HP Xw6600 HP xw6600 Workstation Service and Technical Reference Guide - Page 51

DriveLock, DriveLock applications, Using DriveLock, for unauthorized software

Page 51 highlights

DriveLock CAUTION: Enabling DriveLock can render a hard drive permanently inaccessible if the master password is lost or forgotten. No method exists to recover the password or access the data. DriveLock uses an industry-standard security feature that prevents unauthorized access to data on an ATA hard drive. DriveLock has been implemented as an extension to Computer Setup (F10) functions. It is only available when hard drives that support the ATA security command set are detected. On HP workstations, it is not available when the SATA emulation mode is RAID+AHCI or RAID. DriveLock is for HP customers for whom data security is a paramount concern. For such customers, the cost of a hard drive and the loss of the data stored on it is inconsequential when compared to the damage that could result from unauthorized access to its contents. To balance this level of security with the need to address the issue of a forgotten password, the HP implementation of DriveLock employs a two-password security scheme. One password is intended to be set and used by a system administrator, while the other is typically set and used by the user. No back door can be used to unlock the drive if both passwords are lost. Therefore, DriveLock is most safely used when the data contained on the hard drive is replicated on a corporate information system or is regularly backed up. If both DriveLock passwords are lost, the hard drive is rendered unusable. For users who do not fit the previously defined customer profile, this might not be acceptable. For users who fit this profile, it might be a tolerable risk, given the nature of the data stored on the hard drive. DriveLock applications The most practical use of DriveLock is in a corporate environment. The system administrator would be responsible for configuring the hard drive, which involves setting the DriveLock master password and a temporary user password. If the user forgets the user password or if the equipment is passed on to another employee, the master password can be used to reset the user password and regain access to the hard drive. HP recommends that corporate system administrators who enable DriveLock also establish a corporate policy for setting and maintaining master passwords. This should be done to prevent a situation where an employee sets both DriveLock passwords before leaving the company. In such a scenario, the hard drive is unusable and requires replacement. Likewise, by not setting a master password, system administrators might find themselves locked out of a hard drive and unable to perform routine checks for unauthorized software, other asset control functions, and support. For users with less stringent security requirements, HP does not recommend enabling DriveLock. Users in this category include personal users, or users who do not maintain sensitive data on their hard drives as a common practice. For these users, the potential loss of a hard drive resulting from forgetting both passwords is much greater than the value of the data DriveLock protects. Access to Computer Setup (F10) and DriveLock can be restricted through the setup password. By specifying a setup password and not giving it to users, system administrators can restrict users from enabling DriveLock. Using DriveLock When hard drives that support the ATA security command set are detected, the DriveLock option appears under the Security menu in Computer Setup (F10). You are presented with options to set the master password and to enable DriveLock. You must provide a user password must be provided to enable DriveLock. Because the initial configuration of DriveLock is typically performed by a system administrator, a master password should be set first. ENWW Workstation management 41

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170

DriveLock
CAUTION:
Enabling DriveLock can render a hard drive permanently inaccessible if the master
password is lost or forgotten. No method exists to recover the password or access the data.
DriveLock uses an industry-standard security feature that prevents unauthorized access to data on an
ATA hard drive. DriveLock has been implemented as an extension to Computer Setup (F10) functions.
It is only available when hard drives that support the ATA security command set are detected. On HP
workstations, it is not available when the SATA emulation mode is RAID+AHCI or RAID.
DriveLock is for HP customers for whom data security is a paramount concern. For such customers, the
cost of a hard drive and the loss of the data stored on it is inconsequential when compared to the damage
that could result from unauthorized access to its contents.
To balance this level of security with the need to address the issue of a forgotten password, the HP
implementation of DriveLock employs a two-password security scheme. One password is intended to
be set and used by a system administrator, while the other is typically set and used by the user.
No back door can be used to unlock the drive if both passwords are lost. Therefore, DriveLock is most
safely used when the data contained on the hard drive is replicated on a corporate information system
or is regularly backed up.
If both DriveLock passwords are lost, the hard drive is rendered unusable. For users who do not fit the
previously defined customer profile, this might not be acceptable. For users who fit this profile, it might
be a tolerable risk, given the nature of the data stored on the hard drive.
DriveLock applications
The most practical use of DriveLock is in a corporate environment. The system administrator would be
responsible for configuring the hard drive, which involves setting the DriveLock master password and
a temporary user password. If the user forgets the user password or if the equipment is passed on to
another employee, the master password can be used to reset the user password and regain access to
the hard drive.
HP recommends that corporate system administrators who enable DriveLock also establish a corporate
policy for setting and maintaining master passwords. This should be done to prevent a situation where
an employee sets both DriveLock passwords before leaving the company. In such a scenario, the hard
drive is unusable and requires replacement. Likewise, by not setting a master password, system
administrators might find themselves locked out of a hard drive and unable to perform routine checks
for unauthorized software, other asset control functions, and support.
For users with less stringent security requirements, HP does not recommend enabling DriveLock. Users
in this category include personal users, or users who do not maintain sensitive data on their hard drives
as a common practice. For these users, the potential loss of a hard drive resulting from forgetting both
passwords is much greater than the value of the data DriveLock protects.
Access to Computer Setup (F10) and DriveLock can be restricted through the setup password. By
specifying a setup password and not giving it to users, system administrators can restrict users from
enabling DriveLock.
Using DriveLock
When hard drives that support the ATA security command set are detected, the DriveLock option
appears under the Security menu in Computer Setup (F10). You are presented with options to set the
master password and to enable DriveLock.
You must provide a user password must be provided to enable DriveLock. Because the initial
configuration of DriveLock is typically performed by a system administrator, a master password should
be set first.
ENWW
Workstation management
41