Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

SGN 5.50 policy editor challenge wizard not working!

Help!

I created a standalone policy in 5.40 some time ago. The policy was fairly bland basically encrypt hard drive, windows authentication (not using PBA) and pretty much everything else default. Been using this for a whilewithout any real issues.

Bought a new laptop which is a Core-i5 processor which 5.40 doesn't support so waited and it looks like 5.50 seems ok on it. When I installed 5.50, I installed the pre-install package and the SGNClient.msi package, rebooted to check that 5.50 comes up ok which it now does. Once rebooted, I installed the policy package I'd created in 5.40. This went on fine and the machine immediately ecrypted it's HD - perfect! I saved my key files safely away on a network drive.

Since it was some time ago I created the original policy, I loaded on the new policy editor onto another machine and started to have a play at creating a new policy. The original 5.40 policy configuration was lost some time ago but since we run standalone, didn't really matter to me. I only needed the policy editor to create the original standalone package.

Clicking menus, I thought then I'd try the new recovery wizard in the new 5.50 policy editor so I went to my shiny new laptop, put in a rubbish password 16 times and locked out. I rebooted and on the laptop, I got the locked screen and the challenge button which I pressed, obtained my challenge key. I started up the recovery wizard and immediately was asked for a security key file which I pointed at the file I created earlier on the new laptop and immediately, the recovery wizard said 'invalid key file'. Oh dear!

So there you have it, I've a really nice new book end on my desk now which was a lovely new laptop. Once locked out, it appears you're stuffed and I now start the long task of reinstalling from scratch. I think there's someting not right with the new policy editor/recovery wizard. Anyone else tried this :o)

Matt

:2602


This thread was automatically locked due to age.
Parents
  • Hi Gsmdit,

    I've not yet seen this issue with 5.50.0.116 to 5.60 . In my scenario, I had a policy created with a 5.40 policy editor then the editor and machines were upgraded to 5.50.0.116 as per Sophos instructions but no new policy was generated or applied to the clients (again, as per Sophos instructions which at the time said you didn't need to). Turns out that this wasn't correct and jumps from 5.40 to 5.50 or any major version jump, need to have the policy uninstalled, a new policy file generated in that version and then reinstalled on the clients and a new key file generated.

    In essence, I think you're screwed unless you have a backup of the 5.50.0.116 policy as it was at the point of install and can get the policy editor up and running again to generated the challenge response. You may also be able to generate a PE recovery cd and decrypt the disk to retrieve the data. Not going to hold my breath on that though, Sophos couldn't help me when 5.40 to 5.50 failed this way and I ended up ditching and reinstalling

    Talk to Sophos support, it's your best option right now.

    Matt

    :15039
Reply
  • Hi Gsmdit,

    I've not yet seen this issue with 5.50.0.116 to 5.60 . In my scenario, I had a policy created with a 5.40 policy editor then the editor and machines were upgraded to 5.50.0.116 as per Sophos instructions but no new policy was generated or applied to the clients (again, as per Sophos instructions which at the time said you didn't need to). Turns out that this wasn't correct and jumps from 5.40 to 5.50 or any major version jump, need to have the policy uninstalled, a new policy file generated in that version and then reinstalled on the clients and a new key file generated.

    In essence, I think you're screwed unless you have a backup of the 5.50.0.116 policy as it was at the point of install and can get the policy editor up and running again to generated the challenge response. You may also be able to generate a PE recovery cd and decrypt the disk to retrieve the data. Not going to hold my breath on that though, Sophos couldn't help me when 5.40 to 5.50 failed this way and I ended up ditching and reinstalling

    Talk to Sophos support, it's your best option right now.

    Matt

    :15039
Children
No Data