pgpWholeDiskWin 991 Quickstart en
pgpWholeDiskWin 991 Quickstart en
1
What Am I Installing? Key Management — PGP Whole Disk Encryption
also manages PGP keys, both your keypairs and
PGP Whole Disk Encryption uses licensing to provide access the public keys of others. You use your private key
to the features you purchase. Depending on the license you to decrypt messages sent to you encrypted to your
have, some or all of the PGP Whole Disk Encryption family of public key and to secure your PGP Virtual Disk
applications will be active. volumes. You use public keys to encrypt
messages to others or to add users to PGP Virtual
This document contains instructions for viewing the features
Disk volumes.
activated by your license.
PGP Whole Disk Encryption (PGP WDE) is a
member of the PGP Desktop family of
applications. You can use PGP WDE to lock down System Requirements
the entire contents of your system or an external
or USB flash drive you specify. Boot sectors, • Microsoft Windows 2000 (Service Pack 4), Windows
system files, and swap files are all encrypted. Server 2003 (Service Pack 1 and 2), Windows XP
Whole disk encrypting your boot drive means you Professional 32-bit (Service Pack 2 or 3), Windows XP
do not have to worry if your computer is lost or Professional 64-bit (Service Pack 2), Windows Vista (all
stolen: to access your data, an attacker would 32-bit and 64-bit versions, including Service Pack 1),
need the appropriate passphrase. If you have Windows XP Home Edition (Service Pack 2 or 3),
encrypted a USB device, you can share data on Microsoft Windows XP Tablet PC Edition 2005 (requires
that device with other PGP Whole Disk Encryption attached keyboard).
for Windows or Mac OS X users. Note: The above operating systems are supported only
when all of the latest hot fixes and security patches from
PGP Virtual Disk volumes — Uses part of your Microsoft have been applied.
hard drive space as an encrypted virtual disk
volume with its own drive letter. A PGP Virtual PGP Whole Disk Encryption (WDE) is supported on client
Disk is the perfect place for storing your sensitive versions of Windows 2000 (Service Pack 4) and Windows
files; it is as if you have stored them in a safe. XP (Service Pack 1, 2, or 3), and on Windows Vista; it is
When the door of the safe is open (when the not supported on Windows 2000 Server or 2003 Server.
volume is mounted), you can change files stored in • 512 MB of RAM
it, take files out of it, and move files into it. • 64 MB hard disk space
Otherwise (when the volume is unmounted), all
the data on the volume is protected.
Installing PGP Whole Disk
PGP Zip — Adds any combination of files and
folders to an encrypted, compressed, portable Encryption
archive. PGP Whole Disk Encryption must be
installed on a system to create or open a PGP Zip PGP Corporation recommends exiting all open applications
archive. PGP Zip is a tool for securely archiving before you begin the install. The installation process requires a
your sensitive data, whether you want to distribute system restart.
it to others or back it up.
Note: If you are using PGP Whole Disk Encryption in a PGP
PGP Shredder — Completely destroys files and Universal Server-managed environment, your PGP Whole Disk
folders so that even file recovery software cannot Encryption installer may be configured with specific features
recover them. Deleting a file using the Windows and/or settings.
Recycle Bin (on Windows systems) or Trash (on
Mac OS X systems) does not actually delete it; it
sits on your drive and eventually gets overwritten. • To install PGP Whole Disk Encryption
Until then, it is trivial for an attacker to recover that 1. Locate the PGP Whole Disk Encryption installation
file. PGP Shredder, in contrast, immediately program you downloaded.
overwrites files multiple times. This is so effective The installer program may have been distributed by your
that even sophisticated disk recovery software PGP administrator using the Microsoft SMS deployment
cannot recover these files. This feature also tool.
completely wipes free space on your drives so
your deleted data is truly unrecoverable. 2. Double-click the installer.
3. Follow the on-screen instructions.
4. Reboot your system when instructed.
5. When your system restarts, follow the on-screen
instructions to configure PGP Whole Disk Encryption.
2
The PGP Whole Disk Encryption Main
Licensing Screen
To see what features your license supports, open PGP Whole The PGP Whole Disk Encryption application window is your
Disk Encryption and select Help > License. Those features main interface to the product.
with a checkmark are supported by the active license.
• Right-click the PGP Tray icon and then select Open PGP 2 The Toolbar. Gives you access to frequently used
Whole Disk Encryption. features. You can create a new PGP Zip archive,
• From the Start menu, select Programs > PGP > PGP verify an existing PGP Zip archive, shred selected
Whole Disk Encryption. files, search for a key, synchronize your keys, or find
text in the user IDs of the keys currently visible in
the PGP Keys work area.
3 The PGP Keys Control Box. Gives you control of
PGP keys.
4 The PGP Messaging Control Box. Gives you
control over PGP Messaging.
5 The PGP Zip Control Box. Gives you control of
PGP Zip, as well as the PGP Zip Assistant, which
helps you create new PGP Zip archives.
6 The PGP Disk Control Box. Gives you control of
PGP Disk.
7 The PGP NetShare Control Box. Gives you control
of PGP NetShare.
3
10 PGP Keys Find box. Use to search for keys on your 7. Click Encrypt.
keyring. As you type text in this box, PGP Whole
Disk Encryption displays search results based on
either name or email address.
Each Control box expands to show available options, and
collapses to save space (only the Control Box’s banner
displays). Expand a Control Box by clicking its banner. Collapse
a Control Box by clicking its Expand/Collapse arrow in the
upper right corner.
4
initiate encryption. For more information, see Ensure Disk • As a best practice, highly fragmented disks should be
Health Before Encryption (page 5). defragmented before you attempt to encrypt them.
4. Create a recovery disk. While the chances are extremely
low that a master boot record could become corrupt on a
boot disk or partition protected by PGP Whole Disk
Create a Recovery CD
Encryption, it is possible. Before you encrypt a boot disk The following instructions use Roxio software for illustration
or partition using PGP Whole Disk Encryption, create a purposes. The actual steps you perform may differ.
recovery disk. See Create a Recovery CD (page 5) for 1. Make sure PGP Whole Disk Encryption and Roxio Easy
instructions on how to create a recovery disk. Media Creator or Roxio Easy CD Creator (or other
5. Be certain that you will have AC power for the duration software that can create a CD from an ISO image) are
of the encryption process. See Maintain Power installed on your system.
Throughout Encryption (page 5). 2. Open Roxio Easy Media Creator or Roxio Easy CD Creator
6. Run a pilot test to ensure software compatibility. As a and choose to create a Data CD Project.
good security practice, PGP Corporation recommends 3. Select File > Record CD from CD Image.
testing PGP WDE on a small group of computers to
4. From the Files of Type menu, select ISO Image Files
ensure that PGP WDE is not in conflict with any software
(ISO).
on the computer before rolling it out to a large number of
computers. This is particularly useful in environments that 5. Navigate to the PGP directory. The default location is
use a standardized Corporate Operating Environment C:\Program Files\PGP Corporation\PGP
(COE) image. For a list of software known to have Desktop\.
compatibility issues with PGP WDE, see Run a Pilot Test 6. Select bootg.iso and click Open.
to Ensure Software Compatibility (page 6). 7. Insert a blank, recordable CD into a CD drive on your
7. Perform Disk Recovery on Decrypted Disks. Where system.
possible, as a best practice, if you need to perform any 8. On the Record CD Setup screen, click Start Recording.
disk recovery activities on a disk protected with PGP
Whole Disk Encryption (WDE), PGP Corporation 9. When the file is burned to the CD, click OK.
recommends that you first decrypt the disk. Do this by 10. Remove the recovery CD from the drive and label it
Disk > Decrypt in PGP Whole Disk Encryption, using your appropriately.
prepared PGP WDE Recovery Disk, or by connecting the
hard disk via a USB cable to a second system and Caution: PGP WDE recovery disks are compatible only with
decrypting from that system's PGP Whole Disk Encryption the version of PGP Whole Disk Encryption that created the
software. Once the disk is decrypted, proceed with your recovery CD. For example, if you attempt to use a 9.0.x
recovery activities. recovery disk to decrypt a disk protected with PGP WDE 9.7
software, it will render the PGP WDE 9.7 disk inoperable.
5
• select Unmount when inactive for x mins to have
Caution: This holds true for removable disks, such as USB the volume automatically unmount when it has been
devices. Unless you have selected the Power Failure Safety inactive for the specified number of minutes.
option, you run the risk of corrupting the device if you remove
5. From Capacity, select Dynamic (resizeable) if you want
it during encryption.
the volume to grow in size as you add files or Fixed size if
you want the volume to always remain the same size.
Run a Pilot Test to Ensure Software 6. Specify a file system Format for the volume.
Compatibility 7. Specify an Encryption algorithm for the volume.
Certain other disk protection software is incompatible with 8. Click Add User Key to add users who authenticate using
PGP WDE and can cause serious disk problems, up to and public-key cryptography or click New Passphrase User to
including loss of data. add users who authenticate using passphrases.
Please note the following known interoperability issues, and 9. Click Create.
please review the PGP Whole Disk Encryption Release Notes
for the latest updates to this list.
Software that is not compatible:
6
• PGP Self-Decrypting Archive
Creating a PGP Zip Archive • Sign only
PGP Zip archives let you put any combination of files and 6. Click Next.
folders into a compressed, portable archive. There are four
kinds of PGP Zip archives:
• Recipient keys. Encrypts the archive to public keys. Only
the holder of the corresponding private keys can open the
archive. This is the most secure kind of PGP Zip archive.
Recipients must be using PGP software (for Windows or
Mac OS X).
• Passphrase. Encrypts the archive to a passphrase, which
must be communicated to the recipients. Recipients must
be using PGP software (for Windows or Mac OS X).
• PGP Self-Decrypting Archive. Encrypts the archive to a
passphrase. Recipients do not need to be using PGP
software to open it, but their computer must be running
Microsoft Windows. The passphrase must be Passphrase and Sign only are described in detail in the PGP
communicated to the recipients. Desktop User’s Guide.
• Sign only. Signs the archive but does not encrypt it, Refer to the appropriate section on the following pages for the
allowing you to prove you are the sender. Recipients must kind of PGP Zip archive you specified.
be using PGP software (for Windows or Mac OS X) to
open and verify the archive.
Recipient Keys
The Passphrase and Sign only PGP Zip types are described in The Add User Keys screen appears.
detail in the PGP Desktop User’s Guide; they are described 1. Click Add and use the User Selection screen to select the
briefly here. public keys of those persons who you want to be able to
1. Click New PGP Zip in the PGP Zip Control Box. open the archive. If you want to be able to open the
archive yourself, be sure to include your public key.
2. Click Next.
7
5. Click Next. The PGP Zip archive is created. The Finished 4. Specify a name and a location for the archive. The default
screen displays information about the new archive. name is the name of the first file or folder in the archive;
the default location is the location of the files/folders going
into the archive.
5. Click Next. The PGP SDA is created.
6. Click Finish.
6. Click Finish.
8
2. Click Yes. The specified files and folders are shredded.
Note: You can also use PGP Options to control the number of
passes made when shredding (more passes is more secure
but takes longer), whether files in the Windows Recycle Bin
should be shredded when you empty it, and whether the
warning dialog box is displayed when you shred.
9
Copyright and Trademarks
Copyright © 1991-2008 PGP Corporation. All Rights Reserved.
“PGP”, “Pretty Good Privacy”, and the PGP logo are
registered trademarks and PGP Universal is a trademark of
PGP Corporation in the U.S. and other countries. All other
registered and unregistered trademarks in this document are
the sole property of their respective owners.
Getting Assistance
Contacting Technical Support
• To learn about PGP support options and how to contact
PGP Technical Support, please visit the PGP Corporation
Support Home Page (https://pgp.custhelp.com).
• To access the PGP Support Knowledge Base or request
PGP Technical Support, please visit PGP Support Portal
Web Site (https://pgp.custhelp.com). Note that you may
access portions of the PGP Support Knowledge Base
without a support agreement; however, you must
have a valid support agreement to request Technical
Support.
• For any other contacts at PGP Corporation, please visit the
PGP Contacts Page
(http://www.pgp.com/about_pgp_corporation/contact/inde
x.html).
• For general information about PGP Corporation, please
visit the PGP Web Site (http://www.pgp.com).
• To access the PGP Support forums, please visit PGP
Support (http://forum.pgp.com). These are user
community support forums hosted by PGP Corporation.
Available Documentation
Prior to installation, complete Product Documentation is
available through the PGP Support Knowledge Base
(https://support.pgp.com/?faq=589).
PGP Whole Disk Encryption documentation is installed onto
your computer during the installation process. To view it,
select Start > Programs > PGP > Documentation. All
documents are saved as Adobe Acrobat Portable Document
Format (PDF) files. You can view and print these files with
Adobe Acrobat Reader, available on the Adobe Web site
(http://www.adobe.com). PGP Whole Disk Encryption also
includes integrated online help.
.
10