using "encrypting file system" to protect files and folders in "windows.."

163
1 USING "ENCRYPTING FILE SYSTEM" TO PROTECT FILES AND FOLDERS IN "WINDOWS.."

Upload: britain

Post on 24-Feb-2016

33 views

Category:

Documents


1 download

DESCRIPTION

USING "ENCRYPTING FILE SYSTEM" TO PROTECT FILES AND FOLDERS IN "WINDOWS..". Web location for this presentation:. http://aztcs.org Click on “Meeting Notes”. SUMMARY. - PowerPoint PPT Presentation

TRANSCRIPT

Page 1: USING  "ENCRYPTING FILE SYSTEM"  TO PROTECT FILES AND FOLDERS  IN "WINDOWS.."

1

USING "ENCRYPTING FILE SYSTEM" TO PROTECT FILES AND FOLDERS

IN "WINDOWS.."

Page 2: USING  "ENCRYPTING FILE SYSTEM"  TO PROTECT FILES AND FOLDERS  IN "WINDOWS.."

2

Web location for this presentation:

http://aztcs.orgClick on“Meeting Notes”

Page 3: USING  "ENCRYPTING FILE SYSTEM"  TO PROTECT FILES AND FOLDERS  IN "WINDOWS.."

3

SUMMARYMany of the "editions" of "Windows 2000", "Windows XP", "Windows Vista", "Windows 7", and "Windows 8" have the "Encrypting File System" (EFS) for securing files and/or folders inside NTFS hard drive partitions.

Page 4: USING  "ENCRYPTING FILE SYSTEM"  TO PROTECT FILES AND FOLDERS  IN "WINDOWS.."

4

TOPICS• Basics of Encrypting File System• "EFS" versus "BitLocker"• "Encrypting File System" Service• Using the "Certificate Manager" to

Check for Existing Personal "Public Key Certificates"

• Encrypting A File or Folder with EFS• Using the "Certificate Manager" to

Export a Newly-Created Public Key and Private Key

Page 5: USING  "ENCRYPTING FILE SYSTEM"  TO PROTECT FILES AND FOLDERS  IN "WINDOWS.."

5

TOPICS (continued)• .PFX "Personal Information Exchange"

files• Decrypting an EFS-encrypted file/folder• Deleted Certificates Stay in RAM And

Are Active Until You Reboot

Page 6: USING  "ENCRYPTING FILE SYSTEM"  TO PROTECT FILES AND FOLDERS  IN "WINDOWS.."

6

BASICS OF EFS• The "Encrypting File System"

(EFS) is a feature of "NTFS" hard drives (and partitions) for many editions of "Windows 2000" through "Windows 8".

Page 7: USING  "ENCRYPTING FILE SYSTEM"  TO PROTECT FILES AND FOLDERS  IN "WINDOWS.."

7

BASICS OF EFS (continued)• When view in "Windows

Explorer" ("File Explorer"), a folder that contains only "Encrypting File System"-encrypted files will have it's name in green text:

Page 8: USING  "ENCRYPTING FILE SYSTEM"  TO PROTECT FILES AND FOLDERS  IN "WINDOWS.."

8

Page 9: USING  "ENCRYPTING FILE SYSTEM"  TO PROTECT FILES AND FOLDERS  IN "WINDOWS.."

9

BASICS OF EFS (continued)• When viewed in "Windows

Explorer" ("File Explorer"), a file that is encrypted by "Encrypting File System" will have it's name in green text:

Page 10: USING  "ENCRYPTING FILE SYSTEM"  TO PROTECT FILES AND FOLDERS  IN "WINDOWS.."

10

Page 11: USING  "ENCRYPTING FILE SYSTEM"  TO PROTECT FILES AND FOLDERS  IN "WINDOWS.."

11

BASICS OF EFS (continued)• Another user on the same computer

will be unable to open/view the EFS-protected file.

• If someone takes your hard drive, and puts it into an external hard drive enclosure and attaches the enclosure to their own computer, they will be unable to open/view the EFS-protected file.

Page 12: USING  "ENCRYPTING FILE SYSTEM"  TO PROTECT FILES AND FOLDERS  IN "WINDOWS.."

12

Page 13: USING  "ENCRYPTING FILE SYSTEM"  TO PROTECT FILES AND FOLDERS  IN "WINDOWS.."

13

Page 14: USING  "ENCRYPTING FILE SYSTEM"  TO PROTECT FILES AND FOLDERS  IN "WINDOWS.."

14

BASICS OF EFS (continued)• "ESF" is a feature of "NTFS"

hard drives (and partitions) for many editions of "Windows 2000" through "Windows 8".

Page 15: USING  "ENCRYPTING FILE SYSTEM"  TO PROTECT FILES AND FOLDERS  IN "WINDOWS.."

15

BASICS OF EFS (continued)• In EFS, "public key

certificates", "private keys", and passwords to controll the various keys all work together to give you "two factor authentication".

Page 17: USING  "ENCRYPTING FILE SYSTEM"  TO PROTECT FILES AND FOLDERS  IN "WINDOWS.."

17

BASICS OF EFS (continued)• According to

http://en.wikipedia.org/wiki/Encrypting_File_System, Ecrypting File System (EFS) is available for the following editions of "Windows..":

Page 18: USING  "ENCRYPTING FILE SYSTEM"  TO PROTECT FILES AND FOLDERS  IN "WINDOWS.."

18

BASICS OF EFS (continued)

Page 19: USING  "ENCRYPTING FILE SYSTEM"  TO PROTECT FILES AND FOLDERS  IN "WINDOWS.."

19

BASICS OF EFS (continued)• "Windows Vista Starter", "..Home

Basic", and "..Home Premium" allow only decryption--so you can read encrypted files but you cannot encrypt them according to http://pcworld.about.net/od/encryption1/The-Simple-Way-to-Keep-Your-Pr.htm

Page 20: USING  "ENCRYPTING FILE SYSTEM"  TO PROTECT FILES AND FOLDERS  IN "WINDOWS.."

20

BASICS OF EFS (continued)• For "Windows Vista Starter",

"..Home Basic", and "..Home Premium" you can decrypt EFS-encrypted files using the cipher command line command. See http://windows.microsoft.com/is-IS/windows-vista/What-is-Encrypting-File-System-EFS

Page 21: USING  "ENCRYPTING FILE SYSTEM"  TO PROTECT FILES AND FOLDERS  IN "WINDOWS.."

21

BASICS OF EFS (continued)• "Windows 7 Starter", "..Home

Basic", and "..Home Premium" allow only decryption--so you can read encrypted files but you not encrypt them

Page 22: USING  "ENCRYPTING FILE SYSTEM"  TO PROTECT FILES AND FOLDERS  IN "WINDOWS.."

22

BASICS OF EFS (continued)• For "Windows 7 Starter", "..Home

Basic", and "..Home Premium" you can decrypt EFS-encrypted files using the cipher command line command.

Page 23: USING  "ENCRYPTING FILE SYSTEM"  TO PROTECT FILES AND FOLDERS  IN "WINDOWS.."

23

BASICS OF EFS (continued)• See

http://answers.microsoft.com/en-us/windows/forum/windows_7-windows_programs/cipherexe-returns-error-the-request-is-not/9d5cb3fc-d092-4551-bc9f-f62dbd46f37c?msgId=5ad136ca-dedf-4013-8f1c-81627b907895

Page 24: USING  "ENCRYPTING FILE SYSTEM"  TO PROTECT FILES AND FOLDERS  IN "WINDOWS.."

24

BASICS OF EFS (continued)

Page 25: USING  "ENCRYPTING FILE SYSTEM"  TO PROTECT FILES AND FOLDERS  IN "WINDOWS.."

25

BASICS OF EFS (continued)• "Encrypting File System" is also

available for NTFS drives/partitions for the "..Pro" and "..Enterprise" editions of "Windows 8".

• "Encrypting File System" will not be available for the "..RT" or "Windows 8" editions of "Windows 8".

• Reference: http://en.wikipedia.org/wiki/Windows_8_editions#Comparison_chart

Page 26: USING  "ENCRYPTING FILE SYSTEM"  TO PROTECT FILES AND FOLDERS  IN "WINDOWS.."

26

"EFS" VERSUS "BITLOCKER"• "Bitlocker" is used to encrypt entire

hard drives or hard drive partitions whiile "Encrypting File System" is used to encrypt individual data files and/or folders

• "EFS" causes less of a performance reduction on your Windows computer

Page 27: USING  "ENCRYPTING FILE SYSTEM"  TO PROTECT FILES AND FOLDERS  IN "WINDOWS.."

27

"EFS" VERSUS "BITLOCKER" (continued)

• See http://www.lockergnome.com/windows/2012/04/25/bitlocker-vs-efs/

Page 28: USING  "ENCRYPTING FILE SYSTEM"  TO PROTECT FILES AND FOLDERS  IN "WINDOWS.."

28

"ENCRYPTING FILE SYSTEM" SERVICE MUST BE SET TO

"MANUAL" OR "AUTOMATIC"• In order to encrypt or decrypt a

file or folder, the "Encrypting File System" services has to be set to "Manual" or "Automatic": You can run services.msc from any search box or "Run" box in "Windows.." to turn it on:

Page 29: USING  "ENCRYPTING FILE SYSTEM"  TO PROTECT FILES AND FOLDERS  IN "WINDOWS.."

29

"ENCRYPTING FILE SYSTEM" SERVICE SET TO "MANUAL" OR "AUTOMATIC" (continued)

• Step 1: Click on the "Start" button in versions of "Windows" prior to "..8" or, for "Windows 8..", hover over the lower-left "Hot Corner" and use the RIGHT mouse" to click on "Run" in the pop-up "Power User Context Menu":

Page 30: USING  "ENCRYPTING FILE SYSTEM"  TO PROTECT FILES AND FOLDERS  IN "WINDOWS.."

30

"ENCRYPTING FILE SYSTEM" SERVICE SET TO "MANUAL" OR "AUTOMATIC" (continued)

• Step 2: Type in services.msc

• Step 3: Press once on the Enter key.

Page 31: USING  "ENCRYPTING FILE SYSTEM"  TO PROTECT FILES AND FOLDERS  IN "WINDOWS.."

31

Page 32: USING  "ENCRYPTING FILE SYSTEM"  TO PROTECT FILES AND FOLDERS  IN "WINDOWS.."

32

"ENCRYPTING FILE SYSTEM" SERVICE SET TO "MANUAL" OR "AUTOMATIC" (continued)

• Step 4: A "Services" Microsoft Management Console window will be displayed:

Page 33: USING  "ENCRYPTING FILE SYSTEM"  TO PROTECT FILES AND FOLDERS  IN "WINDOWS.."

33

Page 34: USING  "ENCRYPTING FILE SYSTEM"  TO PROTECT FILES AND FOLDERS  IN "WINDOWS.."

34

"ENCRYPTING FILE SYSTEM" SERVICE SET TO "MANUAL" OR "AUTOMATIC" (continued)• Step 5: Use the vertical scroll bar

on the right to scroll downward until you locate the "Encrypting File System" service.

• Step 6: Use your RIGHT mouse button to click on it.

• Step 7: A pop-up context menu will be displayed:

Page 35: USING  "ENCRYPTING FILE SYSTEM"  TO PROTECT FILES AND FOLDERS  IN "WINDOWS.."

35

"ENCRYPTING FILE SYSTEM" SERVICE SET TO "MANUAL" OR "AUTOMATIC" (continued)

• Step 8: Click on "Properties" in the pop-up context menu:

Page 36: USING  "ENCRYPTING FILE SYSTEM"  TO PROTECT FILES AND FOLDERS  IN "WINDOWS.."

36

Page 37: USING  "ENCRYPTING FILE SYSTEM"  TO PROTECT FILES AND FOLDERS  IN "WINDOWS.."

37

"ENCRYPTING FILE SYSTEM" SERVICE SET TO "MANUAL" OR "AUTOMATIC" (continued)

• Step 9: A "Properties" dialog box will be displayed.

• Step 10: Make sure that "Startup type" is set to "Manual" or "Automatic". "Manual" is preferable.

• Step 11: Click on the "Apply" button if it is not grayed out.`

Page 38: USING  "ENCRYPTING FILE SYSTEM"  TO PROTECT FILES AND FOLDERS  IN "WINDOWS.."

38

"ENCRYPTING FILE SYSTEM" SERVICE SET TO "MANUAL" OR "AUTOMATIC" (continued)• Step 12: Close the "Properties"

dialog box. • Step 13: Close the "Services"

Microsoft Management Console window.

Page 39: USING  "ENCRYPTING FILE SYSTEM"  TO PROTECT FILES AND FOLDERS  IN "WINDOWS.."

39

Page 40: USING  "ENCRYPTING FILE SYSTEM"  TO PROTECT FILES AND FOLDERS  IN "WINDOWS.."

40

USING THE "CERTIFICATE MANAGER" TO CHECK FOR EXISTING PERSONAL

"PUBLIC KEY CERTIFICATES"• Step 1: Click on the "Start" button in

versions of "Windows" prior to "..8" or, for "Windows 8..", hover over the lower-left "Hot Corner" and use the RIGHT mouse" to click on "Run" in the pop-up "Power User Context Menu":

Page 41: USING  "ENCRYPTING FILE SYSTEM"  TO PROTECT FILES AND FOLDERS  IN "WINDOWS.."

41

Page 42: USING  "ENCRYPTING FILE SYSTEM"  TO PROTECT FILES AND FOLDERS  IN "WINDOWS.."

42

USING THE "CERTIFICATE MANAGER" TO CHECK FOR EXISTING PERSONAL

"PUBLIC KEY CERTIFICATES" (continued)• Step 2: Use the right mouse button

to click on "cmd.exe" in versions of "Windows" prior to "..8" or, for "Windows 8..", use the left mouse button to click on "Command Prompt (Admin) in the pop-up Power User Tasks menu:

Page 43: USING  "ENCRYPTING FILE SYSTEM"  TO PROTECT FILES AND FOLDERS  IN "WINDOWS.."

43

Page 44: USING  "ENCRYPTING FILE SYSTEM"  TO PROTECT FILES AND FOLDERS  IN "WINDOWS.."

44

USING THE "CERTIFICATE MANAGER" TO CHECK FOR EXISTING PERSONAL

"PUBLIC KEY CERTIFICATES" (continued)• Step 3: Use the left mouse button to

click on "Run as administrator" in versions of "Windows" prior to "..8" or, for "Windows 8..", use the left mouse button to click on the "Yes" button of the "User Account Control" dialog box:

Page 45: USING  "ENCRYPTING FILE SYSTEM"  TO PROTECT FILES AND FOLDERS  IN "WINDOWS.."

45

Page 46: USING  "ENCRYPTING FILE SYSTEM"  TO PROTECT FILES AND FOLDERS  IN "WINDOWS.."

46

USING THE "CERTIFICATE MANAGER" TO CHECK FOR EXISTING PERSONAL

"PUBLIC KEY CERTIFICATES" (continued)• Step 4: A command prompt window,

will be displayed:

Page 47: USING  "ENCRYPTING FILE SYSTEM"  TO PROTECT FILES AND FOLDERS  IN "WINDOWS.."

47

Page 48: USING  "ENCRYPTING FILE SYSTEM"  TO PROTECT FILES AND FOLDERS  IN "WINDOWS.."

48

USING THE "CERTIFICATE MANAGER" TO CHECK FOR EXISTING PERSONAL

"PUBLIC KEY CERTIFICATES" (continued)• Step 5: Inside the command prompt

window, type in certmgr.msc

• Step 6: Press once on the Enter key.

Page 49: USING  "ENCRYPTING FILE SYSTEM"  TO PROTECT FILES AND FOLDERS  IN "WINDOWS.."

49

Page 50: USING  "ENCRYPTING FILE SYSTEM"  TO PROTECT FILES AND FOLDERS  IN "WINDOWS.."

50

USING THE "CERTIFICATE MANAGER" TO CHECK FOR EXISTING PERSONAL

"PUBLIC KEY CERTIFICATES" (continued)• Step 7: A "certmgr" Microsoft

Management Console window will be displayed:

Page 51: USING  "ENCRYPTING FILE SYSTEM"  TO PROTECT FILES AND FOLDERS  IN "WINDOWS.."

51

Page 52: USING  "ENCRYPTING FILE SYSTEM"  TO PROTECT FILES AND FOLDERS  IN "WINDOWS.."

52

USING THE "CERTIFICATE MANAGER" TO CHECK FOR EXISTING PERSONAL

"PUBLIC KEY CERTIFICATES" (continued)• Step 8: Double-click on the

Personal group in the right-most pane:

Page 53: USING  "ENCRYPTING FILE SYSTEM"  TO PROTECT FILES AND FOLDERS  IN "WINDOWS.."

53

Page 54: USING  "ENCRYPTING FILE SYSTEM"  TO PROTECT FILES AND FOLDERS  IN "WINDOWS.."

54

Page 55: USING  "ENCRYPTING FILE SYSTEM"  TO PROTECT FILES AND FOLDERS  IN "WINDOWS.."

55

USING THE "CERTIFICATE MANAGER" TO CHECK FOR EXISTING PERSONAL

"PUBLIC KEY CERTIFICATES" (continued)• Step 9: Double-click on

"Certificates" subgroup in the right-most pane:

Page 56: USING  "ENCRYPTING FILE SYSTEM"  TO PROTECT FILES AND FOLDERS  IN "WINDOWS.."

56

Page 57: USING  "ENCRYPTING FILE SYSTEM"  TO PROTECT FILES AND FOLDERS  IN "WINDOWS.."

57

USING THE "CERTIFICATE MANAGER" TO CHECK FOR EXISTING PERSONAL

"PUBLIC KEY CERTIFICATES" (continued)• Step 10: Note that you presently

have no "Public Key Certificates" or subgroups in the "Personal" group:

Page 58: USING  "ENCRYPTING FILE SYSTEM"  TO PROTECT FILES AND FOLDERS  IN "WINDOWS.."

58

Page 59: USING  "ENCRYPTING FILE SYSTEM"  TO PROTECT FILES AND FOLDERS  IN "WINDOWS.."

59

ENCRYPTING A FILE OR FOLDER WITH "ENCRYPTING FILE SYSTEM"• Step 1: Start "Windows

Explorer" ("File Explorer").• Step 2: Locate or create the

folder or file that you want to encrypt.

Page 60: USING  "ENCRYPTING FILE SYSTEM"  TO PROTECT FILES AND FOLDERS  IN "WINDOWS.."

60

Page 61: USING  "ENCRYPTING FILE SYSTEM"  TO PROTECT FILES AND FOLDERS  IN "WINDOWS.."

61

ENCRYPTING A FILE OR FOLDER WITH "ENCRYPTING FILE SYSTEM" (continued)• Step 3: Use the RIGHT mouse

to click on it.• Step 4: A pop-up context menu

will be displayed.• Step 5: Click on "Properties".

Page 62: USING  "ENCRYPTING FILE SYSTEM"  TO PROTECT FILES AND FOLDERS  IN "WINDOWS.."

62

Page 63: USING  "ENCRYPTING FILE SYSTEM"  TO PROTECT FILES AND FOLDERS  IN "WINDOWS.."

63

ENCRYPTING A FILE OR FOLDER WITH "ENCRYPTING FILE SYSTEM" (continued)• Step 6: A "..Properties" dialog

box will be displayed.• Step 7: Click on the "Advanced"

button.

Page 64: USING  "ENCRYPTING FILE SYSTEM"  TO PROTECT FILES AND FOLDERS  IN "WINDOWS.."

64

Page 65: USING  "ENCRYPTING FILE SYSTEM"  TO PROTECT FILES AND FOLDERS  IN "WINDOWS.."

65

ENCRYPTING A FILE OR FOLDER WITH "ENCRYPTING FILE SYSTEM" (continued)• Step 8: An "Advanced

Attributes" box will be displayed:

Page 66: USING  "ENCRYPTING FILE SYSTEM"  TO PROTECT FILES AND FOLDERS  IN "WINDOWS.."

66

Page 67: USING  "ENCRYPTING FILE SYSTEM"  TO PROTECT FILES AND FOLDERS  IN "WINDOWS.."

67

ENCRYPTING A FILE OR FOLDER WITH "ENCRYPTING FILE SYSTEM" (continued)• Step 9: Put in a checkmark for

"Encrypt contents to secure data".

• Step 10: Click on the "OK" button:

• Step 11: The "Advanced Attributes" box will disappear.

Page 68: USING  "ENCRYPTING FILE SYSTEM"  TO PROTECT FILES AND FOLDERS  IN "WINDOWS.."

68

Page 69: USING  "ENCRYPTING FILE SYSTEM"  TO PROTECT FILES AND FOLDERS  IN "WINDOWS.."

69

ENCRYPTING A FILE OR FOLDER WITH "ENCRYPTING FILE SYSTEM" (continued)• Step 12: Click on the "Apply"

button of the "..Properties" dialog box, if the "Apply" button is not grayed out. Step 11: The "Advanced Attributes" box will disappear.

Page 70: USING  "ENCRYPTING FILE SYSTEM"  TO PROTECT FILES AND FOLDERS  IN "WINDOWS.."

70

Page 71: USING  "ENCRYPTING FILE SYSTEM"  TO PROTECT FILES AND FOLDERS  IN "WINDOWS.."

71

ENCRYPTING A FILE OR FOLDER WITH "ENCRYPTING FILE SYSTEM" (continued)• Step 13: Select the desired

"option button":

Page 72: USING  "ENCRYPTING FILE SYSTEM"  TO PROTECT FILES AND FOLDERS  IN "WINDOWS.."

72

Page 73: USING  "ENCRYPTING FILE SYSTEM"  TO PROTECT FILES AND FOLDERS  IN "WINDOWS.."

73

ENCRYPTING A FILE OR FOLDER WITH "ENCRYPTING FILE SYSTEM" (continued)• Step 14: Click on the "Continue"

button of the "Access Denied" dialog box:

Page 74: USING  "ENCRYPTING FILE SYSTEM"  TO PROTECT FILES AND FOLDERS  IN "WINDOWS.."

74

Page 75: USING  "ENCRYPTING FILE SYSTEM"  TO PROTECT FILES AND FOLDERS  IN "WINDOWS.."

75

ENCRYPTING A FILE OR FOLDER WITH "ENCRYPTING FILE SYSTEM" (continued)• Step 15: The "Access Denied"

box will disappear.• Step 16: The file name(s) of the

newly-encrypted file(s) will now be displayed in a green font to indicate that the file(s) is/are encrypted by "Encrypting File System".

Page 76: USING  "ENCRYPTING FILE SYSTEM"  TO PROTECT FILES AND FOLDERS  IN "WINDOWS.."

76

Page 77: USING  "ENCRYPTING FILE SYSTEM"  TO PROTECT FILES AND FOLDERS  IN "WINDOWS.."

77

USING THE "CERTIFICATE MANAGER" TO EXPORT A NEWLY-CREATED

"PUBLIC KEY" AND "PRIVATE KEY"• Step 1: Click on the "Start" button in

versions of "Windows" prior to "..8" or, for "Windows 8..", hover over the lower-left "Hot Corner" and use the RIGHT mouse" to click on "Run" in the pop-up "Power User Context Menu":

Page 78: USING  "ENCRYPTING FILE SYSTEM"  TO PROTECT FILES AND FOLDERS  IN "WINDOWS.."

78

Page 79: USING  "ENCRYPTING FILE SYSTEM"  TO PROTECT FILES AND FOLDERS  IN "WINDOWS.."

79

USING THE "CERTIFICATE MANAGER" TO EXPORT A NEWLY-CREATED "PUBLIC KEY"

AND "PRIVATE KEY" (continued)

• Step 2: Use the right mouse button to click on "cmd.exe" in versions of "Windows" prior to "..8" or, for "Windows 8..", use the left mouse button to click on "Command Prompt (Admin) in the pop-up Power User Tasks menu:

Page 80: USING  "ENCRYPTING FILE SYSTEM"  TO PROTECT FILES AND FOLDERS  IN "WINDOWS.."

80

Page 81: USING  "ENCRYPTING FILE SYSTEM"  TO PROTECT FILES AND FOLDERS  IN "WINDOWS.."

81

USING THE "CERTIFICATE MANAGER" TO EXPORT A NEWLY-CREATED "PUBLIC KEY"

AND "PRIVATE KEY" (continued)

• Step 3: Use the left mouse button to click on "Run as administrator" in versions of "Windows" prior to "..8" or, for "Windows 8..", use the left mouse button to click on the "Yes" button of the "User Account Control" dialog box:

Page 82: USING  "ENCRYPTING FILE SYSTEM"  TO PROTECT FILES AND FOLDERS  IN "WINDOWS.."

82

Page 83: USING  "ENCRYPTING FILE SYSTEM"  TO PROTECT FILES AND FOLDERS  IN "WINDOWS.."

83

USING THE "CERTIFICATE MANAGER" TO EXPORT A NEWLY-CREATED "PUBLIC KEY"

AND "PRIVATE KEY" (continued)

• Step 4: A command prompt window, will be displayed:

Page 84: USING  "ENCRYPTING FILE SYSTEM"  TO PROTECT FILES AND FOLDERS  IN "WINDOWS.."

84

Page 85: USING  "ENCRYPTING FILE SYSTEM"  TO PROTECT FILES AND FOLDERS  IN "WINDOWS.."

85

USING THE "CERTIFICATE MANAGER" TO EXPORT A NEWLY-CREATED "PUBLIC KEY"

AND "PRIVATE KEY" (continued)

• Step 5: Inside the command prompt window, type in certmgr.msc

• Step 6: Press once on the Enter key.

Page 86: USING  "ENCRYPTING FILE SYSTEM"  TO PROTECT FILES AND FOLDERS  IN "WINDOWS.."

86

Page 87: USING  "ENCRYPTING FILE SYSTEM"  TO PROTECT FILES AND FOLDERS  IN "WINDOWS.."

87

USING THE "CERTIFICATE MANAGER" TO EXPORT A NEWLY-CREATED "PUBLIC KEY"

AND "PRIVATE KEY" (continued)

• Step 7: A "certmgr" Microsoft Management Console window will be displayed:

Page 88: USING  "ENCRYPTING FILE SYSTEM"  TO PROTECT FILES AND FOLDERS  IN "WINDOWS.."

88

Page 89: USING  "ENCRYPTING FILE SYSTEM"  TO PROTECT FILES AND FOLDERS  IN "WINDOWS.."

89

USING THE "CERTIFICATE MANAGER" TO EXPORT A NEWLY-CREATED "PUBLIC KEY"

AND "PRIVATE KEY" (continued)

• Step 8: Double-click on the Personal group in the right-most pane:

Page 90: USING  "ENCRYPTING FILE SYSTEM"  TO PROTECT FILES AND FOLDERS  IN "WINDOWS.."

90

Page 91: USING  "ENCRYPTING FILE SYSTEM"  TO PROTECT FILES AND FOLDERS  IN "WINDOWS.."

91

USING THE "CERTIFICATE MANAGER" TO EXPORT A NEWLY-CREATED "PUBLIC KEY"

AND "PRIVATE KEY" (continued)

• Step 9: Double-click on "Certificates" subgroup in the right-most pane:

Page 92: USING  "ENCRYPTING FILE SYSTEM"  TO PROTECT FILES AND FOLDERS  IN "WINDOWS.."

92

Page 93: USING  "ENCRYPTING FILE SYSTEM"  TO PROTECT FILES AND FOLDERS  IN "WINDOWS.."

93

USING THE "CERTIFICATE MANAGER" TO EXPORT A NEWLY-CREATED "PUBLIC KEY"

AND "PRIVATE KEY" (continued)

• Step 10: Note that you now have a newly-created "Public Key Certificate" in the "Certificates" subgroup of the "Personal" group:

Page 94: USING  "ENCRYPTING FILE SYSTEM"  TO PROTECT FILES AND FOLDERS  IN "WINDOWS.."

94

Page 95: USING  "ENCRYPTING FILE SYSTEM"  TO PROTECT FILES AND FOLDERS  IN "WINDOWS.."

95

USING THE "CERTIFICATE MANAGER" TO EXPORT A NEWLY-CREATED "PUBLIC KEY"

AND "PRIVATE KEY" (continued)

• Step 11: Note that you now have a newly-created "Public Key Certificate" in the "Certificates" subgroup of the "Personal" group:

Page 96: USING  "ENCRYPTING FILE SYSTEM"  TO PROTECT FILES AND FOLDERS  IN "WINDOWS.."

96

Page 97: USING  "ENCRYPTING FILE SYSTEM"  TO PROTECT FILES AND FOLDERS  IN "WINDOWS.."

97

USING THE "CERTIFICATE MANAGER" TO EXPORT A NEWLY-CREATED "PUBLIC KEY"

AND "PRIVATE KEY" (continued)

• Step 12: Use the RIGHT mouse button to click on the newly-created "Public Key Certificate":

Page 98: USING  "ENCRYPTING FILE SYSTEM"  TO PROTECT FILES AND FOLDERS  IN "WINDOWS.."

98

Page 99: USING  "ENCRYPTING FILE SYSTEM"  TO PROTECT FILES AND FOLDERS  IN "WINDOWS.."

99

USING THE "CERTIFICATE MANAGER" TO EXPORT A NEWLY-CREATED "PUBLIC KEY"

AND "PRIVATE KEY" (continued)

• Step 13: Click on "All Tasks" in the pop-up context menu:

Page 100: USING  "ENCRYPTING FILE SYSTEM"  TO PROTECT FILES AND FOLDERS  IN "WINDOWS.."

100

Page 101: USING  "ENCRYPTING FILE SYSTEM"  TO PROTECT FILES AND FOLDERS  IN "WINDOWS.."

101

USING THE "CERTIFICATE MANAGER" TO EXPORT A NEWLY-CREATED "PUBLIC KEY"

AND "PRIVATE KEY" (continued)

• Step 14: Click on "Advanced Operations" in the secondary context menu:

Page 102: USING  "ENCRYPTING FILE SYSTEM"  TO PROTECT FILES AND FOLDERS  IN "WINDOWS.."

102

Page 103: USING  "ENCRYPTING FILE SYSTEM"  TO PROTECT FILES AND FOLDERS  IN "WINDOWS.."

103

USING THE "CERTIFICATE MANAGER" TO EXPORT A NEWLY-CREATED "PUBLIC KEY"

AND "PRIVATE KEY" (continued)

• Step 15: A "Certificate Export Wizard" dialog box will be displayed.

• Step 16: Click on the "Next" button:

Page 104: USING  "ENCRYPTING FILE SYSTEM"  TO PROTECT FILES AND FOLDERS  IN "WINDOWS.."

104

Page 105: USING  "ENCRYPTING FILE SYSTEM"  TO PROTECT FILES AND FOLDERS  IN "WINDOWS.."

105

USING THE "CERTIFICATE MANAGER" TO EXPORT A NEWLY-CREATED "PUBLIC KEY"

AND "PRIVATE KEY" (continued)

• Step 17: Select the "Yes, export the private key" option.

• Step 18: Click on the "Next" button:

Page 106: USING  "ENCRYPTING FILE SYSTEM"  TO PROTECT FILES AND FOLDERS  IN "WINDOWS.."

106

Page 107: USING  "ENCRYPTING FILE SYSTEM"  TO PROTECT FILES AND FOLDERS  IN "WINDOWS.."

107

USING THE "CERTIFICATE MANAGER" TO EXPORT A NEWLY-CREATED "PUBLIC KEY"

AND "PRIVATE KEY" (continued)

• Step 19: Click on the "Next" button:

Page 108: USING  "ENCRYPTING FILE SYSTEM"  TO PROTECT FILES AND FOLDERS  IN "WINDOWS.."

108

Page 109: USING  "ENCRYPTING FILE SYSTEM"  TO PROTECT FILES AND FOLDERS  IN "WINDOWS.."

109

USING THE "CERTIFICATE MANAGER" TO EXPORT A NEWLY-CREATED "PUBLIC KEY"

AND "PRIVATE KEY" (continued)

• Step 20: Click on the "Next" button:

Page 110: USING  "ENCRYPTING FILE SYSTEM"  TO PROTECT FILES AND FOLDERS  IN "WINDOWS.."

110

Page 111: USING  "ENCRYPTING FILE SYSTEM"  TO PROTECT FILES AND FOLDERS  IN "WINDOWS.."

111

Page 112: USING  "ENCRYPTING FILE SYSTEM"  TO PROTECT FILES AND FOLDERS  IN "WINDOWS.."

112

USING THE "CERTIFICATE MANAGER" TO EXPORT A NEWLY-CREATED "PUBLIC KEY"

AND "PRIVATE KEY" (continued)

• Step 21: Type in a password and record it somewhere in a secure manner (such as with "Roboform" or "LastPass"):

Page 113: USING  "ENCRYPTING FILE SYSTEM"  TO PROTECT FILES AND FOLDERS  IN "WINDOWS.."

113

Page 114: USING  "ENCRYPTING FILE SYSTEM"  TO PROTECT FILES AND FOLDERS  IN "WINDOWS.."

114

USING THE "CERTIFICATE MANAGER" TO EXPORT A NEWLY-CREATED "PUBLIC KEY"

AND "PRIVATE KEY"(continued)

• Step 22: Type in the same password again.

• Step 23: Click on the "Next" button:

Page 115: USING  "ENCRYPTING FILE SYSTEM"  TO PROTECT FILES AND FOLDERS  IN "WINDOWS.."

115

Page 116: USING  "ENCRYPTING FILE SYSTEM"  TO PROTECT FILES AND FOLDERS  IN "WINDOWS.."

116

USING THE "CERTIFICATE MANAGER" TO EXPORT A NEWLY-CREATED "PUBLIC KEY"

AND "PRIVATE KEY" (continued)

• Step 24: Click on the "Browse" button:

Page 117: USING  "ENCRYPTING FILE SYSTEM"  TO PROTECT FILES AND FOLDERS  IN "WINDOWS.."

117

Page 118: USING  "ENCRYPTING FILE SYSTEM"  TO PROTECT FILES AND FOLDERS  IN "WINDOWS.."

118

USING THE "CERTIFICATE MANAGER" TO EXPORT A NEWLY-CREATED "PUBLIC KEY"

AND "PRIVATE KEY" (continued)

• Step 25: Use the "Save As" box to work your way to the hard drive or flash drive location where you wish to place the .PFX file:

Page 119: USING  "ENCRYPTING FILE SYSTEM"  TO PROTECT FILES AND FOLDERS  IN "WINDOWS.."

119

Page 120: USING  "ENCRYPTING FILE SYSTEM"  TO PROTECT FILES AND FOLDERS  IN "WINDOWS.."

120

Page 121: USING  "ENCRYPTING FILE SYSTEM"  TO PROTECT FILES AND FOLDERS  IN "WINDOWS.."

121

USING THE "CERTIFICATE MANAGER" TO EXPORT A NEWLY-CREATED "PUBLIC KEY"

AND "PRIVATE KEY" (continued)

• Step 26: When you arrive at the desired location for the .PFX file, type in a name for the .PFX file.

• Step 27: Click on the "Save" button:

Page 122: USING  "ENCRYPTING FILE SYSTEM"  TO PROTECT FILES AND FOLDERS  IN "WINDOWS.."

122

Page 123: USING  "ENCRYPTING FILE SYSTEM"  TO PROTECT FILES AND FOLDERS  IN "WINDOWS.."

123

USING THE "CERTIFICATE MANAGER" TO EXPORT A NEWLY-CREATED "PUBLIC KEY"

AND "PRIVATE KEY" (continued)

• Step 28: Click on the "Next" button:

Page 124: USING  "ENCRYPTING FILE SYSTEM"  TO PROTECT FILES AND FOLDERS  IN "WINDOWS.."

124

Page 125: USING  "ENCRYPTING FILE SYSTEM"  TO PROTECT FILES AND FOLDERS  IN "WINDOWS.."

125

USING THE "CERTIFICATE MANAGER" TO EXPORT A NEWLY-CREATED "PUBLIC KEY"

AND "PRIVATE KEY" (continued)

• Step 29: Click on the "Finish" button:

Page 126: USING  "ENCRYPTING FILE SYSTEM"  TO PROTECT FILES AND FOLDERS  IN "WINDOWS.."

126

Page 127: USING  "ENCRYPTING FILE SYSTEM"  TO PROTECT FILES AND FOLDERS  IN "WINDOWS.."

127

Page 128: USING  "ENCRYPTING FILE SYSTEM"  TO PROTECT FILES AND FOLDERS  IN "WINDOWS.."

128

USING THE "CERTIFICATE MANAGER" TO EXPORT A NEWLY-CREATED "PUBLIC KEY"

AND "PRIVATE KEY" (continued)

• Step 30: Click on "OK" button:

Page 129: USING  "ENCRYPTING FILE SYSTEM"  TO PROTECT FILES AND FOLDERS  IN "WINDOWS.."

129

Page 130: USING  "ENCRYPTING FILE SYSTEM"  TO PROTECT FILES AND FOLDERS  IN "WINDOWS.."

130

USING THE "CERTIFICATE MANAGER" TO EXPORT A NEWLY-CREATED "PUBLIC KEY"

AND "PRIVATE KEY" (continued)

• Step 31: Click on "x" button to close the "certmgr" window:

Page 131: USING  "ENCRYPTING FILE SYSTEM"  TO PROTECT FILES AND FOLDERS  IN "WINDOWS.."

131

Page 132: USING  "ENCRYPTING FILE SYSTEM"  TO PROTECT FILES AND FOLDERS  IN "WINDOWS.."

132

USING THE "CERTIFICATE MANAGER" TO EXPORT A NEWLY-CREATED "PUBLIC KEY"

AND "PRIVATE KEY" (continued)

• Step 32: Click on "x" button to close the Command Prompt window:

Page 133: USING  "ENCRYPTING FILE SYSTEM"  TO PROTECT FILES AND FOLDERS  IN "WINDOWS.."

133

Page 134: USING  "ENCRYPTING FILE SYSTEM"  TO PROTECT FILES AND FOLDERS  IN "WINDOWS.."

134

Page 135: USING  "ENCRYPTING FILE SYSTEM"  TO PROTECT FILES AND FOLDERS  IN "WINDOWS.."

135

• .PFX file(s) = "Personal Information Exchange" files

• .PFX file(s) an be moved, copied, renamed, and e-mailed without restrictions.

.PFX FILE(S) (continued)

Page 136: USING  "ENCRYPTING FILE SYSTEM"  TO PROTECT FILES AND FOLDERS  IN "WINDOWS.."

136

• Double-click on it to "Import" the certificate and the private key into any computer or Windows user account. Then you can open/view the associated the EFS-encrypted data file

.PFX FILE(S) (continued)

Page 137: USING  "ENCRYPTING FILE SYSTEM"  TO PROTECT FILES AND FOLDERS  IN "WINDOWS.."

137

If your Windows user account or your Windows computer cannot open an EFS-encrypted file, do the following:•Step 1: Obtain the .PFX file (from the creator/owner of the EFS-encrypted file) and double-click on the .PFX file:

DECRYPTING AN EFS-ENCRYPTED FILE/FOLDER

Page 138: USING  "ENCRYPTING FILE SYSTEM"  TO PROTECT FILES AND FOLDERS  IN "WINDOWS.."

138

Page 139: USING  "ENCRYPTING FILE SYSTEM"  TO PROTECT FILES AND FOLDERS  IN "WINDOWS.."

139

Page 140: USING  "ENCRYPTING FILE SYSTEM"  TO PROTECT FILES AND FOLDERS  IN "WINDOWS.."

140

• Step 2: Click on the "Next" button of the "Certificate Import Wizard":

DECRYPTING AN EFS-ENCRYPTED FILE/FOLDER (continued)

Page 141: USING  "ENCRYPTING FILE SYSTEM"  TO PROTECT FILES AND FOLDERS  IN "WINDOWS.."

141

Page 142: USING  "ENCRYPTING FILE SYSTEM"  TO PROTECT FILES AND FOLDERS  IN "WINDOWS.."

142

• Step 3: Click on the "Next" button:

DECRYPTING AN EFS-ENCRYPTED FILE/FOLDER (continued)

Page 143: USING  "ENCRYPTING FILE SYSTEM"  TO PROTECT FILES AND FOLDERS  IN "WINDOWS.."

143

Page 144: USING  "ENCRYPTING FILE SYSTEM"  TO PROTECT FILES AND FOLDERS  IN "WINDOWS.."

144

Page 145: USING  "ENCRYPTING FILE SYSTEM"  TO PROTECT FILES AND FOLDERS  IN "WINDOWS.."

145

• Step 4: Type in the password for the .PFX file (which you should have obtained from the creator/owner of the EFS-encrypted data file):

DECRYPTING AN EFS-ENCRYPTED FILE/FOLDER (continued)

Page 146: USING  "ENCRYPTING FILE SYSTEM"  TO PROTECT FILES AND FOLDERS  IN "WINDOWS.."

146

Page 147: USING  "ENCRYPTING FILE SYSTEM"  TO PROTECT FILES AND FOLDERS  IN "WINDOWS.."

147

• Step 5: Select the "Mark this key as exportable" option.

• Step 6: Click on the "Next" button:

DECRYPTING AN EFS-ENCRYPTED FILE/FOLDER (continued)

Page 148: USING  "ENCRYPTING FILE SYSTEM"  TO PROTECT FILES AND FOLDERS  IN "WINDOWS.."

148

Page 149: USING  "ENCRYPTING FILE SYSTEM"  TO PROTECT FILES AND FOLDERS  IN "WINDOWS.."

149

• Step 7: Click on the "Next" button:

DECRYPTING AN EFS-ENCRYPTED FILE/FOLDER (continued)

Page 150: USING  "ENCRYPTING FILE SYSTEM"  TO PROTECT FILES AND FOLDERS  IN "WINDOWS.."

150

Page 151: USING  "ENCRYPTING FILE SYSTEM"  TO PROTECT FILES AND FOLDERS  IN "WINDOWS.."

151

• Step 8: Click on the "Finish" button:

DECRYPTING AN EFS-ENCRYPTED FILE/FOLDER (continued)

Page 152: USING  "ENCRYPTING FILE SYSTEM"  TO PROTECT FILES AND FOLDERS  IN "WINDOWS.."

152

Page 153: USING  "ENCRYPTING FILE SYSTEM"  TO PROTECT FILES AND FOLDERS  IN "WINDOWS.."

153

• Step 9: Click on the "OK" button:

DECRYPTING AN EFS-ENCRYPTED FILE/FOLDER (continued)

Page 154: USING  "ENCRYPTING FILE SYSTEM"  TO PROTECT FILES AND FOLDERS  IN "WINDOWS.."

154

Page 155: USING  "ENCRYPTING FILE SYSTEM"  TO PROTECT FILES AND FOLDERS  IN "WINDOWS.."

155

• Step 10: If you EFS-encrypted files are inside an EFS-encrypted folder, double-click on the folder to open it:

DECRYPTING AN EFS-ENCRYPTED FILE/FOLDER (continued)

Page 156: USING  "ENCRYPTING FILE SYSTEM"  TO PROTECT FILES AND FOLDERS  IN "WINDOWS.."

156

Page 157: USING  "ENCRYPTING FILE SYSTEM"  TO PROTECT FILES AND FOLDERS  IN "WINDOWS.."

157

• Step 11: Double-click on the EFS-encrypted data file to open it:

DECRYPTING AN EFS-ENCRYPTED FILE/FOLDER (continued)

Page 158: USING  "ENCRYPTING FILE SYSTEM"  TO PROTECT FILES AND FOLDERS  IN "WINDOWS.."

158

Page 159: USING  "ENCRYPTING FILE SYSTEM"  TO PROTECT FILES AND FOLDERS  IN "WINDOWS.."

159

• Step 12: The EFS-encrypted data file will open with its default associated software application program ("app"):

DECRYPTING AN EFS-ENCRYPTED FILE/FOLDER (continued)

Page 160: USING  "ENCRYPTING FILE SYSTEM"  TO PROTECT FILES AND FOLDERS  IN "WINDOWS.."

160

Page 161: USING  "ENCRYPTING FILE SYSTEM"  TO PROTECT FILES AND FOLDERS  IN "WINDOWS.."

161

DELETED CERTIFICATES STAY IN RAM UNTIL YOU RE-BOOT

• If you run certmgr.msc to delete a certificate from your computer's hard drive, the certificate will stay active in RAM, so you have to re-boot to flush out the active certificate.

Page 162: USING  "ENCRYPTING FILE SYSTEM"  TO PROTECT FILES AND FOLDERS  IN "WINDOWS.."

162

OPTIONS IN "ACRONIS TRUE IMAGE.." FOR BACKING UP HARD DRIVES THAT

CONTAIN EFS-ENCRYPTED FILES• According to

http://www.acronis.com/support/documentation/ATIH2012/index.html#267.html:

Page 163: USING  "ENCRYPTING FILE SYSTEM"  TO PROTECT FILES AND FOLDERS  IN "WINDOWS.."

163