PGP Product Update Juha Ropponen Arrow ECS Finland Oy 1
Symantec Encryption tuoteperhe uudet nimet PGP Universal Server = Encryption Management Server Whole Disk Encryption = Drive Encryption Netshare = File Share Encryption PGP Universal Gateway Email = Gateway Email Encryption PGP Desktop Email = Desktop Email Encryption PGP Desktop = Encryption Desktop Powered By PGP Technology 2
Summary of features offered PGP Universal Server Client management Email protection Key management PGP Desktop Full disk encryption Shared file and folder protection Local file and folder protection Email encryption 3
PGP Universal Server Centralized management for all PGP Applications Eventually will manage all encryption applications Cannot manage any Symantec Endpoint Encryption (SEE) products at the moment 4
PGP Universal Server Defined PGP Universal Server is the primary component of a PGP security architecture PGP Universal Server is PGP Universal Server 5
A Management System PGP Universal Server can provide policy and encrypted data recovery mechanisms for PGP Desktop clients PGP Universal Server PGP Desktop PGP Desktop PGP Desktop 6
An Email Proxy PGP Universal Server can proxy standard email protocols: SMTP POP IMAP Outbound mail PGP Universal Server Inbound mail It can also encrypt, decrypt, sign and verify email 7
A Key Management Server PGP Universal Server can act as a key server It can also search other servers for keys It can generate and issue keys for users PGP Keys PGP Universal Server SMIME It will also maintain and provide verification for keys that it manages 8
A Soft Appliance Our software + Your hardware = (or VMware ESX) PGP Universal Server 9
PGP Universal Server Components Open-Source components CentOS PostgreSQL - back end database OpenLDAP - public/private key query operations Postfix - mail transfer agent Apache httpd and Jakarta Tomcat - administration and user access Custom PGP components PGP proxy daemon A user does not need to understand how to configure any of these components to administer PGP Universal Server PGP key maintenance tools PGP update/backup utilities 10
PGP Desktop Defined A client that offers access to many cryptographic functions Hard disk protection File & folder protection Volume protection Secure file deletion Messaging security PGP Desktop 11
PGP Desktop Defined Can be used by itself or be managed by PGP Universal Server If managed, all PGP application settings come from the server Recovery data is stored on the server Managed PGP Desktop is the focus of this class 12
PGP Desktop file and folder protection PGP Desktop also has file and folder protection A Winzip style product called PGP Zip An encrypted virtual container feature called PGP Virtual Disk A way to wipe data securely 13
PGP Volume Protection 14
PGP Whole Disk Encryption Can secure an entire hard drive by encrypting all data sector-bysector Can secure partitions of a hard drive 15
Hard Drive Protection Internal drives USB hard drives Boot drive protection includes boot sectors, system, and swap files 16
BootGuard Protection If an internal drive (or partition) is protected, users enter a passphrase before the system will boot 17
Windows Single Sign On Enter the Windows password at BootGuard and boot directly into the Operating System without entering a password at the Windows prompt 18
PGP NetShare What is PGP NetShare? A PGP Desktop feature meant to protect shared folders Can also be used on local folders Windows only Can synchronize with LDAP directory groups and encrypt files to a group key 19
Encrypts And Decrypts As Needed The plans for the big project PGP Desktop Plans.doc 20
Usage is transparent The plans for the big project PGP Desktop Plans.doc Plans.doc 21
Messaging Security 22
Where Is Sensitive Data at Risk? Email Resides at Multiple Points Client Systems Email at Risk Corporate Mail Server Email at Risk In Motion Email at Risk Recipients Mail Server Email at Risk Recipients Systems Email at Risk Internet Email is Vulnerable at Multiple Points SSL/TLS Security Alone is Not Sufficient 23
PGP Messaging Security Three PGP products can secure email PGP Universal Server PGP Desktop PGP for BlackBerry and Mobile devices 24
PGP Email Protection - Products at a Glance PGP Desktop Email Desktop-based Email Encryption Automatic end-to-end email encryption PGP Universal Gateway Email PGP Web Messenger PGP PDF Messenger Gateway-based Email Encryption Clientless email encryption Secure, Restricted Webmail for External Users Stored on PGP Universal Server Recipient does not need to have encryption keys Statement Delivery via PDF For secure delivery to internal or external recipients Recipient does not need to have encryption keys PGP Mobile products Blackberry Support Package PGP Viewer for ios devices Encryption for Windows Mobile Devices 25
PGP Desktop Email How it Works Client Systems Email at Risk Corporate Mail Server Email at Risk Recipients Recipients In Motion Mail Server Systems Email at Risk Email at Risk Email at Risk PGP Desktop Email PGP Desktop Email PGP Desktop Email Internet PGP Desktop Email PGP Support Package for BlackBerry PGP Support Package for BlackBerry End-to-End Email Encryption Protects Email in Motion and at Rest 26
PGP Desktop Messaging Proxy PGP Desktop can secure POP, IMAP, SMTP, MAPI and Notes email traffic It will enforce its own policies Or it can enforce PGP Universal Server mail policies PGP Desktop 27
PGP Universal Server Messaging Proxy PGP Universal Server can encrypt, decrypt, sign and verify email Email at Risk Email at Risk In Motion Email at Risk Recipients Mail Server Email at Risk Recipients Systems Email at Risk PGP Desktop Email Internet PGP Universal Web Messenger PGP Universal Gateway Email + PGP PDF Messenger PGP Universal Server PGP Universal Gateway Email Secures All Communications 28
PGP Universal Gateway Email Gateway-based Email Encryption Easy, automatic operation Email secured at gateway No client software or end user involvement Secure delivery options without client software PGP Universal Server management Enables automated, centrally deployed and managed policies, users, keys and configurations Corporate access to encrypted data SEC108: Encryption Portfolio & Roadmap 29
Symantec Encryption tuoteperhe uudet nimet PGP Universal Server = Encryption Management Server Whole Disk Encryption = Drive Encryption Netshare = File Share Encryption PGP Universal Gateway Email = Gateway Email Encryption PGP Desktop Email = Desktop Email Encryption PGP Desktop = Encryption Desktop Powered By PGP Technology 30
Thank you! SYMANTEC PROPRIETARY/CONFIDENTIAL INTERNAL USE ONLY Copyright 2010 Symantec Corporation. All rights reserved. 31