This article will go over the steps on how to use Symantec File Share to encrypt shares using Group Keys, which will save you a lot of time and effort. Using Group Key will mean you no longer need to reencrypt shares when you want to add or remove user access. All you need to do is add the users to the existing Group in Symantec Encryption Management Server, and the users will then be able to immediately access the shares, all without needing to enter a passphrase.
Group Keys are secure as well. When the user authenticates to the Encryption Server for policy this group access is automatically determined. If the user is part of an applicable group, whenever accessing the share is performed, the share is automatically unlocked and the keys are never stored locally, which means you don't need to worry about user key management.
155519 - Best Practices for Creating and Managing Symantec File Share Encrypted Folders
180791 - Symantec File Share Encryption Group Key FAQ's.
180789 - How do I create a new Group with a File Share Encryption Group Key on Symantec Encryption Management Server?
155582 - Adding a Group Key to an Existing Group on the Symantec Encryption Management Server
Tip: Network Drives should not be added in whitelist from consumer policy. If we do so, the content of the folder are encrypted to the key of the first user to receive the policy setting who has the shared folder mapped on their computer as a network drive, and no other user can assess the encrypted network drive.
This is an article that will discuss all the frequently asked questions for Symantec File Share Encryption Group Keys, a critical feature to ensure ease of encryption and management of your encrypted shares (especially in scenarios where the share is very large).
For information on other topics for File Share Encryption, see the following articles:
155519 - Best Practices for Creating and Managing Symantec FileShare Encrypted Folders
180789 - How do I create a new Group with a File Share Encryption Group Key on Symantec Encryption Management Server?
155582 - Adding a Group Key to an Existing Group on the Symantec Encryption Management Server
161242 - Encrypting network file shares to Group Keys with Symantec File Share Encryption
225452- Using File Share Encryption to send encrypted files to Group Keys (Shared Key Method)
A: A Group Key is a server-managed keypair associated to a specific group that contains users. This group can have manually assigned users or Active Directory users assigned to it dynamically via Directory Synchronization and AD Matching. AD Matching allows membership in the Active Directory security group to be modified and having the group membership in the SEMS group to change automatically, leaving Active Directory as the sole group management tool for any particular group.
- The users don't have to be added or removed manually to encrypted shares.
- The folder does not need to be re-encrypted whenever you add or remove users.
- The header of the files is not as large as with regular PGP keys.
- No need to edit the File Share encrypted folder when a new user joins, the new user only needs to be added to the Group on Symantec Encryption Management Server.
A: It is possible to add a Group Key to an existing group on the PGP Server.
For more information on how to set up a Group Key for an existing group on the Symantec Encryption Management Server, see article 155582.
A: The end users must have access to the Symantec Encryption Management Server. This means that offline mode will not work. This is typically not seen as a limitation because if you are accessing an encrypted share, this usually means you are also accessing the share on an internal resource, and would also have access to other resources on the network, such as Symantec Encryption Management Server.
Once the File Share encrypted file/folder is unlocked, the data remains unlocked for the duration of the Windows session, subsequent access to protected data can be offline (no connectivity to Symantec Encryption Management Server) until user logs out.
A: For users that need to access the data in the offline mode, include their individual keys with the Group Key and copy the encrypted files to a local PGP NetShare folder that is encrypted to local keys.
This option is not recommended if you can avoid it, because it also means that when the user attempts to access the share, the user's key will always be used, instead of the Group Key, which is more convenient.
A: If you add a new Group Key the old Group Key will be revoked first. The old files will be accessible, but all new files added to the folder will be encrypted to the new key.
It is not recommended to add new group keys to existing Groups on Symantec Encryption Management Server. The only scenario to replace a key is if you feel the key was compromised. Because the private portion of the Group Key is held only on the Symantec Encryption Management Server, this scenario is highly unlikely.
A: Group keys are different than using Active Directory groups. Using a Group Key adds only the single key to a protected folder. Using an Active Directory group adds every key found for members of that group.
Question 14: I've added users to an Active Directory Security group and they're properly showing up in that group, but on the PGP server, none of the users are matching the group properly. Because of this, they are not getting access to the Group Key for File Share and can't unlock the share encrypted to this corresponding Group key.
A: This is most likely due to the LDAP Syntax being wrong for the Attributes or Values, Double-check to make sure the syntax is correct so that the users will then match the proper AD groups associated to the Group on the PGP server. Additionally, make sure Directory Synchronization is working for other users to make sure it's not broken for everyone.
This continues our blog series on Symantec Data Loss Prevention (DLP) 16 where we have been discussing a number of new features and capabilities. We are excited to showcase High Speed Discovery for File Systems, a feature that can enable organizations to scan more and more data in their on-prem network shares in a shorter time span. It enables organizations to achieve high scan throughputs of up to 1TB/hour while scanning on-prem file/network shares.
Today organizations deal with a lot of data. There are terabytes or even petabytes of data that have been lying in organizations for decades and new data are being added every second. Scanning such huge volumes of data has been both time consuming and resource intensive.
One of the common use cases that we hear from our customers is for Audit purposes. Organizations need to scan all their data on a regular basis to ensure audit compliance. However, achieving this is challenging because of the current scan speeds, petabytes of data, and the dynamic nature of new data growth. This complexity adds to the difficulty to accurately identify and scan all this data in time for audit.
To add further to the challenge, new compliance regulations are introduced frequently across the globe or to specific industries, which makes it imperative for organizations to ensure compliance at regular intervals, because the cost of not doing so is extremely high. Again, the current scanning speeds make it very difficult to scan such high volume data sets in a timely manner.
We are also seeing many of our customers move their data to the cloud. However, this is not always straightforward as some want to scan and identify data that is critical to them and retain that data on-premises. For example, consider a large enterprise that has decades of data, managing and orchestrating the data discovery process can feel never ending as the process is both highly time and resource intensive.
In DLP 16, we provide a solution to these problems by introducing a newly re-architected Discovery solution to scan File systems i.e. File System High Speed Discovery. This enables organizations to scan more and more data quickly, ensuring data compliance and achieving high scan throughputs of 1 TB/hour or more depending on the environment.
Customers that participated in the DLP 16 beta test program expressed excitement about this feature making it one of the most anticipated features they were looking forward to. It not only offers industry leading performance but also optimum utilization of their resources.
The DLP File System High Speed Discovery solution offers one of the highest speeds to scan on-prem data in the market and is one of our key differentiating features. As many organizations are and will continue to work in a hybrid mode in their cloud journey, this new solution will elevate their experience to discover and protect data in their on-prem environment.
To summarize, as organizations scale their High Speed Discovery server setup they will observe higher scan throughput of up to (but not limited to) 1 TB/hour depending on certain factors like network I/O speeds, files being scanned, DLP policies, etc.
We understand that the need to discover more and more sensitive data at a high speed goes beyond network and file shares. And we are committed to offering solutions that would make data discovery easier, faster and more convenient. File System High Speed Discovery is the first step in that direction. Symantec will continue to invest to achieve this goal and to discover and protect more and more data.
LinkedIn and 3rd parties use essential and non-essential cookies to provide, secure, analyze and improve our Services, and to show you relevant ads (including professional and job ads) on and off LinkedIn. Learn more in our Cookie Policy.
The San Jose, Calif.-based semiconductor manufacturer said the monster acquisition is expected to drive $2 billion of revenue and $1.3 billion of EBITDA (earning before interest, taxation, depreciation, and amortization), as well as upwards of $1 billion of cost synergies in the year following close. The Symantec name will be sold to Broadcom as part of the transaction. Read more at CRN.
4a15465005