Deployment Guide

Network requirement for a bare-metal wipe

A bare-metal wipe erases the whole internal drive, including Windows, so the device reboots into the WipeCert Erasure Engine to do the work. That environment needs to reach WipeCert over the network to claim the job and report back. Here is what that requires today, and where Wi-Fi support currently stands.

What a device needs, at a glance

A wired connection
A cable in the device at wipe time. Wi-Fi is not supported on the engine shipping today.
An address from DHCP
No static address is possible, so the segment it boots on has to offer DHCP.
Outbound HTTPS, plus DNS
Port 443 out to wipecert.com and a resolver it can reach. Nothing inbound.

Today

What the device needs today

  • A wired connection. The erasure engine we ship today (WipeCert Erasure Engine 1.7) brings up wired networking only. If the device has no cable connected at wipe time, it cannot get online and the wipe does not run.

  • An address from DHCP. The erasure environment requests its address automatically. There is no way to give it a static address, so the segment the device boots on has to offer DHCP.

  • Outbound HTTPS to wipecert.com, plus working name resolution. During the wipe the erasure engine makes one kind of connection: it resolves wipecert.com and calls out to it over HTTPS on port 443, to claim the wipe and to report when it is done. It accepts no incoming connection, needs no port opened toward it, and does not need to be reachable from anywhere else on your network. If you are locking a segment down for wiping, allow DNS as well as the outbound HTTPS, or the engine cannot find us.

Important

If your network requires devices to authenticate before they get an IP address at all (802.1X on the wired side, or a similar NAC setup), talk to us before you queue a wipe on that segment.

Wi-Fi

Wi-Fi support: in lab testing, not available today

Wi-Fi support for bare-metal wipes is in development and currently runs on lab hardware only. It is not available on any customer's wipe today. We are not naming a release date and we are not promising one; parts of it depend on decisions that are not ours alone to make. Plan around a wired connection until we tell you otherwise.

If it ships, here is what it will do and what it will not.

  • It will connect to WPA2-Personal and WPA3-Personal networks the device is already configured for. If the device is already joined to a standard password-protected Wi-Fi network in Windows, the erasure engine will be able to use that same network to complete the wipe, no cable required.

  • It will not connect to corporate (802.1X / enterprise) Wi-Fi. Most managed office networks authenticate each device or user individually rather than using a single shared password. That kind of network is not supported. If a device's only network is a corporate Wi-Fi network, the wipe will not run over that network. Connect a cable or a USB Ethernet adapter, or put the device on a supported network, and queue the wipe again.

  • The failure is safe. If there is no supported network, nothing is erased and the device is left exactly as it was. Depending on which version of the WipeCert launcher the device is running, the wipe either stays queued until a supported connection is available, or is reported as failed with a reason naming the network so you can fix it and queue the wipe again. Neither outcome touches any data on the device.

Corporate sites

Recommended pattern for corporate sites

If your fleet lives on corporate Wi-Fi, the pattern that will work once Wi-Fi support is available is a separate network scoped specifically for wiping. It needs no change to WipeCert, so you can build it now and have it ready. Until then, a wired connection is still required. Stand up a separate network scoped specifically for wiping:

  • A dedicated WPA2-Personal or WPA3-Personal SSID, or a MAC-authenticated VLAN if your network team prefers that model.

  • Isolated and outbound-only. Scope it so it can reach wipecert.com and nothing else on your internal network. It should have no path to anything worth protecting.

  • A pre-shared key you control. Rotate it on whatever schedule you use for other shared keys. What protects you here is the isolation of the network, not the freshness of the key, so isolate it properly first. Do not rotate it while a wipe is already queued: a device that has been staged carries the old key and will not be able to join.

Put the device on that network in Windows before you queue its wipe. This needs no change to the erasure engine, so it will work as soon as Wi-Fi support is available, and it is the pattern we recommend for any site where running a cable to every device is impractical.

Disclosure

What the launcher stores, and for how long

When you queue a wipe on a device that will use Wi-Fi, the WipeCert launcher exports that network's profile, including the password, and writes it into the wipe job file. That file is written in two places: on the Windows system drive, where it is restricted to SYSTEM and local administrators and sits behind whatever disk encryption you already have, and on the device's own boot partition (the small system partition every Windows device already has, used to start the machine), which by its nature has neither. We are telling you this plainly because you should know it: while that file is present, anything that can boot the device could read the password out of it, without needing a Windows account or your disk encryption key.

That exposure is deliberately short. The file is written just before the device restarts, and as soon as the erasure engine has attempted the network connection, whether it succeeded or failed, its first action is to remove the network name and password from the boot-partition copy and to verify the removal by reading the file back. In practice that window is the length of one restart, a few minutes. The copy on the Windows system drive is removed when the launcher finishes with that wipe, and is destroyed with the rest of the drive when the wipe runs.

Two limits worth stating plainly. If the device never reaches the erasure environment, nothing has attempted a connection, so nothing has removed the credential yet; the launcher clears it from the boot partition when it stops working on that wipe. And if the removal itself fails, the erasure engine reports that on screen and continues with the wipe rather than stopping it.

This is exactly why we recommend a dedicated erasure network above: it means the credential that briefly touches that partition is one you built to be worthless if it were ever seen by anyone else.

No cable

No cable? USB Ethernet and phone tethering

If a device has no built-in Ethernet port, either of these counts as a wired connection:

  • A USB or USB-C Ethernet adapter.

  • A phone tethered over its USB cable. A hotspot joined over Wi-Fi does not count; it has to be the USB cable.

One condition either way: plug it in and let Windows finish installing it before you queue the wipe. When the wipe is queued, the launcher copies that specific device's own network drivers into the erasure engine, so anything the device has already used is handled automatically. An adapter or phone the device has never seen has no driver to copy, and the erasure engine will not have one either.

Note

To check a tethered phone before queueing: connect it by cable, open Settings, Network and Internet, and confirm it shows up as Ethernet rather than Wi-Fi. If it says Ethernet, it will work.

Not sure your network fits?

Send us the shape of the segment you want to wipe on and we will tell you whether it works before you queue anything.