File Share Encryption

 View Only
  • 1.  Understanding PGP and how it works?

    Posted Jun 15, 2012 06:47 AM

    Hi all,

    I have been tasked with the job to set up, configure and play around with a trial version of PGP Universal Server.

    Our main aim is to get all of our clients using the disk encryption feature.

    Now I am struggling to get my head around exactly what this system does and how to set it up correctly.

    We are currently using Oracle for our email set up.

    My understanding so far.

    1. From the universal server I can control and manage all of the clients which are running PGP desktop.
    2. To install the desktop software I download it from server console and configure the policy settings to control the PGP desktop software
    3. I have configured directory sync to enrol a user. Does PGP validate a user from Active Directory?
    4. I assume if I want the enrolment to happen silently there is a options for this??
    5. Whenever a action is performed by PGP desktop I get a certificate error which I need to allow. I assume I need to publish this certificate to the domain?
    6. What about email? I don’t understand this part all. We don’t need to use this feature at the moment but It would be good to get a understanding on how it works? and how to set it up correctly?

    And lastly can someone give me a quick brief overview on exactly what PGP can do? (I have read the admin guide but I don’t think it is clear enough)

    Sorry for all the questions I am new to data encryption so I could do with abit of input.

    Thanks and Regards

    Mac

     



  • 2.  RE: Understanding PGP and how it works?

    Posted Jun 19, 2012 04:55 AM

     

    My understanding so far.

    From the universal server I can control and manage all of the clients which are running PGP desktop.

    Correct, as long as they are enrolled to that UN

    To install the desktop software I download it from server console and configure the policy settings to control the PGP desktop software

    Correct, if you are dealing with a large number of clients, using Silent Enrollment is the best option

    I have configured directory sync to enrol a user. Does PGP validate a user from Active Directory?

    The only real way of using PGP in a production network will be via LDAPS like AD, you need to be able to use either LDAP or LDAPS (highly recommended) because otherwise user credentials are sent in the clear between your DC and UN so make sure the port is opened for LDAPS and tick the box to use it in Directory Syncronisation

     

    I assume if I want the enrolment to happen silently there is a options for this??

    There is an option for Silent Enrollment, but if you are using this product for WDE the user will (by default) get prompted to create and answer 5 questions for recovery.  You can turn this off however.  This also depends on what keymode the UN is in, if you are just playing around i suggest using Guarded Key Mode, that way the users private keys are stored on the UN and not under the control of the user.

     

    Whenever a action is performed by PGP desktop I get a certificate error which I need to allow. I assume I need to publish this certificate to the domain?

    What do you mean by this, even if you have a self signed certificate on the server the user experience on PGP Desktop will remain unaffected and you shouldn't get certificate errors

     

    What about email? I don’t understand this part all. We don’t need to use this feature at the moment but It would be good to get a understanding on how it works? and how to set it up correctly?

    You can set up the UN however you want in terms of email encryption.  The most common set up is to put in a setting whereby if the user puts in [ENCRYPT] or [PGP] or [PRIVATE] in the subject line, it goes for encryption, or if sending to a certain domain always encrypt, things like that.  The way you set up the UN depends on your internal setup, if you are SME, it should be in the mailflow to make the initial setup easier, so all mail passes through the UN and only encrypts stuff according to your policy chain, otherwise it passes it through to your MTA or SMTP server etc.

     

     

    PGP is basically a massive range of products to encrypt almost anything, that's pretty much all you need to know looking at it.

     



  • 3.  RE: Understanding PGP and how it works?

    Posted Jun 22, 2012 09:08 AM

    Thank you for your reply. This has made understanding the system far easier.

    I will try and get more information regarding the certificate issue next week.

    Thanks again

    Mac