Pains with EFS and Network Destinations

by Nicholas Dille on 08/04/2010 | 0 Comments | 1,718 Views

A few months ago, I have blogged about an annoying anomaly in the handling of EFS-encrypted files. My case was that copying fails for an EFS-encrypted file to a location where it cannot be encrypted by the source system (e.g. a file share). My colleague Helge Klein has apparently uncovered the cause: CopyFile(Ex).

Although his motivation for the article is the fact that an EFS-encrypted file is alwas copied unencrypted over the network, he describes that CopyFileEx accepts a flag to copy to a destination where the file cannot be encrypted and remains unencrypted (COPY_FILE_ALLOW_DECRYPTED_DESTINATION).

In my case this means that the authors of many backup tools do not seems aware of the existence of this flag. And I have tested at least a dozen of them.

My late article contains a plea to Microsoft to solve this issue. But I must admit that the plea should also go out to the developers of backup tools to include an configurable option to force CopyFileEx to allow for unencrypted files in the destination directory.

Pretty please ... with sugar on top!

+++ Your opportunity +++ Use Profile Migrator 2, the new sepago product that makes migrating user personalities between different platforms a breeze.! Download your free version now!

Add Comment

The content of this field is kept private and will not be shown publicly.
Captcha
This question is for testing whether you are a human visitor and to prevent automated spam submissions.
Image CAPTCHA
Enter the characters shown in the image.