u.trust LAN Crypt 11.0.0 Client release notes

After the acquisition of conpal GmbH in 4/2023 by Utimaco, the product conpal LAN Crypt has been rebranded and will be continued under the different brand name u.trust LAN Crypt. Version 11.0.0 is the first rebranded version, a feature release and replaces the conpal LAN Crypt product.
The product is able to upgrade from the previous conpal LAN Crypt 4.2.1.

The Legacyfilter has been abandoned, and is not supported anymore.
Administration versions earlier than conpal LAN Crypt 4.1.1 are EOL.
Clients earlier than conpal LAN Crypt 4.1.3 are EOL.

We recommend to upgrade the clients to 4.2.1 and the administration to 4.2.0 before upgrading to u.trust LAN Crypt 11.0.0.

 

u.trust LAN Crypt 11.0.0 also comes with improved security functionality and several bugfixes.

New features:

§  Support for new versions of operating systems

§  64 Bit .NET API

§  Several enhancements and extensions for .NET API

§  LCSendP12Password helper tool, automatically send P12 passwords by email

§  New database tool CheckDatabase.exe

§  Improved CreateTables

§  Log Collector Utility

§  Client Performance Improvements, options to cache files for encrypted SMB shares, DsStateCache for caching unencrypted files

§  Rebranding

§  Detail work on dialogs and error messages

§  Option to renew assigned certificates

§  Most important cloud apps pre-registered and maintainable via registry

§  Support for multiple policies

§  Show "Bypass" flag for rules in "Show Profile"

Changes/Improvements in V11:

§  u.trust LAN Crypt2Go replaces conpal LAN Crypt Portable

§  Improvement of accessibility

§  Accelerated create-profile functionality

§  Improved certificate handling

§  Accelerated certificate creation

§  Support for certificates in computer-store, e.g. for services

§  Optimizations, additional verifications and acceleration of CreateTables for MS SQL and Oracle

§  ClearCache Option for DsStateCache

§  Removed support for

§  deprecated Oracle versions

§  profiles in legacy format

§  Improved messages

§  .Net API update to support version 8

§  Throttling when creating certificates to preserve resources for OS accessibility

§  Performance tracing

§  When importing certificates (p12) from a file server, certificates are now checked in true descending order (by number suffix).

§  Default ignored apps can be maintained via registry

 

The EULA has been updated and is now only available in English and German.

The English version is valid for all non-German speaking countries.

The actual versions can be obtained from:

https://utimaco.com/sites/default/files/2024-02/Utimaco_IS_GmbH_EULA_2024_EN.pdf

https://utimaco.com/sites/default/files/2024-02/Utimaco_IS_GmbH_EULA_2024_DE.pdf


Please note the LAN Crypt 11.0.0 Administration release notes.

Older release notes for LAN Crypt remain valid, if not stated otherwise.

 

 

Requirements

The below listed platforms have been tested and are officially supported. Other Service Pack levels might work as well but have not run through a QA cycle and won´t be analysed in case of occurring issues.

Supported Windows 64-bit operating system platforms

Pro/Enterprise versions of Windows 10 21H2 (LTSC), 22H2

Pro/Enterprise versions of Windows 11 21H2, 22H2, 23H2

Windows Server 2022

Supported Citrix Environments

Citrix Virtual Apps and Desktop 7 1912 LTSR CU2 on WS 2019

 

 New in LAN Crypt Client release 11.0.0

All network files (encrypted or not) appear closed to the upper layers on the client, but in reality they remain open for a short time so that they can be read from the cache when they are accessed quickly again. The maximum time to final closure is about 30 seconds. If someone on the network accesses the file during this time, the network driver will immediately report the access to the minifilter, and the minifilter will attempt to close the file as quickly as possible. Unfortunately, this is not always successful, and in this case the accessing application from the other client may receive a SHARING_VIOLATION message on the first access. The next attempt would be successful, but may be too late for some applications. For this case, the “DelayedCloseExcludedPaths” registry parameter is provided, where you can configure the paths that are excluded from this optimization. Please contact support for details. (LC-4074)

 

 

Changes in LAN Crypt Client release 11.0.0

If the 'Check certificate extension' group policy is not configured, this policy is treated as 'Enabled'.

Certificates without an appropriate key usage will be rejected.

 

This applies to

    Importing a user certificate into the LC Client

    Importing a SO certificate into the LC Client

    Assigning a user certificate in the LC Administration Console

    Assigning a SO certificate in the LC Administration Console

    Logging in to the LC Administration Console

 

Starting with LC v4.2.0, the behaviour was inadvertently treated as "disabled" if the "Check certificate extension" group policy was not configured.

With LC v11.0.0 this has been fixed so that LC behaves as it did before LC v4.2.0. (LC-3938)

 

Therefore, before upgrading LCA and LCC to v11.0.0, make sure that the group policy is set to "disabled" when using certificates without the x509v3 key usage option.

Virus Scanner

Executable

Authenticode

Sophos Endpoint Security and Control

Old:
SavService.exe

Now:
SophosFileScanner.exe

 

e.g.:
C:\Program Files\Sophos\Endpoint Defense\SEDService.exe
C:\Program Files\Sophos\Sophos File Scanner\SophosFS.exe
C:\Program Files\Sophos\Sophos File Scanner\SophosfileScanner.exe
C:\Program Files\Sophos\Endpoint Defense\SSPService.exe
C:\Program Files\Sophos\Clean\SophosCleanM64.exe
C:\Program Files (x86)\HitmanPro.Alert\hmpalert.exe

Yes

Microsoft Defender

MsMpEng.exe 

 

CrowdStrike

CsScan.exe

 

In case EDR, XDR, or MDR is used, it makes sense to exclude them or some of their processes from decrypting files and at the same time allow these processes to access them. This is done by adding the executable names to the unhandled applications settings in the LC Group Policy

                          EDR/XDR/MDR

Executable

GPO unhandled applications recommended

Sophos XDR

OsQuery.exe

Yes

Palo Alto Cortex

cyserver.exe*

Yes

* Guess, not verified at release time

 

Bugfixes in LAN Crypt Client release 11.0.0

 

New and known issues in LAN Crypt Client release 11.0.0

However, if another application or somebody in the network accesses the file earlier and wants to open it exclusively, this can in rare cases lead to an error.

Important note: In any case, all data is "flushed" (written to disk) but not "purged" (deleted from cache), so no data is lost in the event of a system crash.

With the setting OptimizeNetworkDelayedClose=0, this behaviour does not occur in either case. (LC-4201)

 

 

 

Manuals, documentation and support

At https://support.conpal.de registered customers with active maintenance contracts get access to downloads, documentation and knowledge items.

 

Read or download the client product documentation at

https://help.lancrypt.com/docs/windows/11_0_0/de/ in German language, at

https://help.lancrypt.com/docs/windows/11_0_0/en/ in English language and at

https://help.lancrypt.com/docs/windows/11_0_0/fr/ in French language.

 

API documentation can be obtained from:

https://help.lancrypt.com/docs/api/client/en/

https://help.lancrypt.com/docs/api/admin/en/

 

 

conpal LAN Crypt 4.2.1 Client release notes

 

conpal LAN Crypt 4.2.1 is a maintenance release, there are no new features included.
Please refer to the conpal LAN Crypt 4.2.0 part of the release notes.

Older release notes for LAN Crypt remain valid, if not stated otherwise.

LAN Crypt 4.2.1 was built solely to provide workarounds for behavioral changes of Microsoft technologies.
We recommend that all LAN Crypt clients, that are operated with MiniFilter, should be updated, when affected by the described issue.

IMPORTANT LAN Crypt Notice: Windows Update results in changed behavior with LAN Crypt

Issue

In rare cases, copying files to network shares results in a change in the size of the destination file. This is increased to the next 512-byte limit. The behavior is independent of the encryption status. It does not occur without LAN Crypt installed, nor does it affect file operations on local media. Removable media or cloud storage likewise are not affected according to our tests.

Affected systems

Windows 10 and 11 with KB505221 or KB5023774 or KB5025239 in combination with LAN Crypt Client (4.x with MiniFilter).

Other systems/combinations are not affected to our current knowledge.

 

Countermeasures/fixes:

LAN Crypt 4.2.1 contains a workaround for that behavior.

We are categorizing this issue as a potential data corruption and classify it as critical. We advise installing the LAN Crypt client version 4.2.1 on affected systems.

There are currently no other known workarounds, despite delaying the referenced Microsoft patches.

 

Background:

Microsoft continues to make significant changes to Windows to increase the performance of file copy operations*. While this is mostly transparent to file system filter drivers, in our testing we have discovered an incompatibility between our drivers and a recent change to this code path in the OS.

 

Example:

A non-cached copy operation of a 7-byte source file to a network share will result in a 512-byte destination file.
xcopy /v /j localsource networkdestination

 

Occurrence:

The issue affects Windows machines with all LAN Crypt versions using MiniFilter (4.0 - 4.2). We have determined the change in OS behavior was introduced to Windows 10 via KB5025221. Further testing shows that this issue is also present in recent releases of Windows 11 21H2 and can be traced back to KB5023774. For Windows 11 22H2, the issue seems to be present since at least KB502523.

 

Severity:

The issue arises sporadically, in most cases the change in file size is inconsequential or easily remedied by the associated app.

 

Related Links:

 

 

2023-04 Cumulative Update for Windows 10 *** Systems (KB5025221)

https://support.microsoft.com/help/5025221

KB5025221 - Microsoft Update Catalog

 

2023-03 Cumulative Update Preview for Windows 11 21H2 *** Systems (KB5023774)

https://support.microsoft.com/help/5023774

KB5023774 - Microsoft Update Catalog

 

2023-04 Cumulative Update for Windows 11 Version 22H2 *** Systems (KB5025239)

https://support.microsoft.com/help/5025239

KB5025239 - Microsoft Update Catalog

 

 

*Further details about these changes by Microsoft in general can be found here:

Kernel-mode file copy and detecting copy file scenarios - Windows drivers | Microsoft Learn

Changes in conpal LAN Crypt Client release 4.2.1

§  Based on the recent OS changes it is no longer valid to clear the FO_NO_INTERMEDIATE_BUFFERING bit in non-cached opens to network files. LAN Crypt previously cleared this bit to have better control over caching on network files, however the I/O subsystem now uses the presence of this bit to determine if files should or should not be truncated to a non-aligned size during non-cached copies. While we do not believe that the I/O subsystem should be using this bit for the determination, the OS releases are now in the wild and we must change our handling within LAN Crypt.
Using different mechanisms for the operations (LC-3337)

§  Due to a bug in the current sysinternals Sysmon version (14.6), LC performance problems may occur. A workaround has been implemented (LC-3173). The workaround might be benefcial for other situations, where users face performance problems when opening and saving files

In general Sophos virus scanners have to be configured differently:

Virus Scanner

Executable

Authenticode

Sophos Endpoint Security and Control

Old:
SavService.exe

Now:
SophosFileScanner.exe

Yes

 

 

 

 

conpal LAN Crypt 4.2.0 Client release notes

 

conpal LAN Crypt 4.2.0 is a feature release that also comes with improved security functionality and several bugfixes. New features:

Please note the LAN Crypt 4.2.0 Administration release notes.

Older release notes for LAN Crypt remain valid, if not stated otherwise.

 

Important information, if you had early access to LAN Crypt Client 4.2.0

During the release of LAN Crypt v4.2.0.5550, we detected a data corruption,
if encrypted files were copied from an unregulated server share to an unregulated folder on the same server share, when server side copy was utilized by the LCC.
Shipment of the version has been stopped, but it is possible that this version still arrived at individual customers or partners.

We strongly advise against productive use of LAN Crypt for Windows Client v4.2.0.5550.
The version can be identified by the build number of the binaries,
the information in the info/about-box of the client or you can already distinguish the MSI:
The client of the defective version 4.2.0.5550 has the revision number {2F4D80EF-733F-48B1-AA67-8EABD636C7C6}.

The root cause for the possible corruption has been found and the problem is fixed with LAN Crypt v4.2.0.5559,
which is currently available as a released version.
The MSI of the released LAN Crypt client version 4.2.0.5559 has the revision number {BAFCA5AD-9B37-4BBE-A8B9-973ED914A50F}.

The defective version cannot be updated to the released version, so it would have to be uninstalled and reinstalled.

 

 

Requirements

The below listed platforms have been tested and are officially supported. Other Service Pack levels might work as well but have not run through a QA cycle and won´t be analysed in case of occurring issues.

Supported Windows 64-bit operating system platforms

Pro/Enterprise versions of Windows 10 1809 (LTSC), 20H2, 21H2, 21H2 (LTSC), 22H2

Pro/Enterprise versions of Windows 11 21H2, 22H2

Windows Server 2019

Windows Server 2022

Supported Citrix Environments

Citrix Virtual Apps and Desktop 7 1912 LTSR CU2 on WS 2019

 

 New in conpal LAN Crypt Client release 4.2.0

 

Changes in conpal LAN Crypt Client release 4.2.0

 

Bugfixes in conpal LAN Crypt Client release 4.2.0

 

New and known issues in conpal LAN Crypt Client release 4.2.0

 

Manuals, documentation and support

At https://support.conpal.de registered customers with active maintenance contracts get access to downloads, documentation and knowledge items.

 

Read or download the client product documentation at

https://help.lancrypt.com/docs/windows/4_2_0/de/ in German language, at

https://help.lancrypt.com/docs/windows/4_2_0/en/ in English language and at

https://help.lancrypt.com/docs/windows/4_2_0/fr/ in French language.

 

API documentation can be obtained from:

https://help.lancrypt.com/docs/api/client/en/

https://help.lancrypt.com/docs/api/admin/en/

 

 

 

 

 

conpal LAN Crypt 4.1.2 Client release notes

 

conpal LAN Crypt 4.1.2 is a Japanese language version and functional identical to LAN Crypt 4.1.1.
Please refer to the conpal LAN Crypt 4.1.1 part of the release notes.

Please note the LAN Crypt 4.1.2 Administration release notes.

Older release notes for LAN Crypt remain valid, if not stated otherwise.

Manuals, documentation and support

At https://support.conpal.de registered customers with active maintenance contracts get access to downloads, documentation and knowledge items.

Download the client product documentation at

https://docs.lancrypt.com/ja/client/lc_412_hjpn.pdf in Japanese language, at

https://docs.lancrypt.com/de/client/lc_411_hdeu.pdf in German language, at

https://docs.lancrypt.com/en/client/lc_411_heng.pdf in English language and at

https://docs.lancrypt.com/fr/client/lc_411_hfra.pdf in French language. Please note, the French manual will be published delayed, for the time being use the English manual

 

 

 

 

 

conpal LAN Crypt 4.1.1 Client release notes

 

conpal LAN Crypt 4.1.1 is a maintenance release, there are no new features included.
Please refer to the conpal LAN Crypt 4.1.0 part of the release notes.

Please note the LAN Crypt 4.1.1 Administration release notes.

Older release notes for LAN Crypt 4.00.x remain valid, if not stated otherwise.

 

Requirements

The below listed platforms have been tested and are officially supported. Other Service Pack levels might work as well but have not run through a QA cycle and won´t be analysed in case of occurring issues.

Platforms supported

32-bit

64-bit

Pro/Enterprise versions of Windows 10 1809 (LTSC), 20H2, 21H1, 21H2, Windows 11

No

Yes

Windows Server 2019

No

Yes

Windows Server 2022

No

Yes

Citrix XenApp, Citrix XenApp LTSR *

No

Yes

*Citrix Environments are supported, but have not been extensively retested

 

Bugfixes in conpal LAN Crypt Client, Release 4.1.1

 

Manuals, documentation and support

At https://support.conpal.de registered customers with active maintenance contracts get access to downloads, documentation and knowledge items.

Download the client product documentation at

https://docs.lancrypt.com/de/client/lc_411_hdeu.pdf in German language, at

https://docs.lancrypt.com/en/client/lc_411_heng.pdf in English language and at

https://docs.lancrypt.com/fr/client/lc_411_hfra.pdf in French language. Please note, the French manual will be published delayed, for the time being use the English manual

 

 

 

 

 

conpal LAN Crypt 4.1.0 Client release notes

conpal LAN Crypt 4.1.0 comes with support for new operating systems new functionality, improved security functionality and new features

e.g.

·          Support for SGN/SafeGuard Fileshare customers

·          Portable file encryption

·          Minifilter with caching capabilities for SMB network shares

·          New .NET Administration API

·          Client API login with user context

·          LAN Crypt-Service functionality

·          Manipulation protection for processes

·          Multi factor Authentication based on 3rd party technology

·          Oracle 19 Support

The Legacyfilter has been abandoned, but is still supported with the 4.00.x version of the product.

Older release notes for LAN Crypt 4.00.x remain valid, if not stated otherwise.

Please note the LAN Crypt 4.1.0 Administration release notes.

Requirements

The below listed platforms have been tested and are officially supported. Other Service Pack levels might work as well but have not run through a QA cycle and won´t be analysed in case of occurring issues.

Platforms supported

32-bit

64-bit

Pro/Enterprise versions of Windows 10 1809 (LTSC), 1909 (19H2), 20H2, 21H1, 21H2, Windows 11

No

Yes

Windows Server 2016

No

Yes

Windows Server 2019

No

Yes

Windows Server 2022

No

Yes

Citrix XenApp 7.18 on Windows Server 2016*

No

Yes

Citrix XenApp 7.15 LTSR on Windows Server 2016*

No

Yes

*Citrix Environments are supported, but have not been extensively retested

 New in conpal LAN Crypt Client release 4.1.0

Non-default Legacy-filter registry settings are migrated to respective Minifilter Settings (where necessary) (LC-1681)

 

Changes in 4.1.0

 

Bugfixes in 4.1.0

 

New known issues

https://docs.microsoft.com/en-us/cpp/windows/latest-supported-vc-redist?view=msvc-170
https://aka.ms/vs/17/release/vc_redist.x86.exe
https://aka.ms/vs/17/release/vc_redist.x64.exe

 

 

Manuals, documentation and support

At https://support.conpal.de registered customers with active maintenance contracts get access to downloads, documentation and knowledge items.

 

The client manuals in French language will be available in form of a pdf manual a couple of days after release for download. For the time being an old manual with a testpage will be available at the link for the French manual.

 

Download the client product documentation at

https://docs.lancrypt.com/de/client/lc_410_hdeu.pdf in German language, at

https://docs.lancrypt.com/en/client/lc_410_heng.pdf in English language and at

https://docs.lancrypt.com/fr/client/lc_410_hfra.pdf in French language. Please note, the French manual will be published delayed, for the time being use the English manual

 

 

 

 

 

conpal LAN Crypt 4.00.3 Client release notes

conpal LAN Crypt 4.00.3 comes with support for additional operating systems, support for SGN/SafeGuard FileShare and bugfixes. Older release notes for LAN Crypt 4.00.x remain valid, if not stated otherwise.

Please note the LAN Crypt 4.00.3 Administration release notes.

 

Requirements

The below listed platforms have been tested and are officially supported. Other Service Pack levels might work as well but have not run through a QA cycle and won´t be analysed in case of occurring issues.

Platforms supported

32-bit

64-bit

Windows 10 1909 (19H2), 2004 (20H1) Pro/Enterprise, 20H2 Pro/Enterprise, 21H2 Pro/Enterprise, Windows 11

No

Yes

Windows Server 2012 R2

No

Yes

Windows Server 2016

No

Yes

Windows Server 2019

No

Yes

Citrix XenApp 7.9 on Windows Server 2012 R2

No

Yes

Citrix XenApp 7.18 on Windows Server 2016

No

Yes

Citrix XenApp 7.15 LTSR on Windows Server 2016

No

Yes

 New in conpal LAN Crypt Client release 4.00.3

 

Changes in 4.00.3

 

Bugfixes in 4.00.3

 

Manuals, documentation and support

At https://support.conpal.de registered customers with active maintenance contracts get access to downloads, documentation and knowledge items.

 

The client manuals in French language will be available in form of a pdf manual a couple of days after release for download. For the time being an old manual with a testpage will be available at the link for the French manual.

 

Download the client product documentation at

https://docs.lancrypt.com/de/client/lc_400_hdeu.pdf in German language, at

https://docs.lancrypt.com/en/client/lc_400_heng.pdf in English language and at

https://docs.lancrypt.com/fr/client/lc_400_hfra.pdf in French language.

 

 

 

 

conpal LAN Crypt 4.00.2 Client release notes

conpal LAN Crypt 4.00.2 is a maintenance release.Older release notes for LAN Crypt 4.00.x remain valid, if not stated otherwise.

Please note the LAN Crypt 4.00.2 Administration release notes.

 

Requirements

The below listed platforms have been tested and are officially supported. Other Service Pack levels might work as well but have not run through a QA cycle and won´t be analysed in case of occurring issues.

Platforms supported

32-bit

64-bit

Windows 10 1909 (19H2), 2004 (20H1) Pro/Enterprise, 20H2 Pro/Enterprise

No

Yes

Windows Server 2012 R2

No

Yes

Windows Server 2016

No

Yes

Windows Server 2019

No

Yes

Citrix XenApp 7.9 on Windows Server 2012 R2

No

Yes

Citrix XenApp 7.18 on Windows Server 2016

No

Yes

Citrix XenApp 7.15 LTSR on Windows Server 2016

No

Yes

Bugfixes in 4.00.2

 

Manuals, documentation and support

At https://support.conpal.de registered customers with active maintenance contracts get access to downloads, documentation and knowledge items.

 

The client manuals in French language will be available in form of a pdf manual a couple of days after release for download. For the time being an old manual with a testpage will be available at the link for the French manual.

 

Download the client product documentation at

https://docs.lancrypt.com/de/client/lc_400_hdeu.pdf in German language, at

https://docs.lancrypt.com/en/client/lc_400_heng.pdf in English language and at

https://docs.lancrypt.com/fr/client/lc_400_hfra.pdf in French language.

 

 

 

 

 

 

 

 

conpal LAN Crypt 4.00.1 Client release notes

conpal LAN Crypt 4.00.1 is in focus a maintenance release and brings support for W10 20H2. If not referenced in the sections New in conpal LAN Crypt Client release 4.00.1, changes in 4.00.1, Bugfixes in 4.00.1 the release notes for LAN Crypt 4.00 remain valid.

Please note the LAN Crypt 4.00.1 Administration release notes.

 

Requirements

The below listed platforms have been tested and are officially supported. Other Service Pack levels might work as well but have not run through a QA cycle and won´t be analysed in case of occurring issues.

Platforms supported

32-bit

64-bit

Windows 10 1803 (RS4), 1809 (RS5), 1903 (19H1), 1909 (19H2), 2004 (20H1) Pro/Enterprise, 20H2 Pro/Enterprise

No

Yes

Windows Server 2012 R2

No

Yes

Windows Server 2016

No

Yes

Windows Server 2019

No

Yes

Citrix XenApp 7.9 on Windows Server 2012 R2

No

Yes

Citrix XenApp 7.18 on Windows Server 2016

No

Yes

Citrix XenApp 7.15 LTSR on Windows Server 2016

No

Yes

 New in conpal LAN Crypt Client release 4.00.1

Changes in 4.00.1

 

Bugfixes in 4.00.1

 

New known issues

The switch IgnoredApplicationsChildProcs is used for the internal default processes as well. That leads to problems especially with Office applications, when preview and accessing lead to concurrent access.
The workaround recommendation is to avoid the setting 2 for inheritance to childs and to use 1 instead. (LC-1603).

 

Manuals, documentation and support

At https://support.conpal.de registered customers with active maintenance contracts get access to downloads, documentation and knowledge items.

 

The client manuals in French language will be available in form of a pdf manual a couple of days after release for download. For the time being an old manual with a testpage will be available at the link for the French manual.

 

Download the client product documentation at

https://docs.lancrypt.com/de/client/lc_400_hdeu.pdf in German language, at

https://docs.lancrypt.com/en/client/lc_400_heng.pdf in English language and at

https://docs.lancrypt.com/fr/client/lc_400_hfra.pdf in French language.

 

 

 

 

conpal LAN Crypt 4.00.0 Client release notes

Please note the LAN Crypt 4.00.0 Administration release notes.

conpal LAN Crypt is the successor of SafeGuard LAN Crypt.

conpal LAN Crypt 3.97 Client was the initial release of conpal for the client. It contained fixes and hotfixes of the previous SafeGuard LAN Crypt 3.95 Client version, fixed several known issues and came with support for current operating systems.

conpal LAN Crypt 4.00 Client is a significant rework of the client technology. The cryptographic base has been reworked for potential certifications and approvals. The underlying filter technology has been built on Minifilter technology to be future-proof and assure long term support for the technology by Microsoft.

conpal will develop new client features based on the Minifilter technology.

Due to the strong customer demand, even stronger during Corona times, we have decided to deliver legacy and Minifilter technology with the client and also to implement some features, which were originally only intended for the Minifilter, also for the legacy filter.

This was done primarily in order to offer business continuity for the client based on the legacy filter.

We recommend the use of the legacy filter for existing customers, if Minifilter functionality is not essentially required.

We have invested a great effort in compatibility with old encryption methods from LAN Crypt and were able to ensure extensive compatibility and thus also simple migration.

Nevertheless, we strongly recommend piloting the use of the new technologies.

 

Manuals, documentation and support

At https://support.conpal.de registered customers with active maintenance contracts get access to downloads, documentation and knowledge items.

 

The client manuals in French language will be available in form of a pdf manual a couple of days after release for download. For the time being an old manual with a testpage will be available at the link for the French manual.

 

Download the client product documentation at

https://docs.lancrypt.com/de/client/lc_400_hdeu.pdf in German language, at

https://docs.lancrypt.com/en/client/lc_400_heng.pdf in English language and at

https://docs.lancrypt.com/fr/client/lc_400_hfra.pdf in French language.

 

Last minute changes

Due to recently urgent customer requests, we decided at the very last moment to consider the legacy driver as the primary filter driver, which is now also installed by default. This was requested by the clients mainly because new technologies are currently difficult or impossible to pilot.

In this context, we therefore recommend that the necessity for the use of the Minifilter be carefully examined once again.

Requirements

The below listed platforms have been tested and are officially supported. Other Service Pack levels might work as well but have not run through a QA cycle and won´t be analysed in case of occurring issues.

Platforms supported

32-bit

64-bit

Windows 10 1803 (RS4), 1809 (RS5), 1903 (19H1), 1909 (19H2), 2004 (20H1) Pro/Enterprise, 20H2 Pro/Enterprise

No

Yes

Windows Server 2012 R2

No

Yes

Windows Server 2016

No

Yes

Windows Server 2019

No

Yes

Citrix XenApp 7.9 on Windows Server 2012 R2

No

Yes

Citrix XenApp 7.18 on Windows Server 2016

No

Yes

Citrix XenApp 7.15 LTSR on Windows Server 2016

No

Yes

 

Upgrade

conpal LAN Crypt 4.00 Client has been essentially tested to upgrade conpal LAN Crypt 3.97. SafeGuard LAN Crypt 3.95.3.2. or newer might be upgraded to conpal LAN Crypt 4.00 on the supported platforms, but the upgrades have not been tested on a broader base and might require paid professional service.

We recommend that you install the latest Windows security patches on your clients before installing the conpal LAN Crypt Client release.

New in conpal LAN Crypt Client release 4.00.0

 

Operation of LAN Crypt 4.00 environments

A mixed operation of LAN Crypt v4 Admin and LAN Crypt v3.x Admin is not supported.

It is possible to run a v3.97 Admin with v4 Clients and v3 Clients.

It is possible to run a v4.00 Admin with v4 Clients and v3 Clients.

XML is the only supported policy file format of v4.00 Admin and v4.00 Clients.

New profile files are created by v4.00, with sections for v3 and v4 Clients.

The new encryption rules for Removables, Opticals etc. are transported in the new section.

Once new rules have been created with v4.00, it is no longer possible to create profiles with a v3 Admin. Doing so would potentially have negative effects on the client.

 

Changes

 

Bugfixes

 

Known issues

When an upgrade to Windows 10 is done or a feature update is applied to Windows 10 all data stored in the registry hive HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Utimaco will be removed.

The problem occurs when an unencrypted file on a network drive is moved (=renamed) to an encrypted folder.

In this case the driver should encrypt the file when moving / renaming. With 20H1, however, this does not happen because it cannot determine the name of the target file due to an error in the filter manager of Microsoft.

The error was fixed by Microsoft with KB4557957

https://support.microsoft.com/de-de/help/4557957/windows-10-update-kb4557957
https://support.microsoft.com/en-us/help/4557957/windows-10-update-kb4557957

Some regular expressions in rules might be handled differently than in 3.97, and different between legacy- and Minifilter:

Files are not handled properly according to the profile rules:

Shared folders in VMware virtual machines are not supported properly:

Encryption behaviour has changed when moving files:

The registry key

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\LCENCM\Parameters]

"NovellSupport"=dword:00000001

used for a different timestamp handling, compared to windows fileservers, e.g. for Isilon support, has been removed for the Minifilter.
Please use instead

[HKLM\SYSTEM\CurrentControlSet\Services\cplcisolate]

"AlwaysWriteThroughOnMUP"=dword:00000001

Key visualization and handling in recycle bin might be different to LAN Crypt version 3.97 and in particular wrong (red key symbol visible, when key is accessible).

The encryption status of legacy and Minifilter is determined and visualized differently.

Ignored device types are not supported with the legacy filter

If the legacy filter is operated with CBC and a file encrypted with a respective rule is moved (cut and pasted) to a folder with a different AES rule (XTS), the display of the encryption method remains on CBC.

Moving XTS encrypted files to CBC ruled folders as well display the wrong initial method.

Long path names can be used for. For convenience reasons short names are internally completed by searching some protected paths when program names are configured without path information. The client will search in the following directories:

 

CSIDL_SYSTEM (typical C:\Windows\System32, non-recursive)

CSIDL_WINDOWS (typical C:\Windows, non-recursive)

CSIDL_PROGRAM_FILES (typical C:\Program Files, recursive)

 

If an EXE file with the specified name is found, the full path will be internally added.

Other paths are now untrusted for short file names. (LC-1218).
When mixed environments (LAN Crypt 3.9x and 4.0) are administrated by LAN Crypt Administration 4.00.0, it is best practice to add the executable names for virus scanners in short form (executable name only), when the virus scanner is located in one of the referenced paths (note, that program files on 64 bit system includes the 64 bit path only). When the scanner executables are in other paths, the long pathname including the executable and a second entry with a short name should be used. The long name for the version 4 clients and the short name for the version 3 clients.

Virus Scanner

Executable

Authenticode

Avast 20.6.2420 (Build 20.6.2420.5495.561)

AvastSVC.exe

Yes

TotalAV(5.8.7)

SecurityService.exe

No

Norton Security (22.17.3.50)

NortonSecurity.exe; nsWscSvc.exe

No

BullGuard (20.0.0.381)

BullGuardCore.exe; BullGuardScanner.exe; BullGuardFileScanner.exe

No

Microsoft Defender

msseces.exe
MsMpEng.exe
or
without configuration

 

FSecure v17.8

fsulprothoster.exe, fshoster64.exe, fshoster32.exe, fsorsp64.exe

No

Kaspersky Antivirus 20.0.14.1085

avp.exe
avpui.exe

Yes
Yes

TrendMicro 16.0.1151

 

 

Eset NOD32 Antivirus

ekrn.exe, egui.exe, eguiProxy.exe

No

McAfee Total Protection 16.0 R25

Mcshield.exe
mfeavfk.sys

Yes
Yes

Symantec Endpoint Protection 14.2

ccSvcHst.exe

 

 

 

 

 

Virus Scanner

Executable

Authenticode

Sophos Endpoint Security and Control, Version 10.8.4

SavService.exe

Yes

McAfee Security Center v16.0, McAfee SC 17.8

Mcshield.exe
mfeavfk.sys

Yes
Yes

Symantec Endpoint Protection 14.2

ccSvcHst.exe
srtsp.sys

Yes
No

Trend Micro Antivirus+ 15.0.1163

coreServiceShell.exe

Yes

Microsoft Security Essentials 4.8.1904.1

msseces.exe
MsMpEng.exe

Yes
Yes

FSecure v17.6

Fshoster32.exe
Fshoster64.exe

Yes
Yes

Kaspersky v19.0.0.1088(b)

avp.exe
avpui.exe

Yes
Yes

Sophos Endpoint Security and Control, Version 11.3.1 Cloud

SavService.exe

Yes

Symantec Endpoint Protection 11.0.6 MP1

rtvscan.exe

Yes

McAfee Endpoint Security 10.2

Mcshield.exe
mfeavfk.sys

Yes
Yes

Microsoft Forefront client

msseces.exe
MsMpEng.exe

Yes
Yes

when using UDF formatted DVD+RW media, with installed LAN Crypt Legacyfilter massive problems occur after a few accesses. (LC-1138)

https://docs.lancrypt.com/de/client/lc_400_hdeu.pdf,

https://docs.lancrypt.com/en/client/lc_400_heng.pdf or

https://docs.lancrypt.com/fr/client/lc_400_hfra.pdf, depending on the language.

The first part of the URL (domain name) can be specified in strictly internally operated environments in the registry under "HKLM\SOFTWARE\Policies\conpal\LAN Crypt\HelpURL”