Restoring EFS encrypted files and dirs from backup?
Tech details:
Acronis Backup & Recovery 10
Windows 7 x64 Professional
Here's my situation:
I have been doing periodic system backups of my desktop computer to an external portable hard drive. I have several directories containing sensitive information (email archives, tax and social security data, etc.) that I encrypted with EFS. I absolutely need those directories; some of them are Quickbooks and Quicken archives.
I had a system crash last week. I attempted to restore everything to the same hard drive using the latest boot disk (date of the latest for version 10 seems to be 9/2011) that I found on this support site. I kept getting the restore bombing in the middle of about 450 GB with a message that the archive is corrupted. (I know I should run "validate" on the archive to be certain, but I just haven't had the time... my laptop will take about 10 hours to complete this.)
So, perhaps I will need to drag individual folders of data off of the backup and just restore them to a new version of Windows on the desktop.
I tried working with the "Explorer" quick view of the last backup set on my laptop (Windows Vista Home). (I mean the view you get when you double click one of the .tib files.)
What I am finding is that the Explorer view of the backup does not permit any of the encrypted files to be dragged and dropped from the explorer window to a "real" directory. I realized that the EFS encryption on those files (from my desktop computer) is not allowing that access.
So, I found the "certificate" file, with extension .pfx, from when I set up the encryption on the desktop. I successfully installed this certificate file to the laptop, and I can view its fields in Microsoft Management Console and it is assigned to the laptop user account.
NOW when I double click an encrypted file in the backup set on that laptop, Notepad opens up and I do see data in the files from the encrypted files. (It came up blank before.) I'm opening up like log files that are encrypted and they show lines of log text.
HOWEVER... I have tried to restore individual encrypted directories from the backup set to my laptop by restoring by file. (By using Restore in Acronis and specifying individual folders to restore.) Nothing gets restored - just empty directories.
There is a field in the certificate in MMC - Enhanced Key Usage - that seems to be the issue:
Encrypting File System (1.3.6.1.4.1.311.10.3.4)
I found by Googling that if a .1 is present at the end of this code, then the usage is good for recovery, not just EFS. The "Intended Purposes" column in MMC says "Encrypting File System." Says nothing about recovery. I'm thinking that is the issue.
This is the only certificate I have. I do have the old hard drive from the desktop. I know there is a key ID written to the HDD that somehow is used by EFS.
I have a new hard drive on order. I am suspecting that the old hard drive had problems.
Two questions:
1) Will I be able to extract my encrypted data with what I have in hand now and see it in the clear on the desktop again?
2) Is there any way without doing a full partition level restore of obtaining the encrypted files in the backup set, by restoring by file or directory?
Thanks.

- Log in to post comments