Jump to content

Recommended Posts

Posted

Hi folks,

 

I'm trying to setup Bitlocker on the system drive of a laptop. The laptop does not have a TPM chip.

 

Currently the laptop is not on a domain, so I have enabled the ability to set a PIN through local group policy (GPEDIT.MSC).

 

Oddly though when I try and enable bitlocker it's only giving me the option to use a Startup Key. I don't want to use a Startup Key because it's not particularly secure IMO, I'd much rather use a PIN.

 

Is there some trick to permitting usage of a PIN, or something I'm missing?

 

TIA

Posted

AFAIK you can't do this in Win 7:

from BitLocker Drive Encryption Overview

On computers that do not have a TPM version 1.2, you can still use BitLocker to encrypt the Windows operating system drive. However, this implementation will require the user to insert a USB startup key to start the computer or resume from hibernation, and it does not provide the pre-startup system integrity verification offered by BitLocker with a TPM.

This must have been changed in Win 8 as our laptops without TPM can use a PIN.

  • Thanks 1
Posted
if you don't have a tpm which iirc basically stores a certificate you need to store the certificate in some way i.e. a flash drive a pin on its own wont do that's not big enough for an encryption key. You could sort of do it by setting it up with a usb pen then using the 40 digit recovery key as an effective pin number but I cant see that going down well (based on 2008r2/win7 but I think 8/9.1/2012/2012r2 are roughly the same)
  • Thanks 1
Posted

Thanks. Just spotted this also:

 

To use BitLocker to protect an operating system drive on a computer without a TPM, the following option is available:

 

Startup key only. All of the required encryption key information is stored on a USB flash drive. The user must insert the USB flash drive into the computer during startup. The key stored on the USB flash drive unlocks the computer. When the computer does not have a TPM, all of the information required to read the encrypted drive is included in the startup key. Using a TPM is recommended because it helps protect against attacks made against the computer's critical startup process.

 

Learn more about BitLocker Drive Encryption

 

To Win 8.1 I go!

Posted
Thanks. Just spotted this also:

 

To use BitLocker to protect an operating system drive on a computer without a TPM, the following option is available:

 

Startup key only. All of the required encryption key information is stored on a USB flash drive. The user must insert the USB flash drive into the computer during startup. The key stored on the USB flash drive unlocks the computer. When the computer does not have a TPM, all of the information required to read the encrypted drive is included in the startup key. Using a TPM is recommended because it helps protect against attacks made against the computer's critical startup process.

 

Learn more about BitLocker Drive Encryption

 

To Win 8.1 I go!

 

just make sure you add the extra management bits to your server and store the recovery keys in active directory it could save you a lot of hassle down the line when a key gets broken/lost

  • Thanks 1
Posted
just make sure you add the extra management bits to your server and store the recovery keys in active directory it could save you a lot of hassle down the line when a key gets broken/lost

 

^this :p

  • Thanks 2

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...