Endpoint Encryption

 View Only
  • 1.  Cannot decrypt laptop with admin credentials

    Posted Oct 12, 2015 10:16 AM

    I'm trying to decrypt my laptop's hard drive. In Window's command prompt I cd to the directory in which Symantec Endpoint Encryption is installed and type the following commands:

    eedAdminCli --decrypt --disk 0 --au admin --ap password

    To which I receive the following error:

    Admin could not be authenticated

    Please provide the correct managed Admin credentials using --au and --ap

    Operation start decrypt failed:

    Error code -11500: PGPClientError #-11500

    Admin is the only account on the laptop. There are no other users on this laptop. I am running command prompt as the administrator. My password is correct. 

    I have tried different iterations of "admin" to no success. I am using Windows 8.0. 

    Any assistance would be great. 



  • 2.  RE: Cannot decrypt laptop with admin credentials

    Posted Oct 13, 2015 12:36 PM

    Was this a standalone installation, or a system in an environment with a management server?

    Can you try logging into the Client Admin console and decrypting the drive from that interface?

    What is the full version of the product?  I suspect 11.0.0, possibly mp1-3.

    If it is a standalone installation, one of the big reasons it was not supported outside of hardware testing is this type of issue.  If set to not contact a management server, it could potentially encrypt without properly adding a user or client administrator.  On the latest versions it is completely unsupported.  If that is the case, you would need to back up your data and reimage the system.



  • 3.  RE: Cannot decrypt laptop with admin credentials

    Posted Oct 14, 2015 10:36 AM

    It's a standalone installation. No management server. 

    A coworker was able to successfully remove the encryption (same configuration as mine) via the above commands and didn't have any issues. 

    How do I access the client admin console?



  • 4.  RE: Cannot decrypt laptop with admin credentials

    Posted Oct 14, 2015 12:25 PM

    That's what I was afraid of.  Standalone installations can be very tricky.  Two nearly identical systems side by side with the same software setup can experience completely different results. 

    If the Client Administrator Console is not located under in the Start menu (Start>All Programs>Symantec Endpoint Encryption>Client Administrator Console), you should be able to find it in
    C:\Program Files\Symantec\Endpoint Encryption Clients\Management Agent

    The filename to start the client admin console is SeemaAdminUIApp.

    You could also try to run the eedRecoveryGUI, located in:
    C:\Program Files\Symantec\Endpoint Encryption Clients\Drive Encryption

    As a final option, you can attempt to decrypt through the command prompt.  Open a Command Prompt as Administrator, navigate to "C:\Program Files\Symantec\Endpoint Encryption Clients\Drive Encryption", then try to run a decryption command.  An example is here:
    eedAdminCLI --decrypt --disk 0 --au ClientAdminName --ap ClientAdminPassword

    If none of those options work, then it is likely your system encrypted without any users or client admins registering properly.  The only option from there would be to back the data up and reimage.



  • 5.  RE: Cannot decrypt laptop with admin credentials

    Posted Oct 14, 2015 03:54 PM
      |   view attached

    Yes, I have tried those commands. Symantec is rejecting the admin username and password even though it's the only account on the host. 

    SeemaAdminUIApp didn't really help me. It only confirmed that the disks are encrypted, which I already knew. 

    As referenced in the attached image, both the GUI and the command line returned errors for the admin username and password. 

    Basically what I am trying to do is upgrade this laptop from Windows 8.0 to Windows 10. Is there an easier way to do this without decrypting the drives?



  • 6.  RE: Cannot decrypt laptop with admin credentials

    Posted Oct 14, 2015 05:51 PM

    Unfortunately, no.  You will need to backup your data and reformat the drive.  If you are 100% certain that the admin username and password are correct, then the software failed to register any users, including the admin user, and encryped the drive anyway.



  • 7.  RE: Cannot decrypt laptop with admin credentials

    Posted Oct 15, 2015 07:56 AM
      |   view attached

    I figured as such. Are you aware if the standard GUI option of reformatting Windows is sufficient to remove the encryption? I don't have a boot CD for this laptop.