


SecureDoc for Macintosh FileVault 2
Release Notes
Product Version: 9.0
Build# : 9.0.000.xxx
Published October 28, 2021
Important Notes
Feature Deprecation
On July 6, 2018 WinMagic customers and partners were notified that the SecureDoc pre-boot authentication feature for macOS – known as SecureDoc On Top (SDOT) for FileVault 2 – would be deprecated in SecureDoc 8.2 SR1. As of this release, customers will no longer see this feature available for macOS configuration settings.
Please visit Knowledge Base Article 1760 for more information.
SecureDoc Support
WinMagic strongly recommends that you install the most recent software release to stay up-to-date with the latest functional improvements, stability fixes, security enhancements and new features.
Please visit Knowledge Base Article 1397 for more information on End of Life and End of Support timelines for SecureDoc software releases.
Customers running SecureDoc 6.5 and earlier should upgrade their server and clients to an actively supported software version. For more information on upgrading from SecureDoc 6.5 and earlier, please visit http://downloads.winmagic.info/SD8.2SR1/HF2/Release_Notes_8.2SR1HF2.pdf.
This document contains important information about the current release. We strongly recommend that you read the entire document.
Recommended – WinMagic recommends this service release for all environments. Apply this update at your earliest convenience.
Previous Versions
Version | Build# | Release Date | Details |
8.5 | 8.5.000.480 | December 5th 2019 | New Features, Improvements and fixes (server/client) |
8.5 SR1 | 8.5.100.638 | April 8th 2020 | New features, improvements and fixes (server/client) |
8.5 SR2 | 8.5.200.688 | June 11th 2020 | New Features, Improvements and fixes (server/client) |
8.6 | 8.6.0.603 | December 9th 2020 | New Features, Improvements and fixes (server/client) |
8.6 SR1 | 8.6.100.148 | February 30th 2021 | New Features, Improvements and fixes (server/client) |
Download the latest release notes for each version listed within Knowledge Base Article 1756.
System Requirements
For server and client system requirements: https://www.winmagic.com/support/technical-specifications For supported devices, drives, smartcards and tokens: https://www.winmagic.com/device-compatibility
Note: It is strongly recommended to initially install Full-Text Indexing feature (Full-Text Search) into the Database Engine, before performing an SES installation.
More information is available here: http://msdn.microsoft.com/en-us/library/ms143786(v=sql.100).ASPX
During the installation of SES, if Full-Text Indexing has not been installed, a message will appear indicating the absence of the Full-Text Indexing. This message will not allow the user to stop the installation of SES which will require retrofitting Full-Text Indexing into an existing SQL Server.
Note: Use of the SES Console will require the user to have at least local admin rights on the server or client device (e.g. Admin desktop) on which it runs, in order for the console to function properly
Client OS Support
This section shows supported operating systems and upgrade paths for SecureDoc Endpoint Clients. Apple macOS
Version | Editions | SR/Update |
Monterey | 12.x | SDFV2 9.0+ |
Big Sur | 11.X | SD 8.6 for Intel-processor devices SD 8.6SR1 for Intel and M1 processor devices |
Catalina | 10.15.X | SDFV2 8.5+ |
Mojave | 10.14.X | SDFV2 8.3+ |
High Sierra | 10.13.X | SDFV2 8.2+ |
Improvements
SD-31974: Improvements have been made to the macOS Client Recovery Key functionality and access to Recovery Partition for macOS Catalina and BigSur
A number of improvements have been applied to this version relating to aiding users in recovering access to macOS endpoints protected by SecureDoc for FileVault 2.
Scenarios where this improvement is of benefit:
1 - Where users cannot log in to the macOS system and require the emergency disk to unlock the disk to copy data out. This can be required is where customers need to boot into the Recovery Partition, for example because they forgot their user password and cannot log into system.
On new macOS Catalina, Apple implemented a new protection layer. Customers need to provide an Admin (not Standard User) password to bypass the RecoveryAssistant sector.
With this improvement to SecureDoc, if the user had forgotten all passwords, SecureDoc offers another option to provide a Recovery Key. This is the Personal Key generated when SecureDoc enabled FileVault 2. After providing the correct credential, it makes available Recovery Mode.
2. The Recovery Key is also useful when it is necessary to reset the regular user's user password in order to login FV2 pre-boot successfully. It has the same function as the WinMagic recovery account, and if there should be some situation in which the WinMagic recovery account doesn't work for resetting the password, this Recovery Key can work as a back-up to the WinMagic recovery account.
NOTE: Whenever the Administrator uses or views this Recovery Key, a process will automatically be applied, causing the Client device to rotate this key, generating (and transmit to SES) a new key. In this way, this key can only be seen or used once, for the sake of enhanced security.
This Recovery key is generated a) when enabling FileVault 2 while SecureDoc is being deployed to the device; A Recovery Key is generated and sent to the SES server to be stored; or b) whenever the client is notified by the server that the Recovery Key has been viewed, following which the client will change to a new Recovery Key process and send it to the server to be stored.
3. If the Recovery key is manually changed using Terminal (customers manually run change recovery key command), the updated Key will be sent to the SES Server side to be stored
Note: if FileVault 2 is suspended on the device (making it protect Removable Media Only in SecureDoc terms), the option to show the Recovery Key will not be available to the SES Administrator or the User. Once the device has FileVault 2 re-enabled, access to the Recovery Key will be reinstated.
SD-37971: Support has been added for IPV6 network addressing for SecureDoc for macOS devices
SecureDoc Profile configuration settings now permit defining IPV6 addresses for both SDConnex Servers and a Proxy Server for SecureDoc for macOS endpoint devices. At the Endpoint, it will be capable of communicating to SDConnex servers (and through a Proxy if defined) using IPV6-format addressing.
SD-38401: SecureDoc now supports macOS 12.X Monterey
Issue: macOS continues to evolve and SecureDoc must provide support for newer versions of macOS.
Solution: SES V9.0 supports client devices running macOS 12.X Monterey.
Depreciation Note
SD-38514: In SES V9.0, macOS High Sierra support is being dropped.
Issue: As SES Client support grows to encompass new macOS versions, the oldest versions are dropped from support.
Solution: Please do not install or upgrade to SecureDoc V9.0 on macOS High Sierra client devices.
Customers with an active support plan should contact [email protected] to receive the latest download link for their SecureDoc upgrade.
Contact WinMagic
WinMagic 5770 Hurontario Street, Suite 501 Mississauga, Ontario, L5R 3G5 Toll free: 1-888-879-5879 Phone: (905) 502-7000 Fax: (905) 502-7001 | Sales: Marketing: Human Resources: Technical Support: For information: For billing inquiries: | [email protected] [email protected] [email protected] [email protected] |
Acknowledgements
This product includes cryptographic software written by Antoon Bosselaers, Hans Dobbertin, Bart Preneel, Eric Young ([email protected]) and Joan Daemen and Vincent Rijmen, creators of the Rijndael AES algorithm.
This product includes software developed by the OpenSSL Project for use in the OpenSSL Toolkit (http://www.OpenSSL.org/).
WinMagic would like to thank these developers for their software contributions.
©Copyright 1997 – 2021 by WinMagic Corp. All rights reserved.
Printed in Canada Many products, software and technologies are subject to export control for both Canada and the United States of America. WinMagic advises all customers that they are responsible for familiarizing themselves with these regulations. Exports and re-exports of WinMagic Inc. products are subject to Canadian and US export
controls administered by the Canadian Border Services Agency (CBSA) and the Commerce Department’s Bureau of Industry and Security (BIS). For more information, visit WinMagic’s web site or the web site of the appropriate agency.
WinMagic, SecureDoc, SecureDoc Enterprise Server, Compartmental SecureDoc, SecureDoc PDA, SecureDoc Personal Edition, SecureDoc RME, SecureDoc Removable Media Encryption, SecureDoc Media Viewer, SecureDoc Express, SecureDoc for Mac, MySecureDoc, MySecureDoc Personal Edition Plus, MySecureDoc Media, PBConnex, SecureDoc Central Database, and SecureDoc Cloud Lite are trademarks and registered trademarks of WinMagic Inc., registered in the US and other countries. All other registered and unregistered trademarks herein are the sole property of their respective owners. © 2019 WinMagic Corp. All rights reserved.
Copyright 2021 WinMagic Corp. All rights reserved. This document is for informational purpose only. WinMagic Corp. makes NO WARRANTIES, expressed or implied, in this document. All specification stated herein are subject to change without notice.