Use BitLocker to encypt system partition, but have USB key contain boot information.
Hi,Normally, the default Win 7 install wants to make two partitions, one small onefor boot loader information and one for the OS. However, I would like to do the partitioning before hand to make one big partition instead of doing the hidden partition scheme to boot Windows. Then. I want to use BitLocker to encrypt the whole system partition, but have the keyfile and the boot loader information on a USB key. Is it possible to tell BitLocker to use the USB key for all boot information? I know you can have it where the keyfile is placed on a USB Key, but it still uses the small hidden partition on the main hard drive for boot loader information. Can someone provide step by step instructions on how to do this with Windows 7 RTM? Oh, I don't have a TPM chip, but that doesn't matter since I want the keyfile on the USB Key with the boot loader info. :)Thanks.
August 6th, 2009 11:24pm

Hi,Normally, the default Win 7 install wants to make two partitions, one small onefor boot loader information and one for the OS. However, I would like to do the partitioning before hand to make one big partition instead of doing the hidden partition scheme to boot Windows. Then. Dycius, the reason why Win 7 creates that small boot partition is because your OS is not able to boot from an encrypted bitlocker disk.You need that small partition to boot from it. So thatthe bootloader on this partion can decrypt the bitlocker partion and start the OS on the encrypted partion.Quote from the microsoft technet: http://technet.microsoft.com/en-us/library/cc766200(WS.10).aspx#BKMK_Partitions Why are two partitions required? Why does the system volume have to be so large? Two partitions are required to run BitLocker because pre-startup authentication and system integrity verification must happen outside of the encrypted operating system volume. This configuration helps to protect the operating system and the information in the encrypted volume. The unencrypted system volume should be at least 1.5GB, which allows enough space for boot files, the Windows Pre-Execution environment (WinPE), and other files that may be specific to setup or upgrade programs. Computer manufacturers and enterprise customers can also store system tools or other recovery tools in this volume. I want to use BitLocker to encrypt the whole system partition, but have the keyfile and the boot loader information on a USB key. Is it possible to tell BitLocker to use the USB key for all boot information? I know you can have it where the keyfile is placed on a USB Key, but it still uses the small hidden partition on the main hard drive for boot loader information. Can someone provide step by step instructions on how to do this with Windows 7 RTM? Oh, I don't have a TPM chip, but that doesn't matter since I want the keyfile on the USB Key with the boot loader info. :)Thanks. Sure, it is possible to save a keyfile to an usbstick.Check in the bitlocker step by step guide, to be more specific scenario 3. :)http://technet.microsoft.com/en-us/library/cc766295(WS.10).aspx#BKMK_requireDoes answers your questionKind RegardsDFT IM me - TWiTTer: @DFTER
Free Windows Admin Tool Kit Click here and download it now
August 10th, 2009 12:00pm

This topic is archived. No further replies will be accepted.

Other recent topics Other recent topics