Symantec pcAnywhere 12.5 SP5 build 1206 release information

http://www.symantec.com/business/support/index?page=content&id=TECH198989&actp=search&viewlocale=en_US&searchid=1383297176511
Problem

Symantec pcAnywhere 12.5.5 build 1206 is the latest available build. This update is only to be applied to a machine with pcAnywhere 12.5 sp4 (Build 1086) already installed.

Cause

Issue 1: The pcAnywhere application stops responding when you select a host to launch with Windows or make any changes in the running host that require the host computer to be restarted.
While connecting to the host computer, the pcAnywhere application displays the following message:

“An error occurred while starting of pcAnywhere. Please try to restart pcAnywhere…"
or
“pcAnywhere Main Module has encountered a problem and needs to close. We are sorry for the inconvenience."
http://www.symantec.com/docs/TECH190695

Issue 2: You cannot connect to the host computer using the pcAquickconnect application that is installed on the client computer.
While connecting to the host computer, the pcAquickconnect application displays the following message:
“pcAQuickConnect.chf file is not a valid pcAnywhere file."
http://www.symantec.com/docs/TECH189097

Issue 3: Connection made by the client computer to the host computer cannot be established within the stipulated timeout period of 15 seconds using the pcAnywhere application.
While connecting to the host computer, the pcAnywhere application displays the following message:
“The selected computer is not responding. Connection cannot be made."
http://www.symantec.com/docs/TECH188183

Issue 4: While upgrading to the pcAnywhere application 12.5 SP4 (version 12.5.5 build 1086), the caller files are not upgraded because of which the pcAnywhere Host Service fails to run.
After upgrading to pcAnywhere version 12.5 SP4 (version 12.5.5 build 1086), the Symantec pcAnywhere Host Service fails to run, or a host item (*.BHF) will not launch. Also, any attempts to open the host properties and view the caller items (*.CIF) within the host properties will result in a file read error.
http://www.symantec.com/docs/TECH191515

Issue 5: The host IP address is not updated after the host is restarted or when the connection to the host computer is made.
http://www.symantec.com/docs/TECH198533

Issue 6: Black or gray screen appears on new installation of pcAnywhere application or during authentication while connecting a remote system to a host computer after the new installation.
For more information, see the following article:
http://www.symantec.com/docs/TECH197172

Issue 7: The host computer that is configured for conferencing with no encryption requests for a “symmetric" encryption level when connected.
While connecting to the host computer with no encryption, the pcAnywhere application displays the following message:
“The encryption level for this connection has been raised. Host has requested the encryption level: Symmetric"

Issue 8: The host computer that is configured for conferencing displays a warning that it will be configured for no encryption and will stay at AES 256 when that host is launched and connected to.
On enabling the conferencing feature of a host computer that is set at the default configuration AES 256, the following error message is displayed after which the host computer will be restarted:
“Disabling encryption. Encryption is not supported for conferencing hosts."
http://www.symantec.com/docs/TECH197098

Issue 9: Old version of awechomod.sys file is provided in pcAnywhere version 12.5 SP4.
http://www.symantec.com/docs/TECH111055

Solution

The update installer .exe is attached below if needed to install manually or this update can also be applied by running Live Update from the Software. The readme file is attached below.

How to run live update from with in pcAnywhere

1. Open the full pcAnywhere program.
2. Navigate to the Help menu then About Symantec pcAnywhere
3. Confirm what the current version and build number, Click OK
4. Navigate to the Help menu then LiveUpdate…
5. From with in the Live update window click Start
6. Click OK when done

Once live update is complete you may be prompted to reboot. If prompted please reboot as soon as possible after the reboot is completed perform the above steps again until there are no updates available

Symantec pcAnywhere 12.5 SP4 Release Notes & 系統需求

https://support.norton.com/sp/en/us/home/current/solutions/v78694032_EndUserProfile_en_us

Symantec pcAnywhere 12.5 SP4: Release Notes

What’s new?

    • Uses an updated encryption method to secure the host and remote communications and data

    • Added support for Windows Server 2008 R2 and Mac OS 10.7.x

System requirements

  • To successfully install each of the component of Symantec pcAnywhere, your system must meet the following minimum requirements:

    • Supported operating systems for Symantec pcAnywhere full version:

      • Windows 7 (Home/Professional/Ultimate)

      • Windows Vista (Home/Enterprise/ Ultimate)

      • Windows XP (Home and Professional/Windows XP Tablet and Media Center Edition/Embedded and WEPOS)

      • Windows 2000 (Professional/Server/Advanced Server)

      • Windows Server 2003 (Standard/Enterprise)

      • Windows Server 2008

      • Windows Server 2008 R2

    • Supported operating systems for Symantec pcAnywhere thin host:

      • Windows 7 (Home/Professional/Ultimate)

      • Windows Vista (Home/Enterprise/ Ultimate)

      • Windows XP (Home and Professional/Windows XP Tablet and Media Center Edition/Embedded and WEPOS)

      • Windows 2000 (Professional/Server/Advanced Server)

      • Windows Server 2003 (Standard/Enterprise)

      • Windows Server 2008

      • Windows Server 2008 R2

      • Red Hat Enterprise Linux 4.0

      • SUSE Linux Enterprise 10.0

      • Mac OS X 10.5.x

      • Mac OS X 10.6.x

      • Mac OS X 10.7.x

    • Supported operating systems for Symantec Packager:

      • Windows Vista (Home/Enterprise/Ultimate)

      • Windows XP (Professional)

      • Windows 2000 (Professional/Server/Advanced Server)

      • Windows Server 2003 (Standard/Enterprise)

    • Hardware requirements:

      • Must meet the minimum hardware requirements as specified by Microsoft (for Windows) or Apple (for Mac) for the operating system that is installed

Upgrading to Symantec pcAnywhere 12.5 SP4

  • Symantec pcAnywhere 12.5 SP4 contains updated security and communication enhancements. The new version is not backward-compatible and does not connect to earlier versions of pcAnywhere due to the changed security model. Symantec recommends installing the latest updated, secured 12.5 SP4 version of the product. For more information about downloading and installing Symantec pcAnywhere 12.5 SP4, read: How to obtain Symantec pcAnywhere 12.5 SP4.

    Symantec will not provide fixes for existing versions of pcAnywhere because of known security risks. If you have pcAnywhere 11.x or earlier versions of pcAnywhere, then you must uninstall the existing version of pcAnywhere before you install pcAnywhere 12.5 SP4.

Features removed in pcAnywhere 12.5 SP4

  • The following features are no longer available in pcAnywhere 12.5 SP4:

    • Access Server

    • Symantec pcAnywhere Web Remote

    • Symantec pcAnywhere Mobile Host

    • Symantec pcAnywhere CrossPlatform for Remote and Host

    • Symantec pcAnywhere Gateway

    • Host Assessment Tool

    • Host Administrator tool

    • Package Deployment Tool

    • Web Deployment Tool

    • NetBIOS and SPX connection type support

    • Support for all authentication types except pcAnywhere, NT, and AD for Windows/pcAnywhere and Apple Open Directory for Mac/pcAnywhere and Linux PAM for Linux

    • Option for making passwords case sensitive on the Security Options tab of Host Properties dialog box

    • Option to deploy thin host if host is not present on pcAnywhere Quick Connect dialog box

    • Encryption tab on pcAnywhere options dialog box

pcAnywhere 原始程式碼遭到暴露,建議客戶安裝最新版的 pcAnywhere (12.5 SP4)

http://www.symantec.com/business/support/index?page=content&id=DOC5442&locale=zh_TW

賽門鐵克在 2012 年 1 月,確認 pcAnywhere 原始程式碼遭到暴露,由駭客公開張貼。當時,賽門鐵克發布了一個修補程式來因應直接的漏洞。

此外,賽門鐵克也當下決定 pcAnywhere 安全性模型需要更新。

此更新既要針對傳統 pcAnywhere 產品又要針對 pcAnywhere Solution (是 Symantec Client Management Suite (CMS) 的一部分),確保 pcAnywhere 通訊的安全性。

由於安全更新,這個新版的 pcAnywhere 與舊版不相容,也不連線至較舊版本的 pcAnywhere。

賽門鐵克建議客戶安裝最新版的 pcAnywhere (12.5 SP4 或 Solution 12.6.7),並遵循一般安全性最佳實務準則。最新版的 pcAnywhere 包括所有先前的修補程式及更新的安全性模型。

如需升級指示,請參閱以下文章:
pcAnywhere 12.5 SP4 Release Notes (「pcAnywhere 12.5 SP4 版本說明」)

pcAnywhere 12.5 SP4 移除的功能

pcAnywhere 12.5 SP4 移除了過時的產品功能。此版的 pcAnywhere 不再提供下列功能。

  • Symantec pcAnywhere Web Remote
  • Symantec pcAnywhere Mobile
  • Symantec pcAnywhere CrossPlatform
  • Symantec pcAnywhere 閘道
  • 被控端管理員
  • Web 部署工具
  • NetBIOS 和 SPX 連線類型和支援
  • 支援除 Windows 適用的 pcAnywhere、NT 和 AD 以外的所有驗證類型

 

 

 

【完整的英文內容請參考下方資訊】

http://www.symantec.com/business/support/index?page=content&id=DOC5442&locale=en_US

Description

Introduction

In January 2012, Symantec confirmed that pcAnywhere source code was exposed by hackers who posted the code publicly. At that time, Symantec responded with a hot fix to address immediate vulnerabilities. In addition, Symantec determined that the pcAnywhere security model required an update. This update secures pcAnywhere communications for the traditional pcAnywhere product as well as the pcAnywhere Solution, which is part of the Symantec Client Management Suite (CMS).

As a result of the security updates, this new version of pcAnywhere is not backward-compatible with, and will not connect to, older versions of pcAnywhere.

Symantec recommends that customers install the latest version of pcAnywhere (12.5 SP4 or Solution 12.6.7) and follow general security best practices. The latest version of pcAnywhere includes all previous hot fixes and the updated security model.

For additional information visit go.symantec.com/sourcecode

pcAnywhere Access Server
Access Server is not supported by latest version of pcAnywhere. As a result of the source code being exposed, Symantec determined that Access Server is not secure for Internet-based remote control sessions. Since Access Server is not secure, the updated security model in the latest version of pcAnywhere does not allow communication with Access Server.

See the pcAnywhere Security Best Practices guide for risk scenarios and recommended security practices for using pcAnywhere and Access Server. In the absence of Access Server, Symantec recommends that you use VPN for Internet-based remote control sessions.

Upgrading to pcAnywhere 12.5 SP4

What should I do if my organization uses pcAnywhere?

Symantec recommends that customers install the latest version of pcAnywhere and follow general security best practices. The latest version of pcAnywhere includes all previous hot fixes and the updated security model.

For upgrade instructions, see the following article:
pcAnywhere 12.5 SP4 Release Notes

Features removed in pcAnywhere 12.5 SP4

In pcAnywhere 12.5 SP4 outdated product features were removed. The features listed below are no longer available in this version of pcAnywhere.

  • Access Server
  • Symantec pcAnywhere Web Remote
  • Symantec pcAnywhere Mobile
  • Symantec pcAnywhere CrossPlatform for Remote and Host
  • Symantec pcAnywhere Gateway
  • Host Assessment tool
  • Host Administrator tool
  • Package deployment tool
  • Web deployment tool
  • NetBIOS and SPX connection type support
  • Support for all authentication types except pcAnywhere, NT, and AD for Windows/pcAnywhere and Apple Open Directory for Mac/pcAnywhere and Linux PAM for Linux
  • Option for making passwords case sensitive on the Security Options tab of Host Properties dialog box
  • Option to deplo y thin host if host is not present on pcAQuick Connect dialog box
  • Encryption tab on pcAnywhere options dialog box

PGP 產品新舊品名對照 & PGP 產品與內容物

【PGP 產品新舊品名對照】

http://www.symantec.com/business/support/index?page=content&id=TECH197084

clip_image001[4]

clip_image002[6]

clip_image003[4]

 

【PGP 產品與內容物】

 

依據您所購買與輸入的 License key,此畫面會 [勾選] 出相對應的產品 ( 此畫面為 PGP Desktop Enterprise 或稱 PGP Desktop Corporate  )

clip_image014[4]

以下是 PGP Desktop 的產品組合與內容物

 

  • PGP Desktop Email = PGP Messaging
  • PGP 套裝產品均含 (PGP Whole Disk、PGP Virtual Disk、PGP Zip)
  • PGP Portable 已停產 ( 由 SEE RSE 取代 ),但 PGP Universal Server 主控台中仍可啟用 PGP Portable

clip_image015[4]

PGP 還可以進行的操作

image

如何更改 Symantec 合約聯絡人

如果要更改合約聯絡人,請進行以下步驟:

1. 下載並填寫異動申請表

2. 信件書寫範例

主旨:Please help to change the license contract contact
內容:Please check the attachement and change the license contract contact.

3.請使用同單位 (必須要是一樣的 mail domain) 的信箱,將此信件及附件寄至 Data_Management-APAC@symantec.com

 

※ 異動申請表請填寫紅色欄位

image

關於SEE RSE 【限制使用者安裝或使用 SEE client】& 【加密密碼更新】

關於SEE RSE 【限制使用者安裝或使用 SEE client】& 【加密密碼更新】

1. SEE RSE 【限制使用者安裝或使用 SEE client】

SEE RSE 安裝會需要重開機,重開機後會要求註冊

如果勾選註冊時需要密碼驗證,那麼撿到此 SEE client 安裝程式的人,即使安裝了 SEE client 也無法使用(此註冊密碼可以在主控台管控)

clip_image002

也可以透過以下管理員帳戶來反註冊,或設定多久時間沒有登入就自動反註冊

clip_image004

2. 【加密密碼更新】

(1) 加密可以採用密碼加密,或是憑證加密

clip_image006

(2) default password

如果用戶端沒有設定 default password,則每次將檔案拖曳至隨身碟時,會跳出密碼視窗,請於此輸入加密密碼

如果用戶端 有設定 default password,則每次將檔案拖曳至隨身碟時,會直接使用此default password 來對檔案進行加密

先前對檔案加密時所使用的密碼(default password 或自行輸入的密碼)如需更改,僅能透過手動方式修改

不過,如果是透過 default password 加密的使用者,修改則相對簡單,只需要將隨身碟中的檔案拖曳回個人電腦 ( 自動解密 ),再拖曳回隨身碟 ( 就會自動以新的 default password 加密 )

clip_image008

(3) Workgroup Key

Workgroup Key 也是屬於密碼加密,舊的 Workgroup Key 若要異動,也需要重新加密

clip_image010

3. 以下是隨身碟插入有安裝 SEE Client 後的狀況

隨身碟圖示更改

clip_image012

自動複製 Access Utility

未安裝 SEE Client 的用戶端看到加密檔案是以 .XML 格式呈現

clip_image014

直接開啟會顯示亂碼

clip_image016

必須執行 Access Utility 來開啟加密檔案,Access Utility 視窗中加密檔案呈現紅色鎖頭

clip_image018

嘗試開啟會求輸入解密密碼

預設有4次錯誤密碼的容許次數,超次後會暫停1分鐘 (可設定),5分鐘後會再 reset 成4次錯誤密碼的容許次數

clip_image020

clip_image022

PGP Universal integrated with AD

PGP Universal integrated with AD

 

請先 Enable Directory Synchronization

clip_image002

按下左下方【Settings】

image

勾選【Enroll clients using directory authentication】來整合 AD 驗證

image

按下【Add LDAP Directory】

image

name:給予一個 LDAP 識別名稱 (例如:elite2003.intra)

Type:如果是 AD 就選 (Active Directory)

LDAP Credentialsl: 輸入 AD 使用者名稱與帳號密碼

[Bind DN]:請輸入AD帳戶,格式範例 (CN=Administrator,CN=Users,DC=elite2003,DC=intra)

[Passphrase]:請輸入AD帳戶的密碼

Hostname:輸入 AD 主機名稱或 IP (2003.elite2003.intra)

port :(389)

Protocol: (LDAP)

然後按下【Test Connection】確認連線正常

clip_image004

按下【Browse Base DNs】來定義 Base DN 搜尋範圍

image

按下【View Sample Records】來確認有撈到使用者

clip_image008

有撈到使用者

clip_image010

在 Group Setting 中定義 Group Membership

例如:

Attribute:(memberOf)

Value:( CN=pgp_group,OU=PGP_OU,DC=elite2003,DC=intra)

clip_image012

勾選【Enable Silent Enrollment】

image

允許 Single Sign-On

clip_image014

之後就可以下載用戶端安裝程式來安裝

image

Upgrade to SEE 8.2.1 MP7

Upgrade to SEE 8.2.1 MP7

Upgrade Management Server

clip_image001

clip_image002

clip_image003

clip_image004

clip_image005

clip_image007

clip_image009

clip_image011

clip_image012

Upgrade SEE Manager

1.MSIEXEC /i “[path]\Symantec Endpoint Encryption Framework[ x64].msi" REINSTALL="ALL" REINSTALLMODE="vomus"

MSIEXEC /i “D:\Symantec_Endpoint_Encryption_8.2.1_MP7_Removable_Storage_EN\ Symantec Endpoint Encryption Framework x64.msi" REINSTALL="ALL" REINSTALLMODE="vomus"

clip_image013

clip_image014

clip_image015

clip_image016

clip_image017

2.MSIEXEC /i “[path]\Symantec Endpoint Encryption Full Disk Edition[ x64].msi" REINSTALL="ALL" REINSTALLMODE="vomus"

MSIEXEC /i " D:\Symantec_Endpoint_Encryption_8.2.1_MP7_Full_Disk_EN\SEE-FD\Server Installers\ Symantec Endpoint Encryption Full Disk Edition x64.msi" REINSTALL="ALL" REINSTALLMODE="vomus"

3.MSIEXEC /i “[path]\Symantec Endpoint Encryption Removable Storage[ x64].msi" REINSTALL="ALL" REINSTALLMODE="vomus"

MSIEXEC /i “D:\Symantec_Endpoint_Encryption_8.2.1_MP7_Removable_Storage_EN\ Symantec Endpoint Encryption Removable Storage x64.msi" REINSTALL="ALL" REINSTALLMODE="vomus"

clip_image019

Upgrade Windows Client

同上

clip_image020

SEE Removable Storage Edition 用戶端登入

SEE Removable Storage Edition 用戶端登入

123

clip_image001

clip_image003

未來Full Disk 忘記密碼時,可以透過以下問答的驗證來允許登入

clip_image004

clip_image005

clip_image006

clip_image007

clip_image009

clip_image010

SEE Administrator Client

用 Client Administrator 登入後,可以取消註冊到 SEE 的用戶端

clip_image011

clip_image012

clip_image014

clip_image016

clip_image018

插入的 USB 是屬於例外的裝置,新增的檔案不會被加密

clip_image019

SEERemovableStorageAccessUtility (Windows & Mac) 會自動 copy 至 USB 中

clip_image020

clip_image021

clip_image022

clip_image023

clip_image024