Windows Vista Tips

Windows Vista Tips > Newsgroups > Windows Server > Server Security > Folder Level EFS permissions (File Server)

Reply
Thread Tools Display Modes

Folder Level EFS permissions (File Server)

 
 
netsec545
Guest
Posts: n/a

 
      06-20-2009
I'm trying to find a simple way to give multiple users access to my EFS
shares on my file server. Manually importing certificates to each of the
thousands of subfiles, is not an option. Is there any way to grant folder
level EFS permissions? Or is it possible to grant security group permissions
using EFS?

I have the following quote from another website...When is this "Future
Release"

Currently, encrypting files and folders to multiple users is not supported.
Additionally, encrypting files or folders is not supported on network shares.
(This functionality will be enabled in a future release.)

 
Reply With Quote
 
 
 
 
Marcin
Guest
Posts: n/a

 
      06-21-2009
Starting with Windows XP, it become possible to facilitate access to
encrypted files to multiple users. As far as using EFS to protect file
shares is concerned, this is possible via either delegated server mode or
EFS over WebDAV (starting with Windows Server 2003). For more info, refer to
http://technet.microsoft.com/en-us/l...7065.aspx#EJAA

hth
Marcin

"netsec545" <> wrote in message
news:4E1D5168-B95D-4236-9069-...
> I'm trying to find a simple way to give multiple users access to my EFS
> shares on my file server. Manually importing certificates to each of the
> thousands of subfiles, is not an option. Is there any way to grant folder
> level EFS permissions? Or is it possible to grant security group
> permissions
> using EFS?
>
> I have the following quote from another website...When is this "Future
> Release"
>
> Currently, encrypting files and folders to multiple users is not
> supported.
> Additionally, encrypting files or folders is not supported on network
> shares.
> (This functionality will be enabled in a future release.)
>



 
Reply With Quote
 
netsec545
Guest
Posts: n/a

 
      06-21-2009

Thanks Marcin, however, the problem is not facilitating access to the
encrypted files. The problem is managing user access once the files are
encrypted. WebDAV will give me the ability to ensure the file remains
encrypted in transit, but that again is not my problem.

I have already enabled encryption via EFS on the file share. Once I enabled
the encryption, all sub-folders and files became encrypted using the
certificate I enabled the encryption with. The file share contains thousands
of files.

I have opted to export the key of the certificate I encrypted the file with,
and install this key on each end users system which require access, as well,
I installed the cert into their local profile on the file server. I also
plan on researching credential roaming so I don't have to manually install
the cert into their local cert store on the file server, but have not been
able to update my 2003 schema yet.

The problem I know run into is what if I want to add another certiface to
the file share, and then another. Or, what if a user with a valid
certificate is terminated, how do I remove that certificate from the file
share with thousands of sub-folders/files. Or, what do I do when the
certificate expires and I need to renew it on all the sub-folders/files.

The only way I have found to do this so far is manually touch every file,
and add/remove the certificates in question. Or, i'm told the cipher command
can script some of this for me, but this is not ideal as it requires a lot of
administrative overhead.

What I need is a gui interface to manage the certificates at the folder
level, and an option to assign a certificate to a security group, so I can
manage file share access by groups, instead of individuals.

Will this ever be available natively through Windows? It seems like a
fairly easy task to be left out of the EFS infrastructure. Without these
abilities, EFS is essentially useless for the larger enterprise.

Thanks,

Jeremy

"Marcin" wrote:

> Starting with Windows XP, it become possible to facilitate access to
> encrypted files to multiple users. As far as using EFS to protect file
> shares is concerned, this is possible via either delegated server mode or
> EFS over WebDAV (starting with Windows Server 2003). For more info, refer to
> http://technet.microsoft.com/en-us/l...7065.aspx#EJAA
>
> hth
> Marcin
>
> "netsec545" <> wrote in message
> news:4E1D5168-B95D-4236-9069-...
> > I'm trying to find a simple way to give multiple users access to my EFS
> > shares on my file server. Manually importing certificates to each of the
> > thousands of subfiles, is not an option. Is there any way to grant folder
> > level EFS permissions? Or is it possible to grant security group
> > permissions
> > using EFS?
> >
> > I have the following quote from another website...When is this "Future
> > Release"
> >
> > Currently, encrypting files and folders to multiple users is not
> > supported.
> > Additionally, encrypting files or folders is not supported on network
> > shares.
> > (This functionality will be enabled in a future release.)
> >

>
>
>

 
Reply With Quote
 
 
 
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Folder permissions - How to stop users changing top level folder names but allow sub-folders to be altered Alan Windows Small Business Server 6 02-23-2010 08:58 PM
Home Folder server NTFS permissions and share permissions?! UselessUser Windows Server 1 03-10-2008 01:19 PM
Manage all server folder/file permissions from MMC? Neale Active Directory 8 09-02-2006 10:38 AM
File/Folder Permissions on New Server- Access Denied Marlo Montanaro Active Directory 5 08-11-2005 09:38 AM
folder and file secure level pang Windows Small Business Server 1 01-15-2005 02:37 AM



1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59