Windows Vista Forums
Vista Forums Home Join Vista Forums Donate Vista Tutorials Tags

Welcome to Vista Forums we are your forum to discuss Windows Vista x64 and x86 systems. Whether you need help or just want to post an idea you have on Vista, this is the forum for you.
Register at Vista forums...the world biggest Windows Vista resource Join Vista Forums Now

Go Back   Vista Forums > Vista Newsgroups > Vista security

Bitlocker and TMP

Update your Vista Drivers Update Your Drivers Now!!
Closed Thread
 
Thread Tools Display Modes
Old 06-13-2007   #1 (permalink)
Tazinfo
Guest


 

Bitlocker and TMP

I have a machine with a TMP 1.2 that will allow Bitlocker to be turned on.
However, I would like to use only a USB to Bitlock the system partition. I
enabled USB through the Group Policies, but it appears that I can only use
the USB in conjunction with the TPM. I was told that there is a Registry
setting that can allow me to use only the USB even though there is an enabled
TPM 1.2 chip on the board. Is there such a setting and what is it?

Alternatively, I imagine that I could disable the TPM in the BIOS, but I
haven't tried this as it would be my least desired method.

Any help appreciated.

My System SpecsSystem Spec
Old 06-13-2007   #2 (permalink)
Richard
Guest


 

Re: Bitlocker and TMP

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Tazinfo wrote:

> I have a machine with a TMP 1.2 that will allow Bitlocker to be turned on.
> However, I would like to use only a USB to Bitlock the system partition. I
> enabled USB through the Group Policies, but it appears that I can only use
> the USB in conjunction with the TPM. I was told that there is a Registry
> setting that can allow me to use only the USB even though there is an enabled
> TPM 1.2 chip on the board. Is there such a setting and what is it?
>
> Alternatively, I imagine that I could disable the TPM in the BIOS, but I
> haven't tried this as it would be my least desired method.
>
> Any help appreciated.


I think you need to disable the TMP so bitlocker cannot see it.
I don't understand why you don't want to disable it if you are sure you
don't want to use it?
BTW I use bitlocker with a usb key...works great.




-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.7 (MingW32)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org

iD8DBQFGcCHBqDp2fu862vwRAsChAKCLLG0Na+RzRxhLkyS7HKrxA9qgkgCfflfm
DHA9lXu68yiS0PU6e4ioc9o=
=hmFu
-----END PGP SIGNATURE-----
My System SpecsSystem Spec
Old 06-13-2007   #3 (permalink)
Tazinfo
Guest


 

Re: Bitlocker and TMP



"Richard" wrote:

>
> I think you need to disable the TMP so bitlocker cannot see it.
> I don't understand why you don't want to disable it if you are sure you
> don't want to use it?
> BTW I use bitlocker with a usb key...works great.



Thanks,

I tried that both in the BIOS and through the TPM Management (from the
Bitlocker screen). When I click "Turn on Bitlocker," I get the message
telling me that this computer requires the TPM to be enabled. BTW, in the
Group Policy, I disallowed "startup key with TPM" and "startup PIN with TPM."

I have used Bitlocker with a USB key on other machines and it does work great.
My System SpecsSystem Spec
Old 06-13-2007   #4 (permalink)
Richard
Guest


 

Re: Bitlocker and TMP

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Tazinfo wrote:
>
> "Richard" wrote:
>
>> I think you need to disable the TMP so bitlocker cannot see it.
>> I don't understand why you don't want to disable it if you are sure you
>> don't want to use it?
>> BTW I use bitlocker with a usb key...works great.

>
>
> Thanks,
>
> I tried that both in the BIOS and through the TPM Management (from the
> Bitlocker screen). When I click "Turn on Bitlocker," I get the message
> telling me that this computer requires the TPM to be enabled. BTW, in the
> Group Policy, I disallowed "startup key with TPM" and "startup PIN with TPM."
>
> I have used Bitlocker with a USB key on other machines and it does work great.


Sorry, then I cannot help further.
I thought you would be able to disable the TPM in the BIOS.



-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.7 (MingW32)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org

iD8DBQFGcEMcqDp2fu862vwRAqTfAKCEGV8ofcui1hGyjSve4q1lNVZZaACfWLCy
LsrCCJy1EFLVTwttk1avtIE=
=waIH
-----END PGP SIGNATURE-----
My System SpecsSystem Spec
Old 06-13-2007   #5 (permalink)
Tazinfo
Guest


 

Re: Bitlocker and TMP



"Richard" wrote:


> Sorry, then I cannot help further.
> I thought you would be able to disable the TPM in the BIOS.
>


Thanks anyway. My curent thought is that the TPM was enabled when I
installed VISTA and a Registry was set indication a compatible TPM is present
in the machine. I could try to re-install VISTA with the TPM in the disabled
state and see if that makes a difference, but if I can find any such Registry
key, it would save me the effort.
My System SpecsSystem Spec
Old 06-13-2007   #6 (permalink)
Dennis Pack
Guest


 

Re: Bitlocker and TMP

Tazinfo:
If you go into gpedit.msc, Windows Components, BitLocker drive
encryption, right click control panel setup: enable advanced startup
options, properties. You should be able create or skip TPM options. Have a
great day.

--
Dennis Pack
XP x64, Vista Enterprise x64
Office Prof. Plus 2007
"Tazinfo" <Tazinfo@discussions.microsoft.com> wrote in message
news:9E68EBA5-43B9-4F0E-9756-465C088C3415@microsoft.com...
>
>
> "Richard" wrote:
>
>
>> Sorry, then I cannot help further.
>> I thought you would be able to disable the TPM in the BIOS.
>>

>
> Thanks anyway. My curent thought is that the TPM was enabled when I
> installed VISTA and a Registry was set indication a compatible TPM is
> present
> in the machine. I could try to re-install VISTA with the TPM in the
> disabled
> state and see if that makes a difference, but if I can find any such
> Registry
> key, it would save me the effort.


My System SpecsSystem Spec
Old 06-16-2007   #7 (permalink)
Robert Kochem
Guest


 

Re: Bitlocker and TMP

Tazinfo schrieb:

> I have a machine with a TMP 1.2 that will allow Bitlocker to be turned on.
> However, I would like to use only a USB to Bitlock the system partition. I
> enabled USB through the Group Policies, but it appears that I can only use
> the USB in conjunction with the TPM. I was told that there is a Registry
> setting that can allow me to use only the USB even though there is an enabled
> TPM 1.2 chip on the board. Is there such a setting and what is it?


That should not be a big problem if you use the manage-bde.wsf script on
the command-line instead of this incomplete GUI. With this scriipt you can
add/delete as many "protectors" (passwords, externals keys or tpm based
keys for starting up) as you want.

Robert
My System SpecsSystem Spec
Closed Thread

Thread Tools
Display Modes



Similar Threads
Thread Thread Starter Forum Replies Last Post
SSD and Bitlocker Devin Barkley Vista security 1 08-28-2008 06:35 PM
Restored Factory Settings on Laptop that had BitLocker - Now want to do bitlocker again Blake Mengotto Vista General 0 08-24-2008 03:39 PM
bitlocker Ponch Vista security 1 10-10-2007 01:49 PM
Bitlocker =?Utf-8?B?T3IgVHNlbWFo?= Vista security 6 09-08-2006 01:13 AM
Bitlocker bug Vipin Vista security 2 07-21-2006 03:20 PM


Vistax64.com is an independent web site and has not been authorized,
sponsored, or otherwise approved by Microsoft Corporation.
"Windows Vista", the Start Orb, and related materials are trademarks of Microsoft Corp.
© Designer Media 2005-2008

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51