CTE UserSpace Administration
This document describes how to manage client profiles and CTE UserSpace clients on CipherTrust Manager. The guide also provides instructions to encrypt local file systems and network shares using encryption keys stored on the CipherTrust Manager.
It is assumed, for the purpose of this document, that the reader has already configured the CipherTrust Manager appliance.
Note
This document, may at times, abbreviate CipherTrust Transparent Encryption UserSpace client to CTE UserSpace client or client.
Organization
The CTE UserSpace Administrator Guide contains the following sections:
Interfaces: Provides an overview of the CipherTrust Manager interfaces—Command Line Interface (CLI), REST Application Programming Interface (REST API), and Graphical User Interface (GUI).
Client Profiles: Describes client profiles.
Clients: Describes clients.
Access: Describes access policy groups, access policies, group types, and access policies for processes, group association.
Keys: Provides information on keys used for encrypting data using CTE UserSpace.
Rules: Describes encryption rules, migration process, and subdirectories ignored during encryption.
Client-Rule Associations: Describes a client-rule association and cryptographic operations and their state flow.
Network Shares: Describes how to create a network share, prerequisites to protect a network share, and how to link a network share with a client.
- Operations: Describes the process to register a CTE UserSpace client with the CipherTrust Manager. The chapter also provides instructions on how to protect local file systems and network shares using CTE UserSpace.
User Roles
The CTE UserSpace has different kinds of users with different responsibilities in administering and using the system.
Note
CTE UserSpace has the same user roles as ProtectFile—ProtectFile Admins and ProtectFile Users.
Note
It is critical that credentials for these users be kept in a secure location. If a credential is compromised an attacker could gain access to sensitive data.
ProtectFile Administrator
There is a System Defined Group named ProtectFile Admins. Users within the ProtectFile Admins group are CTE UserSpace Administrators.
A CTE UserSpace Administrator is responsible for creating and managing the following CTE UserSpace resources:
Client profiles and clients
Network shares, and share-clients and share-rules associations
Access policies, access policy groups, and their associations
Rules and client-rule associations
Client Registration Tokens (with additional rights of System Defined Group named CA Admins)
ProtectFile User
There is a System Defined Group named ProtectFile Users. CipherTrust Manager clients enrolled for CTE UserSpace are part of this group.