Issue
- Resolve an error where you cannot log in to your Full Disk Encryption (FDE) pre-boot screen in ESET Endpoint Encryption (EEE) version 5.0.0
Details
On a system with UEFI and Full Disk Encryption (FDE) with ESET Endpoint Encryption version 5.0.0, when you type the correct FDE username and password, the system does not boot and prompts you to type your username and password again. This appears as the system is looping.
Windows or another software package has taken partial ownership of the OPAL disk in the machine and that causes EEE to incorrectly assume that OPAL encryption is in use.
If your bootloader version does not match the version in the image below (v2.3.62, ignoring US or UM) do not follow the solution in this article. Instead, contact ESET technical support for further assistance.
Solution
- Create a bootable UEFI USB device on a different machine
- Recover the workstation with this issue with the USB Device
- Confirm the USB script has replaced the bootloader
Follow the steps below to resolve the issue.
I. Create a bootable UEFI USB device on a different machine
ESET provides a hotfix EFI script that will replace the v2.3.62 bootloader with the previous version. You need a blank USB device formatted as FAT32. Ensure any important data is moved off the USB device before formatting it as FAT32.
-
Unzip the file and copy the
efi
folder to the root folder of the formatted USB drive. Your USB device should look like this:
II. Recover the computer with this issue with the USB Device
-
On the computer experiencing the problem, enter the system UEFI settings and turn off Secure Boot. This is temporary.
-
Save and exit the UEFI settings and turn the computer off.
-
Insert the USB device and boot the computer holding the necessary key to access the boot menu.
-
Select the USB device from the boot menu and press Enter to boot from it.
-
The EFI script on the USB device will run automatically, replacing the v2.3.62 bootloader with v2.3.53.
-
If successful, the script will prompt you to restart your system. To do this, press any key on your keyboard.
-
Enter the system UEFI settings again and turn Secure Boot back on. Save and exit the UEFI.
III. Confirm the USB script has replaced the bootloader
-
After restarting the machine, you should now see bootloader v2.3.53 in the bottom right hand corner of the screen.
-
Log in with your FDE username and password to boot Windows as normal.
-
If this has not resolved your issue, contact ESET support for further assistance.