Endpoint Encryption

 View Only
  • 1.  User's to access multiple encrypted network shares

    Posted Feb 05, 2015 01:20 AM

    I'm using Symantec Encryption Server (Version 3.3.2 MP6) and Symantec Encryption Desktop (Version 10.3.2 MP6) on the clients (all Win 7 x64)

    I have two groups of users (drawn in via LDAP AD), one group needs accees to one encrypted folder and the other group needs access to a separate encrypted folder, but also needs access to the first folder as well.

    If I've set the groups up with their own group key, and their own policy, Will the second group be able to read the first encrypted folder? Or will it be encrypted with the first groups key? If so, what would be the best way to solve this issue?

    I'd appreciate any help or advice



  • 2.  RE: User's to access multiple encrypted network shares
    Best Answer

    Posted Feb 05, 2015 01:00 PM

    It should be fairly straight-forward.  Just to verify, let me know if this is correct:
    You have Group A and Group B.
    You have Folder 1 and Folder 2.
    Folder 1 should be encrypted to Group A.
    Folder 2 should be encrypted to both Group A and Group B.

    You should be able to just encrypt one folder using both group keys, which should give both groups access, and encrypt the other folder with the group key for the one group you want to access it.

    When encrypting a folder initially, you have to manually set up which keys are involved.  One keypair is needed (preferably NOT one of the group keys) as an administrator's keypair, then one or both group keys can be added as desired.



  • 3.  RE: User's to access multiple encrypted network shares

    Posted Feb 05, 2015 05:39 PM

    Thank-you for your reply Mike,

    Yes, you are correct in what I am trying to achieve.

    And just to confirm your information.

    The only way to setup the keys is from one of the Client installations and can not be done from the Management server?

    (If so,) If a user, say 'administrator', is the 'Admin' under 'User Access' adds both Group A and Group B to the 'User Access' on the client this will then allow both groups to access the content, and any content that is added by either group can be read and modified by the other group?