Apple Mac OS X Server Migration For Version 10.3 or Later Manual de usuario Pagina 10

  • Descarga
  • Añadir a mis manuales
  • Imprimir
  • Pagina
    / 13
  • Tabla de contenidos
  • MARCADORES
  • Valorado. / 5. Basado en revisión del cliente
Vista de pagina 9
When a NIC is set to a custom link mode, rather than auto-negotiate, the network driver no longer advertises other link speeds.
Symantec Encryption Management Server requires access to the list of possible link speeds to populate the Network Settings Link
Speed menu. If you want to change the Link Speed from a custom setting, and no other custom settings appear, select Auto and
restart Symantec Encryption Management Server. After you restart, the Link Speed menu is populated with all available options for
the NIC. [19287/2464456]
MAC ID, MTU, and Link Speed are not applicable to Symantec Encryption Management Server hosted on VMWare because the
ESX server controls the network settings. However, when you create a new virtual interface, those settings are automatically
populated. If your Symantec Encryption Management Server runs on VMWare and you want to create a new interface or edit an
existing interface, you cannot save your changes until you clear the auto-populated MTU, MAC ID, and Link Speed settings.
[19810/2464749]
Organization Keys with Japanese passphrases cannot be imported. [18620/2463812]
The Silent Enrollment option does not work with existing certificates or keys, such as CAPI and token keys. [16044/2461234]
You cannot use spaces in the name of the backup FTP server. [15491/2460680]
Recovery from a Windows PE environment requires the use of a Whole Disk Recovery Token. TPM and hardware token users
cannot be authenticated from Windows PE. [15101/2460290]
To replace an installation of Symantec Encryption Desktop with an embedded policy with an installation of Symantec Encryption
Desktop that retrieves policy from Symantec Encryption Management Server, you must first delete the PGP Corporation folder in
%ALLUSERSPROFILE%\Application Data. If you do not delete this folder, your new Symantec Encryption Desktop installation will
not receive policy from the Symantec Encryption Management Server. [13252/2458440]
When creating a new group (under Consumers), do not use special characters such as <,>,&,', or". Use regular alphabetic or
numeric characters. [2909579]
PGP Keys
When searching for keys from a key server that uses SSL authentication (either LDAPS or USP), Symantec Encryption
Management Server does not verify the validity of the certificate presented by the keyserver, nor does it verify that the server DNS
name matches the DNS name in the presented certificate. If you need assurance that found keys are trusted, enable the Require
verified key option in the Send (encrypted/signed) action in mail policy. [2735979]
Automatic approval for any Certificate Signing Request (CSR) received by internal users is disabled by default. To change this,
and for information on preventing identity spoofing, contact Symantec Technical Support. [31494/2476451]
After an internal user submits public keys to the Symantec Verified Directory, if you search for the user by Name, you cannot find
the user. There are no issues when you search by Email or Name or Email. [30694/2475651]
After you enroll an internal user to a configured certificate policy, although the enrollment completes without errors, the process
results in the following:
A managed user without a managed key in Symantec Encryption Management Server.
An untrusted user key in the Symantec Encryption Desktop client. [30354/2475311]
The Generate AD Group Keys dialog box in the Managed Keys page does not currently support selecting of Active Directory
group names with non-ASCII characters. The operation fails if a non-ASCII name is selected. [30000/2474957]
When an external user performs a LDAP lookup against an internal user who has both the Lotus Notes and the SMTP address,
the Lotus Notes address may be returned. This may result in some email clients refusing to encrypt to the returned X.509
certificate. [29293/2474249]
After internal user A sends an email to an internal user B, if you revoke a non-SKM key for internal user A, the key displays as
valid until after your regular cron job. After the cron job is complete, the key displays as revoked. There are no issues when you
revoke SKM keys. [29026/2473982]
On the Clustering page, if you deselect the Host private keys for internal users and Consumer Groups checkbox in the
Add/Edit Member dialog box, and then reselect it, saving after each selection, the cluster member repopulates the Managed Key
database with the private keys. However, the indices to the keys are erased and not rebuilt.
Although the server can still perform functions, such as encrypting and decrypting email, it cannot display the existing managed
keys. As a result, key lookup requests through the user interface, Verified Key Directory, or LDAP on that cluster node fail. This
does not affect the key management features on other cluster members, and you can still display and search for keys on those
nodes. On the Managed Key page, if a cluster node is unable to display the existing keys, we recommend that you remove the
node from the cluster and add it back as soon as possible. [25906/2470859]
Signature operations may download the private portion of the MAK key to the managed Symantec Encryption Desktop, even if the
key is SKM. These operations include signing a document and validating the signature on a document. Downloading the private
portion of certain types of keys may be a security problem in some environments. [26106/2471059]
On the Managed Keys page, the name associated with a managed key should be the primary email address associated with the
key, not the last listed email address. [25115/2470067]
Exporting or deleting tens of thousands of user keys at a time can take hours, or can fail. Export fewer keys at a time, or con
tact
Symantec Corporation Technical Support for help. [15998/2461188]
When making any changes that affect which TLS client certificates are permitted to access the Keyserver service, you must
disable, and re-enable the Keyserver service for these changes to take effect. [6533/2451708]
Messaging
To make the exported delivery receipts file for Certified Delivery display Japanese characters correctly, you must save the file as
UTF-8:
1. Export the CSV file.
Pa
g
e 10 of 13S
y
mantec Encr
yp
tion Mana
g
ement Server Version 3.3 Release Notes
Vista de pagina 9
1 2 ... 5 6 7 8 9 10 11 12 13

Comentarios a estos manuales

Sin comentarios