Quantcast
Channel: Configuration Manager 2012 - Operating System Deployment forum
Viewing all articles
Browse latest Browse all 9126

Task Sequence Step "Activate Bitlocker" does not store Recovery Password in Active Directory

$
0
0

Hello,

I try to enable Bitlocker on our computers during installation and backup the recovery keys to Active Directory. This worked fine in our SCCM 2012 site, but with our SCCM 2012 R2 site the recovery password is not stored in Active Directory.

The msFVE-RecoveryInformation-object is created for the installed computer, the msFVE-VolumeGuid and msFVE-RecoveryGuid attributes are set correctly, but the msFVE-KeyPackage and msFVE-RecoveryPassword attributes are empty.

The recovery password can be displayed and exported on the GUI after the installation just fine and the drive shows that is encrypted. Any ideas if this is a bug or a misconfiguration of our site / task sequence?

This is the Bitlocker-Part of the smsts.log.

smsts.log

<![LOG[==============================[ OSDBitLocker.exe ]==============================]LOG]!><time="17:12:26.689-120" date="05-14-2014" component="OSDBitLocker" context="" type="1" thread="2748" file="main.cpp:349">
<![LOG[Command line: "OSDBitLocker.exe" /enable /wait:False /mode:TPM /pwd:AD]LOG]!><time="17:12:26.689-120" date="05-14-2014" component="OSDBitLocker" context="" type="1" thread="2748" file="main.cpp:350">
<![LOG[Initialized COM]LOG]!><time="17:12:26.689-120" date="05-14-2014" component="OSDBitLocker" context="" type="0" thread="2748" file="main.cpp:361">
<![LOG[Command line for extension .exe is "%1" %*]LOG]!><time="17:12:26.704-120" date="05-14-2014" component="OSDBitLocker" context="" type="0" thread="2748" file="commandline.cpp:228">
<![LOG[Set command line: "OSDBitLocker.exe" /enable /wait:False /mode:TPM /pwd:AD]LOG]!><time="17:12:26.704-120" date="05-14-2014" component="OSDBitLocker" context="" type="0" thread="2748" file="commandline.cpp:731">
<![LOG[Target volume not specified, using current OS volume]LOG]!><time="17:12:26.704-120" date="05-14-2014" component="OSDBitLocker" context="" type="0" thread="2748" file="main.cpp:247">
<![LOG[Current OS volume is 'C:']LOG]!><time="17:12:26.704-120" date="05-14-2014" component="OSDBitLocker" context="" type="0" thread="2748" file="main.cpp:249">
<![LOG[Succeeded loading resource DLL 'C:\WINDOWS\CCM\1031\TSRES.DLL']LOG]!><time="17:12:26.782-120" date="05-14-2014" component="OSDBitLocker" context="" type="1" thread="2748" file="util.cpp:964">
<![LOG[Protection is OFF]LOG]!><time="17:12:26.798-120" date="05-14-2014" component="OSDBitLocker" context="" type="0" thread="2748" file="bitlocker.cpp:1478">
<![LOG[Volume is fully encrypted]LOG]!><time="17:12:26.798-120" date="05-14-2014" component="OSDBitLocker" context="" type="0" thread="2748" file="bitlocker.cpp:1509">
<![LOG[Creating key protectors]LOG]!><time="17:12:26.813-120" date="05-14-2014" component="OSDBitLocker" context="" type="0" thread="2748" file="bitlocker.cpp:1520">
<![LOG[Tpm is enabled]LOG]!><time="17:12:27.905-120" date="05-14-2014" component="OSDBitLocker" context="" type="0" thread="2748" file="tpm.cpp:161">
<![LOG[Tpm is activated]LOG]!><time="17:12:27.967-120" date="05-14-2014" component="OSDBitLocker" context="" type="0" thread="2748" file="tpm.cpp:166">
<![LOG[Tpm is owned]LOG]!><time="17:12:28.045-120" date="05-14-2014" component="OSDBitLocker" context="" type="0" thread="2748" file="tpm.cpp:171">
<![LOG[Tpm ownership is allowed]LOG]!><time="17:12:28.123-120" date="05-14-2014" component="OSDBitLocker" context="" type="0" thread="2748" file="tpm.cpp:176">
<![LOG[Tpm has compatible SRK]LOG]!><time="17:12:28.622-120" date="05-14-2014" component="OSDBitLocker" context="" type="0" thread="2748" file="tpm.cpp:180">
<![LOG[Tpm has EK pair]LOG]!><time="17:12:28.700-120" date="05-14-2014" component="OSDBitLocker" context="" type="0" thread="2748" file="tpm.cpp:184">
<![LOG[Initial TPM state: 63]LOG]!><time="17:12:28.700-120" date="05-14-2014" component="OSDBitLocker" context="" type="0" thread="2748" file="bitlocker.cpp:429">
<![LOG[Creating recovery password and escrowing to Active Directory]LOG]!><time="17:12:28.700-120" date="05-14-2014" component="OSDBitLocker" context="" type="1" thread="2748" file="bitlocker.cpp:577">
<![LOG[Set FVE group policy registry keys to escrow recovery password]LOG]!><time="17:12:28.700-120" date="05-14-2014" component="OSDBitLocker" context="" type="0" thread="2748" file="bitlocker.cpp:645">
<![LOG[Set FVE group policy registry key in Windows 7]LOG]!><time="17:12:28.700-120" date="05-14-2014" component="OSDBitLocker" context="" type="0" thread="2748" file="bitlocker.cpp:650">
<![LOG[Set FVE OSV group policy registry keys to escrow recovery password]LOG]!><time="17:12:28.700-120" date="05-14-2014" component="OSDBitLocker" context="" type="0" thread="2748" file="bitlocker.cpp:694">
<![LOG[Using random recovery password]LOG]!><time="17:12:28.700-120" date="05-14-2014" component="OSDBitLocker" context="" type="0" thread="2748" file="bitlocker.cpp:602">
<![LOG[Protecting key with TPM only]LOG]!><time="17:12:30.835-120" date="05-14-2014" component="OSDBitLocker" context="" type="0" thread="2748" file="bitlocker.cpp:1155">
<![LOG[Checking volume 'D:\' for BitLocker]LOG]!><time="17:12:36.058-120" date="05-14-2014" component="OSDBitLocker" context="" type="0" thread="2748" file="bitlocker.cpp:299">
<![LOG[0, HRESULT=80004005 (e:\nts_sccm_release\sms\framework\tscore\encryptablevolume.cpp,437)]LOG]!><time="17:12:36.058-120" date="05-14-2014" component="OSDBitLocker" context="" type="0" thread="2748" file="encryptablevolume.cpp:437">
<![LOG[Process completed with exit code 0]LOG]!><time="17:12:36.073-120" date="05-14-2014" component="TSManager" context="" type="1" thread="256" file="commandline.cpp:1123">
<![LOG[!--------------------------------------------------------------------------------------------!]LOG]!><time="17:12:36.073-120" date="05-14-2014" component="TSManager" context="" type="1" thread="256" file="instruction.cxx:804">
<![LOG[Successfully completed the action (BitLocker aktivieren) with the exit win32 code 0]LOG]!><time="17:12:36.073-120" date="05-14-2014" component="TSManager" context="" type="1" thread="256" file="instruction.cxx:830">


Viewing all articles
Browse latest Browse all 9126

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>