Windows 10: Encrypted My .PFX!

Discus and support Encrypted My .PFX! in Windows 10 Ask Insider to solve the problem; OK, so I fucked up! I backed up and then wiped one of my HDD's and reinstalled Windows 10 Pro. When I went to copy everything back over I realized I... Discussion in 'Windows 10 Ask Insider' started by /u/Line_Stepper2020, Jan 18, 2021.

  1. Encrypted My .PFX!


    OK, so I fucked up! I backed up and then wiped one of my HDD's and reinstalled Windows 10 Pro.

    When I went to copy everything back over I realized I did not decrypt my files before wiping. Oops!

    I have the .pfx files and I do know the password, but I am unable to open it in Certificates Wizard...or anything else...getting the error "Access is Denied" when trying to do anything with any of the files.

    Is there any way around this? I'm going to be losing quite a bit of stuff if so... Encrypted My .PFX! :(

    submitted by /u/Line_Stepper2020
    [link] [comments]

    :)
     
    /u/Line_Stepper2020, Jan 18, 2021
    #1
  2. chriad Win User

    Decrypting bitlocker encrypted OS volume with .pfx certificate

    I have a windows 10 operating system partition that is encrypted with bitlocker.
    Unfortunately I don't remember ever having activated bitlocker encryption nor can find and
    .bek file or numeric pin or password.

    My first uncertainty is in why my device is encrypted in the first place and who encrypted it. There are two possibilities: I have encrypted it myself and forgotten about it. The manufacturer that shipped the laptop has encrypted the device
    when installing the operating system (which I don't think is the case). I contacted the manufacturer and they do not have knowledge of any key.

    My second uncertainty is in why the bitlocker lockout was triggered at this time when it worked fine for the last year or so. It says
    Boot policy has unexpectedly changed. From what I have red so far, there are a lot of reasons why this can happen. Probably it happened because I did not properly remove a external USB harddrive or I changed some BIOS settings without knowing what
    I was doing. The only important question is if it is it in principle possible to roll back the boot policy to its initial state and thus circumvent the necessity to enter the bitlocker code?

    My third uncertainty is concerning the unlock key. I found a
    .pfx certificate file that I might have exported during the encryption procedure, I just don't remember. I found a post

    https://www.einfaches-netzwerk.at/teil-20b-bitlocker-dra/
    where a drive is indeed decrypted with the
    sha1 certificate thumbprint like this:

    manage-bde -unlock i: -cert -ct "46 4f 75 9b f9 67 7a d2 44 d0 7b 64 61 63 16 80 df dc 0b a2"

    which I can easily retrieve from the .pfx file.

    My question is now, assuming this .pfx certificate indeed contains the key to do the decryption, how can I export this certificate to the certificate store so that the above command will work?

    How can I install the .pfx certificate from the elevated command prompt (I cannot do it from within the GUI because it is my OS volume that is locked so I only can access it with the recovery console)?

    I tired:

    certutil -f -p somePassword -importpfx "somePfx.pfx"

    as outlined here
    https://stackoverflow.com/questions/5171117/import-pfx-file-into-particular-certificate-store-from-command-line?noredirect=1
    , but
    certutil command is not found.

    Here is the output of the manage-bde -status command

    Can someone give a hint on how to decrypt a bitlocker encrypted OS partition with a
    .pfx file and clarify if the steps outlined are in principle correct and should work if the certificate is the right one?

    I would appreciate any your comments.
     
    chriad, Jan 18, 2021
    #2
  3. DMGJM Win User
    Windows 10 Encryption Backing Up the Certificate

    Windows 10 Encryption.

    My problem is when I try to backup the Certificate Key to an external drive as is recommended by Microsoft. ("Backup your file certificate key...")

    The Certificate Export Wizard pops up.

    I click NEXT.

    The default display is for a .pfx file (which I assume is the default Certificate format when I encrypted the document).

    I click NEXT.

    Asks for a password and confirm password.

    I complete the password step and click NEXT.

    THEN THE PROBLEM

    It asks for a "file name" for "File to Export.... Specify the name of the file you want to export"

    I DON'T KNOW THE FILE NAME FOR THE CERTIFICATE.

    The Certificate was automatically generated when I encrypted the file - it did not tell me what the certificate name is or where it is stored.

    When I click the browse button, it is looking for a .pfx file but to perform the search I am required to click on every single subfolder individually to search for the .pfx file. It is not in the documents folder fyi.

    How do I find the Certificate .pfx file in order to export it?
     
    DMGJM, Jan 18, 2021
    #3
  4. Encrypted My .PFX!

    Device Encryption not avaiable

    Hello Fraczek,

    Thank you for contacting Microsoft Community.

    We understand your concern in this regard.

    • Are you referring to BitLocker Drive Encryption?
    • What preventing you from doing this?
    • Did you get any error message or code while doing this?

    Before you come up with the above information, suggest you to refer the article

    Help protect your files using BitLocker Drive Encryption
    and see if it help you.

    Do refer the article
    Windows BitLocker Drive Encryption Step-by-Step Guide
    and check if it help you with the required information.

    Keep us posted if you require further assistance.
     
    Yashwanth Kotakuri, Jan 18, 2021
    #4
Thema:

Encrypted My .PFX!

Loading...
  1. Encrypted My .PFX! - Similar Threads - Encrypted PFX

  2. Data Encryption Windows 11 Home

    in Windows 10 Gaming
    Data Encryption Windows 11 Home: Hi.I would like to ask about "Data Encryption" under Windows Security settings.I didn't notice Data Encryption option was there on Windows Security until i enable Intel Total Memory Encryption TME.The Data Encryption option is automatically present on the Windows Security...
  3. Data Encryption Windows 11 Home

    in Windows 10 Software and Apps
    Data Encryption Windows 11 Home: Hi.I would like to ask about "Data Encryption" under Windows Security settings.I didn't notice Data Encryption option was there on Windows Security until i enable Intel Total Memory Encryption TME.The Data Encryption option is automatically present on the Windows Security...
  4. Denied access to my own encrypted files

    in Windows 10 Network and Sharing
    Denied access to my own encrypted files: A while ago I made a backup of my data to an external hard drive. Some of those files are encrypted. For some reason, I am denied access to them.I can't use properties to uncheck the encrypt files option - it's greyed out, and it's already unchecked.I am the administrator of...
  5. Denied access to my own encrypted files

    in Windows 10 Gaming
    Denied access to my own encrypted files: A while ago I made a backup of my data to an external hard drive. Some of those files are encrypted. For some reason, I am denied access to them.I can't use properties to uncheck the encrypt files option - it's greyed out, and it's already unchecked.I am the administrator of...
  6. Denied access to my own encrypted files

    in Windows 10 Software and Apps
    Denied access to my own encrypted files: A while ago I made a backup of my data to an external hard drive. Some of those files are encrypted. For some reason, I am denied access to them.I can't use properties to uncheck the encrypt files option - it's greyed out, and it's already unchecked.I am the administrator of...
  7. Unable to apply Bitlocker encryption using Google endpoint for Window devices.

    in Windows 10 Gaming
    Unable to apply Bitlocker encryption using Google endpoint for Window devices.: Hi Team, I am facing issue to apply bitlocker encryption, Disable USB storage ports and Desktop image for window 11 pro devices using google endpoint. I also connect with Google workspace support team as they told me settings are configured correct in google admin console but...
  8. Unable to apply Bitlocker encryption using Google endpoint for Window devices.

    in Windows 10 Software and Apps
    Unable to apply Bitlocker encryption using Google endpoint for Window devices.: Hi Team, I am facing issue to apply bitlocker encryption, Disable USB storage ports and Desktop image for window 11 pro devices using google endpoint. I also connect with Google workspace support team as they told me settings are configured correct in google admin console but...
  9. Windows 11 After 22H2 Update Forcing BitLocker Encryption on USB Devices Domain-Joined PC

    in Windows 10 Gaming
    Windows 11 After 22H2 Update Forcing BitLocker Encryption on USB Devices Domain-Joined PC: Hello,I’m encountering an issue on multiple PCs running Windows 11, after updating to version 22H2. Whenever a USB drive is plugged in, the system automatically prompts to enable BitLocker encryption on the drive. However, the USB drive itself does not use any encryption, and...
  10. Import EFS File Encryption Certificate and Key (PFX file) in Windows 10

    in Windows 10 News
    Import EFS File Encryption Certificate and Key (PFX file) in Windows 10: [ATTACH] [ATTACH]When you EFS encrypt your files/folders, it’s recommended you create a backup of your file encryption certificate and key to a PFX file, to avoid permanently losing access to your encrypted files and folders if the original certificate and key [...] This...