ToolsTools available for working with EFS-encrypted files include cipher and esfinfo. CipherThe following statement is the syntax of the command. Table 6-2 explains the switches. cipher [{/e | /d}] [/s:foldername] [/a] [/i] [/f] [/q] [/h] [/k] [/u[/n]] [{pathname[...]]To back up certificates and keys to a file called efskeys: To encrypt the reports folder and all subfolders: To encrypt a single file, in this case the JanuarySales.doc in the Midwest\Sales folder: To determine which files in the JanuarySales folder are encrypted: To remove data remnants in the D volume:
Cipher /w does not lock the drive. Other programs can still operate and thus may prevent cipher from erasing portions of the drive. For this reason, stop these programs and do not use the drive until cipher has completed this task. Cipher /w can take a long time to complete. Do not use cipher /w unless it is necessary. EsfinfoEfsinfo.exe is a command-line tool available in the Windows Server 2003 Support Tools and the Windows XP Professional and Windows 2000 Resource Kits. It can be used to display the encrypted files in a folder and list the certificates used to encrypt a file. You can also download esfinfo from http://www.microsoft.com/windows2000/techinfo/reskit/tools/default.asp. |