Print Download PDF Send Feedback

Previous

Next

Upgrading Media Encryption R73.x Devices and Keys

This version includes a wizard that lets you export Media Encryption devices from the R73.x database and import them into an R80.20.M1 Endpoint Security Management Server. When upgrading from Media Encryption R73 to the current version:

Media Encryption (Protector) Encryption Keys and Devices are stored in the MS-SQL database. The Protector Server connects to MS-SQL through named pipelines. To migrate Media Encryption keys and devices, you must configure MS-SQL to accept requests over TCP connections. You must create a login profile that has the permissions required to access the Disknet database.

To configure the MS-SQL server to accept requests over TCP connections:

  1. In the regedit tool, find the "SuperSocketNetLib" key.

    The path to this key can be different according to the platform and installed tools.

  2. Right-click the "SuperSocketNetLib" entry and export it for backup.
  3. Create a reg file to customize the server:

    If the path to the SuperSocketNetLib entry is the same in the Media Encryption (Protector) server and in this article:

    1. Copy this registry fragment to a separate file.
    2. Save it with the "reg" extension, and run it.

    If the path is different, edit the new reg file so that it fits the path on the machine.

    Windows Registry Editor Version 5.00

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MSSQLServer\MSSQLServer]

    "LoginMode"=dword:00000002

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MSSQLServer\MSSQLServer\SuperSocketNetLib]

    "ProtocolList"=hex(7):74,00,63,00,70,00,00,00,6e,00,70,00,00,00,00,00

    "TcpPort"="1433"

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MSSQLServer\MSSQLServer\SuperSocketNetLib\Tcp]

    "TcpHideFlag"=dword:00000000

    "TcpDynamicPorts"=""

    "TcpPort"="1433"

    "Enabled"=dword:00000001

  4. When the registry edit is done, open the regedit utility.
  5. Make sure that the "reg" script ran successfully and that the values in the registry were changed according to the script.
  6. Restart the "MSSQLSERVER" process.

To add a new login profile to the MS-SQL server:

  1. Run the osql tool from the command line: osql -E
  2. Run these commands in the osql command line:

    EXEC sp_addlogin 'ep','ep'
    GO
    EXEC sp_grantdbaccess 'ep', 'Disknet'
    GO
    EXEC sp_addsrvrolemember 'ep', 'sysadmin'
    GO

To run the Migration Wizard:

  1. Make sure that Media Encryption & Port Protection and the Endpoint Security server are up and running.
  2. Make sure that Directory Scanner finished a full scan of the Active Directory.

    Important! This is required to complete the key migration successfully.

  3. Open the SmartEndpoint console.
  4. Click Tools menu > Devices and Keys Migration Tool.
  5. Enter the details of the Media Encryption R73 Database: IP address or server name, Database Username, Database Password, Database Name.
  6. Click Next.
  7. Select Import Devices or Import Keys or both.
  8. Click Next.

    See the import results. When import is done, users can access the media from computers with Endpoint Security client installed.

    Important! Users must access the media at least once to enable Remote Help Key Recovery.

More details can be found in deviceMigrtor.log file, which is located in the same folder as the SmartEndpoint.exe executable. To go to this folder, right-click the SmartEndpoint icon and select Properties > Open File Location.