cancel
Showing results for 
Search instead for 
Did you mean: 
Reply
darcher308
Paper Tape
Posts: 10
Registered: ‎02-25-2014
Location: US
Views: 2,133
Message 1 of 13

Bitlocker - T530 - Docking Station - USB Connected Printer

I have a T530 with a Docking station and a USB connected printer.

The printer is a HP LaserJet Pro 400 color MFP M475dw(CE864A) with a connection for USB Sticks

 

Everytime the laptop is talken off the docking station and powered off then placed back on to the dock and powered by one BitLocker locks.  If the printer is disconnected then there is no issue. 

Has anyone ran into something like with when using bitlocker for encrytion?

-

I did update the Bios and updated the OS and updated the Lenovo system updates as well.

lead_org Microsoft MVP Contributor
Microsoft MVP Contributor
Posts: 21,009
Registered: ‎12-19-2008
Location: Australia, Melbourne
Views: 2,104
Message 2 of 13

Re: Bitlocker - T530 - Docking Station - USB Connected Printer

does the printer cause the same problem when you connect the printer directly to the computer powers it off and then powers it on?
Regards,

Jin Li

May this year, be the year of 'DO'!

I am a volunteer, and not a paid staff of Lenovo or Microsoft
darcher308
Paper Tape
Posts: 10
Registered: ‎02-25-2014
Location: US
Views: 2,090
Message 3 of 13

Re: Bitlocker - T530 - Docking Station - USB Connected Printer

Yes the same thing occurs when the usb cable for the printer is connected directly to the laptop.

It is seeing this model printer as boot device is my guess.

 

Any other ideas with bitlocker.

 

All I can have them do now is to plug in the usb cable after the laptop gets to the Ctrl + Alt + Delete screen

And that can not be the fix for this.

 

All help is appreciated.

darcher308
Paper Tape
Posts: 10
Registered: ‎02-25-2014
Location: US
Views: 2,084
Message 4 of 13

Re: Bitlocker - T530 - Docking Station - USB Connected Printer

Also tested a bootable usb drive.

The Bios is set to have the HD as the first Boot device.

-

Power off the laptop - connected the usb drive and turned on the laptop.

It booted straight into windows.

Rebooted again and still went into windows.

-

If the usb cable for the printer is either connected to the laptop or the docking station it will set off bitloker.

But not after you reset bitlock only if you change something ie.

 - reset bitlocker to not lock with the printer usb cable attached.

 - now power off the laptop - remove it from the dock and power it on - ( no problems goes into Windows  )

 - now power off the laptop - place it back on the docking station - usb for the printer is connected - power it up and

    Bitlocker locks the computer.

lead_org Microsoft MVP Contributor
Microsoft MVP Contributor
Posts: 21,009
Registered: ‎12-19-2008
Location: Australia, Melbourne
Views: 2,073
Message 5 of 13

Re: Bitlocker - T530 - Docking Station - USB Connected Printer

this is to do with the usb slot on the printer.
Regards,

Jin Li

May this year, be the year of 'DO'!

I am a volunteer, and not a paid staff of Lenovo or Microsoft
darcher308
Paper Tape
Posts: 10
Registered: ‎02-25-2014
Location: US
Views: 2,069
Message 6 of 13

Re: Bitlocker - T530 - Docking Station - USB Connected Printer

That was my assumption. you got any ideas around this.????

Lenovo Staff
Lenovo Staff
Posts: 4,830
Registered: ‎10-29-2009
Location: NC
Views: 2,066
Message 7 of 13

Re: Bitlocker - T530 - Docking Station - USB Connected Printer

First, try removing all the USB devices from the boot order in BIOS setup.

 

If that doesn't work, then the only other solution is to find and disable (by experimenting) the PCR that is causing the problem with your printer:

1.  gpedit.msc

2.  local computer policy -> computer configuration -> administrative templates -> windows components -> bitlocker drive encryption -> operating system drives -> configure TPM validation profile

 

Note that you can't change the PCR settings after bitlocker is already enabled.  So you have to disable/decrypt, then change the settings, enable/encrypt/test, etc until you find the setting that works.

 

If I had to guess, it's probably PCR2 option ROM code.

Lenovo Staff
Lenovo Staff
Posts: 4,830
Registered: ‎10-29-2009
Location: NC
Views: 2,065
Message 8 of 13

Re: Bitlocker - T530 - Docking Station - USB Connected Printer

I just remembered that I created a tool a while ago to help debug this type of problem.  Run it from a command prompt with admin rights.

 

It will list the value of all the TPM PCRs.  The idea is to save this output for a successful boot.  Then, attach the printer and do a failed boot (with bitlocker recovery) and run the tool again.  Which PCR is different?

 

Then, modify the policy in gpedit.msc to exclude that PCR.

 

https://dl.dropboxusercontent.com/u/62276273/readPcr.exe

darcher308
Paper Tape
Posts: 10
Registered: ‎02-25-2014
Location: US
Views: 2,035
Message 9 of 13

Re: Bitlocker - T530 - Docking Station - USB Connected Printer

Do I actually need to decrypt the drive or just suspend bitlocker.

 

The exe file worked like a charm showed me which pcr was differnet.

Lenovo Staff
Lenovo Staff
Posts: 4,830
Registered: ‎10-29-2009
Location: NC
Views: 2,031
Message 10 of 13

Re: Bitlocker - T530 - Docking Station - USB Connected Printer

Quote from gpedit.msc:

>> This policy setting does not apply if [...] BitLocker has already been turned on with TPM protection.

 

So you may have to turn off bitlocker, change the policy, and then turn it on again.  suspending bitlocker may not be enough, but I guess you could try it anyway.

 

Which PCR was different based on whether printer is connected or not?  Please share with the forum because it might help someone else with the same problem.

 

Holiday Deals
HAPPENING NOW!

Get the best deals on PCs and tech now during the Holiday Sale
Shop the sale

Top Kudoed Authors