Knowledge Base

How to uninstall Dell Data Protection Enterprise Edition Shield/Dell Encryption Enterprise Shield


This article explains how to uninstall Dell Data Protection | Enterprise Edition Shield/Dell Encryption Enterprise Shield.


Affected Products:

Dell Data Protection | Enterprise Edition Shield
Dell Encryption Enterprise Shield




Uninstall Dell Data Protection | Enterprise Edition Shield/Dell Encryption Enterprise Shield

  1. Launch ddpe_xxbit_setup.exe (replace xx with your installed bit level), approve any required UAC prompts:
    • Installer will check pre-requisites:


(Figure 1: English only - Remove Dell Data Protection | Enterprise Edition Shield/Dell Encryption Enterprise Shield)


(Figure 2: English only - Remove Dell Data Protection | Enterprise Edition Shield/Dell Encryption Enterprise Shield)

  1. Click Next


(Figure 3: English only - Remove Dell Data Protection | Enterprise Edition Shield/Dell Encryption Enterprise Shield)

  1. The recommended way to decrypt the system is through the use of the Decryption Agent (DA). Use of the DA enables the end user to continue using their system while the system is decrypted.
Note: In this example we will be using the 'Download Keys from Server' version of the encryption removal agent uninstall. If you have a previously downloaded key bundle you can use the 'Import Keys from a File' option. Contact support for more information if needed.


(Figure 4: English only - Remove Dell Data Protection | Enterprise Edition Shield/Dell Encryption Enterprise Shield)

Note: Most server information will already be populated. Note that the Device Server URL cannot be changed here, and only the back end server will service forensic key requests. If this URL is pointing to the front end server you will either need to use the 'Import Keys from a File', using the CMGAD.EXE tool to download the bundle, or you will need to edit the Servlet address in the registry. This change could be pushed via GPO or a .reg file manually imported into the local registry. Any account with forensics admin rights can be used.

HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\CMGshield\Servlet(default)=:8443/xapi/


(Figure 5: English only - Remove Dell Data Protection | Enterprise Edition Shield/Dell Encryption Enterprise Shield)

  1. Click next and download the keys:
    • The default of "Local System Account" is usually used to perform the decrypt:


(Figure 6: English only - Remove Dell Data Protection | Enterprise Edition Shield/Dell Encryption Enterprise Shield)


(Figure 7: English only - Remove Dell Data Protection | Enterprise Edition Shield/Dell Encryption Enterprise Shield)

  1. Click remove to start the shield removal and removal agent installation:


(Figure 8: English only - Remove Dell Data Protection | Enterprise Edition Shield/Dell Encryption Enterprise Shield)

  1. Click Finish to complete the operation. Reboot when possible to start the removal agent service.


(Figure 9: English only - Remove Dell Data Protection | Enterprise Edition Shield/Dell Encryption Enterprise Shield)

Upon reboot the Encryption Removal Agent service will start decrypting. You can check the service status to determine when the decryption is complete and you can continue with the Windows upgrade.


(Figure 10: English only - Remove Dell Data Protection | Enterprise Edition Shield/Dell Encryption Enterprise Shield)

Possible states include:

  • Waiting for Deactivation – Dell Data Protection | Enterprise Edition Shield/Dell Encryption Enterprise Shield is still installed, is still configured, or both. Decryption does not start until DDP|E is uninstalled.
  • Initial sweep – The Service is making an initial sweep, calculating the number of encrypted files and bytes. The initial sweep occurs one time.
  • Decryption sweep – The Service is decrypting files and possibly requesting to decrypt locked files.
  • Decrypt on Reboot (partial) – The decryption sweep is complete and some locked files (but not all) are to be decrypted on the next restart.
  • All files could not be decrypted – The decryption sweep is complete, but all files could not be decrypted. This status means one of the following occurred:
    • The locked files could not be scheduled for decryption because they were too big, or an error occurred while making the request to unlock them.
    • An input/output error occurred while decrypting files.
    • The files could not be decrypted by policy.
    • The files are marked as should be encrypted.
    • An error occurred during the decryption sweep.
  • Complete – The decryption sweep is complete. The Service, the executable, the driver, and the driver executable are all scheduled for deletion on the next restart.

For additional support, US based customer can call Dell Data Security ProSupport at: 877.459.7304 Ext. 4310039 or you may also contact us via the Chat Portal. For support outside the US, reference ProSupport’s International Contact Numbers list. Visit the Dell Security Community Forum to get insights from other community members and additional resources to help you manage your environment.


Article ID: SLN298367

Last Date Modified: 07/27/2017 08:48 AM


Rate this article

Accurate
Useful
Easy to understand
Was this article helpful?
Yes No
Send us feedback
Feedback shows invalid character, not accepted special characters are <> () &#92;
Sorry, our feedback system is currently down. Please try again later.

Thank you. Your feedback has been sent.