This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Problems slaving drive with full disk encryption (not bitlocker)

I am testing policies and various situations with a new installation of SafeGuard Enterprise. 

I have a drive from a laptop that has full disk encryption with POA that I have attached using USB to a desktop.  The desktop has SafeGuard but not the POA peice.  My policies are setup such that laptops get the boot drive encrypted (non bitlocker as the post title says) and use POA.  All PC's including desktop are getting file encryption for removeable media so all of them will have SafeGuard but the desktops will not have the POA module. (I am wondering if not having the module is the source of my issue - setting up another laptop to test that theory...)

According to the documentation: http://sophserv.sophos.com/repo_kb/108156/file/Recovery_in_SafeGuard_Device_Encryption.pdf

I should see a red key on the laptop drive in "my computer" on the desktop.  I actually see a yellowish-orange key but close enough I supposed.  If I simply try and browse the laptop drive I get a message "You need to format the disk in drive G: before you can use it".  After acknowledging that message it says "G:\ Is not accessible.  The volume does not contain a recognized file system.  Please make sure that all file system drivers are loaded and that the volume is not corrupted."  It is that last line which has me thinking maybe the POA module of the SafeGuard client needs to be installed.

If I run RecoverKeys.exe I do show a key ID next to the drive and when I look in the SMC it is the key corresponding to the laptop.  I assigned the key to the appropriate user account but I still can't access the drive and still receive the same errors as indicated above.

:57730


This thread was automatically locked due to age.
  • Well it turned out to be the volume based encryption peice of the SafeGuard client afterall.  I was able to prove this in two ways.  I was able to slave the drive to a laptop which had the POA peice installed and configured and the slaved drive was readable.  In fact it showed no key overlay icon at all.  I could just browse it. 

    I also modified the client installation on a desktop by adding the Volume Based Encryption feature and once again I was able to browse the drive when I attached it to the desktop.

    :57744