Installation and full-disk encryption
22
Administration manual 4603.7988.02 ─ 03
Note:
A restart is required. Please note that shutting down the workstation might
only put it to hybrid shutdown, i.e. the workstation is not really restarted at its next
startup. To make sure that the workstation is restarted properly, do one of the fol-
lowing:
● Confirm the prompt to restart your workstation after the installation.
● Manually restart the workstation.
● Disable hybrid shutdown in your Windows settings.
You have installed R&S
Trusted
Disk.
During the installation, the R&S
Trusted
Disk installer imports a code signing certificate
to the Trusted Publishers certificate store on the workstation. The certificate is needed
to validate the signed PowerShell script contained in the R&S
Trusted
Disk installer.
4.4
Initializing the full-disk encryption
R&S
Trusted
Disk's full-disk encryption secures user data, the operating system and
any temporary data on a workstation. Only the admin and users with permission can
access an encrypted workstation using a smart card and PIN for pre-boot authentica-
tion.
Contents
......................................................................................22
Activating setup mode (UEFI/GPT)
.........................................................................23
4.4.1
Full-disk encryption wizard
After installing R&S
Trusted
Disk and restarting the workstation, the R&S
Trusted
Disk
full-disk encryption wizard is launched.
On Legacy BIOS/MBR-based workstations, the "Compress this drive to save disk
space" option in the properties of the Windows partition needs to be disabled.
1. Connect a smart card personalized for the user.
2. To follow the full-disk encryption wizard, click "Next".
3. Select the partitions that you want to encrypt.
Note:
After the encryption, unencrypted partitions on internal hard disk drives are
hidden and cannot be accessed anymore.
4. To finish the wizard, click "Next".
5.
NOTICE!
Setup mode required for UEFI/GPT. After initializing the full-disk encryp-
tion on an UEFI-based workstation, you need to activate setup mode, so
R&S
Trusted
Disk can perform a system takeover. For instructions on how to acti-
Initializing the full-disk encryption