HP 2210b ProtectTools - Windows Vista and Windows XP - Page 75

the Emergency Recovery Token

Page 75 highlights

Short description Details Solution Secure e-mail is supported, even when secure e-mail is not specified in the User Initialization Wizard or when secure e-mail configuration is disabled in user policies. Embedded security software and the wizard do not control settings of an email client (Outlook, Outlook Express, or Netscape). This behavior is as designed. Configuration of TPM email settings does not prohibit editing encryption settings directly in an e-mail client. Usage of secure email is set and controlled by 3rd-party applications. The HP wizard allows linkage to the three reference applications for immediate customization. Running Large Scale Deployment a second time on the same PC or on a previously initialized PC overwrites Emergency Recovery and Emergency Token files. The new files are useless for recovery. Running Large Scale Deployment on any previously initialized HP ProtectTools Embedded Security system renders existing Recovery Archives and Recovery Tokens useless by overwriting those XML files. HP is working to resolve the XML-file-overwrite issue and will provide a solution in a future SoftPaq. Automated logon scripts do not function during user restore in Embedded Security. The error occurs after the user performs the following actions: ● Initializes owner and user in Embedded Security (using the default locations-My Documents). Click the Browse button on the screen to select the location, and the restore process proceeds. ● Resets the chip to factory settings in the BIOS. ● Reboots the computer. ● Begins to restore Embedded Security. During the restore process, Credential Manager asks if the system can automate the logon to Infineon TPM User Authentication. If the user selects Yes, the location of SPEmRecToken is automatically displayed in the text box. Even though this location is correct, the following error message is displayed: No Emergency Recovery Token is provided. Select the token location the Emergency Recovery Token should be retrieved from. Multiple-User PSDs do not function in a fast-userswitching environment. This error occurs when multiple users have been created and given a PSD with the same drive letter. If an attempt is made to fast-user-switch between users when the PSD is loaded, the second user's PSD is unavailable. The second user's PSD will be available only if it is reconfigured to use another drive letter or if the first user is logged off. The PSD is disabled and cannot be deleted after formatting the hard drive on which the PSD was generated. The PSD icon is still visible, but the error message drive is not accessible is displayed when the user attempts to access the PSD. The user is not able to delete the PSD and the following message is displayed: your PSD is still in use, please be sure that your PSD contains As designed: If a customer force-deletes or disconnects from the storage location of the PSD data, the Embedded Security PSD drive emulation continues to function and will produce errors based on lack of communication with the missing data. Resolution: After the next reboot, the emulations fail to load and user can delete the old PSD emulation and create a new PSD. ENWW Embedded Security for HP ProtectTools 69

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90

Short description
Details
Solution
Secure e-mail is
supported, even when
secure e-mail is not
specified in the User
Initialization Wizard or
when secure e-mail
configuration is disabled in
user policies.
Embedded security software and the
wizard do not control settings of an e-
mail client (Outlook, Outlook Express, or
Netscape).
This behavior is as designed. Configuration of TPM e-
mail settings does not prohibit editing encryption
settings directly in an e-mail client. Usage of secure e-
mail is set and controlled by 3rd-party applications. The
HP wizard allows linkage to the three reference
applications for immediate customization.
Running Large Scale
Deployment a second
time on the same PC or on
a previously initialized PC
overwrites Emergency
Recovery and Emergency
Token files. The new files
are useless for recovery.
Running Large Scale Deployment on any
previously initialized HP ProtectTools
Embedded Security system renders
existing Recovery Archives and
Recovery Tokens useless by overwriting
those XML files.
HP is working to resolve the XML-file-overwrite issue
and will provide a solution in a future SoftPaq.
Automated logon scripts
do not function during user
restore in Embedded
Security.
The error occurs after the user performs
the following actions:
Initializes owner and user in
Embedded Security (using the
default locations—
My
Documents
).
Resets the chip to factory settings
in the BIOS.
Reboots the computer.
Begins to restore Embedded
Security. During the restore
process, Credential Manager asks
if the system can automate the
logon to Infineon TPM User
Authentication. If the user selects
Yes
, the location of
SPEmRecToken is automatically
displayed in the text box.
Even though this location is correct, the
following error message is displayed:
No
Emergency Recovery Token is
provided. Select the token location
the Emergency Recovery Token
should be retrieved from.
Click the
Browse
button on the screen to select the
location, and the restore process proceeds.
Multiple-User PSDs do not
function in a fast-user-
switching environment.
This error occurs when multiple users
have been created and given a PSD with
the same drive letter. If an attempt is
made to fast-user-switch between users
when the PSD is loaded, the second
user's PSD is unavailable.
The second user's PSD will be available only if it is
reconfigured to use another drive letter or if the first user
is logged off.
The PSD is disabled and
cannot be deleted after
formatting the hard drive
on which the PSD was
generated.
The PSD icon is still visible, but the error
message
drive is not accessible
is
displayed when the user attempts to
access the PSD.
The user is not able to delete the PSD
and the following message is
displayed:
your PSD is still in use,
please be sure that your PSD contains
As designed: If a customer force-deletes or disconnects
from the storage location of the PSD data, the
Embedded Security PSD drive emulation continues to
function and will produce errors based on lack of
communication with the missing data.
Resolution: After the next reboot, the emulations fail to
load and user can delete the old PSD emulation and
create a new PSD.
ENWW
Embedded Security for HP ProtectTools
69