cancel
Showing results for 
Search instead for 
Did you mean: 
Reply
Lenovo Staff
Lenovo Staff
Posts: 5,655
Registered: ‎10-29-2009
Location: NC
Views: 2,320
Message 51 of 79

Re: X270 Bitlocker requests recovery key every time


@kuvinod7 wrote:

It failed again. Without Symantec or Checkpoint, after a Shutdown and start, it is asking for the Recovery key again.


I have no idea how to reproduce this here.  We also have other customers deploying X270 and not reporting this probIem.  I still suspect it is something unique in your deployment, but I really have no idea.  Can you reproduce the issue with a clean-installation of Win7 + drivers, and then manually enable BitLocker from Control Panel (not with MBAM)?  Basically I need step-by-step instructions to see the problem here, in order to help further.

kuvinod7
Punch Card
Posts: 62
Registered: ‎07-19-2017
Location: US
Views: 2,313
Message 52 of 79

Re: X270 Bitlocker requests recovery key every time

We use WinPE 10 for this. So do we need to use the following registry key ?

EncryptionMethodWithXtsFdv

Lenovo Staff
Lenovo Staff
Posts: 5,655
Registered: ‎10-29-2009
Location: NC
Views: 2,310
Message 53 of 79

Re: X270 Bitlocker requests recovery key every time


@kuvinod7 wrote:

We use WinPE 10 for this. So do we need to use the following registry key ?

EncryptionMethodWithXtsFdv


That registry entry is about a new encryption method in Win10, but it's not supported on Win7.  If you were using that encryption method I think BitLocker would not work at all on Win7.  So I think your problem is not about this.

 

DRW1
Fanfold Paper
Posts: 8
Registered: ‎10-02-2015
Location: GB
Views: 2,308
Message 54 of 79

Re: X270 Bitlocker requests recovery key every time

We're still having the issue on T470s with the recovery key prompt on every start-up. I've had some limited success excluding our customer image by doing the following:

 

  1. Deploy default Windows 7 x64 SP1 Enterprise with drivers from support website
  2. Once deployed, bitlocker using 'right-click on c:z drive in My computer' and follow the wizard, saving the key to a usb stick.
  3. shutdown, power on the recoevery key is requested.

BIOS settings:

Security Chip = 1.2,  Active

Secure Boot = Disabled

UEFI/Legacy Boot = Both, CSM = Yes

 

In honesty, the problem only present very rarely  -although if you simply open the BIOS (F1), do not change ANYTHING, then exit without saving, that also seems to trigger a bitlocker recovery request. I'm pretty sure this should nto happen.

 

Customer has reported the issue on BIOS v1.07, 1.11 & 1.13 (Personally seen on 1.07).

Lenovo Staff
Lenovo Staff
Posts: 5,655
Registered: ‎10-29-2009
Location: NC
Views: 2,306
Message 55 of 79

Re: X270 Bitlocker requests recovery key every time

I really think best way to troubleshoot further is to clean-install Win7+drivers manually and then enable BitLocker after that.  If this works, then go back to your TS and figure out which step(s) is causing the problem.  Disable as many steps from TS as possible until BitLocker starts working without that initial recovery prompt.  Then add back the steps to TS 1 at a time.  I know this is time-consuming but I really don't have any ideas.  I do know that our sample SCCM TS, and then enabling BitLocker post-deployment, is working OK here.

DRW1
Fanfold Paper
Posts: 8
Registered: ‎10-02-2015
Location: GB
Views: 2,303
Message 56 of 79

Re: X270 Bitlocker requests recovery key every time

Can you try to view the BIOS (F1), but don't make any changes and just exit on you working test machine with bitlocker enabled and encrypted please?

kuvinod7
Punch Card
Posts: 62
Registered: ‎07-19-2017
Location: US
Views: 2,301
Message 57 of 79

Re: X270 Bitlocker requests recovery key every time

Yes. If i do it, then it prompts me the recovery key

Lenovo Staff
Lenovo Staff
Posts: 5,655
Registered: ‎10-29-2009
Location: NC
Views: 2,295
Message 58 of 79

Re: X270 Bitlocker requests recovery key every time


@DRW1 wrote:

Can you try to view the BIOS (F1), but don't make any changes and just exit on you working test machine with bitlocker enabled and encrypted please?


This is working as designed.  You changed the way the system booted by going into BIOS setup, so then if you simply exit BIOS setup you will get a recovery prompt.  You can get past this by rebooting the system without going into BIOS setup.  For example, at the recovery prompt, press ctrl-alt-del and this time, don't go into BIOS setup.

 

Same thing happens if you press F12 to launch the boot menu, even if you choose to boot to the HDD.  The process of booting to the F12 menu changed the way the system booted.

DRW1
Fanfold Paper
Posts: 8
Registered: ‎10-02-2015
Location: GB
Views: 2,291
Message 59 of 79

Re: X270 Bitlocker requests recovery key every time

Ok, so we only see this the T470, not T460, X250 etc.... is this expected? Is this 'working by design' for the T470? If so then this is a process item we might be able to avoid.....
Lenovo Staff
Lenovo Staff
Posts: 5,655
Registered: ‎10-29-2009
Location: NC
Views: 2,289
Message 60 of 79

Re: X270 Bitlocker requests recovery key every time


@DRW1 wrote:
Ok, so we only see this the T470, not T460, X250 etc.... is this expected? Is this 'working by design' for the T470? If so then this is a process item we might be able to avoid.....

Just now I checked X250, the behavior is exactly the same:

1.  reboot X250

2.  press F1 to enter BIOS setup

3.  from "restart" menu, do "exit discarding changes"

4.  BitLocker recovery screen appears  <-- working as designed

5.  press ctrl-alt-del

6.  this time, DO NOT press F1 to enter BIOS setup

7.  the system boots to Win7 normally (no Bitlocker recovery screen)

Check out current deals!


Shop current deals

Top Kudoed Authors