professional documents
home
Upload
docsters
Upload
Powerpoint

Windows File Encryption System EFS center doc

educational

 


Windows Encryption File System (EFS) Tech Briefing July 18th 2008 http://www.stanford.edu/services/efs STANFORD UNIVERSITY • INFORMATION TECHNOLOGY SERVICES Agenda Stanford Users • What is EFS • What does it Protect • Is this for me? • Features • Data Recovery Agent • Getting Started • Demo - How to Encrypt • Demo – How to backup Key IT Support Staff • How to setup Data Recovery Agent 7/25/2008 Windows Encrypting File System (EFS) STANFORD UNIVERSITY • INFORMATION TECHNOLOGY SERVICES page 1 What is Encrypting File System (EFS) The Microsoft Windows Encrypting File System (EFS) is feature built into the file system of the Windows XP and Windows Vista operating systems. It lets you encrypt designated files on a local computer so that no other user can access your data. When a file is encrypted, EFS automatically decrypts the file for use and re-encrypts the file when it is saved. EFS is particularly useful for protecting data on a computer that might be physically stolen, such as a laptop. 7/25/2008 Windows Encrypting File System (EFS) STANFORD UNIVERSITY • INFORMATION TECHNOLOGY SERVICES page 2 What It Protects  EFS protects files you designated if your computer is lost or stolen.  If someone tries to break in or has access into your system to retrieve files, they will not be able to open the file even if they can see that it exists (as long as they do not have your SUNet ID and password).  Files copied to a Web folder using WebDAV are kept encrypted. 7/25/2008 Windows Encrypting File System (EFS) STANFORD UNIVERSITY • INFORMATION TECHNOLOGY SERVICES page 3 What It Doesn’t Protect or Prevent  It does NOT provide encryption to files that are: • Sent via email • Kept on a separate flash drive/thumb drive/USB drive/floppy disk • Moved over the network via shared folders (CIFS/AFS) • System and page file • Compress Files • Files moved into folder set to encrypt all files • Files form being deleted  When you are about to move an encrypted file, Windows will warn you that you will lose your EFS encryption. Keep in mind that whenever you move a file off of your computer, it is probably no longer protected by EFS. 7/25/2008 Windows Encrypting File System (EFS) STANFORD UNIVERSITY • INFORMATION TECHNOLOGY SERVICES page 4 Is this for me?  Reasons for using EFS • Want to secure files on your computer incase it is stolen or lost • You work with or store restricted data on your local computer • You travel and need to work with restricted data  Requirements Windows XP Professional Windows Vista Business, Enterprise or Ultimate Computer is a member if University Windows Infrastructure (AD) Users is logged on to the computer with their SUNet ID (WIN Domain), local computer or child domain accounts will NOT work • Hard drive is formatted with NTFS • • • • 7/25/2008 Windows Encrypting File System (EFS) STANFORD UNIVERSITY • INFORMATION TECHNOLOGY SERVICES page 5 Features  Microsoft Windows Encrypting File System (EFS) • Transparent encryption done at the file-system level • If a folder is marked, every file created or moved into it will be encrypted • File encryption keys can be archived (USB Flash Drive, File server) • There is no “back door” • Keys are protected with the users password on the computer • Data Recovery Agent to allow for recovery of files if user’s key is lost  Future Features  Additional Users can be added to a file  Group Policy to Auto Encrypt “My Documents” Folder 7/25/2008 Windows Encrypting File System (EFS) STANFORD UNIVERSITY • INFORMATION TECHNOLOGY SERVICES page 6 Data Recovery Options Once a file is encrypted only the users private key can access the file. Should this key get lost the data will be inaccessible. Options to protect the data include:  User copies key to USB flash drive and store separately from computer  Configure Data Recover Agent (DRA) • Domain Wide DRA • Local/Departmental DRA 7/25/2008 Windows Encrypting File System (EFS) STANFORD UNIVERSITY • INFORMATION TECHNOLOGY SERVICES page 7 Data Recovery Agent (DRA) These data recovery agents (DRAs) are a separate set of issued recovery certificates with public and private keys that can be used to recover files. Recommendation for DRAs • Local Systems Administrators • Separate flash drive (Iron Key) stored in secure location (safe) Requirements for Recovery • Admin will need read access to files at time of recovery • Password for the DRA Private Key 7/25/2008 Windows Encrypting File System (EFS) STANFORD UNIVERSITY • INFORMATION TECHNOLOGY SERVICES page 8 Getting Starting For End Users  Open a HelpSU Request  Once you have approval from your Local Support Staff that they have setup the DRA you can then choose directories to start encrypting.  Copy your Key to a External USB Drive 7/25/2008 Windows Encrypting File System (EFS) STANFORD UNIVERSITY • INFORMATION TECHNOLOGY SERVICES page 9 Demo 1 How To Encrypt Files 7/25/2008 Windows Encrypting File System (EFS) STANFORD UNIVERSITY • INFORMATION TECHNOLOGY SERVICES page 10 Demo 2 How to back-up Your Keys 7/25/2008 Windows Encrypting File System (EFS) STANFORD UNIVERSITY • INFORMATION TECHNOLOGY SERVICES page 11 Storing User Keys  Export and then Delete Key on local computer  External USB Flash Drive • NOT stored with your computer or in laptop bag • Encrypted (optional)What 7/25/2008 Windows Encrypting File System (EFS) STANFORD UNIVERSITY • INFORMATION TECHNOLOGY SERVICES page 12 Known Issues  DCOM Required 1. Start Registry Editor. 2. Locate the following path: HKEY_LOCAL_MACHINE\Software\Microsoft\OLE 3. Change the EnableDCOM string value to Y. 4. Restart the operating system for the changes to take effect. Note: There is a BigFix fixlet to re-enable DCOM  Vista and Symantec Bug – Patch available on ESS 7/25/2008 Windows Encrypting File System (EFS) STANFORD UNIVERSITY • INFORMATION TECHNOLOGY SERVICES page 13 Demo 3 How to Setup DRA 7/25/2008 Windows Encrypting File System (EFS) STANFORD UNIVERSITY • INFORMATION TECHNOLOGY SERVICES page 14 Questions and Answers  Extra Info for users and admins • Stanford Data Classification http://www.stanford.edu/group/security/securecomputing/datacl ass_chart.html • Windows Desktop File Encryption and EFS 7/25/2008 Windows Encrypting File System (EFS) STANFORD UNIVERSITY • INFORMATION TECHNOLOGY SERVICES page 15
flag this doc
69
1
not rated
0
7/24/2008
English
Preview

Storage Switch File Sytem Gateway Whitepaper

D27 12/29/2007 | 150 | 4 | 0 | technology
Preview

How File Fragmentation Occurs on the Windows XP/Windows Server 2003 by Diskeeper

emartin74 3/17/2008 | 111 | 0 | 0 | technology
Preview

Scalable Windows-Based NAS Using Melio File System

Biscuit350 4/8/2008 | 121 | 4 | 0 | technology
Preview

Chapter 5, File Services, from the book Windows to Linux Migration Toolkit

emartin74 3/17/2008 | 68 | 0 | 0 | technology
Preview

Encryption Strategies Whitepaper

D27 12/29/2007 | 129 | 2 | 0 | technology
Preview

Encryption Strategies Whitepaper

D27 12/29/2007 | 139 | 1 | 0 | technology
Preview

Lustre File System Whitepaper

D27 12/29/2007 | 237 | 5 | 0 | technology
Preview

Insight File System Outsourcing Report

daveingram 2/15/2008 | 172 | 4 | 0 | technology
Preview

About Encryption and Making Your System Secure

PrivateLabelArticles 3/15/2008 | 39 | 0 | 0 | business
Preview

3. File System Specifications for BD-RE, R, ROM

emartin74 3/16/2008 | 266 | 12 | 0 | technology
Preview

World Dairy Expo Sale Catalog.

PrivateLabelArticles 10/10/2008 | 18 | 0 | 0 | educational
Preview

Vendor Reservation Form 2008

PrivateLabelArticles 10/10/2008 | 19 | 0 | 0 | educational
Preview

UNMLA Calendar 2008 09

PrivateLabelArticles 10/10/2008 | 20 | 0 | 0 | educational
Preview

Troy Center October Calendar of Events

PrivateLabelArticles 10/10/2008 | 17 | 0 | 0 | educational
Preview

Troop schedule 2008 09

PrivateLabelArticles 10/10/2008 | 16 | 0 | 0 | educational
Preview

Guilderland New York Townews

PrivateLabelArticles 10/10/2008 | 15 | 0 | 0 | educational
Preview

Tillamook County Library Newsletter

PrivateLabelArticles 10/10/2008 | 16 | 1 | 0 | educational
Preview

Tiffany Dance Academy Newsletter

PrivateLabelArticles 10/10/2008 | 14 | 1 | 0 | educational
Preview

State Holidays 2008

PrivateLabelArticles 10/10/2008 | 13 | 0 | 0 | educational
Preview

Academy of Natural Sciences

PrivateLabelArticles 10/10/2008 | 16 | 0 | 0 | business
 
review this doc