<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>RO Windows Administrators Weblog &#187; Bitlocker</title>
	<atom:link href="http://www.winadmin.ro/tag/bitlocker/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.winadmin.ro</link>
	<description>Weblogul adminilor de Windows din Romania.</description>
	<lastBuildDate>Fri, 03 Sep 2010 16:02:24 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
		<item>
		<title>Testing Bitlocker in VMWare</title>
		<link>http://www.winadmin.ro/2009/10/24/testing-bitlocker-in-vmware/</link>
		<comments>http://www.winadmin.ro/2009/10/24/testing-bitlocker-in-vmware/#comments</comments>
		<pubDate>Sat, 24 Oct 2009 02:41:30 +0000</pubDate>
		<dc:creator>Andrei Ungureanu</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Windows Client]]></category>
		<category><![CDATA[Windows Server]]></category>
		<category><![CDATA[Bitlocker]]></category>
		<category><![CDATA[VMWare Workstation]]></category>

		<guid isPermaLink="false">http://www.winadmin.ro/2009/10/24/testing-bitlocker-in-vmware/</guid>
		<description><![CDATA[Acesta e un exemplu prin care voi demonstra cum poti testa Bitlocker in VMWare Workstation. Sau de ce nu, sa iti criptezi discul masinii virtuale folosite pentru “cine stie ce” (sunt totusi convins ca exista metode mai bune). Prima data e nevoie sa avem un Windows instalat (am folosit Windows 7 ca exemplu) si mare [...]]]></description>
			<content:encoded><![CDATA[<p>Acesta e un exemplu prin care voi demonstra cum poti testa Bitlocker in VMWare Workstation. Sau de ce nu, sa iti criptezi discul masinii virtuale folosite pentru “cine stie ce” (sunt totusi convins ca exista metode mai bune).</p>
<p>Prima data e nevoie sa avem un Windows instalat (am folosit Windows 7 ca exemplu) si mare atentia la dimensiunea discului, chiar daca nu alocati tot spatiul de la inceput, discul o sa creasca la dimensiunea maxima atunci cand este criptat.</p>
<p>Mai trebui spus ca porturile USB mapate in VMWare nu ne sunt de mare folos acum. Chiar daca reusim sa scriem cheia folosita la boot pe USB, la reboot nu o sa o putem citi. In schimb merge pe floppy disk.</p>
<p>Putem face unul virtual din VMWare:</p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2009/10/image66.png"><img style="border-bottom: 0px;border-left: 0px;float: none;margin-left: auto;border-top: 0px;margin-right: auto;border-right: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2009/10/image_thumb65.png" width="629" height="484" /></a>&#160;</p>
<p>Nu uitati sa il setati pe connected si sa-l formatati.</p>
<p>Acum trebuie sa setam bitlocker in asa fel incat sa functioneze si fara TPM (ca altfel nu o sa reusim sa-l activam). By default cere TPM.</p>
<p>O facem cu GPEDIT.MSC – Computer Settings/Administrative Templates/Windows Components/Bitlocker Drive Encription/Operating System Drives</p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2009/10/image67.png"><img style="border-bottom: 0px;border-left: 0px;float: none;margin-left: auto;border-top: 0px;margin-right: auto;border-right: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2009/10/image_thumb66.png" width="644" height="383" /></a> </p>
<p>Iata si ce trebuie sa setam:</p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2009/10/image68.png"><img style="border-bottom: 0px;border-left: 0px;float: none;margin-left: auto;border-top: 0px;margin-right: auto;border-right: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2009/10/image_thumb67.png" width="529" height="484" /></a></p>
<p>Aplicam noile setari:</p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2009/10/image69.png"><img style="border-bottom: 0px;border-left: 0px;float: none;margin-left: auto;border-top: 0px;margin-right: auto;border-right: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2009/10/image_thumb68.png" width="644" height="324" /></a>&#160; </p>
<p>Si acum vine smecheria; asta pentru ca e Windows 7 (pe Vista tin minte ca mergea; pe 7 am incercat de mi-a venit rau; am ajuns pana la codurile de eroare de pe MSDN si tot degeaba).</p>
<p>Comanda care ar trebui sa o rulam e urmatoarea:</p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2009/10/image70.png"><img style="border-bottom: 0px;border-left: 0px;float: none;margin-left: auto;border-top: 0px;margin-right: auto;border-right: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2009/10/image_thumb69.png" width="644" height="326" /></a> </p>
<p>Pe Vista exista manage-bde.wsf (si pe Vista mergea), aici e manage-bde.exe. De fapt prin manage-bde poti sa configurezi bitlocker asa cum vrei fara sa mai intampini restrictiile din GUI. Doar ca dupa cum observati in output, nu prea merge. Eroarea e documentata pe <a href="http://msdn.microsoft.com/en-us/library/aa376470(VS.85).aspx">aici</a> doar ca nu prea ajuta. Ce am setat in GPO se potriveste cu ce am rulat eu.</p>
<p>Workaround:</p>
<p>Rulam Bitlocker din interfata grafica</p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2009/10/image71.png"><img style="border-bottom: 0px;border-left: 0px;float: none;margin-left: auto;border-top: 0px;margin-right: auto;border-right: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2009/10/image_thumb70.png" width="644" height="482" /></a>&#160;</p>
<p>Si incercam sa-l activam de aici (de fapt vom face doar prepararea disk-ului).</p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2009/10/image72.png"><img style="border-bottom: 0px;border-left: 0px;float: none;margin-left: auto;border-top: 0px;margin-right: auto;border-right: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2009/10/image_thumb71.png" width="631" height="484" /></a> </p>
<p>Acum ma gandesc ca daca as fi facut partitionarea disk-ului ca la Vista ar fi mers din prima cu manage-bde. Dar de cand cu 7 m-am lenevit.</p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2009/10/image73.png"><img style="border-bottom: 0px;border-left: 0px;float: none;margin-left: auto;border-top: 0px;margin-right: auto;border-right: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2009/10/image_thumb72.png" width="630" height="484" /></a> </p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2009/10/image74.png"><img style="border-bottom: 0px;border-left: 0px;float: none;margin-left: auto;border-top: 0px;margin-right: auto;border-right: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2009/10/image_thumb73.png" width="629" height="484" /></a> </p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2009/10/image75.png"><img style="border-bottom: 0px;border-left: 0px;float: none;margin-left: auto;border-top: 0px;margin-right: auto;border-right: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2009/10/image_thumb74.png" width="630" height="484" /></a></p>
<p>Si la pasul asta ii dam Cancel, altfel din UI singura optiune ar fi fost sa folosim un drive USB. Deschidem un CMD (nu uitati de Run as Administrator) si rulam:</p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2009/10/image76.png"><img style="border-bottom: 0px;border-left: 0px;float: none;margin-left: auto;border-top: 0px;margin-right: auto;border-right: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2009/10/image_thumb75.png" width="644" height="473" /></a> </p>
<p> Comanda este: manage-bde -on C: -RecoveryPassword -StartupKey A: –skiphardwaretest. Am adaugat si –skiphardwaretest ca sa evit inca un restart. Pe un sistem cu date NU e recomandat sa rulati cu acest parametru. Fara el sistemul s-ar fi restartat si ar fi verificat daca poate citi startup key-ul de pe device-ul specificat.</p>
<p>Retineti: Criptarea datelor poate fi uneori mai periculoasa decat stergerea lor.</p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2009/10/image77.png"><img style="border-bottom: 0px;border-left: 0px;float: none;margin-left: auto;border-top: 0px;margin-right: auto;border-right: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2009/10/image_thumb76.png" width="364" height="179" /></a></p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2009/10/image78.png"><img style="border-bottom: 0px;border-left: 0px;float: none;margin-left: auto;border-top: 0px;margin-right: auto;border-right: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2009/10/image_thumb77.png" width="367" height="141" /></a></p>
<p>Si cam asta e tot. Acum daca restartam sistemul o sa citeasca automat startup key-ul de pe floppy. Daca il deconectam putem vedea urmatorul mesaj:</p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2009/10/image79.png"><img style="border-bottom: 0px;border-left: 0px;float: none;margin-left: auto;border-top: 0px;margin-right: auto;border-right: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2009/10/image_thumb78.png" width="644" height="475" /></a>&#160;&#160; </p>
<p>E destul de simplu atunci cand drumul e deja batatorit. Urmariti site-ul pentru ca vor aparea si alte articole despre Bitlocker.</p>
<p>PS: Procesul e cam acelasi si pentru Windows Server 2008 R2</p>
]]></content:encoded>
			<wfw:commentRss>http://www.winadmin.ro/2009/10/24/testing-bitlocker-in-vmware/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
