PGP Whole Disk Encryption behavior with Fixed Disks versus External Disks when encrypting a Primary Fixed Disk

Article:TECH196919  |  Created: 2012-09-19  |  Updated: 2012-09-19  |  Article URL http://www.symantec.com/docs/TECH196919
Article Type
Technical Solution


Problem



PGP Whole Disk Encryption behavior with Fixed Disks versus External Disks when encrypting a Primary Fixed Disk


Solution



PGP Whole Disk Encryption has the ability to encrypt both Fixed disks and External disks.  The behavior can differ between the two types of disks, namely what happens when encrypting a primary disk.

Fixed disks include disks that are connected directly to the motherboard as well as disks that can be used in place of a CD/DVD drive bay.

External disks consist of USB drives and the like that are connected via USB, Firewire ports, etc.

Encryption Process:

If a Primary Fixed disk is encrypted with PGP Whole Disk Encryption, as part of this encryption process, the secondary Fixed disk will be instrumented with PGP Whole Disk, and Whole Disk users are added to the disk matching that of the Primary Disk currently being encrypted.  The the secondary Fixed disk, however, is not encrypted. 

If a secondary Fixed disk that was instrumented, but not encrypted as outlined above, is then removed from the Encrypted system, and placed into another system, the disk will appear as though it was encrypted because it is instrumented and users added to the disk.

If this behavior is not desired, it is possible to decrypt the secondary Fixed disk if Whole Disk Policy allows this operation and the disk will then behave as an unencrypted disk. 

Alternatively, if the disk is disconnected prior to the encryption process, the disk will not be instrumented and will not be affected.

External Drives are not instrumented or encrypted when Primary Fixed disks are being encrypted.  These drives are considered separate and are actually treated in a different manner via PGP Encryption Policy.  As such, when encrypting a Primary Fixed disk, the external disks are not encrypted and will need to be encrypted separately.




Article URL http://www.symantec.com/docs/TECH196919


Terms of use for this information are found in Legal Notices