Dell Data Protection | Encryption Guide de l'utilisateur Page 73

  • Télécharger
  • Ajouter à mon manuel
  • Imprimer
  • Page
    / 188
  • Table des matières
  • DEPANNAGE
  • MARQUE LIVRES
  • Noté. / 5. Basé sur avis des utilisateurs
Vue de la page 72
Enterprise Edition Administrator Guide 73
Encryption Client Uninstallation and Decryption Tasks
When using
System Data Encryption (SDE)
,
User
, or
Common
encryption, file decryption optionally occurs at
uninstallation if you choose to install the
Encryption Removal Agent. This enables you to decide whether or not to decrypt
files.
When using HCA encryption, all HCA-encrypted drives m
ust be decrypted prior to uninstallation. The Encryption
Removal Agent does not decrypt HCA encrypted drives. To decrypt HCA encrypted drives, publish the policy Hardware
Crypto Accelerator=False, allow the decryption process to complete, and then initiate the uninstall process.
Before beginning the unins
tall process, see
How to Create an Encryption Removal Agent Log File (Optional)
. This log file is
useful for troubleshooting an uninstall/decryption operation. If
you do not intend to decrypt SDE, User, or Common
encrypted files during the uninstall process, you do not need to create an Encryption Removal Agent log file.
Best Practices
1
Back up all data.
2
To reduce decryption time, run the Windows Disk Cleanup Wizard to remove temporary files and other unneeded data.
3
Disable UAC. UAC may prevent uninstallation of the Encryption client.
4
Plan to decrypt overnight, if possible.
5
Turn off sleep mode to prevent an unattended computer from going to sleep. Decryption cannot occur on a sleeping
computer.
6
Ensure that you have the correct version of the DDPE_
XX
bit_setup.exe file. Use the same version to uninstall as was
used to install.
7
Shut down all processes and applications to minimize decryption failures because of locked files.
8
Follow your existing process for decrypting data, such as issuing a policy update.
9
Before performing a restart, run WSScan to ensure that all data is decrypted. See Use WSScan for instructions.
10
Disable all network connectivity. Otherwise new policies may be acquired that would re-enable encryption.
11
Periodically Check Encryption Removal Agent Status. If the
Encryption Removal Agent
Service exists, then data
decryption is still in process.
Prerequisites
When using the option
Encryption Removal Agent - Download Keys from Server,
you must first configure the Dell Key
Server and DDP Enterprise Server. See Configure Dell Key Server for instructions. The Dell Key Server is not used with
the DDP Enterprise Server - VE.
When using the option
Encryption Removal Agent - Import Keys from a file
, you must use the CMGAd utility prior to
launching the Encryption Removal Agent to obtain the encryption key bundle. The CMGAd utility and its instructions
are located in the Dell installation media (Dell-Offline-Admin-
XX
bit-8.x.x.xxx.zip)
Vue de la page 72
1 2 ... 68 69 70 71 72 73 74 75 76 77 78 ... 187 188

Commentaires sur ces manuels

Pas de commentaire