{"id":1262,"date":"2018-01-26T13:47:33","date_gmt":"2018-01-26T13:47:33","guid":{"rendered":"http:\/\/help.sealionshipping.co.uk\/?p=1262"},"modified":"2018-01-26T13:47:33","modified_gmt":"2018-01-26T13:47:33","slug":"gtmailplus-server-2012-installation-prerequisite-efs-data-encryption","status":"publish","type":"post","link":"http:\/\/gardiner.tech\/bluebook\/blog\/2018\/01\/26\/gtmailplus-server-2012-installation-prerequisite-efs-data-encryption\/","title":{"rendered":"GTMailPlus &#8211; Server 2012 Installation Prerequisite &#8211; EFS DATA Encryption"},"content":{"rendered":"<p>\t\t\t\tOther than the .NET FRAMEWORK v4.6.2 prerequisite that needs to be installed on a Windows 2012 server, once \u00a0GTMailPlus \u00a0is installed you will need to enable <strong>EFS folder encryption<\/strong> on the MailBoxRepository folder located in the C:\\Encore folder or the Encore service (essential to mail transmission) will fail.<\/p>\n<p><strong>Data Recovery Agent<\/strong><br \/>\nNote that EFS requires a certificate and this is associated with the logged on user. In the case of the server that logged on user is the Administrator. In the event the server goes down the files in the folder will be locked and can only be opened with the correct certificate. \u00a0The Administrator is therefore the only EFS Data Recovery Agent. Any other user will need a copy of the key installed on their computer before the files can be opened. So it is good practice to export the key(s) and keep it\/them in a safe place just in case.<\/p>\n<p>&nbsp;<\/p>\n<p><span style=\"font-size: 14pt;\">Step By Step Guide<\/span><\/p>\n<p><strong>Create a New EFS Data Recovery Agent<\/strong><br \/>\nOn the server go to Administration Tools,\u00a0 Group Policy Management<br \/>\nClick on the domain name and expand<\/p>\n<p>Right Click on Default Domain Policy object, Edit<\/p>\n<p>In the Group Policy Management Editor interface, click<strong>\u00a0Computer Configuratio<\/strong>n, expand\u00a0<strong>Policies<\/strong>,\u00a0expand\u00a0<strong>Windows Settings<\/strong>, expand\u00a0<strong>Security Settings<\/strong>, expand\u00a0<strong>Public Key Policies<\/strong>, and then click\u00a0<strong>Encrypting File System<\/strong>.<\/p>\n<p>Next,<strong>\u00a0right-click the Administrator certificate<\/strong>, and then click\u00a0<strong>Delete<\/strong>\u2026\u00a0 and confirm Delete. Click Yes<\/p>\n<p>In the Group Policy Management Editor,\u00a0<strong>right-click Encrypting File System<\/strong>, and then click\u00a0<strong>Create Data Recovery Agent<\/strong>\u2026<br \/>\nClose Group Policy Management Editor interface and Group Policy Management tool<\/p>\n<p>Next, open\u00a0<strong>Windows PowerShell<\/strong>\u00a0, then type<strong>\u00a0gpupdate \/force<\/strong>\u00a0and press Enter\u2026<\/p>\n<p><strong><br \/>\nCreate the Data Recovery Agent Certificates<br \/>\n<\/strong>Now Go to Start, Run and type MMC press Enter<br \/>\nIn the Console1 interface, click File, and then click\u00a0<strong>Add\/Remove Snap-i<\/strong>n\u2026<br \/>\nIn the Add or Remove Snap-ins interface,\u00a0click\u00a0<strong>Certificates<\/strong>, and then click\u00a0<strong>Add<\/strong>\u2026<br \/>\nIn the Add Or Remove Snap-ins interface, click\u00a0<strong>OK<\/strong>\u2026<br \/>\nIn the left pane, expand\u00a0<strong>Certificates \u2013 Current Use<\/strong>r,<strong>\u00a0right-click Personal<\/strong>, click\u00a0<strong>All Tasks<\/strong>, and then\u00a0click\u00a0<strong>Request New Certificate<\/strong>\u2026<br \/>\nThe\u00a0<strong>Certificate Enrollment<\/strong>\u00a0interface pops up, click\u00a0<strong>Next<\/strong>\u2026<br \/>\nOn the\u00a0<strong>Select Certificate Enrollment Policy<\/strong>\u00a0interface, verify that you have\u00a0<strong>Active Directory Enrollment Policy<\/strong>, and then click Next\u2026<br \/>\nOn the Request Certificates interface, click\u00a0the<strong>\u00a0Basic EFS<\/strong>\u00a0check box, and then click\u00a0<strong>Enroll<\/strong>\u2026<br \/>\nOn the Certificate Installation Results interface, verify that the<strong>\u00a0Status : Succeeded<\/strong>\u00a0and then click\u00a0<strong>Finish<\/strong>\u2026<br \/>\n<span style=\"font-family: inherit; font-style: inherit; font-weight: inherit;\">In the Console1 interface, expand Certificates \u2013 Current User, expand Personal, and\u00a0then click Certificates, on the right pane verify that under issued to, your present Log in User Name is listed and verify also\u00a0that it was issued by\u00a0SERVERNAME<br \/>\n<\/span>Right click on the Administrator certificate, All Tasks, Export&#8230;<br \/>\nIn the Certificate Export Wizard click Next, select Yes export the private key. Next<br \/>\nPersonal Information Exchange &#8211; PKCS #12(.PFX) and check Include all certificates in certification path if possible. Next<br \/>\nCheck Password and enter password (sealion). Next<br \/>\nBrowse to a location and enter a filename (EFSkey) to save the .pfx file.<\/p>\n<p>If there is a second EFS Certificate &#8211; save that also<\/p>\n<p>&nbsp;<\/p>\n<p><strong>Enable EFS Encryption on MailBoxRepository folder<\/strong><\/p>\n<ol>\n<li>Navigate to the GTMAIL&#8217;s MailRepository folder &#8211; C:\\Encore<\/li>\n<li>Select MailBoxRepository &#8211; right click, Properties.<\/li>\n<li>In the General tab &#8211; select Advanced button<\/li>\n<li>Check Encrypt contents to secure data. OK<\/li>\n<li>In the General tab &#8211; click Apply<\/li>\n<\/ol>\n<p>NB: If enabled (Folder Options, View &#8211; check Show encrypted or compressed files in colour) you will see the folder and any files within coloured green (Windows 10 has this off by default. For Windows Server 2012 it is on)<\/p>\n<p>&nbsp;<\/p>\n<p><strong>References<\/strong><\/p>\n<p><a href=\"https:\/\/mizitechinfo.wordpress.com\/2014\/07\/29\/step-by-step-encrypting-user-data-with-efs-in-windows-server-2012-r2\/\">Step by Step : Encrypting User Data with EFS in Windows Server 2012&nbsp;R2<\/a><\/p>\n<p><a href=\"http:\/\/windowsitpro.com\/security\/fast-way-find-efs-folders-and-files\">http:\/\/windowsitpro.com\/security\/fast-way-find-efs-folders-and-files<\/a><\/p>\n<p><a href=\"https:\/\/www.nextofwindows.com\/how-to-check-a-pfx-certifications-expiry-date-on-windows\">https:\/\/www.nextofwindows.com\/how-to-check-a-pfx-certifications-expiry-date-on-windows<\/a><\/p>\n<p><a href=\"http:\/\/help.sealionshipping.co.uk\/wp-content\/uploads\/2017\/07\/EncryptionFilesystem.pdf\">EncryptionFilesystem<\/a><\/p>\n<p>&nbsp;\t\t<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Other than the .NET FRAMEWORK v4.6.2 prerequisite that needs to be installed on a Windows 2012 server, once \u00a0GTMailPlus \u00a0is installed you will need to enable EFS folder encryption on the MailBoxRepository folder located in the C:\\Encore folder or the Encore service (essential to mail transmission) will fail. Data Recovery Agent Note that EFS requires a certificate and this is associated with the logged on user. In the case of the server that logged on [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[23,75],"tags":[109,127,129,151,153,155],"_links":{"self":[{"href":"http:\/\/gardiner.tech\/bluebook\/wp-json\/wp\/v2\/posts\/1262"}],"collection":[{"href":"http:\/\/gardiner.tech\/bluebook\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/gardiner.tech\/bluebook\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/gardiner.tech\/bluebook\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"http:\/\/gardiner.tech\/bluebook\/wp-json\/wp\/v2\/comments?post=1262"}],"version-history":[{"count":0,"href":"http:\/\/gardiner.tech\/bluebook\/wp-json\/wp\/v2\/posts\/1262\/revisions"}],"wp:attachment":[{"href":"http:\/\/gardiner.tech\/bluebook\/wp-json\/wp\/v2\/media?parent=1262"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/gardiner.tech\/bluebook\/wp-json\/wp\/v2\/categories?post=1262"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/gardiner.tech\/bluebook\/wp-json\/wp\/v2\/tags?post=1262"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}