HP dc73 Blade Client Clicks Restore under Backup, Wizard fails with An internal Embedded Security

Page 70

Short description

Details

Solution

 

 

 

PSD is disabled and cannot be deleted after formatting the hard drive on which the PSD was generated

The PSD is disabled and cannot be deleted after formatting the secondary hard drive on which the PSD was generated. The PSD icon is still visible, but the error message drive is not accessible appears when the user attempts to access the PSD.

User is not able to delete the PSD and a message appears that states: your PSD is still in use, please ensure that your PSD contains no open files and is not accessed by another process. User must reboot the system in order to delete the PSD and it is not loaded after reboot.

As designed: If a customer force-deletes or disconnects from the storage location of the PSD data, the Embedded Security PSD drive emulation continues to function and will produce errors based on lack of communication with the missing data.

Resolution: After the next reboot, the emulations fail to load and user can delete the old PSD emulation and create a new PSD.

An internal error has been

If the user

If the user selects SpSystemBackup.xml when the

detected restoring from

clicks Restore under Backup

SpBackupArchive.xml is required, Embedded Security

Automatic Backup

Wizard fails with: An internal Embedded Security

Archive.

option of Embedded Security in

error has been detected.

 

HPPTSM to restore from the

 

 

automatic backup Archive

User must select the correct .xml file to match the

 

selects SPSystemBackup .xml

required reason.

 

The processes are working as designed and function

 

the Restore Wizard fails and the

 

properly; however, the internal Embedded Security

 

following error message is displayed:

error message is not clear and should state a more

 

The selected Backup Archive does

appropriate message. HP is working to enhance this in

 

not match the restore reason. Please

future products.

 

select another archive and continue.

 

 

 

 

Security System exhibits a

During the restore process, if the

The non-selected users can be restored by resetting

restore error with multiple

administrator selects users to restore,

the TPM, running the restore process, and selecting all

users.

the users not selected are not able to

users before the next default daily back runs. If the

 

restore the keys when trying to restore at

automated backup runs, it overwrites the non-restored

 

a later time. A decryption process

users and their data is lost. If a new system backup is

 

failed error message is displayed.

stored, the previous non-selected users cannot be

 

 

restored.

 

 

Also, user must restore the entire system backup. An

 

 

Archive Backup can be restored individually.

 

 

 

Resetting System ROM to

Resetting the system ROM to default

Unhide the TPM in BIOS:

default hides TPM.

hides the TPM to Windows. This does

Open the Computer Setup (F10) Utility, navigate to

 

not allow the security software to operate

 

properly and makes TPM-encrypted data

Security > Device security, modify the field from

 

inaccessible.

Hidden to Available.

Automatic backup does

When an administrator sets up

not work with mapped

Automatic Backup in Embedded

drive.

Security, it creates an entry in

 

Windows > Tasks > Scheduled Task.

 

This Windows Scheduled Task is set to

 

use NT AUTHORITY\SYSTEM for rights

 

to execute the backup. This works

 

properly to any local drive.

 

When the administrator instead

 

configures the Automatic Backup to save

 

to a mapped drive, the process fails

 

because the NT AUTHORITY\SYSTEM

 

does not have the rights to use the

 

mapped drive.

 

If the Automatic Backup is scheduled to

 

occur upon login, Embedded Security

 

TNA Icon displays the following

 

message: The Backup Archive

 

location is currently not accessible.

The workaround is to change the NT AUTHORITY \SYSTEM to (computer name)\(admin name). This is the default setting if the Scheduled Task is created manually.

HP is working to provide future product releases with default settings that include computer name\admin name.

64 Chapter 7 Troubleshooting

ENWW

Image 70
Contents ProtectTools First Edition July Document Part Number Table of contents Embedded Security for HP ProtectTools Java Card Security for HP ProtectToolsTroubleshooting Bios Configuration for HP ProtectToolsDrive Encryption for HP ProtectTools Enww Introduction to security HP ProtectTools features Module Key featuresAccessing HP ProtectTools Security Achieving key security objectives Restricting access to sensitive dataProtecting against targeted theft Creating strong password policies Additional security elements Managing HP ProtectTools passwordsAssigning security roles Java Card PIN also protects access to Creating a secure password HP ProtectTools Backup and RestoreBacking up credentials and settings Restoring credentials Configuring settings Credential Manager for HP ProtectTools Using the Credential Manager Logon Wizard Setup proceduresLogging on to Credential Manger Logging on for the first time Registering credentialsRegistering fingerprints Registering a Java Card, USB eToken, or virtual token Setting up the fingerprint readerUsing your registered fingerprint to log on to Windows Registering a USB eTokenCreating a virtual token Changing the Windows logon passwordGeneral tasks Changing a token PINManaging identity Clearing an identity from the systemLogging on to Windows with Credential Manager Using Windows LogonLocking the computer Adding an accountRemoving an account Using Single Sign OnUsing automatic registration Registering a new applicationModifying application properties Using manual drag and drop registrationManaging applications and credentials Removing an application from Single Sign OnImporting an application Using Application ProtectionModifying credentials Changing restriction settings for a protected application Restricting access to an applicationRemoving protection from an application Enww Advanced tasks administrator only Specifying how users and administrators log onConfiguring custom authentication requirements Configuring credential propertiesConfiguring Credential Manager settings Select Start All Programs HP ProtectTools Security Manager Embedded Security for HP ProtectTools Select Embedded security device state and change to Enable Enabling the embedded security chipInitializing the embedded security chip Setting up the basic user account Encrypting files and folders Using the Personal Secure DriveSending and receiving encrypted e-mail Changing the Basic User Key password Advanced tasks Creating a backup fileRestoring certification data from the backup file Backing up and restoringEnabling Embedded Security after permanent disable Changing the owner passwordResetting a user password Enabling and disabling Embedded SecurityMigrating keys with the Migration Wizard Java Card Security for HP ProtectTools Changing a Java Card PIN Selecting the card readerAdvanced tasks administrators only Assigning a Java Card PINSetting power-on authentication Assigning a name to a Java CardTo enable Java Card power-on authentication Disabling Java Card power-on authentication Creating a user Java CardBios Configuration for HP ProtectTools Managing boot options Enabling and disabling system configuration options Enww Managing HP ProtectTools add-on module settings Under Smart Card Security, click EnableClick Apply, and then click OK in the HP ProtectTools window Enabling and disabling DriveLock hard drive protection Using DriveLockDriveLock Applications Changing the power-on password Managing Computer Setup passwordsSetting the power-on password Setting the setup passwordSetting password options Changing the setup passwordEnabling and disabling stringent security Enww Drive Encryption for HP ProtectTools Encryption management User management Recovery Right pane, click Click here to backup your keysCredential Manager for ProtectTools TroubleshootingSecurity Change password option, but, since Virtual Token duringConnect Click Advanced SettingsClick Service & Applications Click Java Cards and TokensReader to log on to Credential ManagerSelect Enable Save changes and exit F10 = ROM Based Setup message is displayedIt to Embedded Security Device-Enable Security Restore IdentityEmbedded Security for ProtectTools Select File Save Changes and Exit Being used by another Process cannot accessFile because it is ProcessOut with access denied Selects SPSystemBackup .xml Clicks Restore under BackupError has been detected Selected Backup Archive doesEnww Miscellaneous Click All Programs Click HP ProtectTools Security ManagerPower-on Computer Setup, the Power-on Authentication support Glossary Enww Access IndexEnww Enww
Related manuals
Manual 65 pages 2.14 Kb