When multiple Encrypting File System certificates are installed, which one is used for encryption? (2024)

7

To encrypt a file or folder in Windows, you basically go to its Properties and check Encrypt contents to secure data. Windows will use the certificate for Encrypting File System (EFS) that is installed in the Certificates Manager (certmgr.msc) that usually goes under Personal → Certificates. So when there is only one EFS certificate available, you know which one is used to encrypt files.

In my case, I have several EFS certificates installed. I don't know which one is the original one and which ones were installed later, and more importantly, I don't know which one is actually used to encrypt a file when I check that box.

Is there any way to know exactly which certificate is used for encryption?

In Microsoft's instructions for Backing up Encrypting File System (EFS) certificate it says "If there is more than one EFS certificate, you should back up all of them." Does that mean all installed certificates will be used for encrypting files and therefore all of them will be needed for decrypting?

When multiple Encrypting File System certificates are installed, which one is used for encryption? (1)

Ben N

39.2k1717 gold badges137137 silver badges173173 bronze badges

asked Aug 15, 2015 at 6:39

When multiple Encrypting File System certificates are installed, which one is used for encryption? (2)

oradorad

37166 silver badges1717 bronze badges

Add a comment |

7

Answering to myself:

Use this command to list all encrypted files on the system:

cipher /u /n

Use this command to display certificate info for the specified file.

cipher /c <file>

By default Windows uses the EFS certificate that expires latest for encrypting files and folders. The easiest way to manage EFS certificates in Windows is to use the Manage File Encryption Certificates wizard (rekeywiz) to renew and backup certificates.

answered Aug 16, 2015 at 1:02

When multiple Encrypting File System certificates are installed, which one is used for encryption? (4)

oradorad

37166 silver badges1717 bronze badges

Add a comment |

4

To find:

  1. which certificate was actually used on a particular file:you right click on the file to see the propertiesSelect Advanced Select Details next to the Encrypt check box

A popup appears which tell you which certificate and thumbprint was used to encrypt that particular file The thumbprint match the certificate thumbprint inside the certificate manager.

  1. which Certificate is going to be used (the default encryption certificate)

Answer: There is a wizard under user accountWindows7Control Panel\All Control Panel Items\User AccountsLeft:Manage your files encryption

The wizard will let you:Select which certificate to use for ALL new encryptionExport ItREencrypt all/select disk/folders with the new certificate

Command Line for wizard (rekeywiz) thanks to http://pcsupport.about.com/od/commandlinereference/a/run-commands-windows-7.htm

cf:http://www.windows7teacher.com/user-accounts-tutorials/63/how-to-manage-your-file-encryption-certificates-in-windows-7.html

If there is more than one EFS certificate, you should back up all of them.

a) Only the current one is used for future encryption

b) But, When multiple certificate are present, you dont know which one were used in the past. So you potentially need all of them to decrypt any file. Thats why microsoft recommends to save all of them. Otherwise you can re-encypt all your files using the wizard mentionned above (which basically replace the old certificate by the current one)

When multiple Encrypting File System certificates are installed, which one is used for encryption? (5)

laverya

58711 gold badge44 silver badges1111 bronze badges

answered Jul 26, 2016 at 18:16

When multiple Encrypting File System certificates are installed, which one is used for encryption? (6)

sysarchiteksysarchitek

8155 bronze badges

1

Add a comment |

2

Only one certificate is used by default, the one with the public key registered to that user. (Verified experimentally.)

If you don't want to use a command-line utility to figure out which certificate will be used, you can use the Certificates Manager snap-in for MMC. Open the Local Machine scope (or run certlm.msc) - no administrator privileges necessary, but you will be asked to elevate if you are an admin. Navigate with the left pane to Trusted PeopleCertificates. You'll see a list of users on the machine who have EFS certificates. Double-clicking an entry produces the properties dialog of the user's EFS certificate.

If you had instead opened the Current User scope (certmgr.msc) and navigated to the same folder, the one used for your EFS files would be the only one with your name that does not have a key on the icon.

answered Mar 3, 2016 at 23:56

When multiple Encrypting File System certificates are installed, which one is used for encryption? (7)

Ben NBen N

39.2k1717 gold badges137137 silver badges173173 bronze badges

1

  • It's a bit counterintuitive that the one used for EFS is the one without a key on the icon. What's the reason for that? And by the way within the Current User scope I have other certificates (with the key on the icon) which were used to encrypt data in the past, I'm no longer able to decrypt, when trying to export these certificate it says "the associated private key cannot be found", any ideas?

    kuma

    Apr 4, 2022 at 10:25

Add a comment |

Not the answer you're looking for? Browse other questions tagged

or ask your own question.

When multiple Encrypting File System certificates are installed, which one is used for encryption? (2024)
Top Articles
How To Pay Off High-Interest Debt | Money Guy
Genital Warts: Causes, Symptoms, Treatment & Prevention
Login Page
Euro (EUR), aktuální kurzy měn
Boomerang Media Group: Quality Media Solutions
Devotion Showtimes Near Mjr Universal Grand Cinema 16
Encore Atlanta Cheer Competition
Notary Ups Hours
Bbc 5Live Schedule
Culver's Flavor Of The Day Monroe
Mawal Gameroom Download
Labor Gigs On Craigslist
fort smith farm & garden - craigslist
Straight Talk Phones With 7 Inch Screen
111 Cubic Inch To Cc
Skyward Login Jennings County
1-833-955-4522
Loves Employee Pay Stub
Joann Ally Employee Portal
Craigslist Prescott Az Free Stuff
Conan Exiles Sorcery Guide – How To Learn, Cast & Unlock Spells
Empire Visionworks The Crossings Clifton Park Photos
Optum Urgent Care - Nutley Photos
How to Download and Play Ultra Panda on PC ?
John Chiv Words Worth
Utexas Iot Wifi
Pain Out Maxx Kratom
Delta Township Bsa
Pronóstico del tiempo de 10 días para San Josecito, Provincia de San José, Costa Rica - The Weather Channel | weather.com
Marlene2295
Page 2383 – Christianity Today
Kaiserhrconnect
Hermann Memorial Urgent Care Near Me
Afspraak inzien
Acadis Portal Missouri
Felix Mallard Lpsg
Cal Poly 2027 College Confidential
Wrigley Rooftops Promo Code
Riverton Wyoming Craigslist
Who Is Responsible for Writing Obituaries After Death? | Pottstown Funeral Home & Crematory
Acts 16 Nkjv
Locate phone number
Sechrest Davis Funeral Home High Point Nc
How To Customise Mii QR Codes in Tomodachi Life?
4k Movie, Streaming, Blu-Ray Disc, and Home Theater Product Reviews & News
Lawrence E. Moon Funeral Home | Flint, Michigan
26 Best & Fun Things to Do in Saginaw (MI)
Aznchikz
Ty Glass Sentenced
Skyward Login Wylie Isd
7 Sites to Identify the Owner of a Phone Number
Latest Posts
Article information

Author: Sen. Emmett Berge

Last Updated:

Views: 6262

Rating: 5 / 5 (60 voted)

Reviews: 91% of readers found this page helpful

Author information

Name: Sen. Emmett Berge

Birthday: 1993-06-17

Address: 787 Elvis Divide, Port Brice, OH 24507-6802

Phone: +9779049645255

Job: Senior Healthcare Specialist

Hobby: Cycling, Model building, Kitesurfing, Origami, Lapidary, Dance, Basketball

Introduction: My name is Sen. Emmett Berge, I am a funny, vast, charming, courageous, enthusiastic, jolly, famous person who loves writing and wants to share my knowledge and understanding with you.