Endpoint Encryption

 View Only
  • 1.  Endpoint Encryption Disk Recovery

    Posted Sep 14, 2015 04:06 PM

    I am trying to "get back into" a laptop that is failing on boot.

    SEE Ver 11.0.1 (Build 7342) is installed. There was an issue with initial install. And bootrec /fixmbr has brought me to the current state of 'Missing operating system'.

    Attempts at decrytping using the eedAdmindCli utility have been proving unfruitful. For some reason the au (admin username) and ap (admin password) are not being accepted. So now I am at the following screen which appears I need to contact Symantec. So here I am. The screen I am at now has 7-8 lines of text. The are...

    Symantec Endpoint Encryption Disk Recovery

    Select a recovery method.

    Client Admin or Heldp Desk Recovery. (When I choose 'Help Desk Recovery', the following 5 lines are:

    1. Advanced Help Desk Recovery

    2. Computer

    3. Sequence Number 0

    4. Challenge key

        -  "26 characters" followed by [BY]

        -  "26 more characters followed by [A9]

    5. Response Key dialog box.

     

    My question is:

    If I provide the 2 challenge keys, do you provide to me a 'response key' which will in turn decrypt my drive? [My goal is that I want to boot into the drive (or attach as external storage) to retrieve files off of it.]

     

    Thanks!

                                



  • 2.  RE: Endpoint Encryption Disk Recovery

    Posted Sep 24, 2015 02:02 PM

    If you performed a /fixmbr, you have removed the key and the user accounts that could have been used for recovery.  You will need to find the backup records as follows:
    eedAdminCli --recover --disk 0 --au ClientAdmin --ap Passphrase

    That should start a sector-by-sector search for the backup user records and encryption key, and if successful, it should restore the drive to pre-fixmbr state.