站观点。请注意甄别内容中的联系方式、诱导购买等信息,谨防诈骗。如发现有害或侵权内容,请点击一键举报。
    转藏 分享 献花(0

    0条评论

    发表

    请遵守用户 评论公约

    类似文章 更多