Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | Re: MS KB887742 Install and EFS |
|---|---|
| Date: | Tue, 12 Apr 2005 13:13:59 -0400 |
I wanted to let everyone know that the issue has been resolved and
was not related to KB887742 as initially thought. The problem was that the
recovery agent certificate referenced in our domain group policy had
expired. Once a new certificate was generated (with cipher /k) and
referenced the problem went away. Clients who experienced problems only had
to run "cipher /u" to update their encrypted files with the right hey
information.
FYI - The reason it was not mattering if you logged in as a local or
domain account was because the GP had already been applied to the machine.
Once the machine was removed from the domain EFS worked properly.
Thanks for the responses,
Mike Libby
ISX Corporation
-----Original Message-----
From: Windows NTBugtraq Mailing List
[mailto:NTBUGTRAQ@LISTSERV.NTBUGTRAQ.COM] On Behalf Of Mike Libby
Sent: Friday, March 18, 2005 1:51 PM
To: NTBUGTRAQ@LISTSERV.NTBUGTRAQ.COM
Subject: MS KB887742 Install and EFS
I have encountered a problem with installing the fix for
KB887742 onto an XP professional machine in a domain environment breaking
EFS. This happens whether or not you login with a domain account. The
error received when encrypting objects is "Recovery policy configured for
this system contains invalid recovery certificate". I am curious to see if
anyone else has experienced a similar problem and if so, if there are
suggested solutions to the problem.
Thanks,
Mike Libby
ISX Corporation
--
NTBugtraq Editor's Note:
Most viruses these days use spoofed email addresses. As such, using an
Anti-Virus product which automatically notifies the perceived sender of a
message it believes is infected may well cause more harm than good. Someone
who did not actually send you a virus may receive the notification and
scramble their support staff to find an infection which never existed in the
first place. Suggest such notifications be disabled by whomever is
responsible for your AV, or at least that the idea is considered.
--
--
NTBugtraq Editor's Note:
Most viruses these days use spoofed email addresses. As such, using an
Anti-Virus product which automatically notifies the perceived sender of a
message it believes is infected may well cause more harm than good. Someone who
did not actually send you a virus may receive the notification and scramble
their support staff to find an infection which never existed in the first
place. Suggest such notifications be disabled by whomever is responsible for
your AV, or at least that the idea is considered.
--
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | Malicious Software Removal Tool, Abdelhakim Aliane |
|---|---|
| Next by Date: | MajorRev: v2.0 Microsoft Security Bulletin MS05-002 - Vulnerability in Cursor and Icon Format Handling Could Allow Remote Code Execution (891711), Russ Cooper |
| Previous by Thread: | MS KB887742 Install and EFS, Mike Libby |
| Next by Thread: | Security Development Lifecycle Whitepaper Available, Michael Howard |
| Indexes: | [Date] [Thread] [Top] [All Lists] |