conpal LAN Crypt 4.1.1 Client release notes

 

conpal LAN Crypt 4.1.1 is a maintenance release, there are no new features included.
Please refer to the conpal LAN Crypt 4.1.0 part of the release notes.

Please note the LAN Crypt 4.1.1 Administration release notes.

Older release notes for LAN Crypt 4.00.x remain valid, if not stated otherwise.

 

Requirements

The below listed platforms have been tested and are officially supported. Other Service Pack levels might work as well but have not run through a QA cycle and won´t be analysed in case of occurring issues.

Platforms supported

32-bit

64-bit

Pro/Enterprise versions of Windows 10 1809 (LTSC), 20H2, 21H1, 21H2, Windows 11

No

Yes

Windows Server 2019

No

Yes

Windows Server 2022

No

Yes

Citrix XenApp, Citrix XenApp LTSR *

No

Yes

*Citrix Environments are supported, but have not been extensively retested

 

Bugfixes in conpal LAN Crypt Client, Release 4.1.1

 

Manuals, documentation and support

At https://support.conpal.de registered customers with active maintenance contracts get access to downloads, documentation and knowledge items.

Download the client product documentation at

https://docs.lancrypt.com/de/client/lc_411_hdeu.pdf in German language, at

https://docs.lancrypt.com/en/client/lc_411_heng.pdf in English language and at

https://docs.lancrypt.com/fr/client/lc_411_hfra.pdf in French language. Please note, the French manual will be published delayed, for the time being use the English manual

 

 

 

 

 

conpal LAN Crypt 4.1.0 Client release notes

conpal LAN Crypt 4.1.0 comes with support for new operating systems new functionality, improved security functionality and new features

e.g.

·          Support for SGN/SafeGuard Fileshare customers

·          Portable file encryption

·          Minifilter with caching capabilities for SMB network shares

·          New .NET Administration API

·          Client API login with user context

·          LAN Crypt-Service functionality

·          Manipulation protection for processes

·          Multi factor Authentication based on 3rd party technology

·          Oracle 19 Support

The Legacyfilter has been abandoned, but is still supported with the 4.00.x version of the product.

Older release notes for LAN Crypt 4.00.x remain valid, if not stated otherwise.

Please note the LAN Crypt 4.1.0 Administration release notes.

Requirements

The below listed platforms have been tested and are officially supported. Other Service Pack levels might work as well but have not run through a QA cycle and won´t be analysed in case of occurring issues.

Platforms supported

32-bit

64-bit

Pro/Enterprise versions of Windows 10 1809 (LTSC), 1909 (19H2), 20H2, 21H1, 21H2, Windows 11

No

Yes

Windows Server 2016

No

Yes

Windows Server 2019

No

Yes

Windows Server 2022

No

Yes

Citrix XenApp 7.18 on Windows Server 2016*

No

Yes

Citrix XenApp 7.15 LTSR on Windows Server 2016*

No

Yes

*Citrix Environments are supported, but have not been extensively retested

 New in conpal LAN Crypt Client release 4.1.0

Non-default Legacy-filter registry settings are migrated to respective Minifilter Settings (where necessary) (LC-1681)

Changes in 4.1.0

 

Bugfixes in 4.1.0

 

 

 

New known issues

https://docs.microsoft.com/en-us/cpp/windows/latest-supported-vc-redist?view=msvc-170
https://aka.ms/vs/17/release/vc_redist.x86.exe
https://aka.ms/vs/17/release/vc_redist.x64.exe

 

 

Manuals, documentation and support

At https://support.conpal.de registered customers with active maintenance contracts get access to downloads, documentation and knowledge items.

 

The client manuals in French language will be available in form of a pdf manual a couple of days after release for download. For the time being an old manual with a testpage will be available at the link for the French manual.

 

Download the client product documentation at

https://docs.lancrypt.com/de/client/lc_410_hdeu.pdf in German language, at

https://docs.lancrypt.com/en/client/lc_410_heng.pdf in English language and at

https://docs.lancrypt.com/fr/client/lc_410_hfra.pdf in French language. Please note, the French manual will be published delayed, for the time being use the English manual

 

 

 

 

 

conpal LAN Crypt 4.00.3 Client release notes

conpal LAN Crypt 4.00.3 comes with support for additional operating systems, support for SGN/SafeGuard FileShare and bugfixes. Older release notes for LAN Crypt 4.00.x remain valid, if not stated otherwise.

Please note the LAN Crypt 4.00.3 Administration release notes.

 

Requirements

The below listed platforms have been tested and are officially supported. Other Service Pack levels might work as well but have not run through a QA cycle and won´t be analysed in case of occurring issues.

Platforms supported

32-bit

64-bit

Windows 10 1909 (19H2), 2004 (20H1) Pro/Enterprise, 20H2 Pro/Enterprise, 21H2 Pro/Enterprise, Windows 11

No

Yes

Windows Server 2012 R2

No

Yes

Windows Server 2016

No

Yes

Windows Server 2019

No

Yes

Citrix XenApp 7.9 on Windows Server 2012 R2

No

Yes

Citrix XenApp 7.18 on Windows Server 2016

No

Yes

Citrix XenApp 7.15 LTSR on Windows Server 2016

No

Yes

 New in conpal LAN Crypt Client release 4.00.3

Changes in 4.00.3

Bugfixes in 4.00.3

 

Manuals, documentation and support

At https://support.conpal.de registered customers with active maintenance contracts get access to downloads, documentation and knowledge items.

 

The client manuals in French language will be available in form of a pdf manual a couple of days after release for download. For the time being an old manual with a testpage will be available at the link for the French manual.

 

Download the client product documentation at

https://docs.lancrypt.com/de/client/lc_400_hdeu.pdf in German language, at

https://docs.lancrypt.com/en/client/lc_400_heng.pdf in English language and at

https://docs.lancrypt.com/fr/client/lc_400_hfra.pdf in French language.

 

 

 

 

conpal LAN Crypt 4.00.2 Client release notes

conpal LAN Crypt 4.00.2 is a maintenance release.Older release notes for LAN Crypt 4.00.x remain valid, if not stated otherwise.

Please note the LAN Crypt 4.00.2 Administration release notes.

 

Requirements

The below listed platforms have been tested and are officially supported. Other Service Pack levels might work as well but have not run through a QA cycle and won´t be analysed in case of occurring issues.

Platforms supported

32-bit

64-bit

Windows 10 1909 (19H2), 2004 (20H1) Pro/Enterprise, 20H2 Pro/Enterprise

No

Yes

Windows Server 2012 R2

No

Yes

Windows Server 2016

No

Yes

Windows Server 2019

No

Yes

Citrix XenApp 7.9 on Windows Server 2012 R2

No

Yes

Citrix XenApp 7.18 on Windows Server 2016

No

Yes

Citrix XenApp 7.15 LTSR on Windows Server 2016

No

Yes

Bugfixes in 4.00.2

 

Manuals, documentation and support

At https://support.conpal.de registered customers with active maintenance contracts get access to downloads, documentation and knowledge items.

 

The client manuals in French language will be available in form of a pdf manual a couple of days after release for download. For the time being an old manual with a testpage will be available at the link for the French manual.

 

Download the client product documentation at

https://docs.lancrypt.com/de/client/lc_400_hdeu.pdf in German language, at

https://docs.lancrypt.com/en/client/lc_400_heng.pdf in English language and at

https://docs.lancrypt.com/fr/client/lc_400_hfra.pdf in French language.

 

 

 

 

 

 

 

 

conpal LAN Crypt 4.00.1 Client release notes

conpal LAN Crypt 4.00.1 is in focus a maintenance release and brings support for W10 20H2. If not referenced in the sections New in conpal LAN Crypt Client release 4.00.1, changes in 4.00.1, Bugfixes in 4.00.1 the release notes for LAN Crypt 4.00 remain valid.

Please note the LAN Crypt 4.00.1 Administration release notes.

 

Requirements

The below listed platforms have been tested and are officially supported. Other Service Pack levels might work as well but have not run through a QA cycle and won´t be analysed in case of occurring issues.

Platforms supported

32-bit

64-bit

Windows 10 1803 (RS4), 1809 (RS5), 1903 (19H1), 1909 (19H2), 2004 (20H1) Pro/Enterprise, 20H2 Pro/Enterprise

No

Yes

Windows Server 2012 R2

No

Yes

Windows Server 2016

No

Yes

Windows Server 2019

No

Yes

Citrix XenApp 7.9 on Windows Server 2012 R2

No

Yes

Citrix XenApp 7.18 on Windows Server 2016

No

Yes

Citrix XenApp 7.15 LTSR on Windows Server 2016

No

Yes

 New in conpal LAN Crypt Client release 4.00.1

Changes in 4.00.1

 

Bugfixes in 4.00.1

 

New known issues

The switch IgnoredApplicationsChildProcs is used for the internal default processes as well. That leads to problems especially with Office applications, when preview and accessing lead to concurrent access.
The workaround recommendation is to avoid the setting 2 for inheritance to childs and to use 1 instead. (LC-1603).

 

Manuals, documentation and support

At https://support.conpal.de registered customers with active maintenance contracts get access to downloads, documentation and knowledge items.

 

The client manuals in French language will be available in form of a pdf manual a couple of days after release for download. For the time being an old manual with a testpage will be available at the link for the French manual.

 

Download the client product documentation at

https://docs.lancrypt.com/de/client/lc_400_hdeu.pdf in German language, at

https://docs.lancrypt.com/en/client/lc_400_heng.pdf in English language and at

https://docs.lancrypt.com/fr/client/lc_400_hfra.pdf in French language.

 

 

 

 

conpal LAN Crypt 4.00.0 Client release notes

Please note the LAN Crypt 4.00.0 Administration release notes.

conpal LAN Crypt is the successor of SafeGuard LAN Crypt.

conpal LAN Crypt 3.97 Client was the initial release of conpal for the client. It contained fixes and hotfixes of the previous SafeGuard LAN Crypt 3.95 Client version, fixed several known issues and came with support for current operating systems.

conpal LAN Crypt 4.00 Client is a significant rework of the client technology. The cryptographic base has been reworked for potential certifications and approvals. The underlying filter technology has been built on Minifilter technology to be future-proof and assure long term support for the technology by Microsoft.

conpal will develop new client features based on the Minifilter technology.

Due to the strong customer demand, even stronger during Corona times, we have decided to deliver legacy and Minifilter technology with the client and also to implement some features, which were originally only intended for the Minifilter, also for the legacy filter.

This was done primarily in order to offer business continuity for the client based on the legacy filter.

We recommend the use of the legacy filter for existing customers, if Minifilter functionality is not essentially required.

We have invested a great effort in compatibility with old encryption methods from LAN Crypt and were able to ensure extensive compatibility and thus also simple migration.

Nevertheless, we strongly recommend piloting the use of the new technologies.

 

Manuals, documentation and support

At https://support.conpal.de registered customers with active maintenance contracts get access to downloads, documentation and knowledge items.

 

The client manuals in French language will be available in form of a pdf manual a couple of days after release for download. For the time being an old manual with a testpage will be available at the link for the French manual.

 

Download the client product documentation at

https://docs.lancrypt.com/de/client/lc_400_hdeu.pdf in German language, at

https://docs.lancrypt.com/en/client/lc_400_heng.pdf in English language and at

https://docs.lancrypt.com/fr/client/lc_400_hfra.pdf in French language.

 

Last minute changes

Due to recently urgent customer requests, we decided at the very last moment to consider the legacy driver as the primary filter driver, which is now also installed by default. This was requested by the clients mainly because new technologies are currently difficult or impossible to pilot.

In this context, we therefore recommend that the necessity for the use of the Minifilter be carefully examined once again.

Requirements

The below listed platforms have been tested and are officially supported. Other Service Pack levels might work as well but have not run through a QA cycle and won´t be analysed in case of occurring issues.

Platforms supported

32-bit

64-bit

Windows 10 1803 (RS4), 1809 (RS5), 1903 (19H1), 1909 (19H2), 2004 (20H1) Pro/Enterprise, 20H2 Pro/Enterprise

No

Yes

Windows Server 2012 R2

No

Yes

Windows Server 2016

No

Yes

Windows Server 2019

No

Yes

Citrix XenApp 7.9 on Windows Server 2012 R2

No

Yes

Citrix XenApp 7.18 on Windows Server 2016

No

Yes

Citrix XenApp 7.15 LTSR on Windows Server 2016

No

Yes

 

Upgrade

conpal LAN Crypt 4.00 Client has been essentially tested to upgrade conpal LAN Crypt 3.97. SafeGuard LAN Crypt 3.95.3.2. or newer might be upgraded to conpal LAN Crypt 4.00 on the supported platforms, but the upgrades have not been tested on a broader base and might require paid professional service.

We recommend that you install the latest Windows security patches on your clients before installing the conpal LAN Crypt Client release.

New in conpal LAN Crypt Client release 4.00.0

Operation of LAN Crypt 4.00 environments

A mixed operation of LAN Crypt v4 Admin and LAN Crypt v3.x Admin is not supported.

It is possible to run a v3.97 Admin with v4 Clients and v3 Clients.

It is possible to run a v4.00 Admin with v4 Clients and v3 Clients.

XML is the only supported policy file format of v4.00 Admin and v4.00 Clients.

New profile files are created by v4.00, with sections for v3 and v4 Clients.

The new encryption rules for Removables, Opticals etc. are transported in the new section.

Once new rules have been created with v4.00, it is no longer possible to create profiles with a v3 Admin. Doing so would potentially have negative effects on the client.

 

Changes

 

 

Bugfixes

 

 

 

Known issues

When an upgrade to Windows 10 is done or a feature update is applied to Windows 10 all data stored in the registry hive HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Utimaco will be removed.

The problem occurs when an unencrypted file on a network drive is moved (=renamed) to an encrypted folder.

In this case the driver should encrypt the file when moving / renaming. With 20H1, however, this does not happen because it cannot determine the name of the target file due to an error in the filter manager of Microsoft.

The error was fixed by Microsoft with KB4557957

https://support.microsoft.com/de-de/help/4557957/windows-10-update-kb4557957
https://support.microsoft.com/en-us/help/4557957/windows-10-update-kb4557957

Some regular expressions in rules might be handled differently than in 3.97, and different between legacy- and Minifilter:

Files are not handled properly according to the profile rules:

Shared folders in VMware virtual machines are not supported properly:

Encryption behaviour has changed when moving files:

The registry key

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\LCENCM\Parameters]

"NovellSupport"=dword:00000001

used for a different timestamp handling, compared to windows fileservers, e.g. for Isilon support, has been removed for the Minifilter.
Please use instead

[HKLM\SYSTEM\CurrentControlSet\Services\cplcisolate]

"AlwaysWriteThroughOnMUP"=dword:00000001

Key visualization and handling in recycle bin might be different to LAN Crypt version 3.97 and in particular wrong (red key symbol visible, when key is accessible).

The encryption status of legacy and Minifilter is determined and visualized differently.

Ignored device types are not supported with the legacy filter

If the legacy filter is operated with CBC and a file encrypted with a respective rule is moved (cut and pasted) to a folder with a different AES rule (XTS), the display of the encryption method remains on CBC.

Moving XTS encrypted files to CBC ruled folders as well display the wrong initial method.

Long path names can be used for. For convenience reasons short names are internally completed by searching some protected paths when program names are configured without path information. The client will search in the following directories:

 

CSIDL_SYSTEM (typical C:\Windows\System32, non-recursive)

CSIDL_WINDOWS (typical C:\Windows, non-recursive)

CSIDL_PROGRAM_FILES (typical C:\Program Files, recursive)

 

If an EXE file with the specified name is found, the full path will be internally added.

Other paths are now untrusted for short file names. (LC-1218).
When mixed environments (LAN Crypt 3.9x and 4.0) are administrated by LAN Crypt Administration 4.00.0, it is best practice to add the executable names for virus scanners in short form (executable name only), when the virus scanner is located in one of the referenced paths (note, that program files on 64 bit system includes the 64 bit path only). When the scanner executables are in other paths, the long pathname including the executable and a second entry with a short name should be used. The long name for the version 4 clients and the short name for the version 3 clients.

Virus Scanner

Executable

Authenticode

Avast 20.6.2420 (Build 20.6.2420.5495.561)

AvastSVC.exe

Yes

TotalAV(5.8.7)

SecurityService.exe

No

Norton Security (22.17.3.50)

NortonSecurity.exe; nsWscSvc.exe

No

BullGuard (20.0.0.381)

BullGuardCore.exe; BullGuardScanner.exe; BullGuardFileScanner.exe

No

Microsoft Defender

msseces.exe
MsMpEng.exe
or
without configuration

 

FSecure v17.8

fsulprothoster.exe, fshoster64.exe, fshoster32.exe, fsorsp64.exe

No

Kaspersky Antivirus 20.0.14.1085

avp.exe
avpui.exe

Yes
Yes

TrendMicro 16.0.1151

 

 

Eset NOD32 Antivirus

ekrn.exe, egui.exe, eguiProxy.exe

No

McAfee Total Protection 16.0 R25

Mcshield.exe
mfeavfk.sys

Yes
Yes

Symantec Endpoint Protection 14.2

ccSvcHst.exe

 

 

 

 

 

Virus Scanner

Executable

Authenticode

Sophos Endpoint Security and Control, Version 10.8.4

SavService.exe

Yes

McAfee Security Center v16.0, McAfee SC 17.8

Mcshield.exe
mfeavfk.sys

Yes
Yes

Symantec Endpoint Protection 14.2

ccSvcHst.exe
srtsp.sys

Yes
No

Trend Micro Antivirus+ 15.0.1163

coreServiceShell.exe

Yes

Microsoft Security Essentials 4.8.1904.1

msseces.exe
MsMpEng.exe

Yes
Yes

FSecure v17.6

Fshoster32.exe
Fshoster64.exe

Yes
Yes

Kaspersky v19.0.0.1088(b)

avp.exe
avpui.exe

Yes
Yes

Sophos Endpoint Security and Control, Version 11.3.1 Cloud

SavService.exe

Yes

Symantec Endpoint Protection 11.0.6 MP1

rtvscan.exe

Yes

McAfee Endpoint Security 10.2

Mcshield.exe
mfeavfk.sys

Yes
Yes

Microsoft Forefront client

msseces.exe
MsMpEng.exe

Yes
Yes

when using UDF formatted DVD+RW media, with installed LAN Crypt Legacyfilter massive problems occur after a few accesses. (LC-1138)

https://docs.lancrypt.com/de/client/lc_400_hdeu.pdf,

https://docs.lancrypt.com/en/client/lc_400_heng.pdf or

https://docs.lancrypt.com/fr/client/lc_400_hfra.pdf, depending on the language.

The first part of the URL (domain name) can be specified in strictly internally operated environments in the registry under "HKLM\SOFTWARE\Policies\conpal\LAN Crypt\HelpURL”