Jump to content

encryption certificates


michael879
 Share

Recommended Posts

ok last month I had no clue what certificates were. Some abbreviation made me think they were related to https. I kept being blocked by a site by something I couldnt figure out. It was browser dependent so it wasnt my IP (turned out to be user agent). Stupidly, I went into certificates a removed a bunch of them. One of them was the one used for file encryption. This was about a week after I had encrypted all of my documents.

Ive read that removing certificates doesnt delete the key, which is good since I know how hard RSA is to crack (Id have to build a quantum computer). Im pretty sure Ive found some files from my old certificate since they match the new one pretty well. the files are:

C://documents and settings/Michael/Application Data/Microsoft/Crypto/RSA/some long hex number

there are 5 files here, 2 are completely irrelevant (unless JSE and JavaWebStart are random strings) and one simply has a bunch of "blanks" and then my name. The other two are long, and contain two hex numbers one of which is the thumbprint of my current certificate. The two documents are very similar but the hex numbers are different.

C://documents and settings/Michael/Application Data/Microsoft/SystemCertificates/My/Keys/some long hex number

there are two files here, both very similar to each other. They also both contain the long hex numbers contained in the previous two documents.

C://documents and settings/Michael/Application Data/Microsoft/SystemCertificates/My/Certificates/some long hex number

There is only one file here, and it contains one of the hex numbers in the previous documents.

Since it seems like the key file is still there for my old encryption (and Ive read people mentioning restoring removed certificates) Im guessing there must be some way to recover my documents. any help?

Link to comment
Share on other sites

I would first try login in as the default admin or whatever recovery agent you have and see if you can decrypt the files that way first.

You could also try changing your password through the control panel, user account tool, restarting, login then change it back to the original, restart, login. Then try using cipher.exe from a command prompt to backup your efs cert/keys. If you have cipher, xp home does not.

Or maybe this...

http://www.beginningtoseethelight.org/efsrecovery/index.php

Link to comment
Share on other sites

I never changed my password and I am the admin. Before this problem I didnt know anything about windows encryption so I didnt make a recovery agent. The only way I can think of to fix this is to make a new certificate from the files that were left behind. However I have no idea how to do this. Im almost positive that the key is somewhere in the 2 kb file in the keys folder but Im also guessing that the public key is the hex number that is in all of them and the private key is probably encrypted or something.

Link to comment
Share on other sites

I would first try login in as the default admin or whatever recovery agent you have and see if you can decrypt the files that way first.

You could also try changing your password through the control panel, user account tool, restarting, login then change it back to the original, restart, login. Then try using cipher.exe from a command prompt to backup your efs cert/keys. If you have cipher, xp home does not.

Or maybe this...

http://www.beginningtoseethelight.org/efsrecovery/index.php

why wouldnt it be deleted? windows thinks I meant to remove the certificate (I removed the personal certificate for encryption). I know the files still on my computer because I ran the free trial of EFS and it found the key, but if the file is in my recycling bin or something it may be deleted...

anyway, what did you tell me that would help? I am the admin of my computer, I have no recovery agent, and I dont see how changing my password would do anything, I deleted the certificate and now the new one uses a different key. I didnt see that link and the cipher command before, Ill check them out.

Link to comment
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

 Share

×
×
  • Create New...

Important Information

We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue. Privacy Policy