myITforum and Windows IT Pro Forums

 OSD problem - enable Bitlocker on HP-computers

Author Message
cpierer

  • Total Posts : 63
  • Scores: 0
  • Reward points : 11660
  • Joined: 11/25/2008
  • Status: offline
OSD problem - enable Bitlocker on HP-computers Friday, June 18, 2010 5:09 AM (permalink)
0
Hello,

I just created a tasksequence to deploy windows 7 on a machine and now I stuck in the step activating tpm which i do with the command manage-bde -tpm -turnon, followed by a reboot.
My problem now: When the system is rebooted the Bios prompts me to press F1 to accept the changes made to the tpm settings.
Is there a way to do this unattended? Any possibilities to script this step?

Thx
Chris
<message edited by cpierer on Friday, June 18, 2010 6:12 AM>
 
#1
    cnackers

    • Total Posts : 1437
    • Scores: 63
    • Reward points : 44970
    • Joined: 9/22/2006
    • Location: Madison, WI
    • Status: offline
    Re:OSD problem - enable Bitlocker on HP-computers Friday, June 18, 2010 10:26 AM (permalink)
    0
    are you using the default bitlockers steps in the task sequence or custom steps you created?
    My Blog
    Follow me on Twitter
    Microsoft MVP - System Center Configuration Manager
    Most Valued Community Contributor - 2011



     
    #2
      cpierer

      • Total Posts : 63
      • Scores: 0
      • Reward points : 11660
      • Joined: 11/25/2008
      • Status: offline
      Re:OSD problem - enable Bitlocker on HP-computers Monday, June 21, 2010 1:03 AM (permalink)
      0
      Here the steps in detaol:
      Activate tpm                    -  manage-bde.exe -tpm -TurnOn
      restart              
      create BL partition          - BdeHdCfg.exe -target c: shrink -newdriveletter b: -size 1500 -quiet
      restart
      enable BL                         - Built in step with current os driv, tpm only and AD - no wait

      Chris
       
      #3
        dmkalam

        • Total Posts : 8
        • Scores: 0
        • Reward points : 3340
        • Joined: 8/20/2010
        • Status: offline
        Re:OSD problem - enable Bitlocker on HP-computers Friday, August 20, 2010 1:08 AM (permalink)
        0
        Hi Chris,

        I am having the same problem. Did you resolve it? If yes, can you please let me know how you did it?

        Best Regrads,
        Kalam
        <message edited by dmkalam on Friday, August 20, 2010 2:25 AM>
         
        #4
          stellachilled

          • Total Posts : 2
          • Scores: 0
          • Reward points : 810
          • Joined: 8/13/2010
          • Status: offline
          Re:OSD problem - enable Bitlocker on HP-computers Friday, August 20, 2010 5:13 AM (permalink)
          0
          We are using bitlocker on Vista clients during deployment.  Fortunately for us we have an HP agreement whereby machines are delivered with the BIOS configured for bitlocker (as well as the core WIM already cached on clients)

          What you could do is use the HP SSM Bios configuration tool to set the necessary BIOS settings early on in the task sequence.   We have used this to set the Wireless lan switching setting (as this it yet configured for us inthe HP factory).  We have also used the BIOS update tool to make sure all clients running a minimum BIOS level across the estate.
           
          #5
            dmkalam

            • Total Posts : 8
            • Scores: 0
            • Reward points : 3340
            • Joined: 8/20/2010
            • Status: offline
            Re:OSD problem - enable Bitlocker on HP-computers Saturday, August 21, 2010 4:49 AM (permalink)
            0
            I downloaded the tool, installed and  ran on HP 6930 P in order to enable TPM in BIOS
            firstly I run the following command
            c:\program Files\Hewlett-Packard\SSM>BiosConfigUtility.EXE /GETCONFIG:CONFIG.TXT

            opened the CONFIG.txt
             

            By default, "Embedded Security Device Availability" is Hidden

            I modified the settings as below and made "Embedded Security Device Availability" Available as follows and saved it



            ran the following command to se the settings in BIOS

            Here I got the error message saying "Dependency condition is not Met" and return value is 13 which is " Falied to change setting"

            Can you please advise what am I doing wrong?

            Best Regards
            Kalam

             
            #6
              dmkalam

              • Total Posts : 8
              • Scores: 0
              • Reward points : 3340
              • Joined: 8/20/2010
              • Status: offline
              Re:OSD problem - enable Bitlocker on HP-computers Tuesday, August 24, 2010 9:57 PM (permalink)
              0
              I have solved the problems . Please let me know if you need to know how I did it.
               
              #7
                jconnor

                • Total Posts : 55
                • Scores: 0
                • Reward points : 21930
                • Joined: 1/22/2009
                • Status: offline
                Re:OSD problem - enable Bitlocker on HP-computers Thursday, August 26, 2010 1:13 AM (permalink)
                0
                dmkalam were you able to make C:\Windows\System32\manage-bde.exe -tpm -turnon silent?
                Ours is disabled now due to another issue but we ended up putting this near the end when it was on.
                 
                #8
                  Barker

                  • Total Posts : 86
                  • Scores: 30
                  • Reward points : 19040
                  • Joined: 8/26/2010
                  • Location: St. Paul, MN
                  • Status: offline
                  Re:OSD problem - enable Bitlocker on HP-computers Thursday, August 26, 2010 9:45 AM (permalink)
                  0
                  I've been fighting the same problem and I don't think there is a method to Turn on and active the TPM without going through the BIOS at some point.  I'm actually looking at using a modified WinPE with a shortcut that runs manage-bde.exe -tpm -turnon and then reboot the machine to actually turn it on the in BIOS and then boot back into WinPE to run the Task Sequence.  If you find a better way, please post because I'd love to use it myself.
                   
                  #9
                    crobl

                    • Total Posts : 63
                    • Scores: 2
                    • Reward points : 10630
                    • Joined: 12/22/2004
                    • Status: offline
                    Re:OSD problem - enable Bitlocker on HP-computers Thursday, August 26, 2010 6:04 PM (permalink)
                    0
                    dmkalam


                    I have solved the problems . Please let me know if you need to know how I did it.


                    Yes, please.
                     
                    #10
                      dmkalam

                      • Total Posts : 8
                      • Scores: 0
                      • Reward points : 3340
                      • Joined: 8/20/2010
                      • Status: offline
                      Re:OSD problem - enable Bitlocker on HP-computers Thursday, September 02, 2010 7:18 PM (permalink)
                      0
                      Sorry for late response.
                      @jconnor, not possible to run it silently

                      @Barker and Crobl
                      Please post your email address, I will send it by email as it has multiple files.
                      Best Regards,
                      Kalam
                       
                      #11
                        crobl

                        • Total Posts : 63
                        • Scores: 2
                        • Reward points : 10630
                        • Joined: 12/22/2004
                        • Status: offline
                        Re:OSD problem - enable Bitlocker on HP-computers Friday, September 03, 2010 11:33 AM (permalink)
                        0
                        cyrus dot robl at gmail dot com
                         
                        #12
                          zaez

                          • Total Posts : 1
                          • Scores: 0
                          • Reward points : 720
                          • Joined: 11/15/2010
                          • Status: offline
                          Re:OSD problem - enable Bitlocker on HP-computers Tuesday, November 16, 2010 9:36 AM (permalink)
                          0
                          Hi  Kalam,
                          can you please let me know how you solved it ( dimagon at gmx dot at)?
                          THX,
                          Dima
                           
                          #13
                            npherson

                            • Total Posts : 398
                            • Scores: 59
                            • Reward points : 74620
                            • Joined: 8/19/2009
                            • Location: Saint Paul, Minnesota
                            • Status: offline
                            Re:OSD problem - enable Bitlocker on HP-computers Tuesday, November 16, 2010 11:15 AM (permalink)
                            0
                            First and foremost, your task sequence should be updating the HP BIOS.  All the HP laptops, desktops, and workstations we use have fixes for either BitLocker directly, or for the BiosConfigUtility.exe used to change the TPM settings.  We have the BIOS upgrade steps right at the start of our Task Sequence.  Basically, it is just a Group that runs if manufacturer=Hewlett-Packard, a step to remove the BIOS password, and a Run Command Line steps that upgrade the BIOS using a package.  (Alternately, you can include a password file with the BIOS rather than removing the password.)

                            In the State Restore group, we have a package that sets the BIOS password and applies the BIOS settings for the TPM so it silently activates on next reboot.  After the reboot, we have a step to take ownership of the TPM using mange-bde.exe and then the Enable BitLocker step.

                            You need to check the BiosConfigUtility.exe /GetConfig file for each of your models (after you have upgraded the BIOS) as some of the settings have different names on different models.  You can use one config file for all of the models - the utility ignores settings that don't exist on that particular model.  Be sure the order of changes in the config file makes sense - you can't change the Embedded Security Activation Policy if the Embedded Security Device is not Available.    Be sure you have a BIOS password set before doing /SetConfig, as most security settings cannot be changed if no password is set.  Refer to the documentation that comes for HP SSM for all the command line switches and about the config file.

                            (Side Note:  If you have a bunch of BitLocker-enabled machines that keep prompting for the recovery code, then check to ensure you are running the latest BIOS!  You can upgrade the BIOS of a BitLocker-enabled machine after suspending the protectors with 'manage-bde.exe -protectors -disable C:'.  This allows you to access the hard drive but doesn't actually go through the long process of decrypting.  After rebooting, you can do 'manage-bde -protectors -enable C:'. )   



                            Nash
                            <message edited by npherson on Monday, March 19, 2012 11:19 AM>
                             
                            #14
                              Dimitri

                              • Total Posts : 1
                              • Scores: 0
                              • Reward points : 100
                              • Joined: 3/19/2012
                              • Status: offline
                              Re:OSD problem - enable Bitlocker on HP-computers Monday, March 19, 2012 9:14 AM (permalink)
                              0
                              thx for the information !
                               
                              #15
                                hcortez463

                                • Total Posts : 1144
                                • Scores: 95
                                • Reward points : 26830
                                • Joined: 4/8/2005
                                • Status: offline
                                Re:OSD problem - enable Bitlocker on HP-computers Wednesday, March 21, 2012 3:09 PM (permalink)
                                If it Helps, Please rate....
                                 
                                #16
                                  Online Bookmarks Sharing: Share/Bookmark

                                  Jump to:

                                  Current active users

                                  There are 0 members and 2 guests.

                                  Icon Legend and Permission

                                  • New Messages
                                  • No New Messages
                                  • Hot Topic w/ New Messages
                                  • Hot Topic w/o New Messages
                                  • Locked w/ New Messages
                                  • Locked w/o New Messages
                                  • Read Message
                                  • Post New Thread
                                  • Reply to message
                                  • Post New Poll
                                  • Submit Vote
                                  • Post reward post
                                  • Delete my own posts
                                  • Delete my own threads
                                  • Rate post

                                  2000-2014 ASPPlayground.NET Forum Version 3.9