EFS, password change denies access to encrypted data

Hi,
Has anyone had the issue with admin changing users password in Console One
resulting in users not being able to access their encrypted data.
Laptop users are using EFS to encrypt their data.
These users have WinXPPro SP2 and we are running ZfD 6.5SP2.
I have found IR 1 for ZfD 6.5 SP2 which includes TID3003874 "Personal IE
certificates and EFS stop working after password change" however this does
not fix the issue.
Could someone explain in more detail what this fix does as I may have
misunderstood what this fix is.
Regards,
Eric.

I know this is an old thread, but I thought it would be best to those who
found it realized that the best method for addressing this issue may be
found here:
http://www.novell.com/support/viewCo...rnalId=3724689
However the MS article could still be useful for some.
Craig Wilson - MCNE, MCSE, CCNA
Novell Support Forums Volunteer Sysop
Novell does not officially monitor these forums.
Suggestions/Opinions/Statements made by me are solely my own.
These thoughts may not be shared by either Novell or any rational human.
"ghoskins" <[email protected]> wrote in message
news:[email protected]..
>
> I'm having the same problem. I ran acrosss this Microsoft KB and it
> seems to fix the issue. I'm not certain this is the best security
> practices, but it does work.
>
> 'User cannot gain access to certificate functionality after password
> change or when using a roaming profile'
> (http://support.microsoft.com/default...b;en-us;331333)
>
>
> --
> ghoskins
> ------------------------------------------------------------------------
> ghoskins's Profile: http://forums.novell.com/member.php?userid=12306
> View this thread: http://forums.novell.com/showthread.php?t=215857
>

Similar Messages

  • Password change issue when updating user data in SAP ABAP system

    Hi Guru's,
    One of my reconciliation tasks part of the reconciliation job I've created is doing some strange password updates.
    As you can see below the task selects all users part of my identity store that are part of the account attribute of the particular ABAP system.
    Once these users are selected the task updates different data like username, validto, ... but the task is updating a lot of other things that are not part of the destination tab. What is causing the biggest issue is the password fields that are updated in the ABAP system like, password, productive password, ...
    Can you please advise if I missed something and how to solve?
    Thanks a lot,
    Laurent

    Hello Steffi,
    Yes in the ABAP systems they have the same timestamp. No other jobs are running at the same time.
    It is only happening to a few users depending on the ABAP system. On some ABAP systems there are only a few users for which the PW is reset and other systems 300.
    Example below of a system where I updated all user. In my pass only the following attributes should have been pushed thru to the ABAP system.
    However the valid from, accounting number and password have been updated as well.
    Thx,
    Laurent

  • Keychain, private encrypted data

    I had to reset my Adobe password, and chose the auto password suggestion that popped up, and said yes to saving it in my keychain. It is now saved there and will auto fill when I need it, but I also want to open it in keychain to see what the password actually is. When I go to keychain, the new password is there in "private encrypted data" and it asks for a password to open the keychain window that shows the password.
    Trouble is, i don't know what the password is; I didn't set one for it, and my keychain ones don't work. How do I find out what the password is to open the keychain file to find out what my Adobe password is..?
    Thanks

    If the prompt looks like this
    Then it wants your Mac OS X Admin password, unless you have given your keychain a different unique password (something you would have had to manually do, and hopefully you would remember if you did).

  • Oracle encryption vs encryption in servers - dba access to unencrypted data

    Hi Guys,
    I have an application that consists of ca. 20 java servers and batch programs connecting to an oracle 11g instance. Some of the columns of the database are enrypted. This is achieved via jce (keys stored in HSMs, one can configure specified database columns etc).
    I would love to use Oracle encryption instead but I gather there was some requirement from the customer that dbas could not just get access to the unencrypted data.
    Is there any way around this requirement ?
    Rgds
    Peter

    Hello,
    ... there was some requirement from the customer that dbas could not just get access to the unencrypted data.
    Is there any way around this requirement ?I'm not sure to understand, for all I know, in 11g you have the possibility to Encrypt data (Data Transparent Encryption) at the Table level or Tablespace level as well.
    For that Oracle uses a Master Encryption Key. This is true, the Master Key is stored outside from the Database (for instance by using an Oracle Wallet) so that the Security Administrator responsability can be separated from the Database Administrator one.
    So, afterwards, it depends on who has the Security duty. The access to the Master Key is a key question:
    "+Security is enhanced because the wallet password can be unknown to the database administrator, requiring the security administrator to provide the password.+"
    You'll have much more informations on the link below:
    http://download.oracle.com/docs/cd/E11882_01/network.112/e10746/asotrans.htm#g1011122
    Hope this help.
    Best regards,
    Jean-Valentin

  • My computer continually asks me to enter my password for Keychain access. This problem is continuos and I am having trouble with eliminating it. I have changed my password through Security and my Accounts numerous times to no avail.  Is there anythin

    My computer continually asks me to enter my password for Keychain access. This problem is continuos and I am having trouble with eliminating it.
    I have changed my password through Security and my Accounts numerous times to no avail.
    Is there anything I can do other than Resetting the entire computer and re installing all of the software, apps, etc.etc.

    Back up all data before proceeding.
    Launch the Keychain Access application in any of the following ways:
    ☞ Enter the first few letters of its name into a Spotlight search. Select it in the results (it should be at the top.)
    ☞ In the Finder, select Go ▹ Utilities from the menu bar, or press the key combination shift-command-U. The application is in the folder that opens.
    ☞ Open LaunchPad and start typing the name.
    Select the login keychain from the list on the left side of the Keychain Access window. If your default keychain has a different name, select that.
    If the lock icon in the top left corner of the window shows that the keychain is locked, click to unlock it. You'll be prompted for the keychain password, which is the same as your login password, unless you've changed it.
    Right-click or control-click the login entry in the list. From the menu that pops up, select
              Change Settings for Keychain "login"
    In the sheet that opens, uncheck both boxes, if not already unchecked.
    From the menu bar, select
              Keychain Access ▹ Preferences... ▹ First Aid
    There are four checkboxes in the window that opens. Check all of them. if they're not already checked. Close the window.
    Select
              Keychain Access ▹ Keychain First Aid
    from the menu bar and repair the keychain. Quit Keychain Access.
    If you use iCloud Keychain, open the iCloud preference pane and uncheck the Keychain box. You'll be prompted to delete the local iCloud keychain. Confirm. Then re-check the box. Follow one of the procedures described in this support article to set up iCloud Keychain on an additional device.

  • RBACx Encrypted Password Change Utility

    Hi all,
    In the OIA/SRM installation guide, there is a reference to a tool, to find out the password of rbacxservice.
    "Oracle Identity Analytics utilizes an encrypted password when communicating with the database.
    To change the default database password, use the RBACx Encrypted Password Change Utility"
    Could you please help me finding out this tool.
    Many thanks in advance.
    Warm regards,
    Manipradeep Sunku.

    The mentioned tool only encrypts the password so that you don't have to store a plain text password in the config file. It does not decrypt it. The default rbacxservice password is rbacxservice.
    The tool does not come with the OIA/SRM distribution so if you need it, you will need to contact support.

  • I am being asked to upgrade to iCloud Drive but indications are that I will not be able to access up to date details on any of my documents on my Mac without going into iCloud first.  Have I got this interpretation right or can I save changes to acce

    I am being asked to upgrade to iCloud Drive but indications are that I will not be able to access up to date details on any of my documents on my Mac without going into iCloud first.  Have I got this interpretation right or can I save changes to access the new versions on my iMac?

    That is Apple's statement:
    Using iWork with iCloud Drive - Apple Support
    Options for iWork customers
    You can upgrade to iCloud Drive today if you want to keep your documents up to date in iOS 8 and OS X Yosemite, and you want to use the iWork web apps on iCloud.com and the Share via iCloud feature.
    You can upgrade to iCloud Drive later if you want to keep your documents up to date with your apps on iOS 7 or earlier and OS X Mavericks or earlier.
    Upgrade to iCloud Drive today
    To access the most recent versions of your documents from a Mac with OS X Mavericks or earlier, you’ll need to go to iCloud.com and access Pages, Numbers, and Keynote from there. On a PC, you can install iCloud for Windows and set up iCloud Drive.
    If you upgrade to iCloud Drive now:
    Your documents will keep up to date across devices with iOS 8, Macs with OS X Yosemite, PCs with iCloud for Windows, and iCloud.com.
    Your documents will no longer keep up to date on devices with iOS 7 and Macs with OS X Mavericks or earlier.
    You’ll be able to use the iWork web apps on iCloud.com.
    You’ll be able to use the Share via iCloud feature with iOS 8, OS X Yosemite, and iCloud.com.
    Documents you previously shared via iCloud will be accessible to collaborators.
    Upgrade to iCloud Drive later
    Note that until you upgrade your iCloud account to iCloud Drive, you won’t be able to use the iWork web apps on iCloud.com or the Share via iCloud feature.     If you don’t upgrade to iCloud Drive at this time:
    Your documents will keep up to date across devices with iOS 8 and across devices with iOS 7 and Macs with OS X Mavericks or earlier.
    You won’t be able to use the iWork web apps on iCloud.com.
    You won’t be able to use the Share via iCloud feature.
    Documents you previously shared via iCloud won’t be accessible to collaborators until you upgrade to iCloud Drive.

  • Data access in reports after changing Member Access profile

    Hi All
    I made changes in the member access profile of a user (while current system was available for User Planning).
    After making and applying these changes in Access profile, the Current view in the report accessible to user got updated.
    But the problem was in reporting, where the updates didnot happen.
    Please suggest for necessary steps so that user get updated report as per change in Member access profile.
    Thanks in advance.
    Regards
    Abhishek

    Hi Lokesh
    Thanks for the reply.
    1. Report is based on CV
    2. With another ID assigned to same member access profile, the report is showing complete data.
    I mean with X user id 100 data sets are showing while with Y user id only 95 data sets. Where both X and Y are having same Member Access Profiles.
    Regards
    Abhishek

  • Can I change the access password / key? It is so long and not easy for visitors

    Can I change the access password / key? It is so long and not easy for visitors to use and connect to wifi

    Agreed about predefined WiFi key. You will find it in clear and capable of being changed under Advanced Settings / Wireless Settings / WPA.

  • No Thunderbird access now Yahoo password changed

    Hi
    Was advised by BT to change my BT yahoo password. I did this and although I can access my emails direct through BT Yahoo, I can no longer access them in Thunderbird.  I get a message saying
    "Sending of password did not succeed. Mail server mail.btinternet.com responded. Error logging in. Please visit http://mail.yahoo.com"
    This is the 2nd time this has happened.  Clearly the first fix BT sorted gets lost as soon as the password is changed again. Anyone else have this problem? Is there a permanent fix?
    Thanks
    Solved!
    Go to Solution.

    Thunderbird will be unaware of your password change and will keep using your old password and fail.
    You need to go into the account settings within Thunderbird and change the saved password so that it matches your new one, by overwriting the old one.
    Thunderbird will then use the new password when it tries to get your mail.
    There are some useful help pages here, for BT Broadband customers only, on my personal website.
    BT Broadband customers - help with broadband, WiFi, networking, e-mail and phones.

  • HELP! Password Expired & Must Be Changed but Access Denied when trying to do so

    Hi,I have an HP 5740e thin client and for some reason the local user account is requiring a password change.  Yet, when I try to change the password it says Access Denied.  And further, I can't get it to allow me to switch to a different account like Administrator to login.  I've held down the SHIFT key when booting, but it still goes straight to that local user account & the expired password prompt. I'm stuck in an endless loop and don't know how to get out of it.  Safe Mode puts me into the same situation.  And I can't update BIOS because I can't get in at all. OS = Windows Embedded Standard 7 I've also tried to reinstall the latest image off the HP website using a USB drive but it fails every time. I've tried 2 different USB drives with same exact error no each.  Image trying to install = SP56020ERROR:  An unexpected condition occurred Does anyone have a suggestion?

    I was finally able to get in as Administrator using RDP from my desktop.  I didn't realize that the thin client name was missing a digit so that's why I was unsuccessful prior to this. Once I got in remotely, I was able to look at the permissions for the local user account.  Now I see what was wrong.[Checked]      User cannot change password[Unchecked] Password never expires I still don't know why I couldn't install a new factory image, but at least I'm now able to work with this unit.  I also disabled the auto login for now. Sorry to have littered the Forum!  

  • Customizing Oracle Web Access Client password change

    We need to turn off the built in Password Change feature in the Oracle Web Access Client of Collaboration Suite or, an even better option, redirect it to our custom built change password application. It appears in the client under Preferences in the same pop-up window as General and Time Zone. We've been poking around in the file structure and trying to find what renders this page. Can anyone offer any help?
    Thanks.
    Troy

    Hello,
    You can't do that in WAC but in the Webmail interface > Preferences > Account > Folders you can set this for Oracle Mail.
    Hope it helps.
    Irina

  • HT5622 I keep on getting emails asking me to reset my password when I haven't requested a password change. Is somebody trying to access my account as i've had 4 emails now in last 3 days?

    I keep on getting emails asking me to reset my password when I haven't requested a password change. I somebody trying to access my account as i've received this msg like 4 times in last few days now?
    Thanks

    If you use Mail.app, hover your cursor over any of the links in the emails you're receiving to see if they lead directly to an Apple-owned subdomain, like so...
    If the links in the email(s) you received are exactly like this, then it's possible there's an issue with your account that you should probably follow up on. If they don't look like exactly like this, then these are phishes, and you can post screenshots of those links here so that someone from Apple can follow up on them. (Best not to click on these!)

  • Lost old Apple ID password,Apple ID request/did password change,still can't access old ID

    -Went to update some iPad Apps
    -Said I had to sign in with Apple ID
    -My OLD email/Apple ID showed with the prompt for the password
    -I entered what I thought the OLD ID password was
    -Prompt said it was wrong, tried options, still wrong
    -Prompt said I could change my password
    -Changed via an email sent by Apple to my NEW email/Apple ID
    -Went back to sign into my iPad under my OLD email/Apple ID with the new password
    -Still rejected. Most likely because the password change was for the NEW Apple ID but had to try.
    -Tested the NEW password under the new Apple ID and it worked
    -Soooo....I can't get into my apps, under the requested OLD Apple ID because I don't have the OLD password and there's no way to change the OLD password without knowing it. 
    -So now I can't update important apps such as iOS Numbers, iOS Pages and the like..........
    Any suggestions.................?

    Go here, find the instructions for your country and initiate a dialog with Apple in order to get their help.
    Contact Apple for help with Apple ID account security - Apple Support

  • Encrypting Data on part of a file system.

    A few months ago, using hints I found on the internet, I was able to use diskutil command line utililty to create an encrypted partition of the same sort as when turning FileVault on in Security Preferences.  File Vault doe not appear to offer a way to choose some pargt of the disk storage such as an entire drive of a folder on a drive.  I was able to do it and it worked.  When I mount the disk partition to the system (usualy by plugging it in and turning it on), I'm asked for the security pass phrase or key to decrypt it.  Once mounted with the key supplied, I can access it as any other mounted disk with the type of access restrictions that might be present on any disk.Since I want the data to be truly privatem U decline to put the key into the a known place such as the keychain.  I don't want just anyone who has a log on to this iMac to b e able to read this data.  I want them to need to enter a private key to mount the data. 
    My only problem with this is the hoops I needed to go through to do this.  It is complicated and invovlves setting up special partitions for the purpose.
    Searching Finder help for encrypting data it offered a solution for data on a removable drive.  The stepsare very simple and easy to do:
       a) Mount the files to be encrypted if they are not  online.  They also need to be in a folder or even an entire partition.
        b) Open Disk Utility (GUI version)
        c)Choose File > New > Disk Image From Folder (or New-> Disk Image ffrom a Device).
        d) Select the folder or disk you want to encrypt.
        e) A save dialog will pop up.  Select the name of the archive you wish to create and select a location.  I choose a removable disk partition which has enouh space.  Select Compressed if you wish.  Then Select Encryption and choose the key size for encryption from the drop dwon.  When you click Save, Disk Utility begins creating a disk image that is (possibly) compressed and probably encrypted.  Once done, the files in the folder or partiion are hiddent behind the encryption.  To get to them, you much open the DMG file and supply the password to unlock the encryption.  You can save the key in the keychain if you are not worreid about who can get in.  If you wish to restrict access to fewer people, keep the key secret and provide a recovery mechanism that is suitable for you need.
       f)  One the archive is created, the disk partition containing it may b4 mounted on the system (if it is not there already) and by opening the dmg file you will be asked for the key.  The system will validate that the key works and the encryption and comprewssion are working.  The archive will be mounted as a virual disk.  It can be accessed by any useer of that computer unless the file permissions get in the way.  Mounting it only when the computer is being used by authorized people allow you to mount and dismount the archive for use during a limited time.
    I have a couple of questions here.  Is there an easier way to do this?  Is this encryption as strong as that used in FileVault? 

    No. I don't know why it would not be, except it is easier for a person to leave the disk mounted where anyone can then see it. With FileVault forcing a password on wake from sleep, it will likely be encrypted if anyone found it.
    I'm not sure why you went to the trouble you did before, except the instructions might have been to create an encrypted partition as opposed to creating the disk image. Disk images have been around for at least a decade.
    If you plan on backing up the image with Time Machine, use a sparse bundle disk image as it will write the data to small files, called stripes. Only the stripes that change get backed up instead of the entire image.

Maybe you are looking for