Endpoint Encryption

 View Only
  • 1.  Failed Authentication After PGP_INSTALL_DISABLESSOENROLL=0

    Posted Jan 11, 2016 10:38 AM

    So I had everything working correctly and wanted to get it working even better.....so I reinstalled with the PGP_INSTALL_DISABLESSOENROLL=0 MSI switch.  Now anyone on that machine receives the error "returning fault -11286 (authorization failed for this operation)"

      

    I can duplicate this on a working machine by deleting the %appdata%\Roaming\PGP Corporation folder, but can only resolve the issue by restoring that valid data.  Is there anyway to rebuild this data?  Why didn't it reset after I installed?  Can I resolve this issue without reverting back to my original install that didn't enroll super siliently?

      

    CLIENT-00082: client request <AuthenticateInternalPassphrase> returning fault -11286 (authorization failed for this operation)    
    Sat Jan 9, 2016 at 11:17:19 AM -05:00    

      
    CLIENT-00082: failed authentication for internal Encryption Desktop 10.3.2.15238 user 900026557 from [124.4.164.98]    
    Sat Jan 9, 2016 at 11:17:19 AM -05:00



  • 2.  RE: Failed Authentication After PGP_INSTALL_DISABLESSOENROLL=0

    Posted Jan 13, 2016 07:51 PM

    DISABLESSOENROLL allows for the client to enroll without having to enter credentials.  This is a value that can only be set during install time.  That is when it accesses the registry to build that behavior.  If it was not set to 0 on the initial install, you would need to decrypt and uninstall, then reinstall with it set at 0.  Simply doing an upgrade or changing it manually will not get it to function correctly.  It is basically pulling NULL data at this point and submitting it as your Windows credentials.