File Share Encryption

 View Only
  • 1.  ADK - Organization Keys or Consumer Policy

    Posted Oct 24, 2013 06:45 AM

    Hi,

    I have a user who got the following message when trying to create a NetShare:

    ADK.png

     

    Which started me looking into how the ADK is configured on Universal server (we have had an ADK imported for quite some time).

    You can seemingly add an ADK under Keys->Organization Keys AND as part of a Consumer Policy under the General tab.

    The descriptions in the Admin Guide suggest the Organization ADK is used for email only, whereas a policy-specific ADK is used for all encrypted entities. Surely that isn't the case?

    The Admin Guide also indicates that the ADK is "added" to all generated keys, but the message above would suggest it is missing, even though we have it configured.

    Any ideas why the above error is being presented?

    Thanks.

     

     

     



  • 2.  RE: ADK - Organization Keys or Consumer Policy

    Posted Oct 24, 2013 08:05 AM

    Hi,

    Was there a change made in ADK key lately?

    There may be possibility that key is not updated with the new ADK changes. You can check if the user key properties has the ADK key added under it.



  • 3.  RE: ADK - Organization Keys or Consumer Policy

    Posted Oct 24, 2013 09:25 AM

    Hi,

    No, no change of ADK.

    When I asked the user to send me the key properties, it showed the correct ADK.

    Am I correct in thinking that a policy-specific ADK would overide one listed under Keys->Organization Keys?

    Thanks, Neal.



  • 4.  RE: ADK - Organization Keys or Consumer Policy

    Posted Oct 30, 2013 09:14 AM

    Hi there,

    Is your ADK also listed in the Master Key List?

    From the PGP Desktop, you can check it by clickin the tools from the Menu and options and then Master Key Tab.

    Can you check it and let me know?

    Regards,

    bipshr

     



  • 5.  RE: ADK - Organization Keys or Consumer Policy

    Posted Oct 31, 2013 06:52 AM

    Hi,

    Just asked the user, and I can confirm that the ADK is listed on the Master Keys list.

    Interestingly, the user can click OK and create a NetShare quite happily, and the ADK appears on the allowed users list.

    Thanks, Neal.

     



  • 6.  RE: ADK - Organization Keys or Consumer Policy

    Broadcom Employee
    Posted Oct 31, 2013 12:26 PM

    Try to run the following command via SSH in read-only mode and post the feedback:

    [root@keys ~]# psql oviddb -U ovidr -c "Select * from key where subject='adk'" -x

     



  • 7.  RE: ADK - Organization Keys or Consumer Policy

    Posted Oct 31, 2013 01:22 PM

    Hi,

    Here is an extract of the command output:

    # psql oviddb -U ovidr -c "Select * from key where subject='adk'" -x
    -[ RECORD 1 ]--------+-----------------------------------------------------------------
    uuid                 | 6e4361c3-7f0e-4611-ac50-884bf814cfde
    repository           | 0
    subject              | adk
    keyid                | 0xD2B81F8D6B1CE809
    key                  | -----BEGIN PGP PRIVATE KEY BLOCK-----
                         | Version: PGP Universal 3.2.1 (Build 5033)
    .
    .
     
                         | -----END PGP PRIVATE KEY BLOCK-----
                         | -----BEGIN PGP PUBLIC KEY BLOCK-----
                         | Version: PGP Universal 3.2.1 (Build 5033)
                         | 
    .
    .
     
                         | -----END PGP PUBLIC KEY BLOCK-----
                         | 
    key_expiration       | 1970-01-01
    sig_expiration       | 2013-11-02
    cert_status          | 0
    revoked              | f
    revoker              | 
    passphrase_type      | 2
    mode                 | 2
    algorithm            | 1
    size                 | 2048
    creation             | 2013-01-09 16:07:05+00
    encrypt              | f
    sign                 | t
    private_split_usage  | f
    private_shared_usage | f
    netshare_usage       | t
    wde_usage            | t
    zip_usage            | t
    messaging_usage      | t
     

     



  • 8.  RE: ADK - Organization Keys or Consumer Policy

    Posted Nov 01, 2013 05:05 AM

    Hi Neal,

    Sorry, I need to ask you again what the issue is. Do you get the "ADK not found" pop up always when you try to create a netshare folder? Can you please provide us the exact steps how you reproduce the issue?

    Regards,

    bipshr

     



  • 9.  RE: ADK - Organization Keys or Consumer Policy

    Posted Nov 01, 2013 06:18 AM

    Hi,

    Sorry for the confusion! I actually asked the original question about ADKs because a user was getting this error, and it wasn't clear (to me) exactly how the ADK configuration worked.

    I think I understand ADK configuration now, but I'd say that the admin guide isn't particularly good in that respect.

    With respect to the error message - the user gets the message whenever they attempt to create a NetShare. So right-click a network/local folder, select "PGP Desktop" -> "Add <directory> to PGP NetShare.....".

    If the user clicks okay, they can continue to create the NetShare without issue. So its not a massive issue, but rather odd all the same. No other users get the message, just this one.

    Thanks, Neal.



  • 10.  RE: ADK - Organization Keys or Consumer Policy

    Posted Nov 01, 2013 11:57 AM

    Hi,

    Thanks for your clarification.

    If it is only one user who is having this issue, then I would suggest that you re-enroll the user to PGP Universal Server and see whether it resolves the issue. Please click on the link below for more information about how to re-enroll client on the server.

    http://www.symantec.com/docs/HOWTO42029

    Please try it and let me know the results.

    As far as the documentation of ADK is concerned, we also usually refer to the admin guide. However, there is one documentation which is really helpful. It is kind of old but it describes basically everything about the ADK. Please have a look by clicking the link below:

    http://www.symantec.com/business/support/index?page=content&id=TECH149500

    Regards,

    bipshr