File Share Encryption

 View Only
Expand all | Collapse all

Can't change Admin Passphrase after moving drive to new machine

  • 1.  Can't change Admin Passphrase after moving drive to new machine

    Posted Jul 21, 2018 09:33 AM

    I've got a 4 TB SSD that is encrypted with 10.4.2 (under Windows 10 as a secondary drive) with an Admin Passphrase of Password1 (which is also the passphrase of drive 0 too).  I've pulled the SSD from the original machine and put it in a 2nd machine (also under Windows 10 as a secondary drive).  The 2nd machine's drive 0 Admin Passphrase is Password2.  The first machine no longer exists.  When Windows 10 boots on the 2nd machine, PGPTray prompts the password for drive 1, which I have to enter (Password1).  If it go into PGP Desktop, I can update the User password to Password2, but the Admin Passphrase remains at Password1.  If I add a new windows SSO user to both drive 0 and drive 1, I still get prompted for the Admin Passphrase on drive 1 (even though there is a SSO user present).

    So how to I change the Admin Passphrase for drive 1 from Password1 to Password2, and get SSO to function with drive 1?  I know if I decrypt drive 1 (using Password1 as the Admin Passphrase), I can re-encrypt the drive with the new Admin Passphrase (Password2) and add the SSO user, but I don't want to spend hours decrypting, then re-encrypting.

    I've played around various switches on pgpwde.exe --change-passphrase, but I just don't seem to be able to get the Admin Passphrase to change from Password1 to Password2.

    Anyone have any ideas?



  • 2.  RE: Can't change Admin Passphrase after moving drive to new machine

    Posted Jul 23, 2018 06:05 AM

    Is the new Wn10 machine standalone, or is it managed by a SEMS?  Is ti possible you're encountering the situation described in the below article?

    https://www.symantec.com/docs/TECH211552

    If so, then it suggests amending the Consumer Policy to allow you to perform User Management, as a possible workaround.