background image

16

www.hp.com

Technical Reference Guide

HP ProtectTools Troubleshooting Guide

HP ProtectTools Embedded 
Security—An internal error 
has been detected restoring 
from Automatic Backup 
Archive

If the user

1. clicks 

Restore under 

Backup

 option of 

Embedded Security in 
HPPTSM to restore from 
the automatic backup 
Archive

2. selects 

SPSystemBackup
.xml

the Restore Wizard fails and 
the following error message is 
displayed: 

The selected 

Backup Archive does not 
match the restore 
reason. Please select 
another archive and 
continue.

If the user selects the SpSystemBackup.xml when 
the SpBackupArchive.xml is required, 
Embedded Security Wizard fails with: 

An 

internal Embedded Security error has 
been detected

.

User must select the correct .xml file to match the 
required reason.
The processes are working as designed and 
function properly; however, the internal 
Embedded Security error message is not clear 
and should state a more appropriate message. 
We are working to enhance this in future 
products.

HP ProtectTools Embedded 
Security—Security System 
restore error with multiple 
users

During the restore process, if 
the administrator selects users 
to restore, the users not 
selected are not able to 
restore the keys when trying 
to restore at a later time. An 
error that a 

decryption 

process failed

 message is 

displayed.

The non-selected users can be restored by 
resetting the TPM, running the restore process, 
and selecting all users before the next default 
daily back runs. If the automated backup runs, it 
overwrites the non-restored users and their data 
is lost. If a new system backup is stored, the 
previous non-selected users cannot be restored.
Also, user must restore the entire system backup. 
An Archive Backup can be restored individually.

HP ProtectTools Embedded 
Security—After reinstalling 
Embedded Security, user 
sees general driver error

After reinstalling Embedded 
Security, either by setup.bat 
or through supplemental CD 
autorun, a general driver 
error is displayed when 
opening Security Manager, 
Embedded Security, user 
settings, configure, check 
PSD.

A reboot is not requested, but it is required. The 
reinstallation of Embedded Security produces 
this error if it is used before the computer is 
rebooted.
HP is working on an enhancement to be made 
available in future product versions.

HP ProtectTools Embedded 
Security—Resetting System 
ROM to default hides TPM.

Resetting the system ROM to 
default hides the TPM to 
Windows. This does not 
allow the security software to 
operate properly and makes 
TPM-encrypted data 
inaccessible.

Unhide the TPM in BIOS:
Open the Computer Setup (F10) Utility, navigate 
to 

Security > Device security

, modify the 

field from 

Hidden

 to 

Available

.

Software 

Impacted-Short 

description

Details

Solution / Workaround

Содержание 413742-001

Страница 1: ...aq Business Desktops Document Part Number 413742 001 January 2006 This document contains information and recommendations for the ProtectTools administrator concerning questions that may arise in the administration and operation of HP ProtectTools ...

Страница 2: ...nical or editorial errors or omissions contained herein This document contains proprietary information that is protected by copyright No part of this document may be photocopied reproduced or translated to another language without the prior written consent of Hewlett Packard Company ÅWARNING Text set off in this manner indicates that failure to follow directions could result in bodily harm or loss...

Страница 3: ...off chip memory functions and firmware are located on an external flash integrated with the system board All TPM functions are encrypted or protected to ensure secure flash or communications Software The software HP ProtectTools has two parts HP ProtectTools Security Manager and HP plug in modules Security Manager is the interface shell that centralizes all security applications plug ins The compu...

Страница 4: ... applications and protected network resources Support for optional security devices such as smart cards and biometric readers Support for additional security settings such as requiring authentication with an optional security device to unlock the computer and access applications Enhanced encryption for stored passwords when implemented with a TPM Embedded Security chip Smart Card Security for Prot...

Страница 5: ...cure Multipurpose Internet Mail Extensions A specification for secure electronic messaging using PKCS S MIME offers authentication via digital signatures and privacy via encryption TCG Trusted Computing Group Industry association set up to promote the concept of a Trusted PC TCG supersedes TCPA TCPA Trusted Computing Platform Alliance Trusted computing alliance now superseded by TCG TPM Trusted Pl...

Страница 6: ...lete or move contents of the folder This is as designed It is a feature of EFS not the Embedded Security TPM Embedded Security uses Microsoft EFS software and EFS preserves file folder access rights for all administrators HP ProtectTools Embedded Security Encrypted folders with EFS in Windows 2000 are not shown highlighted in green Encrypted folders with EFS are highlighted in green in Windows XP ...

Страница 7: ...s security approach and instruct users never to encrypt or delete the recovery archive files HP ProtectTools Embedded Security HP ProtectTools Embedded Security EFS interaction with Norton Antivirus produces longer encryption decryption and scan times Encrypted files interfere with Norton Anti Virus 2005 virus scan During the scan process the Basic User Key password prompt asks the user for a pass...

Страница 8: ... is not initialized To use the wizard the Embedded Security must be initialized first Perform the following procedure to recover from the power loss Use the Arrow keys to select various menus menu items and to change values unless otherwise specified 1 Start or restart the computer 2 Press F10 when the F10 Setup message appears on screen or as soon as the monitor LED turns green 3 Select the appro...

Страница 9: ...incorrect password or cancels the password dialog the encrypted file will open as if the administrator had entered the correct password This happens regardless of the security settings used when encrypting the data The Data Recovery Policy is automatically configured to designate an administrator as a recovery agent When a user key cannot be retrieved as in the case of entering the wrong password ...

Страница 10: ...r transfer If the user attempts to access the PSD when the removable hard drive is not present an error message is displayed stating that the device is not ready HP ProtectTools Embedded Security During uninstall if user has not initialized the Basic User Key and opens the Administration tool the Disable option is not available and Uninstaller will not continue until the Administration tool is clo...

Страница 11: ...s Embedded Security EFS User Authentication password request times out with access denied The EFS User Authentication password reopens after clicking OK or returning from standby state after timeout This is by design to avoid issues with Microsoft EFS a 30 second timer watchdog timer was created to generate the error message HP ProtectTools Embedded Security Minor truncation during setup of Japane...

Страница 12: ... Click System Devices 5 Click Broadcom TPM The device status should indicate This device is working properly A 3 minute delay occurs as applications and Windows services time out after attempting connection to the damaged TPM The Security Manager recovers and the user can run the self test and confirm damaged module HP ProtectTools Embedded Security Running Large Scale Deployment a second time on ...

Страница 13: ...rforming a firmware update The firmware version is not identified correctly until after the reboot 1 Reinstall HP ProtectTools Embedded Security Software 2 Run the Platform and User configuration wizard 3 Ensure that the system contains Microsoft NET framework 1 1 installation Click Start Click Control Panel Click Add or remove programs Ensure Microsoft NET Framework 1 1 is listed 4 Check the hard...

Страница 14: ...e error occurs after user 1 Initializes owner and user in Embedded Security using the default locations My Documents 2 Resets the chip to factory settings in the BIOS 3 Reboots the machine 4 Begins to restore Embedded Security During the restore process Credential Manager 1 5 0 631 35 asks user if the system can automate the logon to Infineon TPM User Authentication If user selects Yes then the lo...

Страница 15: ...t errors due to the disabling functionality pattern of Single Sign On For example an in a yellow triangle is observed in Internet Explorer indicating an error has occurred Credential Manager Single Sign On does not support all software Web interfaces Disable Single Sign On support for the specific Web page by turning off Single Sign On support Please see complete documentation on Single Sign On wh...

Страница 16: ...ass Security Manager and initialize a basic user During the basic user initialization the guest could create a PSD that monopolizes the hard drive The system administrator can resolve this by deleting the guest user created PSD HP is working with plug in suppliers to be aware of limited guest user capabilities for future product enhancements HP ProtectTools Embedded Security Guest User receives me...

Страница 17: ...PSD HP ProtectTools General Unrestricted access or uncontrolled administrator privileges pose security risk Numerous risks are possible with unrestricted access to the client PC deletion of PSD malicious modification of user settings disabling of security policies and functions Administrators are encouraged to follow best practices in restricting end user privileges and restricting user access Una...

Страница 18: ...cryption process failed message is displayed The non selected users can be restored by resetting the TPM running the restore process and selecting all users before the next default daily back runs If the automated backup runs it overwrites the non restored users and their data is lost If a new system backup is stored the previous non selected users cannot be restored Also user must restore the ent...

Страница 19: ... minutes after the uninstall completes when the user selects Yes to reboot numerous end task errors appear with Japanese JP Taiwanese TW Traditional Chinese TZ These end tasks include persistWnd hkem exe conime exe ccapp PSD HP ProtectTools Embedded Security Icon tray This occurs only on first uninstall attempt Allow more time and the stalled process will successfully complete Software Impacted Sh...

Страница 20: ... currently not accessible Click here if you want to backup to a temporary archive until the Backup Archive is accessible again If the Automatic Backup is scheduled for a specific time however the backup fails without displaying notice of the failure The workaround is to change the NT AUTHORITY SYSTEM to computer name admin name This is the default setting if the Scheduled Task is created manually ...

Страница 21: ... HP is researching a workaround for future product enhancements HP ProtectTools Credential Manager Credential Manager creates long account names that are truncated When registering a password in Credential Manager the user can click Options and select Prompt to select account for this application User must then enter a unique name for each document so Credential Manager can tell which password to ...

Страница 22: ...loop Single Sign On default is set to log users automatically However when creating the second of two different password protected documents Credential Manager uses the last password recorded the one from the first document HP is researching a workaround for future product enhancements HP ProtectTools Credential Manager Incompatibility issues with Corel WordPerfect 12 password gina If the user log...

Страница 23: ...isable opening of Credential Manager upon smart card insertion 1 Click Advanced Settings 2 Click Service Applications 3 Click Smart Cards and Tokens 4 Click when smart card token is inserted 5 Select the Advise to log on checkbox HP ProtectTools Smart Card Manager The option to Require PIN at Boot does not work The Settings button at HP ProtectTools Security Manager Smart Card Security BIOS Smart ...

Страница 24: ...l credentials protected by the TPM This is as designed The TPM Module is designed to protect the Credential Manager credentials HP recommends that the user back up identity from Credential Manager prior to removing the TPM module HP ProtectTools Credential Manager Credential Manager not being set as primary logon in Windows 2000 During Windows 2000 install the logon policy is set for manual or aut...

Страница 25: ... Microsoft knowledge base article 813301 for more information on the cause of the issue Customer Workaround In order to logon user must select Credential Manager and log in After logging into Credential Manager user is prompted to log in to Windows user may have to select the Windows login option to complete login process If user logs into Windows first then user must manually log into Credential ...

Страница 26: ... cannot register smart card in Credential Manager through the More option Cannot register Smart Card in Credential Manager through the My Identity More Register Credentials option User must use Register Smart Card or Token option This functionality was not originally designed into the product This is being implemented in future product revisions being designed by HP HP ProtectTools Credential Mana...

Отзывы: