Encryption in windows file server

I have a client requirement to encrypt the file and folders inside a sharedfolder
I selected the folder and from the properties, enabled a the encryption check mark and saved the generated certificate as recovery/access to users.
Is this a feasible solution or how can I properly encrypt file server in a domain and how to manage access to this folders without any change in file and folder permission
Amal RS

Hi Amal,
Based your description, we are using EFS to encrypt the shared folder.
As the following article states:  
EFS helps secure the information that is contained in our folders and files by creating a unique key that uses a combination of the server’s credentials and the user’s credentials.
Because EFS is so secure, it’s critical to enforce a strong password policy. It’s also a best practice to archive and back up the recovery keys for your domain and keep them in a safe place to ensure recovery should the keys become damaged or lost.
Help Secure your Business Information using Encrypting File System
http://blogs.technet.com/b/sbs/archive/2010/03/09/help-secure-your-business-information-using-encrypting-file-system.aspx
Besides, regarding EFS, the following articles can be referred to for more information.
Best practices for the Encrypting File System
https://support2.microsoft.com/kb/223316?wa=wsignin1.0
Encrypting File System
http://technet.microsoft.com/en-in/library/cc749610(v=ws.10).aspx
Best regards
Frank Shen

Similar Messages

  • Query on integrating windows file server into SAP KM using WEBDAV

    hi
    I have sucessfully integrated windows file server into SAP KM using WEBDAV. I have query in it regarding the possible validation against the portal Database user. Can we configure such that the user comparison happens for LDAP as well as database user. Have anyone configured such a scenario?
    Regards,
    Ganesh N

    Hi Ganesh,
    this should work in principle.
    However you would need a user in Active Directory for each user in the portal database that should connect to the file server if you are using the SSO22KerbMap Module as I assume.
    In my whitepaper I have mentioned this for the internal user index_service that does only exist in the portal database.
    Best regards,
    André

  • Portal on Unix cannot mount Windows File server

    Hi Experts,
    We had installed a NW 7.0 portal onto HP-UNIX server and integrated it with MS AD server. Now, we are facing an issue that we cannot mount windows files server when we tried to configured it with TREX. Had anyone tried this function or it is the limitation? Is the following statement still correct or do we have workaround solutions?
    "If you are using the Microsoft Active Directory Service, you can only integrate documents into a Windows portal. The combination of Microsoft Active Directory Service and a UNIX portal is not supported."
    Best Regards

    Hi Tom,
    have a look at this link:
    [http://help.sap.com/saphelp_nw04s/helpdata/en/ed/b334ea02a2704388d1d2fc3e4298ad/frameset.htm]
    Your issue should work, but the prerequisite is for using the windows permissions:
    "If you are using Microsoft Active Directory Service, you have to operate the Windows domain in mixed mode". If it is running in Native mode you cannot use the windows permissions. Nevertheless integrating documents into KM should work. The KM uses its own permissions instead.
    Best regards,
    Denis

  • Problem while integrating windows file server into SAP KM using WEBDAV

    Hi
    I am trying to integrate windows file server into SAP KM using WEBDAV . I have downloaded the kerberos ini filter and included in the windows system. I am only trying to bring the files in the same system into KM but with no luck. When i check the log file in the kerberos folder i am getting
    <b>12:02:22 10828/10476 E OnPreprocHeaders: Found 0 UserPrincipalNames for ADSI Filter (&(objectCategory=person)(objectClass=user) (userPrincipalName=xxxx))</b>.
    In the log i am getting the following
    ERROR! Delegation Flag:Use any authentication protocol: NOT ACTIVE
                           Open 'Active directory Users and Computers'. Choose <domain> -> 'Computers'.
                           Right-click 'IDBSRV8' and choose 'Properties'.
                           Select 'Delegation' and 'Trust this computer for delegation to specified services only'.
                           Select 'Use any authentication protocol'.
                    ERROR! The Trusted-to-Authenticate-for-Delegation flag is not set for SPN 'HOST/idbsrv8.idbhq.org'.
                           Please check the SPN by calling 'setspn -l IDBSRV8'.
                           If the SPN is well known, configure the Trusted-to-Authenticate-for-Delegation flag:
                           Open 'Active directory Users and Computers'. Choose <domain> -> 'Computers'.
                           Right-click 'IDBSRV8' and choose 'Properties'.
                           Select 'Delegation' and 'Trust this computer for delegation to specified services only'.
                           Select 'Use any authentication protocol' and choose 'Add'.
                           Select 'Users or Computers' and enter IDBSRV8 as object name.
                           Add the ServicePrincipalName HOST/idbsrv8.idbhq.org.
    Can anybody please help me in this regard???
    Regards,
    Ganesh N
    Message was edited by:
            Ganesh Natarajan

    Hi Ganesh,
    this error message tells you that there is no user in your active directory that has the userPrincipalName xxxx.
    The SSO22KerbMapModule works as follows.
    1. It receives a SAP Logon Ticket from the WebDAV request.
    2. If valid the SAP username is extracted. In your case the SAP username is xxxx.
    3. It then searches for a user in AD. It does so using the attribute in the ini-file that has been specified to contain the SAP username. In your case the SAP username should be identical with the userPrincipalName.
    So you have to make sure that the portal user id (j_user) is mapped to the same AD user attribute  that is specified in the ini-file .
    Best regards,
    Andre

  • Can I store referenced master files on a shared folder on a windows file server?

    I have a windows file server where I have setup shared folders that my Macbook can access. Is it a supported configuration to keep my referenced master files on the windows share?

    I hardly ever use the Bridge.  I mostly use the Bridges to work one groups of new image RAW to edit metadata and create ACR settings.  I don't use bridge features like collections or use the bridge to organize my image and I also don't use Lightroom.    I mostly use Photoshop and Window's File explorer with my Image files.  I have installed FastPictureViewer Codeg package to get thumbnails  for RAW and PSD files in a Window's dialog.   I don't like the delays introduced in workflows that are cause by the overhead requires for Bridge Cashes and Lighroom Databases.
    However for you with 50 users sharing assets on network drives I would think you would need a library system above and beyond Bridge and Lightroom. A library system that provides access and version processes so users don't step on each others work.
    If you want to use the bridge I do not believe it would be possible to use a shared cashed where multiple instances of the Bridge could concurrently maintain a common cache. I do not believe either Bridge or Lighroom design would have the locking protocols required for shared concurrent use.

  • Urgent: integrating windows file server into ep using KM.

    hi..
    can somebody give me detail steps of integrating windows file server into ep using KM.
    when i give password in the network path it is not accepting the password of the windows....
      Good answers will be rewarded points...
    bye....

    Hi,
       You can check:
    System Administration-System Configuration-KM-CM-Repository Managers-File System Repository-create a new item
    Root Directory can be:
    machine\sharedirectory
    and in CM-Global Services-Network Paths->create a new item
    in Network Path field:
    machine\sharedirectory
    enter your password
    user: domain\user
    Integrating Documents from a Windows System into KM
    http://help.sap.com/saphelp_nw2004s/helpdata/en/ed/b334ea02a2704388d1d2fc3e4298ad/frameset.htm
    Patricio.

  • When I access a windows files server with the mac I am adding .apple (hidden files). How can I prevent this.

    When I access a windows files server with the mac I am adding .apple (hidden files). How can I prevent this?

    Look for a program called BlueHarvest. I'm not sure if it still works with Mountain Lion.
    I believe your file server can be set up to handle the metadata files, but I suppose that would depend on the Server software and your IT staff.

  • Migrate documents from the windows file server into km

    Hi All,
    I have around 100 GB of documents in a file server and i want to migrate the same data in to KM.
    I am sure that there should be some standard process to do this,can any one please help me out in solving this.
    Thanks
    Ajay

    Hi Ajay,
    what do you mean by migrate? You could use a Windows Filessystem KM-Repository to integrated these files directly into KM (http://help.sap.com/saphelp_nw70/helpdata/en/e3/92322ab24e11d5993800508b6b8b11/frameset.htm)
    Otherwise you could use WebDAV (http://help.sap.com/saphelp_nw70/helpdata/en/4a/217fb6c33c6748a1715a161ac942cd/frameset.htm, http://help.sap.com/saphelp_nw70/helpdata/en/43/9600e5391e25dee10000000a1553f7/frameset.htm) or the Portal Drive (http://help.sap.com/saphelp_nw70/helpdata/en/42/c99b91341a6bade10000000a1553f6/frameset.htm) to copy these files in a (for example) DB repository.
    Regards,
    Holger.

  • FSCT - Having Error "There were errors during running WordFileClose.dll scenario" when running the FSCT in controller & non-windows file server

    I encounter 2 errors in the controller when running FSCT.
    - "There were errors during running WordFileClose.dll scenario"  
    - "There were errors during running WordFileClose.dll scenario"  
    Does anyone has any ideas for this errors?
    I am using the following server to run the FSCT:
    - AD Server: Windows 2008 R2 SP1 x64
    - FSCT Controller: Windows 2008 R2 SP1 x64
    - Client: Windows 7 x64
    - File Server: Non-Windows Server (EMC Isilon)
    And the commands are as follows:
    > fsct prepare dc /users 10 /clients testing /password password
    > fsct prepare controller
    > fsct prepare client /server ofscluster /password password /users 10 /domain abc.local /server_ip 192.168.2.16
    > fsct prepare server /clients testing /password password /users 10 /domain abc.local /volumes \\ofscluster\fsroot1 /workload HomeFolders /create_only_fileset
    > fsct run client /controller fsctcon /server ofscluster /password password /domain abc.local
    fsct run controller /server ofscluster /password password /volumes \\ofscluster\fsroot1 /clients testing /min_users 2 /max_users 10 /step 2 /duration 360 /workload HomeFolders

    Dear all,
    The errors were:
    <Error>1264 DeviceIoControl 1{WINERR}</Error>
    <Error>Error executing scenario: WordFileOpen.dll</Error>
    <Error>943 DeviceIoControl 50{WINERR}</Error>
    <Error>Error executing scenario: WordFileClose.dll</Error>
    Do you have any idea about what the errors mean?
    Thanks,
    Rayson

  • Mount windows file server over vpn

    I have a Windows(2003SP2) file server within some LAN with IP 192.168.10.10 and with shared folder structure like
    /Sity/District/
    I am authorised to connect to this LAN over VPN (it works) and to connect to /Sity, but I am authorized only to see and modify files within /District folder.
    With the command 'smbclient -U username //192.168.10.10/Sity' in Terminal I can connect to the server and e.g. get all the files from /Sity/District/. However, neither mount_smbfs in Terminal nor Connect to Server in Finder can mount the share - error is
    mount_smbfs: negotiate phase failed: syserr = Connection refused, Finder complain about the username and the password. The /etc/nsmb.conf has the following structure
    [default]
    minauth=none
    Is there a way to mount such share?

    Yes, it replies 'could not connect to the server because the name or password is not correct'.
    Same for almost all combinations of smb://WORKGROUP;user:password@IP/Sity[/District]
    I also tried different options for mount_smbfs like '-I' with no result. Error reads
    mount_smbfs: negotiate phase failed: syserr = Connection refused
    There is also no network browsing (mDNSResponder: NOTE: Wide-Area Service Discovery disabled to avoid crashing defective DNS relay 192.168.1.1.)
    But the smbclient works and I can get the folder structure.

  • Mac Lock Files on Windows File Server.

    Hi Pro,
    got some problem with Mac based design studio who have some weird issues with files locking on a Windows Server 2008 R2 server. After investigation, it is 100% a file locking issue. Some programs including preview, acrobat, indesign, finder or opening files (assuming locking them) and not releasing. Killing all the programs or remounting the share is working (releasing all lock files) but it's only a workaround not a fix. Do you any hints ? or Solutions ? all 10.7.3 Mac, using SMB protocol on a windows 2008 R2 File server.
    Thanks to all !!!

    yeah try this ... sorry french blog .. try google translate:
    http://clickpom.com/blog/mac-finder-lock-files-on-windows-server-smb-shared/
    this fix the issue for my client

  • Testing the windows file server documents in KM

    Hi all,
       I have configured WINDOWS as file server in KM.
       After configuring i should be able to share or access the docuemnts from the WINDOWS in KM
       How should i test WINDOWS documents in KM.ie., where can i find all the documents from WINDOWS in order to access it.
    Is it in the ROOT folder of the KM Content in Content administration or somewhere else?
    thanks in advance.
    Regards
    Sireesha.

    Hi,
      I have configured WINDOWS as file server in the following way.
      1.  Created a WINDOWS  system in the system land scape.
      2.  Configured servlet Engine User .
      3.  Created a Network path
      4.  Configured a File repository in the Content Management
      5.   User mapping is  done.
      Now my doubt is where should i go and check the WINDOWS documents or files after configuring it.
    Do v need to do anything else to get the all the files which are in WINDOWS.
    Pls guide me.
    Thanks in advance.
    Regards
    Sireesha.

  • File shares in EMC Isilon NAS not being accessible .........in windows file server

    Hi
    We have an odd issue in windows 2003 server where the users are not being able to access the shares in EMC Isilon NAS drives.
    Found that the KB 3002567 installed on last Tuesday March 10 2015, caused the issue and related to Data that resides on EMC Isilon clusters is unavailable to SMB/SMB2/SMB3 clients.
    Finally resorted to uninstall the particular patch from the Domain controllers of 2003 & 2008 and the shares are being accessible.
    Is there any alternative to this process of uninstallation of the patch KB 3002567 ......since this patch has to be uninstalled in pending DC's?
    Any help is greatly appreciated
    Thanks & Regards S.Swaminathan Live & let others live!!!

    In my own environment, I found the following registry value to be helpful:
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\LanmanWorkstation\Parameters:RequireSecureNegotiate=2
    (DWORD)
    http://blogs.msdn.com/b/openspecification/archive/2012/06/28/smb3-secure-dialect-negotiation.aspx
    Greetings/Grüße,
    Martin
    Mal ein
    gutes Buch über GPOs lesen?
    Good or bad GPOs? - my blog…
    And if IT bothers me -
    coke bottle design refreshment (-:

  • Windows file server installation

    i have a 2k3 file server installed and connected to the mac pro with 3 users 2 of them are able to be accesed from the fileserver but one user is not able to access
    all the 3 users are able to connect to the machine without any prob

    Glad to hear the issue has been resolved.
    We
    are trying to better understand customer views on social support experience, so your participation in this
    interview project would be greatly appreciated if you have time.
    Thanks for helping make community forums a great place.

  • OS X 10.8 Mountain Lion Photoshop CS5 Windows file server save issue

    After Lion to Mountain Lion upgrade.
    Cannot save or save as to Windows server. Due to "program error." Adobe Photoshop CS5. Can save as fine to local drive. Can also drag and drop in the Finder to this server.
    This is Photoshop CS5 12.0.4 (current).
    Once the error "could not save filename due to a program error" occurs, the file disappears from the Windows server.
    I think it has something to due with the SMB connection.
    All other CS5 apps (InDesign, Illustrator, etc.) "save" and "save as" fine. It is also fine performing the same procedure using Preview.

    We're in 2015 and this is still an issue with the latest updates from Apple. Any one confirm that the save to network storage problem in Photoshop is gone with the newest version of Photoshop Creative Cloud?
    Here's what's happening in our shop as of May, 2015 with both AFP and SMB server connections:
    We are using Photoshop CS 5.1, Version 12.1 x64. I believe this is the most up to date version of our CS5.1 software.
    We are on OS X Yosemite Version 10.10.3.
    When connected to the server via afp (in server log it says "AFP client")
    Photoshop gives this error on a save after some changes are made to the file: "Could not save "file name" because write access was not granted." Then, as soon as you hit ok, the file is deleted from the server and is gone within a minute or so. If no change was made to the file, save works fine.
    If you use "save as" and keep the same file name, it will usually fail with the same error as above. If you use save as and type in a new file name, all works fine.
    If logged in via SMB (in the server log is says "CIFS client")
    When you try to save, the error changes to "could not save "file name" because the file was not found." And then as soon as you hit OK on the error, the file is deleted from the server. Using Save As and inputing a different file name presented a new problem, it always says "could not save as "file name" because the file was not found." (in this case SMB seems to be worse than an AFP connection).
    This is very frustrating and has been going on in the forums for over 3 years. Shared network environments are commonplace today. It seems to be centered around photoshop and OSX. All other software we use has been working fine with the server / network attached storage.
    Thanks for any guidance. Sean

Maybe you are looking for

  • Can't login to App Store on more than one device

    Since resetting my Apple ID password I now cannot fully login to get downloads for apps etc in the App Store. I have to revert to downloading on my PC they syncing, very frustrated with this one, I've tried everything including doing a full power dow

  • No capture...no import from imovie hd

    I've just installed FCE HD. Since the add on apple.com said it worked with most of the recent camecorders, I did'nt checked the "official" qualified list . Of course, my SONY DCR-PC330E pal is not listed though rather recent and it seems that only a

  • "Sub Menus" Disappear and I can't change settings

    Hi Everyone, I am having a frusterating problem...and it is happening all over Illustrator. If you look at the attached image below, you can see that the gradient window is open, and I have click on the "gradient colors", to select what my gradient c

  • Spotlight Comments Disappear

    I have never been able to save spotlight comments. Never. Over years and years. I'm trying to organize some files by comment. The comment appears. Turn off the computer. Turn on, GONE. Does this function simply not work?

  • Message content empty after import

    I just tried to switch back from Entourage to Mail and imported all my Entourage Mailboxes. They seemed to come in fine, both the boxes and the list of email content is there - but when I click on the email it is empty - on all mail! What the heck ha