<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.technet.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Digging in : Bitlocker</title><link>http://blogs.technet.com/ganand/archive/tags/Bitlocker/default.aspx</link><description>Tags: Bitlocker</description><dc:language>en-US</dc:language><generator>CommunityServer 2.1 SP1 (Build: 61025.2)</generator><item><title>You will not get the option to reset Pin in bitlocker when using TPM+PIN+StartupKey protectors in vista sp1</title><link>http://blogs.technet.com/ganand/archive/2008/04/26/you-will-not-get-the-option-to-reset-pin-in-bitlocker-when-using-tpm-pin-startupkey-protectors-in-vista-sp1.aspx</link><pubDate>Sat, 26 Apr 2008 12:17:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3045259</guid><dc:creator>ganand</dc:creator><slash:comments>1</slash:comments><comments>http://blogs.technet.com/ganand/comments/3045259.aspx</comments><wfw:commentRss>http://blogs.technet.com/ganand/commentrss.aspx?PostID=3045259</wfw:commentRss><description>&lt;P&gt;Aah i dont write blogs in such a nice format but this was written for an&amp;nbsp;another document and i am putting same copy-paste here to save time.Hope this helps.&lt;/P&gt;
&lt;P&gt;=======&lt;/P&gt;
&lt;P&gt;SYMPTOMS&lt;BR&gt;&lt;BR&gt;When you are using TPM+PIN+StartupKey protector on vista sp1 bitlocker enabled vista client you will not get the option to reset the pin when you go to Bitlocker drive encryption applet in control panel. The only option you receive when you choose "select keys to manage" is duplicate the recovery passowrd.&lt;BR&gt;&lt;BR&gt;CAUSE&lt;BR&gt;&lt;BR&gt;This is by design. Please use manage-bde.wsf to delete the exiting TPM+PIN+StartupKey protector and then add a new one if you need to reset the PIN. The GUI shows resetting PIN option only when there is a TPM+PIN protector.&lt;BR&gt;&lt;BR&gt;RESOLUTION&lt;BR&gt;&lt;BR&gt;1 Open the command prompt with administrator privilege.&lt;BR&gt;2 Type:- cd c:\windows\system32&lt;BR&gt;3 Type:- cscript manage-bde.wsf -protectors -delete c: (where c: is the volume being protected)&lt;BR&gt;4 This command will remove all key protectors unless you provide additional parameters.&lt;BR&gt;5 Press enter&lt;BR&gt;6 Type :- cscript manage-bde.wsf -protectors -add (volume to be protected, for eg. c: ) -rp -rk (volume to store recovery key, for eg. f:) -tpsk -tp (pin that you want to be set for eg. 1234) -tsk (volume where you want to store the startup key for eg. g:)&lt;BR&gt;7 Finally the command will appear as:- cscript manage-bde.wsf -protectors -add c: -rp -rk f: -tpsk -tp 1234 -tsk g:&lt;BR&gt;8 You have sucessfully reset the pin.&lt;BR&gt;&lt;BR&gt;======&lt;/P&gt;
&lt;P&gt;The Information provided here is "AS IS"&lt;/P&gt;
&lt;P&gt;&amp;nbsp;Gaurav Anand&lt;/P&gt;
&lt;P mce_keep="true"&gt;&amp;nbsp;&lt;/P&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3045259" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/ganand/archive/tags/Bitlocker/default.aspx">Bitlocker</category></item><item><title>Group Policies regarding Bitlocker and TPM</title><link>http://blogs.technet.com/ganand/archive/2007/10/08/group-policies-regarding-bitlocker-and-tpm.aspx</link><pubDate>Mon, 08 Oct 2007 13:32:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:2134232</guid><dc:creator>ganand</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.technet.com/ganand/comments/2134232.aspx</comments><wfw:commentRss>http://blogs.technet.com/ganand/commentrss.aspx?PostID=2134232</wfw:commentRss><description>&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT face="Times New Roman" size=3&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;?xml:namespace prefix = o ns = "urn:schemas-microsoft-com:office:office" /&gt;&lt;o:p&gt;&lt;FONT face="Times New Roman" size=3&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt; 
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;o:p&gt;&lt;FONT face="Times New Roman"&gt;&lt;FONT size=3&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT color=#1f497d&gt;&lt;FONT face=Calibri&gt;Last time we talked about what TPM is and how it works and also about clean boot of pcr’s. This time I will like to throw some light on group policies involved with bitlocker.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT color=#1f497d&gt;&lt;FONT face=Calibri&gt;I will only talk about a few and not all. There is a group policy which if enabled makes user to store backup recovery information in AD which later helps in recovering the OS partition by the help of help desk admin. By default this group policy is enabled but we can disable it too. If due to some problem when you are in the process of enabling bitlocker and unable to access DC, you will get an error message and it won’t let you to enable bitlocker as it is not able to see DC and won’t be able to store backup recovery information. There are few options with this group policy…. Require bitlocker backup to AD DS. If this is unselected you will be able to enable bitlocker even if unable to see DC but will get an event logged on and no error message to the user. You can backup recovery passwords or key packages or both and TPM owner password hash too. You can also choose encryption algorithm and key size but by default it is AES 128-bit with diffuser. I will try to explain what we mean by diffuser in one of the next entries. There is another group policy which makes user to use multi factor authentication which is TPM + pin or TPM + startup key on USB. With longhorn bitlocker (also with vista sp1) you will be able to use TPM+ pin+ USB too. Similarly there are few other group policies for TPM like turn on TPM owner password backup to AD, by default this policy is enabled. You can also block a few TPM commands with another group policy. &lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;o:p&gt;&lt;FONT face=Calibri color=#1f497d size=3&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT color=#1f497d&gt;&lt;FONT face=Calibri&gt;Computer configuration-administrative templates-windows components-bitlocker drive encryption&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;o:p&gt;&lt;FONT face=Calibri color=#1f497d size=3&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT color=#1f497d&gt;&lt;FONT face=Calibri&gt;Computer configuration-administrative templates-system-trusted platform module services. &lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT face=Calibri color=#1f497d size=3&gt;&lt;/FONT&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT face=Calibri color=#1f497d size=3&gt;Gaurav Anand&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT face=Calibri color=#1f497d size=3&gt;------------------------------&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT color=#1f497d&gt;&lt;FONT face=Calibri&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&amp;nbsp;&lt;/P&gt;&lt;FONT size=+0&gt;&lt;FONT color=#1f497d&gt;&lt;FONT face=Calibri&gt;&lt;o:p&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;This posting is provided "AS IS" with no warranties, and confers no rights.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/o:p&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=2134232" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/ganand/archive/tags/Bitlocker/default.aspx">Bitlocker</category></item></channel></rss>