File Share Encryption

 View Only
Expand all | Collapse all

PGP 10.3.1 New Passphrase User

  • 1.  PGP 10.3.1 New Passphrase User

    Posted May 29, 2014 12:51 PM

    Hi,

    Some computers have a problem with new version 10.3.1:

    I have updated the client to 10.3.1 (64 bits). When I go to add new passphrase user, the new user dialog box doesn’t appear... Automatically, the windows that it shows me is “PGP Disk New User” – “Create new User” … However, I have no opportunity to choose the option “User Windows Passowrd”, only it lets me New Passphrase….If I uninstall version 10.3.1 and install 10.2.0 works fine

     In some other computers with 10.3.1 works fine….

     I have noticed that the box “Enter the username or email address of a key” and option “ADD User Key” are enabled (in computer with problems). In the other computer, they are disabled…

     

    Where is the problem?

    Thanks,

    Regards.



  • 2.  RE: PGP 10.3.1 New Passphrase User

    Broadcom Employee
    Posted May 30, 2014 03:21 AM

    Hi Sebi,

    Can you verify if the machine(s) having problem are having policy setup of Drive Encryption (SEMS > Consumers > Consumer Policy > chose the right policy for this machine(s) > Desktop > Drive Encryption tab) to "Allow encryption of disks to existing Windows Single Sign-On password"
    Looks for me like your Drive encryption policy are different for different machines so I strongly advice you to take working machine(s) by comparing their policy and apply the same to not working ones.

    HTH

     



  • 3.  RE: PGP 10.3.1 New Passphrase User

    Posted May 30, 2014 04:15 AM

    Hi,

    Thanks for your reply. We have only one consumer policy which is applied to Everyone... (with Allow encrypt....)

    If I uninstall 10.3.1 and install 10.2.0 works fine... then I don't know.. Can I confirm what policy have this computer?



  • 4.  RE: PGP 10.3.1 New Passphrase User

    Broadcom Employee
    Posted May 30, 2014 04:49 AM

    Sebi,

    You can check the policy applied for the machine in SEMS > Reporting > Logs (Log Type Administrations) but if you have got only one policy apply to all then this will not make any difference.

    What versions of SEMS do you have with build number as you use two different version of clients 10.3.1 and 10.2.0

    Also you mentioned that "In some other computers with 10.3.1 works fine…." can you check please if all 10.3.1 SED clients are managed clients. Maybye some of them are unmanaged. Please navigate to both working and not working machines of 10.3.1 Help > About and check what is licensed to. Also please check PGPSTAMP from the registry editor ( HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\PGP Corporation\PGP for x64 bits)



  • 5.  RE: PGP 10.3.1 New Passphrase User

    Posted Jun 02, 2014 06:29 AM

    Hi again,

     

    The value in PGPSTAMP is the same... When I go to about info, the client are managed...

    The version of SEMS is 3.3.1.

    I have realized that the problem only appear in new laptop DELL E7240, 7440 (32 and 64 bits)  In old laptops which i have tested works fine

    Thanks for you help



  • 6.  RE: PGP 10.3.1 New Passphrase User

    Broadcom Employee
    Posted Jun 02, 2014 09:30 AM

    Hi Sebi,

    I am wondering if in this new laptop you use a smartcards as the SSO is not compatible with smartcards as this is a passhare user only.

    Also can you verify on both different machines with version 10.3.1 (working and not working ones) the following registry entry PGP_INSTALL_SSO.

    ( HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\PGP Corporation\PGP for x64 bits)

     To be able to use SSO this value needs to be 1 there.

    Look at the followig KB please:

    Troubleshooting: Symantec Drive Encryption Single Sign-On 
    http://www.symantec.com/docs/TECH149470

    From above KB please also verify solution 2,3,4 (although I agree that mostly this KB is for troubleshooting synchonization issue rather than just a SSO working or not issue)



  • 7.  RE: PGP 10.3.1 New Passphrase User

    Posted Jun 02, 2014 10:05 AM

    Hi Adam,

    I checked before create this post. The value is 1 :S

    Clarification: In any new laptop work. I am comparing with old laptops

     

    Thanks!



  • 8.  RE: PGP 10.3.1 New Passphrase User

    Posted Jun 02, 2014 10:51 AM

    Can you create a new (identical) policy, and assign it to a different group.  Put the problem computers in that group and force a re-enrol?  Delete the PGP Corporation folder in %APPDATA%\ and reload PGP.  It could be an issue with the policy if the registry entries dont indicate anything.



  • 9.  RE: PGP 10.3.1 New Passphrase User
    Best Answer

    Broadcom Employee
    Posted Jun 03, 2014 09:58 AM

    Hi Sebi,

    ff policy recreation is not giving you a positive result can I also ask you for this specific model laptops DELL E7240, 7440 update your RAID Controler ( Intel® Rapid Storage Technology (Intel® RST) RAID Driver) as per the below KB's.  I think this might be the case in fact so I strongly recommend to do this.

    Symantec Encryption Desktop - Dell E7240 and mSATA SSD SCSI Disk Device SSO issue
    http://www.symantec.com/docs/TECH213653

    and also:

    Symantec Encryption Desktop Single Sign On nonfunctional with Dell BIOS versions A05, or greater
    http://www.symantec.com/docs/TECH213383

    Let me know your feedback please.

    HTH



  • 10.  RE: PGP 10.3.1 New Passphrase User

    Posted Jun 04, 2014 04:37 AM

    Yeeeeees.... The problem was the Raid Controller (IRST)

    I have installed and now it's works fine...

    Thanks a lot!!!



  • 11.  RE: PGP 10.3.1 New Passphrase User

    Broadcom Employee
    Posted Jun 04, 2014 04:49 AM

    Hi Sebi,

    Thanks for your feedback and happy that the issue is resolved.