Quantcast
Channel: Symantec Connect - Security - Articles
Viewing all articles
Browse latest Browse all 397

Symantec Endpoint Encryption - Generating and Deploying a Recovery Certificate

$
0
0

Reference: https://support.symantec.com/en_US/article.HOWTO101011.html

Assumptions:

  • Symantec Endpoint Encryption 11.1.2
  • Server 2012 R2 standard
  • Microsoft Active Directory Certificate Services is installed and configured on the domain

Creating the MMC

  1. Log onto the SEE server as a user who has rights to request a certificate.
  2. Click on the Start button, type cmd and hit the enter key.
  3. Type mmc and hit the enter key.
  4. Click on File, Add/Remove Snap-in…
  5. Choose Certificates and click Add >.
  6. Choose My user account and click Finish.
  7. Click OK.

Creating the Certificate

  1. Open or create an MMC with the Snap-in called Certificate – Current User.
  2. Expand Certificates – Current User.
  3. Right click on Personal and choose All tasks, Request New Certificate...
  4. When the Certificate Enrollment wizard starts, click Next.
  5. On the Select Certificate Enrollment Policy page, click Next.
  6. On the Request Certificates page, select Basic EFS and click details and click Properties.
  7. On the General tab, enter a Friendly Name: SEEM Server Recovery Certificate <Date>.
  8. Click on the Subject tab.
  9. Under Subject name, choose Common name and set the SEEM server FQDN as the Value and click Add.
  10. Click on the Extensions tab and click on Key usage.
  11. Click on Data encipherment and click Add >.
  12. Click OK.
  13. Click Enroll.
  14. Click Finish.

Exporting PKCS #12 (Certificate and Private Key)

  1. Open or create an MMC with the Snap-in called Certificate – Current User.
  2. Expand Certificates – Current User, Personal, Certificate.
  3. Double click the certificate that you just created.
  4. Click on the Details tab.
  5. Click on Copy to File…
  6. On the Certificate Export Wizard click Next.
  7. On the Export Private Key page, choose Yes, export the private key and click Next.
  8. On the Export File Format page ensure Personal Information Exchange – PKCS #12 (.PFX) is selected and click Next.
  9. On the Security page, select Password and type in a password and click Next.
  10. Click Browse and select where to save the file and choose a descriptive file name and click Save.
  11. Click on Finish.
  12. Click OK.

Exporting PKCS #7 (Certificate)

  1. Open or create an MMC with the Snap-in called Certificate – Current User.
  2. Expand Certificates – Current User, Personal, Certificate.
  3. Double click the certificate that you just created.
  4. Click on the Details tab.
  5. Click on Copy to File…
  6. On the Certificate Export Wizard click Next.
  7. On the Export Private Key page, choose No, do not export the private key and click Next.
  8. On the Export File Format page ensure Cryptographic Message Syntax Standard – PKCS #7 Certificates (.P7B) is selected, choose Include all certificates in the certification path if possible and click Next.
  9. Click Browse and select where to save the file and choose a descriptive file name and click Save.
  10. Click on Finish.
  11. Click OK.

Deploying the Recovery Certificate to a SEE Client

  1. Log onto the server that hosts the SEE Management Console.
  2. Open the SEE Management Console.
  3. Expand the Symantec Endpoint Encryption Software Setup node and click on Windows Client.
  4. Work your way through the wizard and when you reach the Removable Media Encryption Installation Settings – Recovery Certificate page, choose Encrypt files with a recovery certificate.
  5. Browse to the PKCS #7 certificate and choose Open.
  6. Review the Confirm Certificate window and click OK.
  7. Complete the wizard.

Deploying the Recovery Certificate to GPO Based Policies

  1. Log onto the server that hosts the SEE Management Console as a user who has rights to deploy GPO based policies.
  2. Open the SEE Management Console.
  3. Click on the Group Policy Management node.
  4. Drill down, Forest, Domains, Domain, Group Policy Objects.
  5. Right click on the desired GPO based policy and choose Edit…
  6. Expand Computer configuration, Policies, Software Settings, Symantec Endpoint Encryption, Removable Media Encryption and choose Recovery Certificate.
  7. Choose Change this setting, choose Encrypt files with a recovery certificate and click Change certificate…
  8. Browse to the PKCS #7 certificate and choose Open.
  9. Review the Confirm Certificate window and click OK.
  10. Click Save.
  11. Click OK.
  12. Click File, Exit.

Viewing all articles
Browse latest Browse all 397

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>