Windows Password accessible via Remote Registry queries
| Article:TECH149940 | | | Created: 2010-08-30 | | | Updated: 2012-04-19 | | | Article URL http://www.symantec.com/docs/TECH149940 |
Problem
When using the PGP Whole Disk Encryption Single Sign-On (SSO) feature, the PGP Disk driver caches user credentials in the pre-boot environment, PGP BootGuard, and passes to the Windows logon process, automatically logging a user into Windows. Using the SSO feature, users are required to enter credentials only once, at PGP BootGuard, to log in to Windows automatically.
Once the user clicks OK to the logon banner, the computer completes the login process and the password is then removed from memory.
Environment
|
Note: This type of behavior is similar to what happens when auto-logon has been enabled in Windows without PGP installed on the system.
|
Solution
PGP Desktop 10.1.0 through 10.1.2 provides improved security of password handling when using PGP Whole Disk Encryption with SSO. This setting is disabled by default and is enabled by modifying a Windows registry Value.
Windows XP
- Click Start>Run.
- Type regedit and click OK.
- Browse to HKEY_LOCAL_MACHINE\SOFTWARE\PGP Corporation\PGP\ folder.
- Right-click the SSOCheckPID value and select Modify.
- Type 1 for the Value data and click OK.
- Close the Registry Editor.
- Click Start.
- Type regedit in the Start Search field, and then click the regedit result in the Programs list.
- Browse to HKEY_LOCAL_MACHINE\SOFTWARE\PGP Corporation\PGP\ folder.
- Right-click the SSOCheckPID value and select Modify.
- Type 1 for the Value data and click OK.
- Close the Registry Editor.
|
Note: If SSO needs to be completely disabled in PGP Whole Disk Encryption, please do so via the PGP Universal Server Consumer Policy
“Deny encryption of disks to existing Windows Single Sign-On password.”
|
|
|
Legacy ID
2221
Article URL http://www.symantec.com/docs/TECH149940
Terms of use for this information are found in Legal Notices









Thank you.