




已阅读5页,还剩13页未读, 继续免费阅读
版权说明:本文档由用户提供并上传,收益归属内容提供方,若内容存在侵权,请进行举报或认领
文档简介
Title : Enable BitLocker on deployed laptop without TPMCreation Date:24 Nov 2010Last Modification:11 11月 2013Ref.: CUW-P024Author:CUW Core TeamPrint Date:28 1月 2020Procedure: Enable BitLocker on deployed laptopWithout TPMDocument ReferenceCUW-P024Document StatusIn preparation To be Validated Validated Other (specify)ValidationNameZoneFunctionDateVersion HistoryNDateAuthorEvolution reason0.125/10/2011Cdric GasnierDocument Creation125/10/2011Cdric GasnierDocument modification1.210/12/2012CUWDocument modification1.323/04/2013Arnaud HenriDocument modification1.3.123/05/2013Arnaud HenriDocument modification1.3.207/11/2013Arnaud HenriDocument modificationTable of Contents1.Context42.Requirements43.Procedure5a.Enable BitLocker5b.Secure USB key method8c.Secure USB key method (alternative)12d.Reset recovery password15e.If Script launch twice15f. If BDE partition is not prepared164.User Notice16This document is part of the CUW project which aims at providing a global master to all Air Liquide employees based on Windows 7.1. ContextThe goal of this procedure is to describe actions to follow in order to configure BitLocker on laptop without TPM that already have CUW master installed.At the end of the procedure, the laptop will have BitLocker enabled.2. RequirementsBefore starting the process, You must have an account having local admin rights. For laptop, you must plug in the computer to power adapter. Make sure that the computer is connected to network via an Ethernet cable. You must have a USB that will be used as Startup Key for the user. Download all PS1 and EXE files for BitLocker activation at the following link: /livelink/llisapi.dll?func=ll&objId=19800884&objAction=browse&viewType=1 Backup all important user data before encryption.CautionNote: If a Secure USB Key as AEGIS model is used, please refer to Secure USB Key method section.3. Procedurea. Enable BitLocker#ActionScreenshot1Log onto the computer with a local administrator account.2Execute setup.bat from the USB key to copy folders to C:_INSTALLBitLocker3Navigate to C:_INSTALLBitLockerNO_TPM and validate that the following script are available: 1ActivationBitlocker.cmd 2ResumeSecondDriveEncryption.cmd ErrorBitlocker.ps1 MsgStatusEncryption.ps1 ResumeSecondDriveEncryption.ps1 SecondDriveEncryption.ps1 StartEncryptionnoTPM.ps1Note: If these scripts are not available, download them at the following link /livelink/llisapi.dll?func=ll&objId=18530918&objAction=browse&viewType=1 and copy them to C:_INSTALLBitLockerNO_TPM4Insert the USB key that will be used as Startup Key and check that it is using F letter5Open a command prompt with administrative privileges (right click + Run as administrator)Navigate to C:_INSTALLBitLockerNO_TPM6Launch the following script using the command prompt:1ActivationBitlocker.cmdNote: The script may fall in error due to the GPO not applied. If it happens launch the script a second time. The startup key inserted is the one youll have to use.7A windows appears noticing that a log file be created in C:_installBitLockerBitLocker_Logs.logClick on OK8An second windows appears:Click on OK9The laptop will restart automatically10When the laptop reboots, the startup key has to be already connected to enable bitlocker. Log-in and wait for the encryption to start againYou can click on the popup for open the dialog box.The encryption of D drive has been scheduled before the reboot of the computer.Once done, D drive encryption will start then will be paused.Encryption of D drive will resume once C drive encryption will be complete.Scheduled task checks every 10 minutes the completion of C drive encryption.11The encryption progress silently and can take up to several hours. Type manage-bde.exe status to know the progress of the encryption.12You can also verify the encryptions progress by opening the following log file: C:_installBitLockerNO_TPMBitLocker_Status.log13At the end of the encryption, the bitlocker window will be:14D drive encryption startsb. Secure USB key method#ActionScreenshot1Log onto the computer with a local administrator account.2Navigate to C:_INSTALLBitLockerNO_TPM and validate that the following script are available: 1ActivationBitlocker.cmd 2ResumeSecondDriveEncryption.cmd ErrorBitlocker.ps1 MsgStatusEncryption.ps1 ResumeSecondDriveEncryption.ps1 SecondDriveEncryption.ps1 StartEncryptionnoTPM.ps1Note: If these scripts are not available, download them at the following link /livelink/llisapi.dll?func=ll&objId=19800884&objAction=browse&sort=name&viewType=-1 and copy them to C:_INSTALLBitLockerNO_TPM3Insert the normal USB key that will be used as Startup Key and check that it is using F: letter4Open a command prompt with administrative privileges (right click + Run as administrator)Navigate to C:_INSTALLBitLockerNO_TPM5Launch the following script using the command prompt:1ActivationBitlocker.cmdNote: The script may fall in error due to the GPO not applied. If it happens launch the script a second time. The startup key inserted is the one youll have to use.6A windows appears noticing that a log file be created in C:_installBitLockerBitLocker_Logs.logClick on OK7An second windows appears:Click on OK8The laptop will restart automatically.9Before laptop rebooting, shutdown it.10From another computer, plug the normal USB key then modify folder options to show hidden files.Open a Windows Explorer window, click the Organize link in the toolbar, and from there click on Folder and Search options. The Hidden files and folders options are to be found on the View tab under Advanced Settings.Under theHidden files and folderssection select the radio button labeledShow hidden files, folders, and drives.Remove the checkmark from the checkbox labeledHide protected operating system files (Recommended).Press theApplybutton and then theOKbutton.You will now able to see all hidden files on your USB key as .BEK file(s).11Copy .BEK created from normal USB key to Secure USB Key.12Unlock your Secure USB key then plug it to the laptop.13Power on the laptop in 30 seconds.14When the laptop reboots, the startup key has to be already connected to enable bitlocker. Log-in and wait for the encryption to start againYou can click on the popup for open the dialog box.The encryption of D drive has been scheduled before the reboot of the computer.Once done, D drive encryption will start then will be paused.Encryption of D drive will resume once C drive encryption will be complete.Scheduled task checks every 10 minutes the completion of C drive encryption.15The encryption progress silently and can take up to several hours. Type manage-bde.exe status to know the progress of the encryption.16You can also verify the encryptions progress by opening the following log file: C:_installBitLockerNO_TPMBitLocker_Status.log17At the end of the encryption, the bitlocker window will be:18D drive encryption startsc. Secure USB key method (alternative)#ActionScreenshot1Log onto the computer with a local administrator account.2Navigate to C:_INSTALLBitLockerNO_TPM and validate that the following script are available: 1ActivationBitlocker.cmd 2ResumeSecondDriveEncryption.cmd ErrorBitlocker.ps1 MsgStatusEncryption.ps1 ResumeSecondDriveEncryption.ps1 SecondDriveEncryption.ps1 StartEncryptionnoTPM.ps1Note: If these scripts are not available, download them at the following link /livelink/llisapi.dll?func=ll&objId=19800884&objAction=browse&sort=name&viewType=-1 and copy them to C:_INSTALLBitLockerNO_TPM3Insert the Secure USB key that will be used as Startup Key and check that it is using F: letter4Open a command prompt with administrative privileges (right click + Run as administrator)Navigate to C:_INSTALLBitLockerNO_TPM5Launch the following script using the command prompt:1ActivationBitlocker.cmdNote: The script may fall in error due to the GPO not applied. If it happens launch the script a second time. The startup key inserted is the one youll have to use.6A windows appears noticing that a log file be created in C:_installBitLockerBitLocker_Logs.logClick on OK7An second windows appears:Click on OK8The laptop will restart automatically.9Before laptop rebooting, shutdown it.10Unlock your Secure USB key then plug it to the laptop.11Power on the laptop in 30 seconds.12When the laptop reboots, the startup key has to be already connected to enable bitlocker. Log-in and wait for the encryption to start againYou can click on the popup for open the dialog box.The encryption of D drive has been scheduled before the reboot of the computer.Once done, D drive encryption will start then will be paused.Encryption of D drive will resume once C drive encryption will be complete.Scheduled task checks every 10 minutes the completion of C drive encryption.13The encryption progress silently and can take up to several hours. Type manage-bde.exe status to know the progress of the encryption.14You can also verify the encryptions progress by opening the following log file: C:_installBitLockerNO_TPMBitLocker_Status.log15At the end of the encryption, the bitlocker window will be:16D drive encryption startsd. Reset recovery password1Open a command prompt with administrative privileges (right click + Run as administrator)Navigate to C:_INSTALLBitLockerNO_TPM2Launch the following script using the command prompt:3ResetRecoveryPassword.cmd3A new password have been created and added to Active Directory.e. If Script launch twice1In the case where 1ActivationTPM.cmdis relaunched, a message box will appears by advising that encryption is in progress.Click OK to close.f. If BDE partition is not prepared1In the case where BDE partition is missing, a message box will appears by advising that Bitlocker Preparation Tool will prepare this partition.Click OK to close.Once done, a mandatory reboot will be required.After computer rebooted, you have to relaunch 1ActivationTPM.cmd script to continue encryption process.4. User NoticeThis system has been encrypted with BitLocker Drive Encryption. The Windows Operating Systemas well as the User Data, Windows Registry and temporary files are all encrypted to meetAir Liquides Security Requirements for all Common User Workstation(CUW) systems.Purpose of the encryption is to help ensure this system is not tampered with even if it isleft unat
温馨提示
- 1. 本站所有资源如无特殊说明,都需要本地电脑安装OFFICE2007和PDF阅读器。图纸软件为CAD,CAXA,PROE,UG,SolidWorks等.压缩文件请下载最新的WinRAR软件解压。
- 2. 本站的文档不包含任何第三方提供的附件图纸等,如果需要附件,请联系上传者。文件的所有权益归上传用户所有。
- 3. 本站RAR压缩包中若带图纸,网页内容里面会有图纸预览,若没有图纸预览就没有图纸。
- 4. 未经权益所有人同意不得将文件中的内容挪作商业或盈利用途。
- 5. 人人文库网仅提供信息存储空间,仅对用户上传内容的表现方式做保护处理,对用户上传分享的文档内容本身不做任何修改或编辑,并不能对任何下载内容负责。
- 6. 下载文件中如有侵权或不适当内容,请与我们联系,我们立即纠正。
- 7. 本站不保证下载资源的准确性、安全性和完整性, 同时也不承担用户因使用这些下载资源对自己和他人造成任何形式的伤害或损失。
最新文档
- 2025年乡镇文化站文艺演出辅导员面试问题集萃与实战演练建议
- 线上预约线下舞蹈培训创新创业项目商业计划书
- 2025年中国刺绣工艺大师认证考试指南
- 2025年乡镇农业技术推广员招聘考试试题及解析
- 2025年乡镇残联专职委员职位面试模拟题与实战演练
- 2025年工程监理员招聘面试模拟题及应对技巧解析
- 2025年LED灯具安装与维护操作指南及考试模拟题
- 2025年大学英语六级听力训练题集
- 2025年人工智能机器学习算法实战指南与模拟题答案
- 2025年中国储备粮管理集团招聘考试复习资料与模拟题集
- 新课标人教版六年级数学上册教材分析课件
- 大学美育(第二版) 课件 第二单元:文学艺术
- 2024年云南文山交通运输集团公司招聘笔试参考题库含答案解析
- 100个红色经典故事【十八篇】
- 《化验室安全管理》课件
- 李毓佩数学历险记
- 3D打印技术(课件)
- (完整版)【钢琴谱】大鱼钢琴谱
- (完整word版)英语四级单词大全
- 取暖器市场需求分析报告
- MATLAB 应用全套课件
评论
0/150
提交评论