File Share Encryption

 View Only

Update to 10.5.1 MP2 leads to "Unknown Key" on Fileshare Endpoints

  • 1.  Update to 10.5.1 MP2 leads to "Unknown Key" on Fileshare Endpoints

    Posted Jul 25, 2023 12:33 PM

    Hi together, hope you can share some insights and thoughts with me?

    I have a customer that upgraded from 10.5.0 MP2 to 10.5.1 MP2 and experienced an "unknown key" scenario on his fileshare clients

    Following aspects from my checklist:

    • Update seemed to went fine, clients stayed at old version
    • Windows 10 in use, Windows fileservices in use
    • Usage of filedata is no issue, re-encryption is because of the unknown keys
    • TLS certificate from own CA is in use - both chain certificates are in trusted key store on server and clients
    • only one management server in use - no load balancer or DNS alias
    • client communicating with new server version shows all keys unknown besides users key and the ADK
    • Key IDs of those unknown keys can not be found on management server (does not matter if old or new version of PGP server)
    • client communicating with old server version shows all keys correctly but with different IDs
    • GKM keys are used, partly more than 10 years old due to "never expire" setting

    Maybe you have some clues in this case, do not want to re-encrypt everything..

    Thank you in advance

    Henning