Support in other languages: 
Showing results for 
Search instead for 
Do you mean 
Reply
Blue Screen Again
rxleon912
Posts: 2
Registered: ‎10-13-2011
Location: Miami, FL
0
Accepted Solution

URGENT: T420s BIOS v1.29 and PGP Whole Disk Encryption

ATTENTION!!!

 

I have multiple T420s laptops (4174-2AU). I recently upgraded 2 of those laptop to the latest BIOS (v1.29). Those two laptops were no longer able to access the encrypted drive.

-----------------------------------------------------------

bootguard stage2...

 

PGPWDE disk data are corrupted...

system halted..

----------------------------------------------------------

 

My corporation does not use recovery disks, for what reason I don't know. All I DO know is that I had to reimage the drives. I attempted to encrypt again and rebooted and received the same error again. So I re-imaged again and didn't encrypt the drive. Other posts say it has to do with the PGP and the Sandy Bridge architecture, but I disagree. I was able to downstep the BIOS using Lenovo's FLASH tools. I went down to v1.25 (Download) and THEN encrypted the drive again. After reboot there was no issue.

 

I hope no one else encounters this problem. If you do, here's your solution.

 

To Lenovo Support:

 

PLEASE ADDRESS THIS ISSUE BEFORE IT AFFECTS TOO MANY PEOPLE!!!!

 

 

Regard,

Rick

Retired Employee
JameZ
Posts: 3,110
Registered: ‎07-11-2010
Location: Malaysia
0

Re: URGENT: T420s BIOS v1.29 and PGP Whole Disk Encryption

@rxleon912,

Appreciate if you can drop me a private message with the following so I can get a case going with engineering on this issue.

Name:
Mobile:
Email:
Company:

MTM:
S/N:

BIOS: 1.29 downgrade to 1.25 (works fine?)
Encryption software: PGP Whole Disk?

Windows 7: Ulti/Pro/Enterprise:
64bit/32bit:
ACHI?

//JameZ

Check out the Community Knowledge Base for hints and tips.


Did someone help you today? Press the star on the left to thank them with a Kudo!

If you find a post helpful and it answers your question, please mark it as an "Accepted Solution"!




W520 | 4176-38U | i7 - 2720QM | Quardo 1000M | 8GB RAM | 60GB OCZ Agility 3

Retired Employee
JameZ
Posts: 3,110
Registered: ‎07-11-2010
Location: Malaysia
0

Re: URGENT: T420s BIOS v1.29 and PGP Whole Disk Encryption

@rxleon912,

Engineering are aware of this issue and they are looking into it. They have advice that you can downgrade to 1.26 instead of 1.25.

Please scroll down this page to find version 1.26.

http://support.lenovo.com/en_US/downloads/detail.page?DocID=DS018884

//JameZ

Check out the Community Knowledge Base for hints and tips.


Did someone help you today? Press the star on the left to thank them with a Kudo!

If you find a post helpful and it answers your question, please mark it as an "Accepted Solution"!




W520 | 4176-38U | i7 - 2720QM | Quardo 1000M | 8GB RAM | 60GB OCZ Agility 3

802.11n
wditters
Posts: 156
Registered: ‎07-30-2009
Location: Netherlands
0

Re: URGENT: T420s BIOS v1.29 and PGP Whole Disk Encryption

I have no experience with that product but what I do know is that with Bitlocker, any configuration change *including* a BIOS upgrade should in every case be preceded by temporary disabling Bitlocker for the purpose of this configuration change. It says so in all the manuals and it offers the possibility in the settings panel. After the upgrade one can enable Bitlocker again to accept the new configuration.

 

Could this by any chance also be the case with this particular product?

Lenovo Premium Business Partner
X1 Carbon Touch | i7-3667U | 8Gb | 256Gb | HD 4000 | 14HD+ | WWAN | W8.1 Pro RTM x64 |
Lenovo Staff
someotherguy
Posts: 2,507
Registered: ‎10-29-2009
Location: NC
0

Re: URGENT: T420s BIOS v1.29 and PGP Whole Disk Encryption


wditters wrote:

I have no experience with that product but what I do know is that with Bitlocker, any configuration change *including* a BIOS upgrade should in every case be preceded by temporary disabling Bitlocker for the purpose of this configuration change. It says so in all the manuals and it offers the possibility in the settings panel. After the upgrade one can enable Bitlocker again to accept the new configuration.

 

Could this by any chance also be the case with this particular product?


No, bitlocker is unique because it uses the TPM and a measurement of the system which includes a hash of the BIOS area.  When the BIOS changes, then so does the bitlocker measurement and this causes the bitlocker key not to load anymore (and a recovery method is needed).  The software encryption tools, such as PGP, Sophos, WinMagic, etc do not use the TPM and therefore are not affected by BIOS changes the way that bitlocker is.

 

This problem with PGP is something completely different.

802.11n
wditters
Posts: 156
Registered: ‎07-30-2009
Location: Netherlands
0

Re: URGENT: T420s BIOS v1.29 and PGP Whole Disk Encryption

Good to know but a shame for RXLeon

Lenovo Premium Business Partner
X1 Carbon Touch | i7-3667U | 8Gb | 256Gb | HD 4000 | 14HD+ | WWAN | W8.1 Pro RTM x64 |
Blue Screen Again
rxleon912
Posts: 2
Registered: ‎10-13-2011
Location: Miami, FL
0

Re: URGENT: T420s BIOS v1.29 and PGP Whole Disk Encryption


JameZ wrote:
@rxleon912,

Engineering are aware of this issue and they are looking into it. They have advice that you can downgrade to 1.26 instead of 1.25.

Please scroll down this page to find version 1.26.

http://support.lenovo.com/en_US/downloads/detail.page?DocID=DS018884

//JameZ

JameZ...

 

The link points to BIOS files for a W520 not a T420 like these laptops are.

 

Please advise.

 

Thanks...

 

802.11n
wditters
Posts: 156
Registered: ‎07-30-2009
Location: Netherlands
0

Re: URGENT: T420s BIOS v1.29 and PGP Whole Disk Encryption

See bottom of the following page for all past BIOS versions:

 

http://support.lenovo.com/en_US/downloads/detail.page?LegacyDocID=MIGR-77010

 

Cheers Willem

 

Lenovo Premium Business Partner
X1 Carbon Touch | i7-3667U | 8Gb | 256Gb | HD 4000 | 14HD+ | WWAN | W8.1 Pro RTM x64 |
What's DOS?
stephen_renaud
Posts: 1
Registered: ‎10-20-2011
Location: Charleston, SC
0

Re: URGENT: T420s BIOS v1.29 and PGP Whole Disk Encryption

I have run into the same problem on a Lenovo X220. Can you please provide the link to downgrade the Bios. Thanks.

Paper Tape
Steve_Renaud
Posts: 5
Registered: ‎10-20-2011
Location: Charelston, SC
0

Re: URGENT: T420s BIOS v1.29 and PGP Whole Disk Encryption

Sorry, I just upgraded to UEFI BIOS Version 8DET51WW (1.21) on a Lenovo X220 tablet (4298-B49). Please provide the link to the previous version as soon as possible. Thank you.