McAfee Endpoint Encryption Manager



Similar documents
McAfee Optimized Virtual Environments - Antivirus for VDI. Installation Guide

McAfee Endpoint Encryption for Files and Folders. Best Practices. For EEFF product version 4.0.0

McAfee Endpoint Encryption for PC 7.0

McAfee Endpoint Encryption Reporting Tool

PrivateServer HSM Integration with Microsoft IIS

Check Point FDE integration with Digipass Key devices

McAfee Optimized Virtual Environments for Servers. Installation Guide

The McAfee SECURE TM Standard

Implementing Federal Personal Identity Verification for VMware View. By Bryan Salek, Federal Desktop Systems Engineer, VMware

Desktop Release Notes. Desktop Release Notes 5.2.1

How To Run A Password Manager On A 32 Bit Computer (For 64 Bit) On A 64 Bit Computer With A Password Logger (For 32 Bit) (For Linux) ( For 64 Bit (Foramd64) (Amd64 (For Pc

SafeGuard Easy upgrade guide. Product version: 7


SafeGuard Enterprise upgrade guide. Product version: 7

FileMaker Server 14. FileMaker Server Help

Entrust Managed Services PKI

Net Protector Admin Console

The Benefits of an Industry Standard Platform for Enterprise Sign-On

Application Note Gemalto Access Client for windows smart card and EFS on Microsoft Windows Vista

Entrust Managed Services PKI. Getting an end-user Entrust certificate using Entrust Authority Administration Services. Document issue: 2.

Did you know your security solution can help with PCI compliance too?

VeriSign PKI Client Government Edition v 1.5. VeriSign PKI Client Government. VeriSign PKI Client VeriSign, Inc. Government.

McAfee Internet Security Suite Quick-Start Guide

HP ProtectTools Embedded Security Guide

G/On Release Note. The latest information regarding the G/On software. G/On Version: 5.3 Document revision: 6

DIGIPASS KEY series and smart card series for Juniper SSL VPN Authentication

RSA SecurID Software Token 3.0 for Windows Workstations Administrator s Guide

DriveLock and Windows 7

Application Note Gemalto.NET 2.0 Smart Card Certificate Enrollment using Microsoft Certificate Services on Windows 2008

Guide to Obtaining Your Free WISeKey CertifyID Personal Digital Certificate (Personal eid) WISeKey 2010 / Alinghi 2010 Smartcards

FileMaker Server 13. FileMaker Server Help

Cyber-Ark Software. Version 4.5

Smart Card Setup Guide

Card Management System Integration Made Easy: Tools for Enrollment and Management of Certificates. September 2006

Integration Guide. SafeNet Authentication Client. Using SAC CBA for Check Point Security Gateway

SafeGuard Enterprise upgrade guide. Product version: 6.1

SafeGuard Enterprise Web Helpdesk. Product version: 6.1

TPM. (Trusted Platform Module) Installation Guide V for Windows Vista

McAfee Home Use Option Program

Abila MIP. Installation User's Guide

SmartCenter for Pointsec - MI Overview

CAC/PIV PKI Solution Installation Survey & Checklist

Shakambaree Technologies Pvt. Ltd.

For Managing Central Deployment, Policy Management, Hot Revocation, Audit Facilities, and Safe Central Recovery.

Chapter 1 Scenario 1: Acme Corporation

Backup and Restore with 3 rd Party Applications

Administrator Manual

Use of Common Access Cards (CACs) from Home on Windows 7 without Middleware

Application Note. Intelligent Application Gateway with SA server using AD password and OTP

Entrust Managed Services PKI. Configuring secure LDAP with Domain Controller digital certificates

Velocity 3.1 KB640 Release Notes

IBM Security SiteProtector System Configuration Guide

GRAVITYZONE HERE. Deployment Guide VLE Environment

TrustKey Tool User Manual

CA SiteMinder. Upgrade Guide. r12.0 SP2

HP ProtectTools User Guide

Two Factor Authentication in SonicOS

McAfee VirusScan Enterprise for Linux Software

Citrix Access Gateway Plug-in for Windows User Guide

Oracle Enterprise Single Sign-on Technical Guide An Oracle White Paper June 2009

System Compatibility. Enhancements. Security. SonicWALL Security Appliance Release Notes

Here you can see an example of the command results:

SAS 9.3 Foundation for Microsoft Windows

Operating System Installation Guide

Symantec Endpoint Encryption Removable Storage

McAfee EETech for Mac 6.2 User Guide

HYPERION SYSTEM 9 N-TIER INSTALLATION GUIDE MASTER DATA MANAGEMENT RELEASE 9.2

Secure Installation and Operation of Your Xerox Multi-Function Device. Version 1.0 August 6, 2012

How To Install Storegrid Server On Linux On A Microsoft Ubuntu 7.5 (Amd64) Or Ubuntu (Amd86) (Amd77) (Orchestra) (For Ubuntu) (Permanent) (Powerpoint

Trend Micro OfficeScan Best Practice Guide for Malware

Mobile App User's Guide

Device LinkUP + Desktop LP Guide RDP

Guide for Securing With WISeKey CertifyID Personal Digital Certificate (Personal eid)

TPM. (Trusted Platform Module) Installation Guide V2.1

McAfee Certified Product Specialist McAfee epolicy Orchestrator

McAfee Total Protection Reduce the Complexity of Managing Security

Core Protection for Virtual Machines 1

HP ProLiant Essentials Vulnerability and Patch Management Pack Release Notes

McAfee Web Gateway Administration Intel Security Education Services Administration Course Training

VPN CLIENT USER S GUIDE

SafeGuard Enterprise Web Helpdesk. Product version: 6 Document date: February 2012

McAfee Firewall Enterprise 8.2.1

Networking Best Practices Guide. Version 6.5

vsphere Upgrade vsphere 6.0 EN

Microsoft Windows Server 2003 Integration Guide

Do "standard tools" meet your needs when it comes to providing security for mobile PCs and data media?

Mobile App User's Guide

Information security guidelines

SEZ SEZ Online Manual Digital Signature Certficate [DSC] V Version 1.2

LifeSize Control Installation Guide

When your users take devices outside the corporate environment, these web security policies and defenses within your network no longer work.

Avira Server Security Product Updates. Best Practice

Installing and Configuring vcenter Multi-Hypervisor Manager

Sophos SafeGuard Native Device Encryption for Mac Administrator help. Product version: 7

Using HP System Software Manager for the mass deployment of software updates to client PCs

SafeNet Cisco AnyConnect Client. Configuration Guide

Importing data from Linux LDAP server to HA3969U

VERITAS Backup Exec TM 10.0 for Windows Servers

Verified for Windows Server 2003 Test Specification

Data Sheet. NCP Secure Enterprise Management. General description. Highlights

Transcription:

McAfee Endpoint Encryption Manager Product Release Notes Version 5.2.6

McAfee, Inc. McAfee, Inc. 3965 Freedom Circle, Santa Clara, CA 95054, USA Tel: (+1) 888.847.8766 Internet: www.mcafee.com Document: Endpoint Encryption Manager Product Release Notes Last updated: Wednesday, 17 November 2010 Copyright (c) 1992-2010 McAfee, Inc., and/or its affiliates. All rights reserved. McAfee and/or other noted McAfee related products contained herein are registered trademarks or trademarks of McAfee, Inc., and/or its affiliates in the US and/or other countries. McAfee Red in connection with security is distinctive of McAfee brand products. Any other non-mcafee related products, registered and/or unregistered trademarks contained herein is only by reference and are the sole property of their respective owners.

Introduction Introduction Intention of the Release Notes Document This paper describes the new functions and features introduced with the new product release of the McAfee Endpoint Encryption Manager (EEM). This document contains two main sections: 1. Notes on the Product issues you should know about. 2. Release Notes - New functions and features in this release. 8BUpgrading from Previous Releases To apply this release to previous V4.0/V5.0 installations please follow the instructions in the Endpoint Encryption Update and Migration Guide which can be found in the root folder of the software build. 3

Notes on the Product Notes on the Product Adding new features and fixes to an existing Enterprise If you want to add the new features and fixes to an existing Endpoint Encryption Manager, please follow the instructions in the Endpoint Encryption Update and Migration Guide, which can be found on the root folder of the software build. This document describes how to update an existing enterprise version of Endpoint Encryption to the latest version and how to implement dedicated features like Smart Cards and Tokens. If you are installing from new, please follow the instructions of the Endpoint Encryption Quick Start Guide. Adding new Smart Cards and Tokens To implement new smart cards and tokens in the Endpoint Encryption Manager please follow the instructions in the Endpoint Encryption Update and Migration Guide, which can be found, on the root folder of the software build. If you are performing a fresh installation, please follow the instructions in the Endpoint Encryption Quick Start Guide. Furthermore, please ensure your PC has the reader drivers installed before trying to install Endpoint Encryption for PC. You can find drivers for supported readers in the Tools software package, which can be downloaded from www.mcafee.com. Split Builds The Endpoint Encryption Manager is now a separate build from the products it manages. This action was taken to allow Endpoint Encryption Manager and other products to have their own release schedules. Moving forward these builds will be maintained, updated, installed/upgraded and potentially released separately. Administrators will need to install the Endpoint Encryption Manager first, followed by the product(s) they wish to use. The overall functionality of the products remains the same but their install/upgrade procedure can and may vary. The Endpoint Encryption Manager can be upgraded independently from the products it manages. Anti-Virus Exceptions It is not necessary to use a virus scanner on the database (SBDATA). Most of the data is encrypted, so there is nothing to be scanned and scanning will reduce much of the performance. 4

Notes on the Product It is recommended you create the following exceptions for the Endpoint Encryption Database Server: SBDATA Database: The Endpoint Encryption Database Folder and all subfolders should be excluded from any scanning. The database is currently stored in c:\sbdata. Database Service: The Database Process should be excluded from any scanning. The process is called SbDbServer.exe. Connector Manager: It is recommended you exclude the active directory connector. The process is SbConnectorManager.exe. Database Backup Tool: The Database Backup Tool should be excluded. The process is called SFDBBack.exe. WebHelpDesk: The WebHelpdesk and WebSelf Recovery https Service should be excluded. The process is called SbHttp.exe. Reporting Tool: The Reporting Tool should be excluded from any scanning. The process is called SbReports.exe. Scripting Tool: The McAfee Encryption administration command line tool should be excluded from the scan process. The process is called SbAdmCL.exe. 5

EEM Release Notes for 5.2.6 EEM Release Notes for 5.2.6 Reference Description 5260.1 The Connector Manager was importing the wrong certificate via LDAP To allow the connector Manager to function in both ways a new setting can be added to the CmSettings file. <CheckCertEncrypt>1</CheckCertEncrypt> is the new setting to check for encryption on a certificate. The default is 0 and works as in previous releases. 5260.2 Modify PIV tokens to allow self-initialization This release now supports the PIV token support and is able to handle selfinitialization. 5260.3 Count incorrect in Machine Client Versions report. This issue has been corrected. It was experienced due to an internal logic error. 5260.4 Users able to request a force password change for users of a higher level. This issue has been corrected. It was experienced due to an internal logic error. 5260.5 Validate PKI Smartcard certificate expiry date Smartcard certificate expiry date is now stored in the management center as the Valid until date. This date is then validated within the client. For Smartcards that use Self-initialization, the certificate is validated from the token when presented for logon. 5260.6 Include support for Gemalto GX4 144K Smartcards Support for these Smartcards has now been implemented. 5260.7 Add additional modules to Self-test verification when operating in FIPS mode. Additional DLL s have been added to the list of modules to verify. 5260.8 Support the internal readers on HP nc8430 Support for the internal reader on the HP nc8430 has now been implemented. 5260.9 Display Pin instead of Password when authenticating using a PIV Smartcard This change to the logon UI has now been implemented. 5260.10 SbDbServer crashing Some issues occurred with the SbDbServer crashing. This was caused by memory release problems which under a rare combination of multiple client interactions eventually lead to the crash. 6

EEM Release Notes for 5.2.6 5260.11 Enhance the Scripting tool command CreateUser to allow the option to Force Password change. A new option ForcePasswordChange has been added to the command. 5260.12 Enhance the Scripting tool command CreateUser to allow the option to Force Password change. A new option ForcePasswordChange has been added to the command. 5260.13 A new report to determine which users have registered/not registered for WebHelpDesk. The Users WebHelpDesk Registration Report is now available. This report determines if a user is registered for WebHelpDesk. 5260.14 The Group Counts report to show the number of items in a group A new report has been produced to see the number of items in a group. 5260.15 A new report to show all machines that have a certain file set attached A new report has been produced to see all machines that have a certain file set attached. 5260.16 When using multiple group mappings within the LDAP or AD connector, the users in the final group do not import. This would result in user deletion if a group mapping was being used to import the users. This issue was due to an internal logic error that failed to correctly handle the final element in the group list. 7