<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Missing Link &#187; PGP Corporation</title>
	<atom:link href="http://john.whelans.net/archives/tag/pgp-corporation/feed" rel="self" type="application/rss+xml" />
	<link>http://john.whelans.net</link>
	<description>Stumbling through life</description>
	<lastBuildDate>Fri, 02 Dec 2011 16:57:11 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=</generator>
		<item>
		<title>Wherein PGP 10 has a bug, and a workaround exists</title>
		<link>http://john.whelans.net/archives/700</link>
		<comments>http://john.whelans.net/archives/700#comments</comments>
		<pubDate>Mon, 22 Feb 2010 16:56:46 +0000</pubDate>
		<dc:creator>John</dc:creator>
				<category><![CDATA[Personal]]></category>
		<category><![CDATA[2010]]></category>
		<category><![CDATA[PGP Corporation]]></category>
		<category><![CDATA[Technology]]></category>

		<guid isPermaLink="false">http://john.whelans.net/?p=700</guid>
		<description><![CDATA[As I write this, I realize that its usefulness to most of you who read my blog regularly is limited, at best.  For that, I apologize.  If you&#8217;re not someone interested in information security (and specifically, the technologies involved therein) you can safely skip this without missing anything you care about reading. Back in January, [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://john.whelans.net/wp-content/uploads/2010/02/pgp_logo.png" rel="lightbox[700]"><img class="alignleft size-medium wp-image-701" title="pgp_logo" src="http://john.whelans.net/wp-content/uploads/2010/02/pgp_logo-300x160.png" alt="" width="300" height="160" /></a>As I write this, I realize that its usefulness to most of you who read my blog regularly is limited, at best.  For that, I apologize.  If you&#8217;re not someone interested in information security (and specifically, the technologies involved therein) you can safely skip this without missing anything you care about reading.</p>
<p>Back in January, PGP Corporation released a much anticipated update to their PGP Desktop lineup -PGP Desktop 10.0.  This update was much anticipated because it finally added support for Mac OS X 10.6 Snow Leopard.  The great benefit here is that those who would be so inclined to utilize whole disk encryption on mac, and choose PGP as their platform of choice, could now upgrade to Snow Leopard and have their drive encrypted.</p>
<p><span id="more-700"></span>In testing this new software I discovered a bug, however.  When utilizing PGP Desktop 10 for Mac in an environment managed by PGP Universal Server (2.12), I was frequently asked to re-enroll my Mac with the universal server.   Until I was able to re-enroll, PGP Desktop was unavailable.   Whole Disk Encryption was thankfully NOT affected.</p>
<p>After working fairly closely with PGP support on this issue it was determined to be a bug,  and after providing them a wealth of information from our environment they were able to reproduce the issue on their end and provide a list of steps that would reproduce it 100% of the time.</p>
<p>Thankfully,  we&#8217;ve also been able to determine a successful workaround for this issue.</p>
<p>The underlying cause for this behavior appears to be on-access scanning by antivirus products on the Mac interfering with the PGP plist files in ~/Library/Preferences/</p>
<p>The workaround that has worked in my testing so far has been to create exclusions in the scanning policy for:</p>
<blockquote><p>~/Library/Preferences/com.pgp.pgp.plist</p>
<p>~/Library/Preferences/com.pgp.desktop.plist</p>
<p>~/Library/Preferences/com.pgp.admin.plist</p>
<p>~/Library/Preferences/com.pgp.engine.plist</p></blockquote>
<p>With those four files excluded from on-access antivirus scanning, I have been unable to get PGP Desktop to prompt me for re-enrollment,  indicating that this does, in fact, provide a workaround for the issue.</p>
<p>A huge thanks goes to the PGP Support team who worked this issue hard and were a pleasure to work with in finding a resolution to this issue.</p>
<p>(note: I am in no way affiliated with PGP Corporation.)</p>
]]></content:encoded>
			<wfw:commentRss>http://john.whelans.net/archives/700/feed</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
	</channel>
</rss>

