Windows 10: Encrypted My .PFX!

Discus and support Encrypted My .PFX! in Windows 10 Ask Insider to solve the problem; OK, so I fucked up! I backed up and then wiped one of my HDD's and reinstalled Windows 10 Pro. When I went to copy everything back over I realized I... Discussion in 'Windows 10 Ask Insider' started by /u/Line_Stepper2020, Jan 18, 2021.

  1. Encrypted My .PFX!


    OK, so I fucked up! I backed up and then wiped one of my HDD's and reinstalled Windows 10 Pro.

    When I went to copy everything back over I realized I did not decrypt my files before wiping. Oops!

    I have the .pfx files and I do know the password, but I am unable to open it in Certificates Wizard...or anything else...getting the error "Access is Denied" when trying to do anything with any of the files.

    Is there any way around this? I'm going to be losing quite a bit of stuff if so... Encrypted My .PFX! :(

    submitted by /u/Line_Stepper2020
    [link] [comments]

    :)
     
    /u/Line_Stepper2020, Jan 18, 2021
    #1
  2. chriad Win User

    Decrypting bitlocker encrypted OS volume with .pfx certificate

    I have a windows 10 operating system partition that is encrypted with bitlocker.
    Unfortunately I don't remember ever having activated bitlocker encryption nor can find and
    .bek file or numeric pin or password.

    My first uncertainty is in why my device is encrypted in the first place and who encrypted it. There are two possibilities: I have encrypted it myself and forgotten about it. The manufacturer that shipped the laptop has encrypted the device
    when installing the operating system (which I don't think is the case). I contacted the manufacturer and they do not have knowledge of any key.

    My second uncertainty is in why the bitlocker lockout was triggered at this time when it worked fine for the last year or so. It says
    Boot policy has unexpectedly changed. From what I have red so far, there are a lot of reasons why this can happen. Probably it happened because I did not properly remove a external USB harddrive or I changed some BIOS settings without knowing what
    I was doing. The only important question is if it is it in principle possible to roll back the boot policy to its initial state and thus circumvent the necessity to enter the bitlocker code?

    My third uncertainty is concerning the unlock key. I found a
    .pfx certificate file that I might have exported during the encryption procedure, I just don't remember. I found a post

    https://www.einfaches-netzwerk.at/teil-20b-bitlocker-dra/
    where a drive is indeed decrypted with the
    sha1 certificate thumbprint like this:

    manage-bde -unlock i: -cert -ct "46 4f 75 9b f9 67 7a d2 44 d0 7b 64 61 63 16 80 df dc 0b a2"

    which I can easily retrieve from the .pfx file.

    My question is now, assuming this .pfx certificate indeed contains the key to do the decryption, how can I export this certificate to the certificate store so that the above command will work?

    How can I install the .pfx certificate from the elevated command prompt (I cannot do it from within the GUI because it is my OS volume that is locked so I only can access it with the recovery console)?

    I tired:

    certutil -f -p somePassword -importpfx "somePfx.pfx"

    as outlined here
    https://stackoverflow.com/questions/5171117/import-pfx-file-into-particular-certificate-store-from-command-line?noredirect=1
    , but
    certutil command is not found.

    Here is the output of the manage-bde -status command

    Can someone give a hint on how to decrypt a bitlocker encrypted OS partition with a
    .pfx file and clarify if the steps outlined are in principle correct and should work if the certificate is the right one?

    I would appreciate any your comments.
     
    chriad, Jan 18, 2021
    #2
  3. DMGJM Win User
    Windows 10 Encryption Backing Up the Certificate

    Windows 10 Encryption.

    My problem is when I try to backup the Certificate Key to an external drive as is recommended by Microsoft. ("Backup your file certificate key...")

    The Certificate Export Wizard pops up.

    I click NEXT.

    The default display is for a .pfx file (which I assume is the default Certificate format when I encrypted the document).

    I click NEXT.

    Asks for a password and confirm password.

    I complete the password step and click NEXT.

    THEN THE PROBLEM

    It asks for a "file name" for "File to Export.... Specify the name of the file you want to export"

    I DON'T KNOW THE FILE NAME FOR THE CERTIFICATE.

    The Certificate was automatically generated when I encrypted the file - it did not tell me what the certificate name is or where it is stored.

    When I click the browse button, it is looking for a .pfx file but to perform the search I am required to click on every single subfolder individually to search for the .pfx file. It is not in the documents folder fyi.

    How do I find the Certificate .pfx file in order to export it?
     
    DMGJM, Jan 18, 2021
    #3
  4. Encrypted My .PFX!

    Device Encryption not avaiable

    Hello Fraczek,

    Thank you for contacting Microsoft Community.

    We understand your concern in this regard.

    • Are you referring to BitLocker Drive Encryption?
    • What preventing you from doing this?
    • Did you get any error message or code while doing this?

    Before you come up with the above information, suggest you to refer the article

    Help protect your files using BitLocker Drive Encryption
    and see if it help you.

    Do refer the article
    Windows BitLocker Drive Encryption Step-by-Step Guide
    and check if it help you with the required information.

    Keep us posted if you require further assistance.
     
    Yashwanth Kotakuri, Jan 18, 2021
    #4
Thema:

Encrypted My .PFX!

Loading...
  1. Encrypted My .PFX! - Similar Threads - Encrypted PFX

  2. Windows RE cannot be enabled on a volume with BitLocker Drive Encryption Enabled

    in Windows 10 News
    Windows RE cannot be enabled on a volume with BitLocker Drive Encryption Enabled: [ATTACH]Windows Recovery Environment allows users to repair their computers when they cannot boot into Windows. It is stored on a separate partition hidden by default and has no drive letter. You can enable or disable it as per your requirements. However, enabling the Windows...
  3. You have chosen to back up drive C which is encrypted

    in Windows 10 News
    You have chosen to back up drive C which is encrypted: [ATTACH]When creating a system image using Windows Backup, you may encounter an error that says “You have chosen drive C is encrypted”, and the backup location is not encrypted. After the error, we noticed that the backup was not created. In this post, we will talk about this...
  4. Does Upgrading W10 to W11 always install BitLocker Encryption on Your C Drive?

    in Windows 10 Software and Apps
    Does Upgrading W10 to W11 always install BitLocker Encryption on Your C Drive?: BACKGROUND:My W10 Desktop Computer only has a Local AccountWhile My W11 Laptop was installed using my Microsoft Account, and I later added a Local Account.Why am I asking this question?I wanted to do a Windows 11 Defender Offline Scan, but I had to turn off encryption for...
  5. Does Upgrading W10 to W11 always install BitLocker Encryption on Your C Drive?

    in Windows 10 Gaming
    Does Upgrading W10 to W11 always install BitLocker Encryption on Your C Drive?: BACKGROUND:My W10 Desktop Computer only has a Local AccountWhile My W11 Laptop was installed using my Microsoft Account, and I later added a Local Account.Why am I asking this question?I wanted to do a Windows 11 Defender Offline Scan, but I had to turn off encryption for...
  6. Drive D: Marked as "BitLocker Encrypted" – Can’t Access HDD on Windows 11 Home No BitLocker...

    in Windows 10 Gaming
    Drive D: Marked as "BitLocker Encrypted" – Can’t Access HDD on Windows 11 Home No BitLocker...: Hi all,I'm facing a sudden and confusing issue on my Windows 11 Home laptop. My setup includes:Drive C SSD: Windows OSDrive D HDD - 1TB: Used only for personal file storageEverything worked fine until one day, I booted up the laptop and couldn't access Drive D. File Explorer...
  7. Drive D: Marked as "BitLocker Encrypted" – Can’t Access HDD on Windows 11 Home No BitLocker...

    in Windows 10 Software and Apps
    Drive D: Marked as "BitLocker Encrypted" – Can’t Access HDD on Windows 11 Home No BitLocker...: Hi all,I'm facing a sudden and confusing issue on my Windows 11 Home laptop. My setup includes:Drive C SSD: Windows OSDrive D HDD - 1TB: Used only for personal file storageEverything worked fine until one day, I booted up the laptop and couldn't access Drive D. File Explorer...
  8. Hello there how can I de encrypt my userkey.psw file on my android

    in Windows 10 Gaming
    Hello there how can I de encrypt my userkey.psw file on my android: My PC's locked and I can't find my recovery key in my Microsoft accBut the key is on my flash drive https://answers.microsoft.com/en-us/windows/forum/all/hello-there-how-can-i-de-encrypt-my-userkeypsw/b1c75067-92db-4a5a-8137-bf36415fe778
  9. Hello there how can I de encrypt my userkey.psw file on my android

    in Windows 10 Software and Apps
    Hello there how can I de encrypt my userkey.psw file on my android: My PC's locked and I can't find my recovery key in my Microsoft accBut the key is on my flash drive https://answers.microsoft.com/en-us/windows/forum/all/hello-there-how-can-i-de-encrypt-my-userkeypsw/b1c75067-92db-4a5a-8137-bf36415fe778
  10. Import EFS File Encryption Certificate and Key (PFX file) in Windows 10

    in Windows 10 News
    Import EFS File Encryption Certificate and Key (PFX file) in Windows 10: [ATTACH] [ATTACH]When you EFS encrypt your files/folders, it’s recommended you create a backup of your file encryption certificate and key to a PFX file, to avoid permanently losing access to your encrypted files and folders if the original certificate and key [...] This...