Question

Management suite for desktop encryption

Asked by: McKnife

Hi experts!

My task is to get information about management suites for full disk desktop encryption. If suitable, we might encrypt every system (mostly win vista business clients in a win2008 domain, some suse linux 11).
What I need is a suite that
-forces users to choose a strong password (preboot authentication) and to change it regularly
-supplies a masterpassword that enables admins to boot any system
-does not require a tpm (if it does, please name it anyway)
-optionally supports linux (if not: what to take for those linux clients?)

So if you know such a suite, name it and also provide a rough cost estimation for 60 clients.

This Question has been solved and asker verified All Experts Exchange premium technology solutions are available to subscription members.

Subscribe now for full access to Experts Exchange and get

Instant Access to this Solution

  • Plus...
  • 30 Day FREE access, no risk, no obligation
  • Collaborate with the world's top tech experts
  • Unlimited access to our exclusive solution database
  • Never be left without tech help again

Subscribe Now

Asked On
2009-09-21 at 00:52:36ID24747660
Topics

Encryption for Network Security

,

Operating Systems Network Security

Participating Experts
2
Points
500
Comments
18

Trusted by hundreds of thousands everyday for fast, accurate and reliable tech support.

  • "The time we save is the biggest benefit of Experts Exchange to Warner Bros. What could take multiple guys 2 hours or more each to find is accessed in around 15 minutes on Experts Exchange." Mike Kapnisakis, Warner Bros.
  • "Our team likes having a resource that is more secure than just using Google and most experts using this service really know their stuff. It's nice to look here first versus using Google." Dayna Sellner, Lockheed Martin
  • "Anytime that I've been stumped with a problem, 9 out of 10 times Experts Exchange has either the accepted solution or an open discussion of the potential solution to the problem." Kenny Red, eBay Inc.

See what Experts Exchange can do for you.

Got a question?

We've got the answer.

Experts Exchange has been collecting answers to technology questions since 1996…3 million and counting! If you have a question, chances are we already have your answer.

Screenshot of Experts Exchange Knowledgebase

Need individual assistance?

Our experts are ready to help.

If you can't find the exact answer you're looking for, ask our exclusive community of 50,000 experts. You’ll get a personalized answer from a trusted professional.

Screenshot of Experts Exchange Knowledgebase

Want to learn from the best?

Read articles from industry experts.

Thousands of free tech tips, tricks, how-to’s and tutorials are available in our peer reviewed articles section. See for yourself how smart our experts are, no login required.

Screenshot of an Article

Working on a long term project?

Store your work and research.

Save solutions to your questions, answers you’ve discovered through searching plus helpful articles in your personal knowledgebase for easy future access.

Screenshot of Experts Exchange Knowledgebase

Access the answers to your technology questions today.

Subscribe Now

30-day free trial. Register in 60 seconds.

What Makes Experts Exchange Unique?

Members of the expert community talk about why the experience at Experts Exchange is different than what you will find anywhere else.

Trusted by the world's most respected brands.

image of each brand's logo

Faithfully serving IT professionals since 1996.

Experts Exchange Logo

Try it out and discover for yourself.

Subscribe Now

30-day free trial. Register in 60 seconds.

Related Solutions

  1. Strong Name?
    What is a strong name?
  2. Strong Name and DLL encryption
    Does Strong Name have anything to do with encrypting the DLL to prevent unauthorized use? I see that it uses RSA asymmetric keys, and that it supposedly prevents tampering. Is this still in use today, most of the articles I found were 3+ years old. Is there another way to ...
  3. Office application suite in SLES 10 - SUSE
    hi, I am trying to install an Office application suite on a SLES 10 SUSE enterprise server LINUX SYSTEM, but I could not find any single install RPM installation source package for it. The one in Openoffice.org download gives me a tar file with lots of RPMS and when I try t...

Free Tech Articles

  1. WARNING: 5 Reasons why you should NEVER fix a computer for free.
    It is in our nature to love the puzzle. We are obsessed. The lot of us. We love puzzles. We love the challenge. We thrive on finding the answer. We hate disarray. It bothers us deep in our soul. W...
  2. SCCM OSD Basic troubleshooting
    SCCM 2007 OSD is a fantastic way to deploy operating systems, however, like most things SCCM issues can sometimes be difficult to resolve due to the sheer volume of logs to sift through and the dispe...
  3. Migrate Small Business Server 2003 to Exchange 2010 and Windows 2008 R2
    This guide is intended to provide step by step instructions on how to migrate from Small Business Server 2003 to Windows 2008 R2 with Exchange 2010. For this migration to work you will need the fo...
  4. Create a Win7 Gadget
    This article shows you how to create a simple "Gadget" -- a sort of mini-application supported by Windows 7 and Vista. Gadgets can be dropped anywhere on the desktop to provide instant information, ...
  5. Outlook continually prompting for username and password
    There have been a lot of questions recently regarding Outlook prompting for a username and password whilst using Exchange 2007. There are a few reasons why this would happen and I will try to cover t...
  6. Backup Exchange 2010 Information Store using Windows Backup
    There seems to be quite a lot of confusion around the ability to backup Exchange 2010 using the built in Windows Backup feature. This stems from the omission of this feature prior to Exchange 2007 s...

Cloud Class Webinars

  1. Avoiding Bugs in Microsoft Access
    Alison Balter takes and in-depth look at avoiding bugs in Access. In this webinar you will learn about using the immediate window to debug your applications, invoking the debugger, using breakpoints to troubleshoot, stepping through code, setting the next statement to execute, ...
  2. Top 10 Best New Features in Visio 2010
    Scott Helmers gives live demonstrations of the top 10 new features in Visio 2010. This webinar will teach you how to create compelling diagrams by adding shapes to the page with a single click, linking the shapes in a diagram to data in Excel (or SQL Server, or SharePoint), ...
  3. IT Consultant Business Secrets Revealed
    Michael Munger, Experts Exchange tech pro and IT consultant, pulls back the curtain on his very successful businesses and answers question on every IT consultant and business owner should know about. He shares secrets on what he did to solve the 5 most common problems in IT, ...
  4. Disaster Recovery and Business Continuity
    Quest CTO, Mike Billon, gives an overview of the steps involved in building a dunamic disaster recovery plan. Through case studies and an examination of software/hardware tooles for monitoring and testing, you'll gain a better understandin of where you are, where you want ...
  5. Organize Your Visio Diagrams with Containers and Lists
    Scott Helmers uses cross functional flowcharts, wireframe diagrams, data graphic legends and seating charts to teach you: how to ustilize all three new structured diagram components in Visio 2010, the best practices for organizeing shapes in previous version of Visio, how to organize ...
  6. How to Us Objects, Properties, Events and Methods in Microsoft Access
    Alison Dalter gives an in-depbth look at objects, properties, events and methods in Microsoft Access. In this webinar you will learn about using the object browser, referring to objects, working with properties and methods, working with object variables, understanding the ...

Join the Community

Give a Little. Get a Lot.

Join the community of experts here and help other tech pros by answering question in your area of expertise. You can earn FREE access to all Experts Exchange's premium features and resources.

Join the Community

Answers

 

by: TolomirPosted on 2009-09-21 at 00:59:03ID: 25380918

Take a look at

DriveCrypt Plus Pack Enterprise Edition
http://www.securstar.com/products_drivecryptpp_MC.php

· Centralized Management Console

 DriveCrypt Plus Pack Enterprise provides centralized management and reporting. Authentication and configuration polices are controlled through the intuitive application interface and provides granular control of the encryption environment.  

Talk to the online Sales representative for the costs:

http://www.securstar.com/purchase.php


Tolomir

 

by: McKnifePosted on 2009-09-21 at 01:22:38ID: 25381046

Hi Tolomir.
I just finished reading the product description. The descr. could not tell if my first 3 requirements are met - do you know if they are met? I am hesitant to contact them at once because it will take a while to find someone that is able to tell.

 

by: TolomirPosted on 2009-09-21 at 02:27:51ID: 25381266

1st:  Strong Authentication Policy    
DriveCrypt Plus Pack Enterprise allows administrators to enforce strong authentication via custom-defined password policies, admin defined password restrictions and supports smartcards (PKCS #11)  for two-factor authentication.

2nd: Offline Password Recovery
    DriveCrypt  Plus Pack Enterprise provides offline password recovery. In the event a user forgets his or her password or is not able to successfully authenticate, an administrator controlled recovery code can be generated and used.


 On Demand Encryption & Decryption
 DriveCrypt Plus Pack Enterprise allows administrators to encrypt and decrypt machines by group or individually. Drive status is clearly displayed for an at-a-glance perspective and is also detailed in the reports section.


3rd: Did just use the drivecrypt version on my computer, there is no need for a TPM  encryption chip. but if you like you can use an USB token:
http://www.securstar.com/products_usbtoken.php

4th: Sorry no Linux support. Pick you poison from http://en.wikipedia.org/wiki/Comparison_of_disk_encryption_software (mostlikely truecrypt)

---

I would suggest to use truecrypt for an all plattform solution, but then you got no centralized management (+policy)

Tolomir



 

by: richrumblePosted on 2009-09-21 at 05:57:54ID: 25382366

Seagate Momentus drives (laptops currently) are universal as their preboot authentication is OS independent. McAfee can manage Momentus drives, as well as other 3rd parties like Wave Systems can as well: http://www.wave.com/products/tdm.asp

PGP is another, and probably considered the defacto standard, but is very pricey by comparison, but works on all major OS's (Mac/M$/*nix)
CheckPoint PointSec Full Disk Encryption is very well priced and fits all the criteria you've asked about:
http://www.checkpoint.com/products/datasecurity/pc/index.html

Changing the password often is probably not a necessary step, it's an antiquated practice that has it's roots in the unix (crypt), windows 9x and windows NT passwords, all of which were very easy to crack... well 9x was encoding and not even considered encryption... nonetheless it's a practice that is good to use on short passwords, but if you require a password of a good length like 10 or more characters with case variances I feel your very secure. We require 15 at a minimum wherever possible in our Lan. http://www.wired.com/politics/security/commentary/securitymatters/2007/01/72458

TrueCrypt is also a fine choice but as stated above, has no centralized management, and does not force the user to change the password, however it does default to requiring a 20 or more character password length. We have Government contracts that subject us to quarterly audits and we have to make a case every time for not requiring passwords to change more often.
-rich

 

by: McKnifePosted on 2009-09-21 at 07:44:18ID: 25383354

@Tolomir: I already read that, it does not really answer 1 and 2.
1) What do these policies consist of? Do passwords expire?
2) Recovery was not the question, do admins get a pw that can unlock all workstations for maintenance tasks? This is the most important aspect.

@Richrumble:
What McAfee product are you talking about? Do you use it and does it fulfil the above criteria?
Same for "PGP".

Thanks

 

by: TolomirPosted on 2009-09-21 at 07:53:17ID: 25383501

I guess you have to talk to a technican from securstar. As said, I don't use that tool in my office.

http://www.securstar.com/contact.php


 

by: richrumblePosted on 2009-09-21 at 09:15:13ID: 25384494

McAfee's EPO manager is supposed to manage Seagate Momentus Laptop drives, but it's only something our McAfee rep mentioned to us afew times. We've used the Wave Systems product for about a year, it's ok but a little steep in price, so we switched to PointSec and are happy with the results. Both products we've used allow the changing of the passwords but require the entire encryption process to be done again, which is ok because it can take place in the background.
http://www.seagate.com/ww/v/index.jsp?locale=en-US&name=null&vgnextoid=eac9eedc1278d110VgnVCM100000f5ee0a0aRCRD
I don't see it on mcafee's site, but I was told it does intergrate with ePO.

Again I don't think one needs to change the boot password often if it's long enough. Even all 20 one's can be harder to brute force than most users passwords (11111111111111111111) Most bruteforcers start low and go high, when you get to about 10 alpha-numeric characters using a few PC's makes brute force almost statistically impossible in a life time.
-rich

 

by: McKnifePosted on 2009-09-21 at 09:54:05ID: 25384934

Rich, can you provide the rough cost estimation I was looking for for the products you used/are using? 50 windows boxes.
Also I really need info about the ability of creating a master password (no recovery password for single drives but for all, allowing the admin to boot the system)
Even if you think it's of no relevance maybe you can answer if the mentioned products (the Wave systems one, and the Pointsec one) can force users to change their passwords.
Also [attention, new aspect ;)], is there a management suite you know that can temporarily disable the need of a password network wide? This would be very useful in some maintenance situations.

 

by: richrumblePosted on 2009-09-21 at 10:52:46ID: 25385553

We have a 5000+ user base, and need 1000+ licenses for our laptop users. I'm sure the discount for 1000 vs 50 is going to be substantial, and I have no idea what we pay in the end sometimes.  McAfee's sales department is quick to reply or to reach by phone. You should also get a quick reply from wave systems:
http://techsupport.wavesys.com/crmrequest/purchase.aspx?product=TDM
Again we bought 1000+ laptop drives from dell at a discount as well, but they weren't marked up much more than normal HD's, however they don't have smaller sizes so a 250gig drive I think is the smallest they have. But if you were to buy a 80-120gig drive from dell it's about half the price sometimes than the FDE's.
The PointSec software has been the cheapest for us, or so I'm told. We've also been able to use the pointsec software on our mobile devices.. so we have one portal for the majority of our devices.
Pointsec is able t use Active Directory for login, so we have our users doing that along with a 2-factor token, we can lock the tokens or the AD accounts if we needed the feature your thinking of. No easy way to push off already authenticated users however.
-rich

 

by: McKnifePosted on 2009-09-21 at 11:09:38ID: 25385719

> Pointsec is able t use Active Directory for login
So Pointsec does or does not use PBA? I guess not, right?

 

by: richrumblePosted on 2009-09-21 at 12:52:14ID: 25386878

Sorry that video was wrong, http://www.svit-it.com.ua/checkpoint_screen/Pointsec_PC_Admin_Guide.pdf
page 179, synchronizing windows and pointsec passwords... sorry about that. There are a few options available with pointsec including one-time passwords and various recovery scenarios.
-rich

 

by: McKnifePosted on 2009-10-06 at 13:28:24ID: 25509586

Folks, I let you waiting because the sales representative for checkpoint is kinda slow. While the secustar people have literally answered all questions within minutes after using their online request template, the local distributor of checkpoint leaves us waiting for a price, the rest is answered more or less.
Secustar - looks good, seems to be suitable for all of our needs and costs about 75¬ per seat.
Checkpoint - also looking good, but I finally will be able to tell after phoning them.

I will reward you now and maybe comeback later to tell you the end of the story.
Thank you!

 

by: richrumblePosted on 2009-10-06 at 17:32:22ID: 25511329

Thanks! Looking forward to your findings.
-rich

 

by: McKnifePosted on 2010-04-01 at 06:03:29ID: 29338901

Months later...
Hi, I'm back. We are about to finish our evaluation.
Secustar is not capable of using single sign on on 64 bit machines which was a k.o. criterion.
Checkpoint FDE looks great in every respect.

Rich, if you allow for one more question:
have you a concept ready for recovery of encrypted machines, that is for machines that are broken and need to have the latest system image applied?

 

by: richrumblePosted on 2010-04-01 at 17:16:13ID: 29395909

Yes, decryption of the HD if the OS should fail to boot properly is easy, remove the HD's, use a usb to IDE/SATA converter like this one: http://www.newegg.com/Product/Product.aspx?Item=N82E16812119244 and open PointSec, using the recovery console and password you'll be able to read the drives contents, as long as the drive is functional.
http://www.google.com/search?q=pointsec+slave+drive+recovery page 13 I think in one of those PDF's explains how to do it. You can also use boot disk's, but I like the slave drive method.
-rich

 

by: McKnifePosted on 2010-04-02 at 02:55:29ID: 29439780

I was looking for a concept to apply an image to an encrypted harddrive with the least effort.
Happy easter!

 

by: richrumblePosted on 2010-04-02 at 04:59:35ID: 29449360

I've never tried, but I don't think it would work, you may contact PointSec directly, I'm sure it won't be the first time they've been asked. The encryption does deploy seamlessly in the background, we have it so that when a LT is joined to the domain the software is pushed and the encryption begins in the background it's really good software for us.
-rich

20120131-EE-VQP-002

3 Ways to Join

30-Day Free Trial

The Experts

98% positive feedback on 31,087 answers since March 2000. angeliii is a Microsoft Most Valuable Professional for his work with MS SQL Server & Develoment.

He has also proven his knowledge of Visual Basic Programming, PHP Scripting and Oracle Databases.

The Experts

97% positive feedback on 10,752 answers since July 2000. lrmoore has more than 18 years experience in the networking industry.

The six-time Mircosoft MVPs specialties include firewalls, virtual private networking, and network management.

Testimonials

"...and excellent source for support... Kind of like having your very own IT dept." Electriciansnet

Testimonials

"I was apprehensive at signing up at first. However... it has already made my life as an IT administrator much easier." JaCrews

Testimonials

"WOW! You guys have great, active, and knowledgeable people on here." moore50

Business Clients

Business Clients

In the Press

"If you’ve got a question... Experts Exchange can supply an answer.”

In the Press

"...an invaluable aid for both IT professionals and those who require tech support."

In the Press

"where IT professionals provide quick answers on just about any topic"

Business Account Plans

Loading Advertisement...