Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

SGN 5.50 policy editor challenge wizard not working!

Help!

I created a standalone policy in 5.40 some time ago. The policy was fairly bland basically encrypt hard drive, windows authentication (not using PBA) and pretty much everything else default. Been using this for a whilewithout any real issues.

Bought a new laptop which is a Core-i5 processor which 5.40 doesn't support so waited and it looks like 5.50 seems ok on it. When I installed 5.50, I installed the pre-install package and the SGNClient.msi package, rebooted to check that 5.50 comes up ok which it now does. Once rebooted, I installed the policy package I'd created in 5.40. This went on fine and the machine immediately ecrypted it's HD - perfect! I saved my key files safely away on a network drive.

Since it was some time ago I created the original policy, I loaded on the new policy editor onto another machine and started to have a play at creating a new policy. The original 5.40 policy configuration was lost some time ago but since we run standalone, didn't really matter to me. I only needed the policy editor to create the original standalone package.

Clicking menus, I thought then I'd try the new recovery wizard in the new 5.50 policy editor so I went to my shiny new laptop, put in a rubbish password 16 times and locked out. I rebooted and on the laptop, I got the locked screen and the challenge button which I pressed, obtained my challenge key. I started up the recovery wizard and immediately was asked for a security key file which I pointed at the file I created earlier on the new laptop and immediately, the recovery wizard said 'invalid key file'. Oh dear!

So there you have it, I've a really nice new book end on my desk now which was a lovely new laptop. Once locked out, it appears you're stuffed and I now start the long task of reinstalling from scratch. I think there's someting not right with the new policy editor/recovery wizard. Anyone else tried this :o)

Matt

:2602


This thread was automatically locked due to age.
Parents
  • Hi Dave,

    XML file is generated by key backup only. When you encrypt, it just kicks off the same process so that you effectively have at least one backup performed as you encrypt.

    When I compared a 5.40 XML and key file and a 5.50 XML from the same policy MSI (generated in 5.40 policy editor), there is a distinct difference between what 5.50 generates (you'd expect with the same policy that it would be identical but it's not). I suspect that it's the same 5.50 to 5.60, a machine generating an XML generated on a 5.60 client with a 5.50 policy MSI will generate an invalid XML key which is what I think you're seeing and would follow exactly the same problem I had 5.40 to 5.50.

    For the clients that are currently running 5.60, I would generate a new policy MSI file and then on each client, uninstall the policy and then install the newly  created 5.60 policy. After that, generate a new key backup by right-clicking the SGN shield and then testing the key backup XML in the recovery wizard. If it generates an error when you load the XML, you'll probably have to completely uninstall and reinstall the entire client.

    Anything back from Sophos technical?

    Matt

    :15059
Reply
  • Hi Dave,

    XML file is generated by key backup only. When you encrypt, it just kicks off the same process so that you effectively have at least one backup performed as you encrypt.

    When I compared a 5.40 XML and key file and a 5.50 XML from the same policy MSI (generated in 5.40 policy editor), there is a distinct difference between what 5.50 generates (you'd expect with the same policy that it would be identical but it's not). I suspect that it's the same 5.50 to 5.60, a machine generating an XML generated on a 5.60 client with a 5.50 policy MSI will generate an invalid XML key which is what I think you're seeing and would follow exactly the same problem I had 5.40 to 5.50.

    For the clients that are currently running 5.60, I would generate a new policy MSI file and then on each client, uninstall the policy and then install the newly  created 5.60 policy. After that, generate a new key backup by right-clicking the SGN shield and then testing the key backup XML in the recovery wizard. If it generates an error when you load the XML, you'll probably have to completely uninstall and reinstall the entire client.

    Anything back from Sophos technical?

    Matt

    :15059
Children
No Data