Reference Guide
Security Management Server v10.2.7 AdminHelp
307
See Encryption Rules for information.
More...
Storage devices which incorporate multi-interface connections, such as Firewire,
USB, eSATA, etc. may require the use of both EMS and encryption rules to encrypt
the endpoint. This is necessary due to differences in how the Windows operating
system handles storage devices based on interface type.
To ensure encrypting an iPod via EMS does not make the device unusable, use the
following rules:
-R#:\Calendars
-R#:\Contacts
-R#:\iPod_Control
-R#:\Notes
-R#:\Photos
You can also force encryption of specific file types in the directories above. Adding
the following rules will ensure that ppt, pptx, doc, docx, xls, and xlsx files are
encrypted in the directories excluded from encryption via the previous rules:
^R#:\Calendars
;ppt.doc
.xls.pptx
.docx.xlsx
^R#:\Contacts
;ppt
.doc.xls
.pptx.docx
.xlsx
^R#:
\iPod_Control
;ppt.doc
.xls.pptx
.docx.xlsx
^R#:\Notes
;ppt.doc
.xls.pptx
.docx.xlsx
^R#:\Photos
;ppt.doc
.xls.pptx
.docx.xlsx
R
eplacing these five rules with the following rule will force encryption of ppt, pptx,
doc, docx, xls, and xlsx files in any directory on the iPod, including Calendars,
Contacts, iPod_Control, Notes, and Photos:
^R#:\;ppt.doc.xls
.pptx.docx.xlsx
These rules disable or enable encryption for these folders and file types for all
removable devices - not just an iPod. Use care when defining rules to exclude an
iPod from encryption.
These rules have been tested against the following iPods:
iPod Video 30gb fifth generation
iPod Nano 2gb second generation
iPod Mini 4gb second generation
Dell does not recommend the use of the iPod Shuffle, as unexpected results may
occur.
As iPods change, this information could also change, so caution is advised when
allowing the use of iPods on EMS-enabled computers.
Because folder names on iPods are dependent on the model of the iPod, Dell
recommends creating an exclusion encryption policy which covers all folder
names, across all iPod models.
EMS Automatic Authentication Local
Disabled, Enable Local, Enable Roaming
Local automatic authentication allows the Dell-encrypted media to be
automatically authenticated when inserted in the originally encrypting computer
when the owner of that media is logged in. When the User Roaming key is applied