> Source: [sk170992](https://support.checkpoint.com/results/sk/sk170992)

# sk170992 - Full Disk Encryption on SED machines fails on upgrade with erros 27122 and 27568

| Property | Value |
|----------|-------|
| Solution ID | sk170992 |
| Date Created | 2020-12-20 |
| Last Modified | 2020-12-20 |
| Technical Level | Advanced |
| Products | Endpoint Security |
| Versions | Cloud, E89.X, E88.X |
| Platform | Open Server |

## Symptoms

- * Upgrade fails with logs:  
  `
  FDE Log: No database initialized (uninstall) allow opal encryption from registry: 1`  
  `
  FDE Log: DriverVolumeEncryptionStatus: SED (Opal) encryption prevented since disk \\.\PhysicalDrive0 is software encrypted`  
  `
  FDE Log: Drive \\?\Volume{xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx}\ is encrypting`  
  `
  FDE Log: Full Disk Encryption cannot be upgraded while encryption is active.`  
  `
  MSI (s) (DC!44) [HH:mm:ss:SSS]: Product: Check Point Endpoint Security -- Error 27122.Full Disk Encryption cannot be upgraded while encryption is active.`  
  `
  `  
  `
  1: return code: 1603`  
  `
  MSI (s) (DC!44) [HH:mm:ss:SSS]: PROPERTY CHANGE: Modifying FDE_PRE_CONDS property. Its current value is '0'. Its new value: '-1'.`  
  `
  1: FDE precheck failed, return code: 1603`  
  `
  MSI (s) (DC!44) [HH:mm:ss:SSS]: Product: Check Point Endpoint Security -- Error 27568.Full Disk Encryption verify pre-install requirements failed`  
  `
  `  
* All partitions on the drive you may see either:  
  `
  "Protected: No"`  
  `
  or `  
  `
  "Protected: Yes" and state is "State: No background encryption/decryption active."`  
  `
  `  
* You may see this in the Opal setup logs:  
  `
  20201005 133306,804+1000 I FDE_srv.exe:e9c OpalEncryptionService Opal activated by Windows: true20201005 133306,804+1000 I FDE_srv.exe:e9c OpalEncryptionService Opal activated by Windows: true`  
  `
  `

## Cause

This is an issue with FDE and eDrive where FDE detects the wrong disk ownership as it is taken by Windows.  
Windows has activated Opal during Windows installation. [sk92970](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk92970) describes how to prevent this. The ownership of the Opal configuration is then tied to the current Windows installation and prevents FDE to create the encryption ranges.  

During upgrade, FDE fails to detect the Windows ownership in a correct way. It can be seen in the FDE_dlog:  

*yyyyMMdd HHmmss,SSS+1000 I FDE_srv.exe:e9c OpalEncryptionService Opal activated by Windows: true20201005 133306,804+1000 I FDE_srv.exe:e9c OpalEncryptionService Opal activated by Windows: **true***   

Normally this is "false", but on eDrive activated by Windows it can be true.   
As a result of the incorrect detection of software encryption caused by the wrong ownership, FDE is not able to create the Opal ranges on the disk.  

*yyyyMMdd HHmmss,SSS+1000 I MsiExec.exe:268 DriverVolumeEncryptionStatus: SED (Opal) encryption prevented since disk \\\\.\\PhysicalDrive0 is software encrypted*

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
