Centrally-Managed Drive Encryption

gimp

[H]F Junkie
Joined
Jul 25, 2008
Messages
10,583
So we're attempting to evaluate a replacement for GuardianEdge.

We want something that gets away from a pre-boot environment. Something that just runs as an agent. Similar to Credant Mobile Guardian.

Are there any other products out there similar to Credant?
We have looked at PGP, but it is similar to GuardianEdge; it has a pre-boot environment. Safeboot is similar, also.

But we need it to be centrally managed, so a hardware-solution will not work.

Bitlocker is a possibility, but unfortunately we have not taken the plunge past XP yet (sadly). Although I don't know what kind of management tools it has, as I haven't looked in to it (since we still don't know when we will get the go-ahead to deploy Win7).
 
How do these products work without the boot loaders?

I have used PGP Universal for something that is managed centrally for around 100 machines and would recommend it.
 
Credant, for example, actually has 3 separate encryption keys.
There's the system level keys that are loaded and unlock (er, decrypt on-the-fly, really) system files at boot time.
Then there's a common key and user key. These don't go into effect until a domain user has successfully authenticated to the computer/domain.
So at the Windows log-on screen, only some files can be decrypted; namely Windows system files. You will not be able to access user files using the C$ share if a user is not logged on; much unlike GuardianEdge. Since once a user authenticates to GE and lets Windows boot, any and all files are accessible from the C$ share (assuming you have rights to access the C$ share, of course).

We are looking to get away from the pre-boot, since that is what we currently have with GuardianEdge, and it has been very, very, very troublesome from the user-support end-point.
 
We have a couple 100+ laptop clients who are using True Crypt for their encryption solution. It works well, though if someone forgets their decryption password they are hosed.

At a previous job we used PGP with a RSA token as our encryption solution. It worked pretty well and was nice because we could issue "Temporary" PINs so if you left your token at home you could still get into your PC.
 
We have a couple 100+ laptop clients who are using True Crypt for their encryption solution. It works well, though if someone forgets their decryption password they are hosed.

TrueCrypt doesn't have a central management console though, does it?

At a previous job we used PGP with a RSA token as our encryption solution. It worked pretty well and was nice because we could issue "Temporary" PINs so if you left your token at home you could still get into your PC.

again, we are looking to get away from pre-boot. Especially now that Symantec has bought both PGP and GuardianEdge, and they (supposedly) want to integrate the "best parts" of each FDE into a single package. Support with GE has been abysmal, and their product makes a huge, horrendous performance hit on all the PCs it's installed on. This includes the new Dell OptiPlex 780's with Core2Duo, 4GB RAM, and 7200RPM hdds.

We do not necessarily need a FDE. Just a centrally-managed file/drive encryption program.
We are currently looking at Credant, and it looks promising, but I need to find if there is anything that is comparable to Credant.
GuardianEdge, Safeboot, PGP, are not comparable, as they are pre-boot FDE; so it's like comparing apples to oranges.
 
Hey j-sta, do you know if this encryption product work on non Seagate Momentus drives? Because one of the whitepapers I pulled from their site keeps mentioning the Seagate Momentus drive.

I'm also looking for this type of encryption for my company too.
 
Hey j-sta, do you know if this encryption product work on non Seagate Momentus drives? Because one of the whitepapers I pulled from their site keeps mentioning the Seagate Momentus drive.

I'm also looking for this type of encryption for my company too.

not a clue. Credant is currently partnered with Dell, LANDesk, and Cisco. And we're strictly a Dell shop. Although I haven't heard of any issues, since Credant is agent-based; they normally don't have the compatibility issues that pre-boot FDE solutions can have.

edit: wait... ok the Momentus is one of the hardware-based "self-encrypting" drives. Now, the 2 Credant folks that were in town yesterday we met with all day, did mention these drives. Currently, Credant is working with Dell to provide centrallized management for these hardware-based encryption drive. That's about all I know.
and I'm going to guess you've seen this? http://www.credant.com/products/credant-drivemanager.html
 
look at SafeNet's ProtectDrive product...not sure your budget, but it should meet all your requirements.
 
look at SafeNet's ProtectDrive product...not sure your budget, but it should meet all your requirements.

Security Certifications
  • Common Criteria EAL-4
  • FIPS 140-2 Level 2 validated
  • FIPS-approved operations are only available on 32-bit platforms. Support for 64-bit platforms will be provided in a future release.
Unfortunately, not all.
 
look at SafeNet's ProtectDrive product...not sure your budget, but it should meet all your requirements.

Thanks, I'll look in to it! We had asked the Credant folks what would be comparable to their product; they didn't have an answer. We weren't sure if it was becuase there is no other agent-drive encryption that has central management, or if it was because they just didn't want to tell us. As for budget... state government. Currently, Credant wants to give us a huge kick ass deal, but our project management office wants to "evaluate other offerings." So I'm trying to find comparable offerings to Credant; otherwise, as I said, it's like comparing apples to oranges.

Security Certifications
  • Common Criteria EAL-4
  • FIPS 140-2 Level 2 validated
  • FIPS-approved operations are only available on 32-bit platforms. Support for 64-bit platforms will be provided in a future release.
Unfortunately, not all.

covers mine. We don't (currently) run 64-bit, except on a couple x64 WinXP's Dell workstations.
 
Hey j-sta,

Whatcha got for secure erase?

We're currently looking at LSoft Technologies' Active@Killdisk and it seems pretty decent.

we just use DBAN.

also @ SafeNet; ProtectDrive isn't really what we're looking for; it's another FDE product. Although ProtectFile looks possible; except that it requires an appliance on the network? Really?
 
so, the only other one I've been able to find after scouring the Google for a few hours is MobileArmor.
Along with SafeNet which jvlazzar mentioned.

Are there really that few agent-based encryption apps with centralized management and reporting?
 
so, the only other one I've been able to find after scouring the Google for a few hours is MobileArmor.
Along with SafeNet which jvlazzar mentioned.

Are there really that few agent-based encryption apps with centralized management and reporting?

The whole point with encryption is to not be able to get into the PC. I understand for large scale IT it is important to have things like central management so if a user forgets their decryption passcode you can reset it, or if someone leaves and doesn't tell you their decryption password, or you can set a universal config etc, the problem with opening back doors for the sysadmin is they can be broken by the bad guys meaning your fancy encryption solution is rendered useless.
 
The whole point with encryption is to not be able to get into the PC. I understand for large scale IT it is important to have things like central management so if a user forgets their decryption passcode you can reset it, or if someone leaves and doesn't tell you their decryption password, or you can set a universal config etc, the problem with opening back doors for the sysadmin is they can be broken by the bad guys meaning your fancy encryption solution is rendered useless.

central management is also a requirement for liability/legality reasons.

We need to be able to prove a device was encrypted. Central management logging provides this. If a piece of hardware with possible PHI data on it is stolen, we can say we are 100% sure the device was encrypted, since the end-user will not be able to decrypt the data.

Without central management, we cannot prove the device was encrypted.

And decyrption pass-codes? The whole point of an enterprise solution is so that it is seamless to the end-user; the only "pass-code" they may need, is a password set on removable storage. Regular access to the computer only requires the user successfully authenticate to the computer via their domain credentials, which is something they regularly do already.
 
central management is also a requirement for liability/legality reasons.

We need to be able to prove a device was encrypted. Central management logging provides this. If a piece of hardware with possible PHI data on it is stolen, we can say we are 100% sure the device was encrypted, since the end-user will not be able to decrypt the data.

Without central management, we cannot prove the device was encrypted.

I agree with the points, and understand the compliance requirements for enterprise, I am just saying that generally speaking with encryption the more holes you open for central management features the less secure it becomes.

And decyrption pass-codes? The whole point of an enterprise solution is so that it is seamless to the end-user; the only "pass-code" they may need, is a password set on removable storage. Regular access to the computer only requires the user successfully authenticate to the computer via their domain credentials, which is something they regularly do already.

It all depends on your setup. If you are doing file / removeable device only, then yes their windows authentication should be all they need, but if you are doing whole disk encryption then you will need to have a boot password so that it can decrypt the windows partition.
 
I agree with the points, and understand the compliance requirements for enterprise, I am just saying that generally speaking with encryption the more holes you open for central management features the less secure it becomes.

Considering the encryption keys aren't constantly passed around, the only real data being passsed via SSL is some system info or updated policies (only when the server is reachable, which would be currently only within our network), there aren't too many "holes" open.

It all depends on your setup. If you are doing file / removeable device only, then yes their windows authentication should be all they need, but if you are doing whole disk encryption then you will need to have a boot password so that it can decrypt the windows partition.

all the FDE solutions we've looked at, and the one we're currently running (GuardianEdge), do not require additional passwords for the bootup process. It syncs your AD credentials, so you log-in with your domain credentials, then logs you in to Windows.
4 or 5 others I've looked at are exactly the same; single sign-on.

Out of them all, they are the same. No additional passwords for the boot-up process, and the only additional password required is for removable storage.

And we are looking to get away from FDE, due to the huge impact it has had on our help desk.

And what enterprise in their right mind would not care about central management? What good would an encryption solution do without central management in an enterprise? Unless they have a ginormous help desk that can update policies manually.
 
What kind of problems have you been having though?

performance issues up the wazzu. Horrendously slow boot times, login times, etc.
Random lock-outs. Machine will, out of the blue, do an admin lock out as if the machine had not communicated with the server within it's 35 day period.
Confusion as to client admin password lengths; GE decided to change password requirements, and the way the software interprets passwords that are too long, a number of times between versions without anything in the release notes.
Users randomly getting unregistered with GE.
The GE admin and logging/reporting tools are very clunky.
GE Tech support is horrible. They don't seem to understand their own product that well (probably because it goes to fucking India).

It's an administrative headache.
 
Symantec has centrally managed encryption, however i believe it als has the pre-boot which you do not want
 
Symantec has centrally managed encryption, however i believe it als has the pre-boot which you do not want

Symantec bought both GuardianEdge and PGP, which are FDE solutions with a pre-boot environment. And we are currently using GuardianEdge :p
 
Symantec bought both GuardianEdge and PGP, which are FDE solutions with a pre-boot environment. And we are currently using GuardianEdge :p

Well that pretty much rules that out lol

Sophos has pre boot as well, and is sucks royal balls (currently deployed at site and will be removed)

have you thought about FDE hard drives with a mgmt console?
 
Well that pretty much rules that out lol

Sophos has pre boot as well, and is sucks royal balls (currently deployed at site and will be removed)

have you thought about FDE hard drives with a mgmt console?

unfortunately that would not be easy to deploy.
We're looking for a software-based solution, because we can deploy to all computers that cover the whole state. No division/section has the budget to replace all the HDDs with the fancy hdds with hardware encryption.

Down the road; maybe.

Here's the thing; it's government, and shit just doesn't make sense. Nobody really knows who originally bought GuardianEdge; or why. Then we got our security officer, who just got it shoved down his throat, basically, that this need to be deployed. We had no way to stop it.

But now, after our desktop support folks do a lot of bitching about how much of their time it's taking with calls related to GE, they've finally started looking elsewhere. If it were up to just our security officer at this point, Credant would be getting deployed.

Unfortunately, our project management office got involved. This basically puts everything in front of a brick wall. They are now wanting to "evaluate all solutions."

More or less, I was just trying to find out if there were any solutions comparable to Credant; which is agent-based data encryption. Not a full disk encryption.

A couple of the Credant folks flew up here earlier this week, and we met with them pretty much all day Tuesday. They did mention that they are currently working with Dell to provide a central management solution for the hardware-based encryption hard drives. But nothing has been released yet.

And with Credant currently partnering with IronPort, Cisco, and Dell (there may have been another), they are looking promising (since we are a Dell shop, we currently use Cisco Security Agent, and although I don't know what the status is, are/were using IronPort).
 
If you are looking for a solution that covers your existing machines and a mixture of Bitlocker and hardware encrypting drives in the future, then you should take a look at the central management server from Wave Systems.

Why did Symantec buy both PGP and GuardianEdge?
 
If you are looking for a solution that covers your existing machines and a mixture of Bitlocker and hardware encrypting drives in the future, then you should take a look at the central management server from Wave Systems.

Why did Symantec buy both PGP and GuardianEdge?

we need something pretty much *now*
hence a software solution.
Bitlocker? We aren't even going down the WIn7 road yet (and nobody knows when we will), and we completely skipped Vista.
A hardware solution really is not the answer (for us).

and I don't think anybody knows why Symantec bought both PGP and GE.
We're thinking they bought PGP more so for the email encryption side. Although they (Symantec) have stated they want to "take the best parts" of both PGP and GE, and essentially merge them into a Symantec-branded encryption solution.
 
Skipping Vista --> smart move.

One of the things I find confusing is how does non-FDE data protection meet compliance requirements. How can I prove after the fact that no valuable data resided outside the encrypted portions of the drive.
1. Non-encrypted folders in my system partition ...etc
2. print spoolers or hibernation files

How is a 3rd party non-FDE solution significantly different from EFS which is already baked into my XP machines.
 
Skipping Vista --> smart move.

One of the things I find confusing is how does non-FDE data protection meet compliance requirements. How can I prove after the fact that no valuable data resided outside the encrypted portions of the drive.
1. Non-encrypted folders in my system partition ...etc
2. print spoolers or hibernation files

How is a 3rd party non-FDE solution significantly different from EFS which is already baked into my XP machines.

through policies, we can select what will and won't be encrypted.
We can choose not to encrypt the Windows\System32 folder, but then add an inclusion that will encrypt all DOC, DOCX, TXT, etc files that are saved in the Windows\System32 folder.

Is EFS centrally managed? Are there policies we can set to choose what to encrypt and what not to encrypt? Are there policies that can be set for what to do with removable media? Does the central-management have logging features to show what policies are applied?

Are files locked down by different keys depending on how the policty is set? ie, can we use the system key to encrypt system files that are open to decryption when the system is booted, and a user key to encrypt user files and are only available when the user successfully authenticates on the machine?
 
I totally agree, Microsoft does not supply a central management solution for EFS.

I have seen EFS centralized management solutions for 3rd party ISVs, I personally don't have experience with them, I wonder if anyone on this forum has used them.

I checked www.wavesys.com site and they don't have centralized management EFS, they a software based solution for PCs, which don't have hardware encrypting drives.

With the solution you are currently checking out is there any downside?
Generally keys, policies and passwords seem to be a common source of help calls
Would multiple policies and multiple keys for different file types and different folders, make life easier or not.
 
I totally agree, Microsoft does not supply a central management solution for EFS.

I have seen EFS centralized management solutions for 3rd party ISVs, I personally don't have experience with them, I wonder if anyone on this forum has used them.

I checked www.wavesys.com site and they don't have centralized management EFS, they a software based solution for PCs, which don't have hardware encrypting drives.

With the solution you are currently checking out is there any downside?
Generally keys, policies and passwords seem to be a common source of help calls
Would multiple policies and multiple keys for different file types and different folders, make life easier or not.

pretty much, we're looking for an all-in-one package. We don't want a separate piece of software to manage a piece of encryption software.

The help calls the desktop support has been getting, is due to admin lockouts from GuardianEdge because of "failure to communicate with the GE server" in a specified amount of time (even if that specified amount of time has not lapsed), or accounts getting unregistered out of the blue. Those are probably the most. And GE tech support is.... lacking. To say the least.

With the non-FDE solution, we won't have that issue since the user doesn't "register" with the software. Keys are generated and stored on the server. They are very very easily recoverable from the server or web interface (if permission has been granted).
There are a total of three different types of keys.
System keys, which are generally used for system files. So that our automated patching process (LANDesk) will still be able to patch Windows and applications even if a user is not logged in (when a user is not logged in, only data encrypted with the system key is accessible).

User keys are unique per each user, and each user gets a different key on each device. These keys are used to access data encrypted with the user key; and can only happen when the user successfully authenticates onto the machine.

The common key is similar to the user key; except that if the common key is used in place of the user key, all encrypted user data on the PC will be accessible, regardless of what user logs on.
 
I would look into WinMagic and McAfee encryption solutions. McAfee just recently started putting out encryption software, both file/folder level (which I'm guessing is what your really looking for), and FDE level encryption.

WinMagic
McAfee Endpoint Encryption
 
It sounds like you have some things misconfigured with GE, we have no performance problems and users are completely unaware it exists unless they do any removable storage stuff.

What version are you running?
 
j-sta,

There is a company called Beachhead Solutions that provides an encryption solution that uses EFS as the encryption engine and its agent targets files based on file extensions defined as data and marks the folder that they are found in which thereafter encrypts any files or folders created or moved to those locations.

They also support Bitlocker and will also support Self Encrypting Drives shortly as well as other technologies. I am a former Security consultant and Bank CIO who had selected and used the product over software full disk products because of concerns simular to what you are experiencing. Because Beachhead uses encryption built into the OS you don't have issues with patching, disk recovery or other related issues. They also have trigger-based rules that can wipe the keys or data if you wish when the computer may be compromised or stolen. They don't require a server in-house since they host the admin console for you.

I have been working in the security field for over a decade holding CISSP and CISA certifications. From a security standpoint file & folder based encryption meets all data encryption/protection requirements without the added performance / IT burden of software full disk solutions. Self Encrypting Drives and BitLocker add protection by encrypting the operating system as well and perform much better than Software Full disk encryption solutions.

Since Beachhead can handle all of these technologies it is a good solution. It will be sometime before anyone can use only one of these technologies.
 
I would look into WinMagic and McAfee encryption solutions. McAfee just recently started putting out encryption software, both file/folder level (which I'm guessing is what your really looking for), and FDE level encryption.

WinMagic
McAfee Endpoint Encryption

hm.. I knew McAfee had an FDE... didn't realize they started doing an agent-based file encryption. May have to look in to that.

It sounds like you have some things misconfigured with GE, we have no performance problems and users are completely unaware it exists unless they do any removable storage stuff.

What version are you running?

#1 - we are using the GE Native Policy manager; it is not integrated into AD (note: I do not remember why it was decided to be setup this way. I had nothing to do with that process).

#2 - we have had numerous issues through all the versions. 9.2.0 through the current 9.5.3. Boot time is horrendously slow. My Dell Optiplex 620 (P4) with Credant is much faster than my Optiplex 745 (Core2Duo). Same model hard drives in both systems, and my 745 has more RAM.


Thanks, I'll look in to that one also.
 
McAfee purchased Safeboot a few years ago and it is Software Full Disk. They don't have file-based encryption as far as I have seen. Safeboot and all other FDE solutions other than BitLocker and SEDs have the boo time issue. And since most offer single signon syncing to the windows password, they also have issues with password synchronization when the user changes passwords, but is not on the domain at the time.
 
If you had checked my link, you would notice one of the features listed as "File/Folder encryption". And, from experience, I know for certain that McAfee can do File and Folder encryption.
 
What is the cheaper but still good option, say for 30 laptops?
I would say that Beachhead would be the cheapest solution for 30 laptops. This is because you don't need a management server in-house. They are also easy to implement, because you can truly push it out via GPO or software distribution application. The initial encryption pass tyically takes less than half an hour depending on how much data not the size of the drive. You will have to contact a Beachhead sales rep for pricing, but it was under $100 per device last I saw.
 
If you had checked my link, you would notice one of the features listed as "File/Folder encryption". And, from experience, I know for certain that McAfee can do File and Folder encryption.

yup, I saw that. Haven't looked too much into it yet.
 
i-sta, I was actually commenting on SecurityGuy's reply directly above mine.

Also, SecurityGuy, I'm not sure how I feel about services that host my security software, especially encryption. In my companies, I would not ever recommend storing encryption keys or management tools on someone else's server. Someone else's datacenter on my hardware, maybe, but not someone else's hardware, inside someone else's database, with someone else responsible for management and source code. At least with things I run on my system, I can reverse engineer the tools to ensure no backdoors are available to the software developers. With the software on someone else's system, that I have no access to, provide access to people I do not have any control over.

SaaS and Cloud software is great, don't get me wrong, but it is not the place for serious IT Security.

Edit: I just finished going over Beachhead's website, and it leaves more questions to ask than it does answer them. And the only supported OSes are XP and Win Server 2003 (which for the OP is good... but doesn't bode well for their support or actual reliability)
 
Back
Top