Aller au contenu principal

Can not back up (and restore) a file encrypted with Windows 7 EFS file level encryption

Thread needs solution

I create a simple text file test.txt, and put the word "Hello" in it.
I right click using Windows Explorer (Windows 7 Enterprise), and go Properties, Advanced, Encrypt file to protect contents.

I make an Acronis File and Folder backup to back-up the file, and in Options, Advanced, File level security settings I check "In backups, store encrypted files in a decrypted state."

The Help says:
"In backups, store encrypted files in a decrypted state (the preset is disabled) - check the option if there are encrypted files in the backup and you want them to be accessed by any user after recovery. Otherwise, only the user who encrypted the files/folders will be able to read them. Decryption may also be useful if you are going to recover encrypted files on another computer....These options relate only to file/folder backups."

I run the backup.

When I explore the backup .tib file and click on the file, the contents are empty.
If I do a file restore, the restored file is there but the contents are gone and the file size is 0KB.

I am in the medical business and my group who has been using Acronis for years are concerned that are backups of encrypted files are worthless....

We just switched to File and Folder backups becasue we just read that Disk/Partition backups will not restore encrypted files to a new computer (if old one lost or stolen or dies); the possibility to check the decrypt state checkbox is not there for disk/partition backups.

I spent a wasted 2 hours with online chat support; we uninstalled and reinstalled and repaired using latest version 5576 that became available tonight, and it still does not work on either of my 2 computers.

Anyone have any ideas? Can someone try this and tell me if it works for you? Thanks much...

0 Users found this helpful

"We just switched to File and Folder backups becasue we just read that Disk/Partition backups will not restore encrypted files to a new computer (if old one lost or stolen or dies); the possibility to check the decrypt state checkbox is not there for disk/partition backups."

If you have the encryption key you should be able to access files from a restored partition on another computer. This is assuming you are using bitlocker. To do this you would have to restore the entire partition to an empty disk. It may also be possible to do the same thing by mounting the *.tib file as a windows drive or double clicking on the *.tib file in Windows explorer - it will only work if you are prompted for the encryption key. I have not tried any of these things but will do so and report back (may not be until Monday).

Ian

Thanks IanL-S; but we are not using Bitlocker. The drive itself is not encrypted, only certain files, via Properties...Encrypt... (i.e., EFS encryption). Thanks for any input.

The problem I have is that even on the SAME computer that had the file that was backed up, I still can't get restore to work - the file size is always 0.

I have exported my EFS certificates to a USB drive hoping that may help me someday... but it seems the data in the files doesn't even make it into the backup! - Not good.

There are reports of similar issues with individual file encryption. you may have better luck if you create a sector-by-sector backup. In ATI 2015 (if I recall correctly) you had to do that if bitlocker was used to encrypt the dirve/folder/file. With normal backup ATI cannot read the file as part of the compression process and apparently treats it as empty rather than jsut skipping the compression for that file. Alternatively the file may be copy portected. I could be wrong about this; may need to follow this up with Acronis technical support.

Ian

I did a test with Bitlocker (Win 10 Pro native encryption) both for individual files and a directory and when I double clicked on the archive file in explorer I was able to open the encrypted files without issue. Another file I encrypted with a third party application. In that case I had to copy the file before I could open it.

For some reason I could not mount the *.tib the module stopped responding.

It occurs to me that the encryption program may result in the file appearing to windows to be an empty file, so when the backup is made it is assumed that it is an empty file and act accordingly.

Ian

PS I was using the Acronis 2016 build 5576 (release two days ago).

Thanks for doing the test, Ian. Glad it works for you with Windows 10.

With Windows 7 Enterprise using native EFS file encryption is does not work on 3 of my computers... the files in the backup have 0 size.

This is with TI 2015 and TI 2016 build 5576.

I paid for a support issue, and verified with the agent that it does not work for me - he is investigating.... I'll post their suggestions/solutions if any.