File Share Encryption

 View Only
  • 1.  PGP - Few Questions

    Posted Apr 04, 2012 08:11 AM

    Hello All

    Currently we are using McAfee Endpoint Encryption (Disk Encryption ONLY) and it is a very easy and feature rich product, unfortunately due to compatibility issues with SEP. I have installed PGP Universal Server (WDE) and configured Directory Synchronisation.

    1) Is it possible to Decrypt a device using PGP Universal Server?

    2) Is it possible to assign AD groups and additional users to a device using the PGP Universal Console? This is for Admin access.

    3) McAfee is capable of installing the Encryption Agent from the management console, I can't seem to see this option in PGP, is this possible?

    4) In an event we can't access a laptop (boot failure) I know we can use PGP Recovery Disk, does this mean anyone can decrypt the hard drive? McAfee provide code of the day for to prevent unauthorised access?

    5) Why am i seeing duplicate computers in the device list?

    Thanks

     



  • 2.  RE: PGP - Few Questions

    Posted Apr 04, 2012 10:29 AM

    1)  Not possible. Has to be done manually from the client. You DO can set universal policy to automatically encrypt when users enroll.

    2) You can match users to group policy using any LDAP parameters using US console.

    3) Installation not possible from server. You can download installation file from server or deploy using GPO or similar.

    4) No,You will need disk password to decrypt the drive using recovery cd.

    5) Probably you are deploying system image with pgp installed.  Then, IDs for that computer are repetead and thats why you see duplicated entries in the server. You should run PGPGuid tool before enrolling users. Please give this article a read:
    http://www.symantec.com/docs/TECH149261



  • 3.  RE: PGP - Few Questions

    Posted Apr 04, 2012 11:46 AM

    Thanks for the response.

     

    1) Not a big issue, don't expect to decrypt unless really needed.

    2) How is this done? Do I need to create a new internal users and a  group and add the internal users to this group?

    3) We can use SCCM

    4) Is this the same password used for the users? Where do I setup this password?

    5) I have downloaded the image from US and manually installed this on the laptop, its not part of the image.



  • 4.  RE: PGP - Few Questions
    Best Answer

    Posted Apr 04, 2012 12:20 PM

    2) http://www.symantec.com/docs/TECH149796

    4) yes its the same password for the user. This is setup when you encrypt the disk.

     

    Please  mark post a solution if all question were answered



  • 5.  RE: PGP - Few Questions

    Posted Apr 13, 2012 10:48 AM

    Thanks Julian.

    I haver the info and manged to successfully work this. I have decided to setup the administrator passphase and in such event we can use this.