EFS in Vista
Hello I have the following problem with EFS. I use the same certificate since july 2000, and tested it on Windows 2000, 2003 Server, XP and different early builds of Windows Longhorn-Vista. But now, afterinstalled Vista RC1 build, I can't access files from Windows XP or 2003 server, whichhave been encrypted in Vista. In the file properties it is shown that files were enypted with AES 256 bit using my certificate - but I still cannot access them in Windows XP. I suppose that encription algorithms were changed, but I found no technical documentation at all, and moreover cipher.exe says all files are encrypted using AES 256 bit, algorithm which is also used in Windows XP. Please, don't tell me about wrong certificate - this not the problem I experience. Can someone explain me what happened with EFS compatibility in Vista?
October 21st, 2006 2:13pm

I am having the same exact problem did you ever find an answer?
Free Windows Admin Tool Kit Click here and download it now
January 31st, 2007 8:34am

Is this on a RTM or on the RC1/ RC2 ? I heard about issues with Non RTM but this work fine for me in the RTM
February 1st, 2007 7:34am

I am using 64 bit RTM
Free Windows Admin Tool Kit Click here and download it now
February 1st, 2007 9:29am

No, I haven't founf thedecision of the problem and I had to install Vista both on my home PC and my notebook :)
February 2nd, 2007 9:36am

both in RC1 and RTM MSDN builds...
Free Windows Admin Tool Kit Click here and download it now
February 2nd, 2007 10:11am

I wish I could do that but I have to keep XP arround so I can VPN into work and for some older games.
February 2nd, 2007 4:49pm

anyone else have an update on this?
Free Windows Admin Tool Kit Click here and download it now
February 17th, 2007 4:17pm

I have the same problem with my files on a UsbDrive. I have vista at work and XP at home. Files encrypted with Vista EFS result in "Access Denied" when opening them in XP, even though Iuse the same certificate. Haven't found anything on this yet. There is probably some difference in implementation. Felipe MCSE+M CCNA Linux+
April 3rd, 2007 1:48am

I tried downgrading the cipher in Vista to use DESX, which is also compatible with Windows 2000. Still no success, though. I get "access denied" on Windows XP. If I encrypt the file on Windows XP I can read it on Vista. But if I encrypt it on Vista, Windows XP gets an access denied. Using a the "cipher /c" command on Vista reveals a difference between files encrypted on XP and on Vista. Look at this dump:--------------------------------E:\>cipher /c Listing E:\New files added to this directory will be encrypted. E classif.txt Users who can decrypt: FelipeC(FelipeC@nonono.br) Certificate thumbprint: 0973 D730 CCAF B4AA 08E3 BF46 1AEF 1380 BC7B 0352 No recovery agent found. Key Information: Algorithm: DESX Key Length: 128 Key Entropy: 128 E test.txt Users who can decrypt: E6489263\user [FelipeC(FelipeC@nonono.br)] Certificate thumbprint: 0973 D730 CCAF B4AA 08E3 BF46 1AEF 1380 BC7B 0352 No recovery agent found. Key Information: Algorithm: DESX Key Length: 128 Key Entropy: 128--------------------------- The first file was encrypted in XP and the second one on Vista. Vista seems to add more information to "Users who can decrypt". Anybody have a clue why?
Free Windows Admin Tool Kit Click here and download it now
April 3rd, 2007 3:44pm

Desx is rather weak, don't want to use it anyway. To my mind there is no difference in "FelipeC(FelipeC@nonono.br)" and "E6489263\user [FelipeC(FelipeC@nonono.br)]". Is"E6489263" the name of your PC? I still haven't found how to decrypt files encrypted in vista, and due to this bug (or unknown feature) and many other things finally gave up of vista temporary. It's so strange, that this "feature" hasn't been documented yet...
April 3rd, 2007 7:48pm

Yes, DES is weak. I tried it though to test for cipher compatibility. Doesn't seem to be a problem with the cipher though, but rather some difference in implementaion of EFS in Vista.
Free Windows Admin Tool Kit Click here and download it now
April 3rd, 2007 8:25pm

I can't but agree :-) I even tried to create newcertificate in vista, encrypt files with it, and try to decrypt them from XP- nothing works. But I will beamazed, if there wil be no workaround... can't believe thatmicrosoft changed the way vista works with cipher without any notification...
April 3rd, 2007 9:18pm

Iam havingthe same problem. For your information, I found a Microsoft article "Determining How Many Operating Systems to Install" (http://technet2.microsoft.com/WindowsVista/en/library/2e329c94-1135-430b-93c2-bad44d22c1691033.mspx), of which last sectionsays that EFSfiles can be shared between Vista and XP by exporting/importing the certificate.
Free Windows Admin Tool Kit Click here and download it now
April 6th, 2007 5:33pm

That's what we are doing. But in my case usinga usb drive. If Vista encrypts the file than XP can't read it. No use in losing sleep over this. I'm using TrueCrypt now...
April 6th, 2007 6:08pm

Any word on a fix for this, same problem here XP SP2 32bit dual booting with Vista 64bit RTM MSDN. Vista is happy but as soon as it encrypts a file XP just gets access denied!! Can't really start using Vista until I can safely access by files from both XP and Vista.
Free Windows Admin Tool Kit Click here and download it now
May 19th, 2007 3:15pm

I found an expert comment saying that Vista's EFS is not compatible with XP's. Also said that SP1 might solve the problem. http://blogs.msdn.com/spatdsg/archive/2007/06/07/efs-and-vista-and-xp.aspx cheers
July 6th, 2007 3:16pm

Windows Vista uses 256-bit AES keys for File Encryption Keys (FEKs), as well as Windows XP (SP1 or later).But the key length for user certificate in Windows Vista is different from that of Windows XP.Microsoft says that Windows Vista uses a 2048-bit RSA key for asymmetric key encryption.http://www.microsoft.com/technet/security/guidance/clientsecurity/dataencryption/planandimplement/54de4f8c-d962-4744-b2da-99f7ad7953df.mspx(Search for "User Asymmetric Key Sizes".)Also Widows Server 2008 uses 2048-bit RSA key.http://technet2.microsoft.com/windowsserver2008/en/library/f843023b-bedd-40dd-9e5b-f1619eebf7821033.mspx?mfr=trueWindos XP and previous versions use 1024-bit RSA key for that.This may be the cause of the problem.
Free Windows Admin Tool Kit Click here and download it now
July 29th, 2007 9:57am

seems it can't cause problem, because I use the same key both in Vista and XP
July 30th, 2007 8:17am

How did you manage? I get the same problem, the files encrypted in Vista Ultimate are not readable on a XP Pro machine. From what I read from the posts here everybody else has the problem, so how did you solve it? Thanks
Free Windows Admin Tool Kit Click here and download it now
August 6th, 2007 10:33am

More information:http://support.microsoft.com/kb/939391
August 8th, 2007 7:29am

lazy assholes, they admit there is problem, but "currently no solution available" - what were they doing all this time?
Free Windows Admin Tool Kit Click here and download it now
August 12th, 2007 8:31pm

I've queried MS on the issue and it doesn't sound like they're going to fix anything: Dear XXXX, Thank you for contacting Microsoft Customer Service Australia. My name is XXXX. As I understand it, before you purchase Windows Vista Ultimate you would like to know if the issue mentioned in Microsoft Support Article KB939391 will be addressed. If my interpretation is incorrect, please do let me know. XXXX, please be advised, I have escalated this enquiry to our escalations team for further assessment. Once I receive an update, I will reply to you immediately. The reference number for this enquiry is: XXXX Should you have further questions relating to other Microsoft products or services, please do not hesitate to let me know. I will be more than happy to assist you further. Alternatively, for immediate assistance, you can contact Microsoft Customer Service on 13 20 58 (Select Option 2 then select Option 1) from Monday to Friday, between 8am - 8pm. Thank you for contacting Microsoft. Kind regards, XXXX XXXX | Correspondence Representative | Microsoft Customer Service | Australia | Fax: +61 2 9870 2466 Dear XXXX, Thank you for your patience. XXXX, firstly, we would like to thank you for your e-mail. It's so important for us to hear from customers using our products, so please continue to send us feedback on what were doing well and what we can improve. Based on broad customer and partner feedback, one of the key changes we made in Windows Vista is around making the PC experience more secure. By design, some of these changes affect the way our partners deliver solutions and consequently, the ways customers use their PCs and work with applications. This can lead to some customer challenges early on. Today, we know more about the customer experience with Windows Vista than ever before around key dimensions of performance, reliability etc. We can use anonymous data to help us triangulate the feedback we get from our call support centers, our OEM partners and other forms of customer feedback. Thats helped us shape and focus the work, so we have the maximum positive impact on customer experience, delivering constant updates over time. Please know that Microsoft is absolutely focused on delivering the best enterprise and consumer experience. Well always have more work to do, but were confident about delivering the best set of experiences for our customers and partners now and in the future. Again, thank you for your feedback. Kind regards, XXXX XXXX | Correspondence Representative | Microsoft Customer Service | Australia | Fax: +61 2 9870 2466Got to love canned responses that do not address specifically asked questions...This is a real issue. It means one cannot access files encrypted via Vista's EFS with any other MS OS despite having the correct certificates!
October 29th, 2007 7:01am

I was wondering whether you have yet found a solution for this problem. You will note also that the RC1 release of SP1 for Vista also seems to have problems in relations to backward compatability between the RTM build and itself. What ever is going on with this still doesnt seem to have been fixed. Anybody want to tell me otherwise - please.
Free Windows Admin Tool Kit Click here and download it now
December 22nd, 2007 3:14pm

Any news about this now that SP1 is final?
April 9th, 2008 6:33pm

I found that this issue was finally resolved by Vista SP1 and XP SP3. Cheers.
Free Windows Admin Tool Kit Click here and download it now
May 9th, 2008 5:29pm

This topic is archived. No further replies will be accepted.

Other recent topics Other recent topics