Symantec Drive Encryption
Supported Input Method Editors (IME) for UEFI systems. Japanese IME is not supported when creating or entering passphrases or self recovery questions on UEFI systems. Use alphanumeric characters when creating your passphrases or your self recovery questions instead. [3353509]
Using non-Latin characters for Local Self Recovery (LSR) on Microsoft Windows UEFI-based systems. The PGP Bootguard screen does not correctly display non-Latin characters, such as Japanese, on Windows systems running in UEFI mode. Use a Latin character set when you define LSR questions and answers. [3351442]
Using Single Sign-On with Microsoft Windows 8/8.1. Symantec Drive Encryption does not support Single Sign-On for systems running Microsoft Windows 8/8.1 in BIOS mode when Fast Startup is enabled. [3298536]
Encrypting disks with large volumes. Symantec Encryption Desktop maps a drive before encrypting it. The time it takes to map the drive adds up to the overall time taken to start the encryption process. The larger the size of the drive is, the longer it takes to map the drive and, therefore, to start encryption. For example, Symantec Encryption Desktop would take over 5 minutes to map a 2-TB drive but only a few seconds to map a 20-GB drive. [3320305]
Incompatibility with Toshiba Qosmio laptops when Secure Boot is enabled on Microsoft Windows 8/8.1 UEFI systems. Symantec Drive Encryption is incompatible with Toshiba Qosmio laptops when Secure Boot is enabled (a boot failure occurs when restarting your system after encrypting it). To temporarily work around this issue, disable Secure Boot in your system UEFI settings. For more information, refer to the instructions that came with your system. Note that this is an issue with the Toshiba Qosmio laptop and could be resolved by Toshiba in the future. [3196142]
Incompatibility with Microsoft Surface Pro laptops when Secure Boot is enabled on Microsoft Windows 8/8.1 UEFI systems. Symantec Drive Encryption is incompatible with Microsoft Surface Pro laptops when Secure Boot is enabled (a boot failure occurs when restarting your system after encrypting it). To temporarily work around this issue, disable Secure Boot in your system UEFI settings. For more information, refer to the instructions that came with your system. Note that this is an issue with the Microsoft Surface Pro laptop and could be resolved by Microsoft in the future. [3319192]
Refreshing or resetting Microsoft Windows 8/8.1 systems. When the boot drive of your Windows 8/8.1 system is encrypted with Symantec Drive Encryption, the refresh and reset features of Windows 8/8.1 do not work properly. To refresh or reset your system, copy your PGP Keys to a USB drive (if applicable), decrypt the boot drive first, refresh or reset your system, install Symantec Drive Encryption, and encrypt the boot drive again. If you have performed refresh or reset operation on your encrypted system and your system does not boot Windows, then decrypt the drive using the Symantec Drive Encryption recovery CD, and then reset or refresh your system using the Windows boot disk. [2984615]
Authenticating with a Microsoft Surface Pro 2 System. In order to authenticate with the keyboard on a Microsoft Surface Pro 2 system, whether you have a Touch cover or a Type cover, you need to "activate" the keyboard first. To do this, from a powered off state, press the Power button and the volume down button at the same time. Once the Symantec Encryption Desktop authentication screen appears, authenticate as usual. [3373863]
Authenticating Using an External Keyboard on a Microsoft Windows 8/8.1 UEFI System. Be sure you have plugged in your keyboard before you have powered on your system. If you are using a USB keyboard, certain BIOS settings (such as Fast/Quick Boot mode) might delay USB initialization and prevent USB and detachable keyboards from working during pre-boot authentication. Refer to your system user guide to determine how to activate the USB connections. In addition, some systems require that XHCI Pre-boot Mode be enabled in the USB Configuration for the external keyboard to work at pre-boot authentication. [3201234, 3218579]
Using Multimedia Keyboards on Microsoft Windows 8/8.1 UEFI Systems. Some multimedia keyboards with a built-in USB hub or smart card reader may not be compatible at preboot on UEFI bootable systems that have Phoenix firmware. Note that normal USB keyboards work as expected. [3228678]
Using the ESC key on Microsoft Windows 8/8.1 UEFI Systems. The ESC key may not work on certain Toshiba laptop models (such as the Satellite U925t) when booting in UEFI mode. In order to reboot those machines without authentication, use the power button. [3228668]
Authenticating at PGP BootGuard using Japanese USB or PS/2 keyboard. On a Windows 8 system, when you boot into an encrypted partition or boot drive, the Yen key next to the BACKSPACE key and the Backslash key next to the SHIFT key on the Japanese keyboard cannot be used to enter your passphrase. Ensure that you do not use these keys while creating a passphrase during encryption. [3222670]
Hibernating on Microsoft Windows 7 and Windows Vista systems. For systems running Microsoft Windows Vista and later, hibernation is not supported during encryption or decryption operations. To avoid data corruption, disable hibernation until the disk is fully encrypted or decrypted. [2827186]
Hibernating on Microsoft Windows 7 and Windows Vista systems. You might run into problems with hibernation after you encrypt your disk. When that happens, delete the hibernation file on resume and continue to boot into Windows. This problem will only occur once after encryption. To avoid the problem, do a reboot after disk encryption is done. [22706/2467652, 27274/2472229]
Backwards compatibility. Disks encrypted with this version of Symantec Drive Encryption can only be accessed with this same version of Symantec Drive Encryption for Mac OS X or versions 10.0 and up for Windows. [19875/2464814]
Symantec Drive Encryption Evaluation Licenses. If you are using Symantec Drive Encryption with an evaluation license in a managed Symantec Encryption Management Server environment, please ensure you obtain a valid license prior to the expiration of your evaluation license. This will prevent the automatic decryption of your disk upon expiration of the evaluation license. [16445/2461635]
Symantec Drive Encryption Authentication: The ActiveIdentity ActivClientCAC model 2002 smart card is not compatible in this release. To use the ActiveClient CAC card, use model 2005. [16259/2461449]
Passphrase Recovery: Token users who use passphrase recovery when authenticating at PGP BootGuard will be prompted to change their passphrase. This prompt can be ignored as your PIN will not be changed even if you enter text in the dialog or click Cancel. [24335/2469287]
Passphrase Recovery: Passphrase recovery is only available for encrypted boot disks. [24510]
Passphrase Recovery: If you use the Forgot Passphrase option at the PGP BootGuard screen and enter an incorrect user name, you will need to click Cancel to return to the PGP BootGuard screen and then select Forgot Passphrase again. [24825/2469777]
Symantec Drive Encryption and Smart Card Readers: When using a smart card reader with a built-in PIN pad, the correct PIN may not be accepted the first time it is entered on the pad, and you will be prompted to provide the PIN again. When this message appears, click OK without entering the anything. This will either allow the PIN to be accepted or will transfer control to the PIN pad of the smart card reader, where you can enter the PIN again. [16143/2461333]
Symantec Drive Encryption and Smart Card Readers: Pre-boot authentication using a smart card reader is not currently supported on Panasonic Toughbook and Sony Vaio P-Series Mini systems. [20638/2465578]
Symantec Drive Encryption and SSO: When you add an SSO user to Symantec Drive Encryption, be sure that there are no leading spaces in the user's name (for example, " acameron"). If the SSO user's name has a leading space, you will receive an error message that there was a login failure. [26995/2471950]
Symantec Drive Encryption and SSO: If you encounter problems with synchronizing a Windows password change on a Windows XP system, follow the steps below to correct the issue: [17269/2462459]
On your Windows Desktop, right-click My Network Places and select Properties from the shortcut menu.
Select Advanced > Advanced Settings.
Select the Provider Order tab.
Rearrange the order of the providers so PGPpwflt is listed above the Intel card.
Click OK.
You can also modify the .msi installation file. Use the PGP_SET_HWORDER=1 command to place PGPpwflt in the first of the list. For example, run the .msi installation file using the following command:
msiexec /i pgpdesktop.msi PGP_SET_HWORDER=1
Symantec Drive Encryption SSO on Novell Networks: The Single Sign-On feature of Symantec Drive Encryption does not work on Windows Vista systems running Novell Network Client. Once you have authenticated at the PGP Bootguard screen you will need to enter your password again to start Windows Vista. [16688/2461878]
Symantec Drive Encryption SSO on Novell Networks: When using the Single Sign-On feature of Symantec Drive Encryption on Windows Vista systems running Novell Network Client, offline users receive a Novell Security Message stating the "tree or server cannot be found." To continue logging in to Windows, click Yes, and the login proceeds normally. [16995/2462185]
TPM Support: We are in the process of validating many different TPM implementations.We are interested in your test results on any additional TPM systems. [14666/2459855]
TPM authentication with Symantec Drive Encryption works on Windows XP systems only. [2469217]
Token