The purpose of encrypting the client's data is to control access to the data by controlling access to the encryption keys. It is important that keys are not accessible to users.
The key that encrypts the hard disk sectors needs to be protected. These keys are referred to as Machine Keys. Each system has its own unique Machine Key. The Machine Key is stored in the ePO - On-prem database to be used for client recovery, when required. There are four different system recovery options available in Drive Encryption that can be reached through: → → → → → .
Option | Definition |
|---|---|
Decrypt offline recovery file | The encrypted machine key is stored in a recovery information file (xml) on the client system. To enable the recovery procedures on the client systems, the user can use ePO - On-prem to decrypt the offline recovery file that is retrieved from the client system. |
Destroy all recovery information | When you want to secure-erase the drives in your Drive Encryption installed system, remove all users from the system (including those inherited from parent branches in the System Tree). This makes the disks inaccessible through normal authentication as there are no longer any users assigned to the system. You need to then destroy the recovery information for the system using the option → → → → → → in the ePO - On-prem console. This means that the system can never be recovered. |
Key Re-use | This option is used to activate the system with the existing key present in the ePO - On-prem server. This option is highly useful when a boot disk gets corrupted and the user cannot access the system. Other disks on the system can be recovered by activating it with the same key from ePO - On-prem. |
Export recovery information | This option is used to export the recovery information file (.xml) for the desired client system from ePO - On-prem. Every client system that is encrypted using Drive Encryption has a recovery information file in ePO - On-prem. Any user trying to enable the recovery procedures on the client systems should get the file from the ePO - On-prem administrator for Drive Encryption. For more information, see the DETech User Guide. NoteThe recovery information file has a general format of client system name.xml. |
Export recovery information based on Disk Keycheck | This option is used to export the recovery information file (.xml) for a disk of a client system from ePO - On-prem. Every disk of a client system has a disk keycheck value. For instance, if a client system has a disk called 'Disk1', you can recover that client system (when on unrecoverable state) using the keycheck value of 'Disk1'. However, if a new disk 'Disk2' is installed and activated in that same client system, you must use the keycheck value of 'Disk2' and the keycheck value of 'Disk1' loses priority. To perform this task, you need to access the client system using DETech and obtain the disk keycheck value using the Disk Information option from the DETech user interface.
|
You cannot log on to the client system before a proper agent-server communication occurs. In this situation, use the DETech tool to obtain the Key Check value from the client and obtain the recovery key for this machine from the ePO - On-prem console to perform an Emergency Boot.