User Manual

18
19
Lock-Override Mode
Certain users may encounter a case where they need the drive to remain
unlocked during a reboot, passing the device through a virtual machine or
other similar situations which, under normal circumstances, would cause the
drive to lock. To help facilitate this use case, “Lock-Override Mode” will allow
the drive to remain unlocked through USB port re-enumeration and will not
lock again until USB power is interrupted.
NOTE: When in this mode, the drive is vulnerable to being moved from
one computer and connected to another computer provided USB power is
uninterrupted. Due to this vulnerability, we strongly recommend this mode be
used ONLY in circumstances where the drive can be physically secured (as
in a locked Server Room) or in a place where it can be visually monitored
while in this mode. Use of a powered hub or a Y-cable increases this security
risk.
Always return the drive to the default Lock-Override Mode OFF when
returning to normal service.
To set the “Lock-Override” to On:
1. Enter the Admin Mode (Press and hold + 0 for ve seconds until the
RED LED blinks, then enter the Admin code and press the button. The
BLUE LED will glow steadily.)
2. Press and hold 7 + 1 for three seconds. The GREEN LED will blink three
times, then the BLUE LED will glow steadily.
3. When the key is unlocked and attached to a USB port in “Lock-Override
Mode”, the BLUE LED will blink once every three seconds to alert you
that “Lock-Override” mode is active.
Note: If “Unattended Auto-Lock” mode has been turned on, “Lock-Override”
will not override it; the key will lock itself upon reaching the selected amount
of inactivity. If you need the key to stay unlocked, Enter the Unattended
Auto-Lock Feature and set the lock timer to “0” (0 = OFF) See Page 10.
To turn Lock-Override Mode off and return to normal operation:
4. Enter the Admin Mode (Press and hold + 0 for ve seconds until the
RED LED blinks. Then enter the Admin code and press the button. The
BLUE LED will glow steadily.)
5. Press and hold 7 + 0 for three seconds. The GREEN LED will blink three
times then the BLUE LED will glow steadily.
6. To verify, unlock the key in User mode and check that the BLUE LED is
no longer blinking.
Troubleshooting
This section contains troubleshooting information and FAQs for the Aegis Padlock 3.
Q: What can I do if I forget the User PIN?
A: Use your Admin PIN to enter the Admin Mode and create another User PIN.
Additionally you may access the drive by enabling a recovery PIN and establishing a
new USER PIN.
Q: What can I do if I forget the Admin PIN?
A: Using a valid User PIN or a data recovery PIN to access the data on the drive, back
up all of the data onto another device. Once the device’s data has been backed up, you’ll
need to perform a complete reset of the Aegis Padlock DT, after which, all data and PINs
will be zeroed out and the drive ready to be reformatted and recongured with a new
Admin PIN.
Q: Why did the operating system not recognize the Aegis Padlock DT, after I did a
complete re-set of the drive?
A: You need to initialize, allocate and format the Aegis Padlock DT manually. For more
information, refer to Initializing and Formatting the Aegis Padlock DT After a Complete
Reset in this manual.
Q: How do I use the Aegis Padlock without a PIN?
A: As a full disk encryption product, the Aegis Padlock can never be used without a PIN.
Q: What encryption algorithm is used in this product?
A: The Aegis Padlock uses AES 256-bit algorithm.
Q: Why could I not initialize, partition, or format the Aegis Padlock?
A: Ensure that you have administrator privileges. You will need Admin privileges to use
the Disk Management Utility.
Q: The LED is blinking RED and I can’t enter a code. Why?
A: Somebody has tried to access the key and the code has been entered 10 times
incorrectly (see Brute Force section of this manual.)
Q: Is there any way to recover my data if I forget the PIN?
A: If an Admin PIN has been previously set, the Admin PIN can be used to unlock the
key and recover the data. Additionally, if recovery PINs have been set and haven’t been
previously depleted in the past (up to 4x) you can access the data on your drive using
this route. If you don’t have any recovery PINs set or they’re depleted, and do not have
an Admin PIN, the data cannot be recovered but the drive can be reset with new PINs
and it can then be used again.
Q: Why does the LED indicate an error when I try to change the PIN?
A: PIN requirements for this drive must meet a minimum security level. There are several
combinations that are not allowed, such as repeating numbers or sequential numbers.
The PIN must be a minimum of six digits, and not longer than 16 digits.
Q: What are the ECCN and HST codes used for shipping this device outside
of the United States?
A: ECCN: 5A992.c and HTS code 8473.50.3000