Jump to content

Admin rights to memory pens for encryption software


Recommended Posts

Posted

Hi,

 

As subject says really, I have ordered in a load of memory pens which i need to apply administrator rights for all logins to so that the built in encryption software can work. Is there a way around this?

 

Cheers

 

James

Posted

You could add a file hash rule in your software restrictions settings for the EXE that the mem stick encryption uses.

 

As long as the version of the EXE on all memory sticks is the same this should work.

 

As long as the exe does not actually install anything on the PC you shouldn't need any privileged access rights for staff.

 

Butuz

Posted
Its only restricted through GPO but can't see where?! It doesn't install anything but for some reason the software embedded into the pens needs admin rights
Posted
As long as the exe does not actually install anything on the PC you shouldn't need any privileged access rights for staff.

Unfortunately the Lexar Secure II encryption software requires admin rights to install a driver (like TrueCrypt does). The driver is located in the "Data" folder on the flash drive.

 

The FAQ also mentions this...

 

Q: Can I run Secure II without admin privileges?

A: You can run Secure II on a non-admin account. However, the Encrypted Vault feature requires admin privileges.

  • Thanks 1
  • 2 weeks later...
Posted
Unfortunately the Lexar Secure II encryption software requires admin rights to install a driver (like TrueCrypt does). The driver is located in the "Data" folder on the flash drive.

 

The FAQ also mentions this...

 

Surely if I install that driver across the network then elsewhere it 'should' be fine?

Posted
Surely if I install that driver across the network then elsewhere it 'should' be fine?

I don't see why not, although Lexar do not appear to provide an easy way to install the driver (LxrSII1d.sys) yourself.

Posted
I've just tried this by creating an MSI to no avail. However the frustrating this is that any machine that I login via admin use it then try using a staff login it works. There must be a way around this :-/
Posted

If it's anything like TrueCrypt, the Secure II driver and service will located somewhere under the following two registry keys. If you search for "LxrSII" I'm sure you will find the relevant bits.

 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root

 

 

I don't have a Secure II flash drive myself so am unable to check, but it looks like it just needs the following four files to work (along with the registry settings above).

 

%SystemRoot%\System32\Drivers\LxrSII1d.sys
%SystemRoot%\System32\LxrSII1s.exe
%SystemRoot%\System32\LxrSII1.dll
%SystemRoot%\System32\LxrUnplug.exe

  • Thanks 1
  • 3 months later...
Posted

Anyone tried this?

 

If it's anything like TrueCrypt, the Secure II driver and service will located somewhere under the following two registry keys. If you search for "LxrSII" I'm sure you will find the relevant bits.

 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root

 

 

I don't have a Secure II flash drive myself so am unable to check, but it looks like it just needs the following four files to work (along with the registry settings above).

 

%SystemRoot%\System32\Drivers\LxrSII1d.sys
%SystemRoot%\System32\LxrSII1s.exe
%SystemRoot%\System32\LxrSII1.dll
%SystemRoot%\System32\LxrUnplug.exe

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...