This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Sophos Disk Encryption Master Certificate Question

Hi,

As part of our Sophos Data Protection Suite we have Disk Encryption 5.61 installed.  We currently have SEC 5.1 installed and I've been tasked with a piece of work to upgrade this to v5.2.1 r2.

The problem I have is we have existing Disk Encryption in place.  I have inherited the server install and documentation as is and I don't have all the information for the Disk Encryption certificates.  I have the Master Officer and Company certificates, but the passwords for the p12 keys have been lost meaning I cannot import the certificates during the v5.2.1 upgrade.

I guess my main question is whether there is any way to export the certificates again from the SEC server, or maybe by using the Policy Editor, or Manage Certificates tools provided in the Safeguard installer?

If this isn't possible without the passwords, what options do I have to upgrade the console and how would this impact on existing machines with disk encryption?

Thanks for any help you can provide.

Gav

:46325


This thread was automatically locked due to age.
Parents
  • Hello Gav,

    you can back up the Company certificate at any time, the MSO certificate is only backed up during install though.

    During Beta tests I have moved an encrypted client from one management server to another (with the same SEC certificates). Can't remember the details though (especially if I did import the encryption certificates before installing the second server). Sounds like you want to migrate the server (i.e. install on a new machine) - in this case you could "move" a test client to the new SEC and check whether it can be managed. This is of course extra work (especially if it doesn't work) so I suggest you contact Support directly.

    Christian 

    :46371
Reply
  • Hello Gav,

    you can back up the Company certificate at any time, the MSO certificate is only backed up during install though.

    During Beta tests I have moved an encrypted client from one management server to another (with the same SEC certificates). Can't remember the details though (especially if I did import the encryption certificates before installing the second server). Sounds like you want to migrate the server (i.e. install on a new machine) - in this case you could "move" a test client to the new SEC and check whether it can be managed. This is of course extra work (especially if it doesn't work) so I suggest you contact Support directly.

    Christian 

    :46371
Children
No Data