Specifications

Endpoint Encryption for Files and Folders client
| 85
Follow target
When a file that is encrypted with key A, for example, and is moved to a folder where
files are encrypted with key B, then the file encrypted with key A will immediately be
re-encrypted with key B. This behavior, known as follow-target-encryption requires
that the user (process) transferring the file has access to both key A and key B, since
the file is first decrypted (with key A) and then instantly re-encrypted (with key B).
This operation takes place instantly when the file is placed in the folder encrypted with
key B.
Process sbceCore.exe automatically restarts
The process SbCeCore.EXE is the main process that manages the Endpoint Encryption
for Files and Folders client. If the user manages to kill this process, thereby attempting
to deviate from the assigned encryption policy, the user will automatically restart.
In previous versions of Endpoint Encryption for Files and Folders, this process was
protected from being killed. However, such protection is not allowed on the Microsoft®
Vista™ operating system. Hence, alterations have been done such that if killed, it will
instantaneously restart. The automatic restart cannot be disabled.
Client Registry controls
This section outlines some of the changes that may be made in the Registry of the
client machine in order to change the behavior of the Endpoint Encryption for Files and
Folders client.
NOTE:AsforallclientRegistrychanges,itisrecommendedthattheyarecarriedoutbyanauthorized
systemadministratorandnotbytheenduserthemselves
Controlling the authentication result dialog
If the authentication to the central database fails, a message can be displayed to the
end user. This will notify the user that there was no connection to the central
database, but the authentication instead happened towards the user’s local database.
The message dialog is disabled by default but can be enabled by configuring the
SbC4.INI file, located in the Endpoint Encryption for Files and Folders program
directory, a subfolder called Data:
Windows 2000/XP: [SYSDRIVE:\Program Files\McAfee\Endpoint
Encryption for Files&Folders\Data]
Windows Vista: [SYSDRIVE:\Program Data\Endpoint Encryption for
Files&Folders\Data]
Add the following entries to the SbC4.INI file to enable the messages: