0% found this document useful (0 votes)
13 views10 pages

pgpWholeDiskWin 991 Quickstart en

PGP Whole Disk Encryption (WDE) is a software tool designed to secure data on desktops, laptops, and removable drives by encrypting the entire contents or creating secure virtual disk volumes. The guide provides instructions for installation, usage, and key management, emphasizing the importance of backing up data and ensuring disk health before encryption. It also outlines system requirements and best practices for using PGP WDE effectively.
Copyright
© © All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
13 views10 pages

pgpWholeDiskWin 991 Quickstart en

PGP Whole Disk Encryption (WDE) is a software tool designed to secure data on desktops, laptops, and removable drives by encrypting the entire contents or creating secure virtual disk volumes. The guide provides instructions for installation, usage, and key management, emphasizing the importance of backing up data and ensuring disk health before encryption. It also outlines system requirements and best practices for using PGP WDE effectively.
Copyright
© © All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
You are on page 1/ 10

PGP Whole Disk Encryption for Windows

Quick Start Guide


Version 9.9

Note: A PGP Whole Disk Encryption license provides you


What is PGP Whole Disk Encryption? with access to a certain set of PGP Whole Disk Encryption
features. Certain other features of PGP Whole Disk
The PGP Whole Disk Encryption (WDE) product is a software Encryption may require a different license. For more
tool that provides multiple ways to protect your data on information, see the Licensing section of the PGP
desktops, laptops, and removable drives. Desktop User’s Guide.
Use PGP WDE to do the following: • For deployment, management, and policy enforcement
information for PGP Whole Disk Encryption, see the PGP
• Lock down the entire contents of your system, or an
Universal Server Administrator’s Guide.
external or USB flash drive you specify.
• Use part of your hard drive space as an encrypted virtual
disk volume with its own drive letter.
• Create secure, encrypted Zip archives. Understanding the Basics
• Put files and folders into a single encrypted, compressed
PGP Whole Disk Encryption uses keys to encrypt, sign,
package that can be opened on Windows systems that do
decrypt, and verify your messages.
not have PGP Desktop Email or PGP Desktop installed.
• Completely destroy files and folders so that even file After installation, PGP Whole Disk Encryption prompts you to
recovery software cannot recover them. create a PGP keypair. A keypair is the combination of a private
key and a public key.
• Securely erase free space on your drives so that your
deleted data is truly unrecoverable. • Keep your private key and its passphrase private, as the
name suggests. If someone gets your private key and its
passphrase, they can read your messages and
Contents impersonate you to others. Your private key decrypts
• What is PGP Whole Disk Encryption? (page 1) incoming encrypted messages and signs outgoing
messages.
• New to PGP Whole Disk Encryption? (page 1)
• Your public key you can give to everyone. It does not have
• Understanding the Basics (page 1)
a passphrase. Your public key encrypts messages that
• What Am I Installing? (page 2) only your private key can decrypt and verifies your signed
• System Requirements (page 2) messages.
• Installing PGP Whole Disk Encryption (page 2) Your keyring holds both your keypairs and the public keys of
• Starting PGP Whole Disk Encryption (page 3) others, which you use to send encrypted messages to them.
• The PGP Whole Disk Encryption Main Screen (page 3) Click the PGP Keys Control Box to see the keys on your
• Using PGP WDE to Encrypt a Drive (page 4) keyring:
• Creating PGP Virtual Disk Volumes (page 10, page 6) 1. The icon for a PGP keypair has two keys, denoting the
• Creating a PGP Zip Archive (page 7) private and the public key. Alice Cameron has a PGP
keypair in this illustration, for example.
• Using PGP Shred to Shred Files (page 8)
2. The icons for the public keys of others have just one key.
• Getting Assistance (page 10)
Ming Pa’s public key, for example, has been added to the
keyring shown in this illustration.

New to PGP Whole Disk Encryption?


Use this step-by-step guide to get started. You will find that,
with PGP Whole Disk Encryption, protecting your data will be
as easy as turning a key in a lock.
• This Quick Start Guide helps you install PGP Whole Disk
Encryption and get started.
• The PGP Desktop User’s Guide provides more detailed
information on PGP Whole Disk Encryption. In it, you will
learn what a keypair is, why you might want to create one,
how to create one, and how to exchange keys with others
so you can encrypt your own data and share data securely
with others.

1
What Am I Installing? Key Management — PGP Whole Disk Encryption
also manages PGP keys, both your keypairs and
PGP Whole Disk Encryption uses licensing to provide access the public keys of others. You use your private key
to the features you purchase. Depending on the license you to decrypt messages sent to you encrypted to your
have, some or all of the PGP Whole Disk Encryption family of public key and to secure your PGP Virtual Disk
applications will be active. volumes. You use public keys to encrypt
messages to others or to add users to PGP Virtual
This document contains instructions for viewing the features
Disk volumes.
activated by your license.
PGP Whole Disk Encryption (PGP WDE) is a
member of the PGP Desktop family of
applications. You can use PGP WDE to lock down System Requirements
the entire contents of your system or an external
or USB flash drive you specify. Boot sectors, • Microsoft Windows 2000 (Service Pack 4), Windows
system files, and swap files are all encrypted. Server 2003 (Service Pack 1 and 2), Windows XP
Whole disk encrypting your boot drive means you Professional 32-bit (Service Pack 2 or 3), Windows XP
do not have to worry if your computer is lost or Professional 64-bit (Service Pack 2), Windows Vista (all
stolen: to access your data, an attacker would 32-bit and 64-bit versions, including Service Pack 1),
need the appropriate passphrase. If you have Windows XP Home Edition (Service Pack 2 or 3),
encrypted a USB device, you can share data on Microsoft Windows XP Tablet PC Edition 2005 (requires
that device with other PGP Whole Disk Encryption attached keyboard).
for Windows or Mac OS X users. Note: The above operating systems are supported only
when all of the latest hot fixes and security patches from
PGP Virtual Disk volumes — Uses part of your Microsoft have been applied.
hard drive space as an encrypted virtual disk
volume with its own drive letter. A PGP Virtual PGP Whole Disk Encryption (WDE) is supported on client
Disk is the perfect place for storing your sensitive versions of Windows 2000 (Service Pack 4) and Windows
files; it is as if you have stored them in a safe. XP (Service Pack 1, 2, or 3), and on Windows Vista; it is
When the door of the safe is open (when the not supported on Windows 2000 Server or 2003 Server.
volume is mounted), you can change files stored in • 512 MB of RAM
it, take files out of it, and move files into it. • 64 MB hard disk space
Otherwise (when the volume is unmounted), all
the data on the volume is protected.
Installing PGP Whole Disk
PGP Zip — Adds any combination of files and
folders to an encrypted, compressed, portable Encryption
archive. PGP Whole Disk Encryption must be
installed on a system to create or open a PGP Zip PGP Corporation recommends exiting all open applications
archive. PGP Zip is a tool for securely archiving before you begin the install. The installation process requires a
your sensitive data, whether you want to distribute system restart.
it to others or back it up.
Note: If you are using PGP Whole Disk Encryption in a PGP
PGP Shredder — Completely destroys files and Universal Server-managed environment, your PGP Whole Disk
folders so that even file recovery software cannot Encryption installer may be configured with specific features
recover them. Deleting a file using the Windows and/or settings.
Recycle Bin (on Windows systems) or Trash (on
Mac OS X systems) does not actually delete it; it
sits on your drive and eventually gets overwritten. • To install PGP Whole Disk Encryption
Until then, it is trivial for an attacker to recover that 1. Locate the PGP Whole Disk Encryption installation
file. PGP Shredder, in contrast, immediately program you downloaded.
overwrites files multiple times. This is so effective The installer program may have been distributed by your
that even sophisticated disk recovery software PGP administrator using the Microsoft SMS deployment
cannot recover these files. This feature also tool.
completely wipes free space on your drives so
your deleted data is truly unrecoverable. 2. Double-click the installer.
3. Follow the on-screen instructions.
4. Reboot your system when instructed.
5. When your system restarts, follow the on-screen
instructions to configure PGP Whole Disk Encryption.

2
The PGP Whole Disk Encryption Main
Licensing Screen
To see what features your license supports, open PGP Whole The PGP Whole Disk Encryption application window is your
Disk Encryption and select Help > License. Those features main interface to the product.
with a checkmark are supported by the active license.

Starting PGP Whole Disk Encryption


To start PGP Whole Disk Encryption, use any of the following
methods:
• Double-click the PGP Tray icon. The PGP Whole Disk Encryption main screen includes:
1 The Menu bar. Gives you access to PGP Whole
Disk Encryption commands. The menus on the
Menu bar change depending on which Control box
is selected.

• Right-click the PGP Tray icon and then select Open PGP 2 The Toolbar. Gives you access to frequently used
Whole Disk Encryption. features. You can create a new PGP Zip archive,
• From the Start menu, select Programs > PGP > PGP verify an existing PGP Zip archive, shred selected
Whole Disk Encryption. files, search for a key, synchronize your keys, or find
text in the user IDs of the keys currently visible in
the PGP Keys work area.
3 The PGP Keys Control Box. Gives you control of
PGP keys.
4 The PGP Messaging Control Box. Gives you
control over PGP Messaging.
5 The PGP Zip Control Box. Gives you control of
PGP Zip, as well as the PGP Zip Assistant, which
helps you create new PGP Zip archives.
6 The PGP Disk Control Box. Gives you control of
PGP Disk.
7 The PGP NetShare Control Box. Gives you control
of PGP NetShare.

8 Expand/Collapse Control Box Control. Use to


display or hide Control Boxes.
9 The PGP Whole Disk Encryption Work area.
Displays information and actions you can take for
the selected Control box.

3
10 PGP Keys Find box. Use to search for keys on your 7. Click Encrypt.
keyring. As you type text in this box, PGP Whole
Disk Encryption displays search results based on
either name or email address.
Each Control box expands to show available options, and
collapses to save space (only the Control Box’s banner
displays). Expand a Control Box by clicking its banner. Collapse
a Control Box by clicking its Expand/Collapse arrow in the
upper right corner.

Using PGP WDE to Encrypt a Drive


The PGP WDE feature locks down the entire contents of your
system or an external or USB flash drive you specify.
The encryption algorithm used by PGP WDE is AES256. The
hashing algorithm is SHA-1. FAT16, FAT32, and NTFS
formatted drives are supported. There is no minimum or
maximum size. If the drive is supported by the operating
system (or your hardware BIOS for the boot drive), it should
work with PGP WDE.
Notes: To encrypt data on floppy disks or CD-RWs, use PGP
Caution: PGP Corporation recommends, as a best practice, Virtual Disk volumes; do not use PGP WDE.
that you back up your data before encrypting your disk.
1. Click Encrypt Whole Disk in the PGP Disk Control box. You can use the PGP Whole Disk Encryption feature on a dual-
boot system, as long as you boot to an operating system
supported by PGP WDE (such as Windows XP, Windows
2000, or Windows Vista) and PGP Whole Disk Encryption is
installed. Partition mode supports dual-booting with another
operating system (such as Linux) as long as you encrypt only
2. Select the drive or partition to be encrypted. your Windows partition. The other operating system must be
3. Select Maximum CPU Usage to protect your disk as on another, non-encrypted partition.
quickly as possible. The encryption process will take Backup software works normally with PGP WDE; any files the
priority over other operations on your system. software backs up will be decrypted before being backed up.
4. Select Power Failure Safety if you think your system
could lose power during the encryption process. PGP WDE Best Practices
When Power Failure Safety is selected, the encryption PGP Corporation recommends the following best practices for
process can safely resume if it is interrupted. This option preparing to encrypt your disk with PGP WDE. Please follow
can cause encryption to take longer to complete. the recommendations below to protect your data during and
5. Click Add User Key to add users who will be able to after encryption.
authenticate to the whole disk encrypted drive using Before you encrypt your disk, there are a few tasks you must
public-key cryptography. perform to ensure successful initial encryption of the disk.
If you are encrypting a fixed drive, you can only use a PGP 1. Determine whether your target disk is supported. PGP
keypair on an Aladdin eToken USB token. If you are WDE feature protects desktop or laptop disks (either
encrypting a partition or a removable (non-fixed) drive, you partitions, or the entire disk), external disks, and USB flash
can use any keypair on your system. disks. CD-RW/DVD-RWs and servers are not supported.
6. Click New Passphrase User to add users who See "Supported Disk Types" in the PGP Desktop User’s
authenticate using a passphrase, including if you want to Guide for more details on what types of disks are
use a USB flash device for two-factor authentication. supported.
Follow the instructions displayed in the PGP Disk 2. Back up the disk before you encrypt it. Before you
Assistant dialog boxes. encrypt your disk, be sure to back it up so that you won’t
If you are encrypting your boot drive, you have the option lose any data if your laptop or computer is lost, stolen, or
of using your Windows logon passphrase so that you only you are unable to decrypt the disk.
have to enter your credentials once on startup. 3. Ensure the health of the disk before you encrypt it. If
PGP WDE encounters disk errors during encryption, it will
pause encryption so you can repair the disk errors.
However, it is more efficient to repair errors before you

4
initiate encryption. For more information, see Ensure Disk • As a best practice, highly fragmented disks should be
Health Before Encryption (page 5). defragmented before you attempt to encrypt them.
4. Create a recovery disk. While the chances are extremely
low that a master boot record could become corrupt on a
boot disk or partition protected by PGP Whole Disk
Create a Recovery CD
Encryption, it is possible. Before you encrypt a boot disk The following instructions use Roxio software for illustration
or partition using PGP Whole Disk Encryption, create a purposes. The actual steps you perform may differ.
recovery disk. See Create a Recovery CD (page 5) for 1. Make sure PGP Whole Disk Encryption and Roxio Easy
instructions on how to create a recovery disk. Media Creator or Roxio Easy CD Creator (or other
5. Be certain that you will have AC power for the duration software that can create a CD from an ISO image) are
of the encryption process. See Maintain Power installed on your system.
Throughout Encryption (page 5). 2. Open Roxio Easy Media Creator or Roxio Easy CD Creator
6. Run a pilot test to ensure software compatibility. As a and choose to create a Data CD Project.
good security practice, PGP Corporation recommends 3. Select File > Record CD from CD Image.
testing PGP WDE on a small group of computers to
4. From the Files of Type menu, select ISO Image Files
ensure that PGP WDE is not in conflict with any software
(ISO).
on the computer before rolling it out to a large number of
computers. This is particularly useful in environments that 5. Navigate to the PGP directory. The default location is
use a standardized Corporate Operating Environment C:\Program Files\PGP Corporation\PGP
(COE) image. For a list of software known to have Desktop\.
compatibility issues with PGP WDE, see Run a Pilot Test 6. Select bootg.iso and click Open.
to Ensure Software Compatibility (page 6). 7. Insert a blank, recordable CD into a CD drive on your
7. Perform Disk Recovery on Decrypted Disks. Where system.
possible, as a best practice, if you need to perform any 8. On the Record CD Setup screen, click Start Recording.
disk recovery activities on a disk protected with PGP
Whole Disk Encryption (WDE), PGP Corporation 9. When the file is burned to the CD, click OK.
recommends that you first decrypt the disk. Do this by 10. Remove the recovery CD from the drive and label it
Disk > Decrypt in PGP Whole Disk Encryption, using your appropriately.
prepared PGP WDE Recovery Disk, or by connecting the
hard disk via a USB cable to a second system and Caution: PGP WDE recovery disks are compatible only with
decrypting from that system's PGP Whole Disk Encryption the version of PGP Whole Disk Encryption that created the
software. Once the disk is decrypted, proceed with your recovery CD. For example, if you attempt to use a 9.0.x
recovery activities. recovery disk to decrypt a disk protected with PGP WDE 9.7
software, it will render the PGP WDE 9.7 disk inoperable.

Ensure Disk Health Before Encryption


Maintain Power Throughout Encryption
PGP Corporation deliberately takes a conservative stance
when encrypting drives, to prevent loss of data. It is not Because encryption is a CPU-intensive process, encryption
uncommon to encounter Cyclic Redundancy Check (CRC) cannot begin on a laptop computer that is running on battery
errors while encrypting a hard disk. If PGP WDE encounters a power. The computer must be on AC power. If a laptop
hard drive or partition with bad sectors, PGP WDE will, by computer goes on battery power during the initial encryption
default, pause the encryption process. This pause allows you process (or a later decryption or re-encryption process) PGP
to remedy the problem before continuing with the encryption WDE pauses its activity. When you restore AC power, the
process, thus avoiding potential disk corruption and lost data. encryption, decryption, or re-encryption process resumes
automatically.
To avoid disruption during encryption, PGP Corporation
recommends that you start with a healthy disk by correcting Regardless of the type of computer you are working with, your
any disk errors prior to encrypting. system must not lose power, or otherwise shut down
unexpectedly, during the encryption process, unless you have
• Before you attempt to use PGP WDE, use a third-party selected the Power Failure Safety option.
scan disk utility that has the ability to perform a low-level
integrity check and repair any inconsistencies with the Do not remove the power cord from the system before the
drive that could lead to CRC errors. Microsoft Windows' encryption process is over. If loss of power during encryption
check disk (chkdsk.exe) utility is not sufficient for is a possibility—or if you do not have an uninterruptible power
detecting these issues on the target hard drive. Instead, supply for your computer—consider choosing the Power
use software such as SpinRite or Norton Disk DoctorTM. Failure Safety option, as described in the PGP Desktop User’s
These software applications can correct errors that would Guide.
otherwise disrupt encryption.

5
• select Unmount when inactive for x mins to have
Caution: This holds true for removable disks, such as USB the volume automatically unmount when it has been
devices. Unless you have selected the Power Failure Safety inactive for the specified number of minutes.
option, you run the risk of corrupting the device if you remove
5. From Capacity, select Dynamic (resizeable) if you want
it during encryption.
the volume to grow in size as you add files or Fixed size if
you want the volume to always remain the same size.
Run a Pilot Test to Ensure Software 6. Specify a file system Format for the volume.
Compatibility 7. Specify an Encryption algorithm for the volume.
Certain other disk protection software is incompatible with 8. Click Add User Key to add users who authenticate using
PGP WDE and can cause serious disk problems, up to and public-key cryptography or click New Passphrase User to
including loss of data. add users who authenticate using passphrases.
Please note the following known interoperability issues, and 9. Click Create.
please review the PGP Whole Disk Encryption Release Notes
for the latest updates to this list.
Software that is not compatible:

• Faronics Deep Freeze (any edition)


• Utimaco Safeguard Easy 3.x
• Absolute Software's CompuTrace laptop security and
tracking product. PGP Whole Disk Encryption is
compatible only with the BIOS configuration of
CompuTrace. Using CompuTrace in MBR mode is not
compatible.
• Hard disk encryption products from GuardianEdge
Technologies: Encryption Anywhere Hard Disk and
Encryption Plus Hard Disk products, formerly known
as PC Guardian products.
The following programs co-exist with PGP Whole Disk
Encryption on the same system, but will block the PGP Whole
Disk Encryption feature:
Use the User Access section to control existing users of a
• Safeboot Solo PGP Virtual Disk volume:
• SecureStar SCPP 1. Click Add User Key to add users who authenticate using
public-key cryptography.
2. Click New Passphrase User to add users who
authenticate using passphrases.
Creating PGP Virtual Disk Volumes
3. Select a passphrase user, then click Change Passphrase
The PGP Virtual Disk Volumes feature uses part of your hard to change their passphrase.
drive space as an encrypted virtual disk volume with its own 4. Select a user, then click Make Admin to give the user
drive letter. You can create additional users for a volume so administrative rights.
that people you authorize can also access the volume. 5. Select a user, then click Delete to delete the user.
1. Click New Virtual Disk in the PGP Disk Control box.

2. Type a Name for the volume.


3. Specify a Disk File Location for the volume.
4. To specify your mount preferences, do the following::
• select a drive letter for the volume to Mount as.
• select Mount at Startup to have your new volume
mount automatically at startup.

6
• PGP Self-Decrypting Archive
Creating a PGP Zip Archive • Sign only
PGP Zip archives let you put any combination of files and 6. Click Next.
folders into a compressed, portable archive. There are four
kinds of PGP Zip archives:
• Recipient keys. Encrypts the archive to public keys. Only
the holder of the corresponding private keys can open the
archive. This is the most secure kind of PGP Zip archive.
Recipients must be using PGP software (for Windows or
Mac OS X).
• Passphrase. Encrypts the archive to a passphrase, which
must be communicated to the recipients. Recipients must
be using PGP software (for Windows or Mac OS X).
• PGP Self-Decrypting Archive. Encrypts the archive to a
passphrase. Recipients do not need to be using PGP
software to open it, but their computer must be running
Microsoft Windows. The passphrase must be Passphrase and Sign only are described in detail in the PGP
communicated to the recipients. Desktop User’s Guide.
• Sign only. Signs the archive but does not encrypt it, Refer to the appropriate section on the following pages for the
allowing you to prove you are the sender. Recipients must kind of PGP Zip archive you specified.
be using PGP software (for Windows or Mac OS X) to
open and verify the archive.
Recipient Keys
The Passphrase and Sign only PGP Zip types are described in The Add User Keys screen appears.
detail in the PGP Desktop User’s Guide; they are described 1. Click Add and use the User Selection screen to select the
briefly here. public keys of those persons who you want to be able to
1. Click New PGP Zip in the PGP Zip Control Box. open the archive. If you want to be able to open the
archive yourself, be sure to include your public key.
2. Click Next.

2. Drag and drop the files/folders you want to be in the


archive or use the buttons to select them.
3. Select Send original files to PGP Shredder when
finished if you want the files/folders you put into the
archive to be shredded when the archive is created.
4. Click Next.

3. Choose a private key on the local system to use to sign


the archive.
4. Specify a name and a location for the archive. The default
name is the name of the first file or folder in the archive;
the default location is the location of the files/folders going
into the archive.

5. Select the desired kind of PGP Zip archive:


• Recipient keys
• Passphrase

7
5. Click Next. The PGP Zip archive is created. The Finished 4. Specify a name and a location for the archive. The default
screen displays information about the new archive. name is the name of the first file or folder in the archive;
the default location is the location of the files/folders going
into the archive.
5. Click Next. The PGP SDA is created.

6. Click Finish.

6. Click Finish.

Note: The Passphrase type of PGP Zip archive is very similar


to Recipient Keys, the difference being that a passphrase is
used to protect the archive instead of a key.

Note: The Sign only type of PGP Zip archive is similar to


Recipient Keys, the difference being that because the archive
is only signed, not encrypted, you do not select public keys.
Using PGP Shred to Shred Files
The PGP Shredder feature completely destroys files and
PGP Self-Decrypting Archive folders so that even sophisticated file recovery software
The Create a passphrase screen appears. cannot recover them. While both the PGP Shredder icon and
1. Type a passphrase for the PGP Zip Self-Decrypting the Windows Recycle Bin appear on your desktop, only PGP
Archive (SDA), then type it again to confirm it. Shredder immediately overwrites the files you specify so that
they are not recoverable.
2. Click Next.
You can shred files using any of the following methods:
• Using the PGP Shredder icon.
• Using the PGP toolbar.
• Using the PGP shortcut menu.

Shredding Files Using the PGP Shredder


Icon

• To shred files using the PGP Shredder icon


1. On your Windows desktop, drag the files and folders you
want to shred into the PGP Shredder. A dialog box
3. Choose a private key on the local system to use to sign appears, asking you to confirm you want to shred the
the archive. files.

8
2. Click Yes. The specified files and folders are shredded.
Note: You can also use PGP Options to control the number of
passes made when shredding (more passes is more secure
but takes longer), whether files in the Windows Recycle Bin
should be shredded when you empty it, and whether the
warning dialog box is displayed when you shred.

Shredding Files Using the PGP Toolbar Shredding Free Space


The PGP Shred Free Space feature completely shreds free
• To shred files using the PGP Toolbar space on your drives so that your deleted data is truly
unrecoverable. Keep in mind that “free space” is actually a
1. Open PGP Whole Disk Encryption. misnomer. What PGP Shred Free Space does is overwrite the
2. Click Shred Files on the PGP Toolbar. portions of your hard drive that Windows believes to be
3. Specify which files you want to shred. Control-click to empty; in fact, that space could be empty or it could be holding
select multiple files or Control-A to select all files showing. files Windows told you were deleted.
4. Click Open. A dialog box appears, asking you to confirm When you put files into the Windows Recycle Bin and empty
you want to shred the files. it, the files are not really deleted; Windows just acts like there
is nothing there and eventually overwrites the files. Until those
5. Click Yes. The specified files and folders are shredded.
files are overwritten, they are easy for an attacker to recover.
PGP Shred Free Space overwrites this “free space” so that
even disk recovery software cannot get those files back.

• To shred free space on your disks


Shredding Files Using the PGP Shortcut
1. Open PGP Whole Disk Encryption.
Menu
2. Select Tools > PGP Shred Free Space.
3. On the Introduction screen, read the information, then
• To shred files in Windows Explorer click Next.
1. Open Windows Explorer. 4. On the Gathering Information screen, in the Shred drive
2. Right-click on the files or folders you want to shred, then field, select the disk or volume you want shredded and
select PGP Desktop > PGP Shred <filename>. Control- the number of passes you want PGP Shred Free Space to
click to select multiple files or Control-A to select all files perform.
showing. The recommended guidelines for passes are:
Tip: If you selected more than one file, the text says PGP • 3 passes for personal use.
Shred x items, where x is the number of files selected.
• 10 passes for commercial use.
A dialog box appears, asking you to confirm you want to
shred the files. • 18 passes for military use.
3. Click Yes. The specified files and folders are shredded. • 26 passes for maximum security.

5. Choose whether to Wipe internal NTFS data structures


(not available on all systems), then click Next.
This option shreds small (less than 1K) files in internal data
structures that might otherwise not get shredded.
6. On the Perform Shred screen, click Begin Shred.
Note: If you do not use the PGP Shredder feature often, you Note: Click Schedule to schedule a shred of your free
can remove the PGP Shredder icon from your desktop via PGP space instead of doing it now. The Windows Task
Options. To do this, select Tools > Options, select the Disk Scheduler must be installed on your system.
tab, deselect the Place PGP Shredder icon on the desktop
option, and then click OK. The length of the shred session depends on the number
of passes you specified, the speed of the processor, how
many other applications are running, and so on.

9
Copyright and Trademarks
Copyright © 1991-2008 PGP Corporation. All Rights Reserved.
“PGP”, “Pretty Good Privacy”, and the PGP logo are
registered trademarks and PGP Universal is a trademark of
PGP Corporation in the U.S. and other countries. All other
registered and unregistered trademarks in this document are
the sole property of their respective owners.

7. When the shred session is complete, click Next.


8. On the Completing screen, click Finish.

Getting Assistance
Contacting Technical Support
• To learn about PGP support options and how to contact
PGP Technical Support, please visit the PGP Corporation
Support Home Page (https://pgp.custhelp.com).
• To access the PGP Support Knowledge Base or request
PGP Technical Support, please visit PGP Support Portal
Web Site (https://pgp.custhelp.com). Note that you may
access portions of the PGP Support Knowledge Base
without a support agreement; however, you must
have a valid support agreement to request Technical
Support.
• For any other contacts at PGP Corporation, please visit the
PGP Contacts Page
(http://www.pgp.com/about_pgp_corporation/contact/inde
x.html).
• For general information about PGP Corporation, please
visit the PGP Web Site (http://www.pgp.com).
• To access the PGP Support forums, please visit PGP
Support (http://forum.pgp.com). These are user
community support forums hosted by PGP Corporation.

Available Documentation
Prior to installation, complete Product Documentation is
available through the PGP Support Knowledge Base
(https://support.pgp.com/?faq=589).
PGP Whole Disk Encryption documentation is installed onto
your computer during the installation process. To view it,
select Start > Programs > PGP > Documentation. All
documents are saved as Adobe Acrobat Portable Document
Format (PDF) files. You can view and print these files with
Adobe Acrobat Reader, available on the Adobe Web site
(http://www.adobe.com). PGP Whole Disk Encryption also
includes integrated online help.
.

10

You might also like