Friday, October 30, 2009
Why Microsoft got out of the restaurant Bussiness !
Waiter: Hi, my name is Bill, and I'll be your Support Waiter. What seems to be the problem?
Patron: There's a fly in my soup!
Waiter: Try again, maybe the fly won't be there this time.
Patron: No, it's still there.
Waiter: Maybe it's the way you're using the soup; try eating it with a fork instead.
Patron: Even when I use the fork, the fly is still there.
Waiter: Maybe the soup is incompatible with the bowl; what kind of bowl are you using?
Patron: A SOUP bowl!
Waiter: Hmmm, that should work. Maybe it's a configuration problem; how was the bowl set up?
Patron: You brought it to me on a saucer; what has that to do with the fly in my soup?!
Waiter: Can you remember everything you did before you noticed the fly in your soup?
Patron: I sat down and ordered the Soup of the Day!
Waiter: Have you considered upgrading to the latest Soup of the Day?
Patron: You have more than one Soup of the Day each day?
Waiter: Yes, the Soup of the Day is changed every hour.
Patron: Well, what is the Soup of the Day now?
Waiter: The current Soup of the Day is tomato.
Patron: Fine. Bring me the tomato soup, and the check. I'm running late now.
[Waiter leaves and returns with another bowl of soup and the check]
Waiter: Here you are, Sir. The soup and your check.
Patron: This is potato soup.
Waiter: Yes, the tomato soup wasn't ready yet.
Patron: Well, I'm so hungry now, I'll eat anything.
[The waiter leaves.]
Patron: Waiter! There's a gnat in my soup!
The check:
Soup of the Day . . . . . . . . . . $5.00
Upgrade to newer Soup of the Day. . $2.50
Access to support . . . . . . . . . $1.00
Essential Hands-on Skills in the 70-270 course !
"Arun, is there a list of important things I need to learn to do with XP Pro?"
What he meant was the hands on skills that he would learn as part of the course.
So I have come up with such a list for the 70-270 course :
Installation Skills
- Run Upgrade Advisor from OS media *!*
- Create an Unattended Installation using Answer Files and Disk Duplication *!*
- Convert a Fat32 Volume to NTFS
Networking Skills
- Configure TCP/IP properties for network cards including DNS Suffixes, WINS Servers etc
- Release and renew an IP address, clear ARP Cache and DNS client cache
- Create / Join a Work group with other Windows Systems
- Join a Windows Active Directory Domain
- Configure ICF/ICS
- Create a VPN Connection to a RAS Server
- Create a Dial-up connection to an ISP
- Install IIS and host two websites
Troubleshooting Skills
- Configure remote Assistance and Send RA Invitations to an Expert
- Start / Stop Services using services console ( Services.msc) and Command prompt ( net start etc. )
- Create, delete and manage Restore Points
- Use Taskmanager to identfy resource hungry processes and to kill them
- Change the startup type of a Service and to manually start / stop / restart a service
- Configure Startup using MSCONFIG Tool
- Edit BOOT.INI file
- Change File Associations for known File Types
- Access, Search and Backup Windows Registry
- Boot to Recovery Console and Install it as a Startup Option
- Boot to Safe mode with networking and use it to roll back a driver
Productivity Skills
- Configure Outlook Express to access a email server
- Configure Dual Display and Extended Desktop
- Install an popular Anti-virus Product like Norton, Avast, Mc Afee and Configure its options and Firewall
- Install 3rd Party Browsers and Update Plugins for Flash, Java
- Install Adminpak.MSI
- Install a Bluetooth Adapter and pair a Bluetooth Device
- Update DirectX and .Net Framework
- Configure a manual Wireless connection to a residential gateway / AP using WPA
- Install a Multifunction Device and configure Printer / Scanner and Fax functions
- Install a CD-DVD Authoring Program and create Data / Audio / DVD Movies
- Use Hot Pluggable USB Devices and to Stop a USB Device before physically un-plugging it
- configure a residential Wireless gateway ( read Wirelss router ) from a Wired connection using the built in Configuration Webpages
Administration and Configuration Skills
- Create Local users and Groups
- Modify Local Computer Policy
- Enable Hibernation and to Create custom Power Management Profiles
- Install a Local / Network Printer and edit Server properties
- Create a file share and configure Share and NTFS permissions
- Map a network Drive
- Configure Multiple Languages and keyboard Layouts
- Configure Accessibility options
- Change a password for an user account without using any console
- Encrypt an NTFS File and Folder
- Use Compressed Drives and Folders
*!* Skills that are needed for your 70-270 exam but are not relevant to the industry in general.
This list is by no means EXHAUSTIVE. Please feel free to add any topics I may have forgotten in the comment section below.
:)
Thursday, October 29, 2009
The History of Computers - According to the Bible
So the Gateskeeper, who was said to be both micro and soft, fashioned a Dosfish, who was small and spry, and could swim the narrow sixteen-bit channel. But the Dosfish was not bright, and could be taught few new tricks. His alphabet had no A's, B's, or Q's, but a mere 640 K's, and the size of his file cabinet was limited by his own fat.
At first the people loved the Dosfish, for he was the only one who could swim the Pea Sea. But the people soon grew tired of commanding his line, and complained that he could be neither dragged nor dropped. "Forsooth," they cried. "the Dosfish can only do one job at a time, and of names, he knows only eight and three." And many of them left the Pea Sea for good, and went off in search of the Magic Apple.
Although many went, far more stayed, because admittance to the Pea Sea was cheap. So the Gateskeeper studied the Magic Apple, and rested awhile in the Parc of Xer-Ox, and he made a Window that could ride on the Dosfish and do its thinking for it. But the Window was slow, and it would break when the Dosfish got confused. So most people contented themselves with the Dosfish.
Now it came to pass that the Blue Giant came upon the Gateskeeper, and spoke thus: "Come, let us make of ourselves something greater than the Dosfish." The Blue Giant seemed like a humbug, so they called the new creature OZ II.
Now Oz II was smarter than the Dosfish, as most things are. It could drag and drop, and could keep files without becoming fat. But the people cared for it not. So the Blue Giant and the Gateskeeper promised another OZ II, to be called Oz II Too, that could swim the fast new 32-bit wide Pea Sea.
Then lo, a strange miracle occurred. Although the Window that rode on the Dosfish was slow, it was pretty, and the third Window was the prettiest of all. And the people began to like the third Window, and to use it. So the Gateskeeper turned to the Blue Giant and said, "Fie on thee, for I need thee not. Keep thy OZ II Too, and I shall make of my Window an Entity that will not need the Dosfish, and will swim in the 32-bit Pea Sea."
Years passed, and the workshops of the Gateskeeper and the Blue Giant were overrun by insects. And the people went on using their Dosfish with a Window; even though the Dosfish would from time to time become confused and die, it could always be revived with three fingers.
Then there came a day when the Blue Giant let forth his OZ II Too onto the world. The Oz II Too was indeed mighty, and awesome, and required a great ram, and the world was changed not a whit. For the people said, "It is indeed great, but we see little application for it." And they were doubtful, because the Blue Giant had met with the Magic Apple, and together they were fashioning a Taligent, and the Taligent was made of objects, and was most pink.
Now the Gateskeeper had grown ambitious, and as he had been ambitious before he grew, he was now more ambitious still. So he protected his Window Entity with great security, and made its net work both in serving domains and with peers. And the Entity would swim, not only in the Pea Sea, but in the Oceans of Great Risk. "Yea," the Gateskeeper declared, "though my entity will require a greater ram than Oz II Too, it will be more powerful than a world of Eunuchs."
And so the Gateskeeper prepared to unleash his Entity to the world, in all but two cities. For he promised that a greater Window, a greater Entity, and even a greater Dosfish would appear one day in Chicago and Cairo, and it too would be built of objects.
Now the Eunuchs who lived in the Oceans of Great Risk, and who scorned the Pea Sea, began to look upon their world with fear. For the Pea Sea had grown, and great ships were sailing in it, the Entity was about to invade their oceans, and it was rumored that files would be named in letters greater than eight. And the Eunuchs looked upon the Pea Sea, and many of them thought to immigrate.
Within the Oceans of Great Risk were many Sun Worshippers, and they wanted to excel, and make their words perfect, and do their jobs as easy as one-two-three. And what's more, many of them no longer wanted to pay for the Risk. So the Sun Lord went to the Pea Sea, and got himself eighty-sixed.
And taking the next step was He of the NextStep, who had given up building his boxes of black. And he proclaimed loudly that he could help anyone make wondrous soft wares, then admitted meekly that only those who know him could use those wares, and he was made of objects, and required the biggest ram of all.
And the people looked out upon the Pea Sea, and they were sore amazed. And sore confused. And sore sore. And that is why, to this day, Ozes, Entities, and Eunuchs battle on the shores of the Pea Sea, but the people still travel on the simple Dosfish.
Notice : Lecture Session on Group Policy
Ramesh would be handling a small lecture on Group Policy tommorrow in the morning. Anyone can choose to attend.
0930 hrs
:)
Dont let your Keyboard twist your Arm
Many people who have carpal tunnel syndrome have gradually increasing symptoms over time. The first symptoms of CTS may appear when sleeping and typically include numbness and paresthesia (a burning and tingling sensation) in the thumb, index, and middle fingers, although some patients may experience symptoms in the palm as well. These symptoms appear at night because people tend to bend their wrists when they sleep, which further compresses the carpal tunnel.
In early stages of CTS individuals often mistakenly blame the tingling and numbness on restricted blood circulation. They may also be at ease and accepting of the symptoms and believe their hands are simply “falling asleep”.
Occupational risk factors of repetitive tasks, force, posture, and vibration have been cited as major causes for CTS.
Thankfully, preventing CTS is not so hard. Here are a few pointers :
* Take frequent breaks from repetitive movement such as computer keyboard usage or use of browser-based games that encourage the user for excessive finger movement. Free software programs such as Workrave and Xwrits are available to remind users to take breaks and stretch their wrists.
* Reduce your force and relax your grip. Most people use more force than needed to perform many tasks involving the hands. If your work involves a cash register, for instance, hit the keys softly. For prolonged handwriting, use a big pen with an over-sized, soft grip adapter and free-flowing ink. This way you won't have to grip the pen tightly or press as hard on the paper.
* Watch your form. Avoid bending your wrist all the way up or down. A relaxed middle position is best. If you use a keyboard, keep it at elbow height or slightly lower.
* Improve your posture. Incorrect posture can cause your shoulders to roll forward. When your shoulders are in this position, your neck and shoulder muscles are shortened, compressing nerves in your neck. This can affect your wrists, fingers and hands.
* Keep your hands warm. You're more likely to develop hand pain and stiffness if you work in a cold environment. If you can't control the temperature at work, put on fingerless gloves that keep your hands and wrists warm.
* Take frequent breaks. Every 15 to 20 minutes give your hands and wrists a break by gently stretching and bending them. Alternate tasks when possible. If you use equipment that vibrates or that requires you to exert a great amount of force, taking breaks is even more important.
If you are already experiencing symptoms, this brace might come in handy.
Always remember Prevention is better than cure.
:)
Download Windows 7 Trial While You can !
For those of you who are thinking about trying out the new. super hyped Windows , here is the link to download the 90 day trial. Just remember to select the right version that matches your hardware. ( 32 bit or 64 bit )
http://technet.microsoft.com/en-us/evalcenter/cc442495.aspx?ITPID=sprblog
Oh ! please practice the Aero Shake and let the class know how much you loved it. :p
Lecture On Demand !
Hello Student ! Taking into account all the recent feedback and in order to make the lecture and hands on instruction more relevant to your current training, we have compiled a list of lecture topics. You can request for a Lecture topic to be dealt with and will be scheduled for you in the coming week. Alternatively, if not many students will be in attendance for that session; then we can handle it as a one-on-one tutoring session. please email me at andy.dell@gmail.com with your lecture requests for the coming weeks.
Windows Administration
[ Covers concepts and objectives from exams 70-270, 290 ]
Topics :
Lecture - Deployment Win XP - Imaging, RIS
Lecture - MS Product Families (From DOS to Win 7) and capabilities
Lecture - Work group vs Domain Architecture
Lecture - NTFS, FAT32, FAT16 - Features
* Lecture - POST, Boot Sequence, ARC Paths and Active Partitions
Lecture - Basic & Dynamic Disks, Partitions and Volumes, Partition Table
Lecture - Volume Shadow Copy
Lecture - Planning a Backup Strategy - Normal, Incremental, Differential and Copy backup
Demo - Creating a Backup Plan and Scheduling
Lecture - Local User Accounts, Domain User accounts
Demo - Creating and Managing user accounts in the Enterprise
Demo - Mass deployment of Multiple user accounts on Windows Domains - CSVDE, LDIFDE
Lecture - Planning and Implementing a Simple Workgroup
Demo - Creating a Windows Workgroup and File and Print Sharing
Demo - Installing Active Directory and Adding Domain Clients
Lecture - Client Server technologies used in the Enterprise ( DNS, DHCP, WINS, Webservers, Certificate Servers, Directory Servers, Domain Controllers, File Servers, WSUS )
Building Network Infrastructure using Windows Server 2003
[ Covers concepts and objectives from exams 291 ]
Lecture - DHCP Concepts 1
- Lease process - DORA
- Exclusions and Reservations
- Scope, Server and Reservation Options
- Lease Renewal and Optimizing Lease Times Fault Tolerance using - 80/20 Rule Across Subnets
Lecture - DHCP Concepts 2
- SupernettingReconciling Scopes
- Rouge Server Detection
- DHCP support in ICS, Residential Gateways and RAS
Lecture - DNS Concepts 1
- Understanding DNS Namespace
- Zones, Domains, Sub-domains & Delegations
- Active Directory Integration
- DNS Server Architecture on the Internet and Intranets
- The Name resolution Process
- Zone Transfers and Replication
Lecture - DNS Concepts 2
- DNS Record Types and Glue Records
- TTL of Name records
- Primary, Secondary and Stub Zones
- Caching Only DNS Servers
- Initiating Zone Transfers
- Securing the DNS Server cache Against Pollution
An Easy Way to Stay in Touch !
Figured we could use a little more interaction and a ready reference tool for communicating with each other in class. From here on, I am going to post all important information to this BLOG and you can access all the buzz that happens in class.
i can also post some interesting trivia and happenings and also announcements for everyone. Feel free to comment on any post at anytime.
And oh.. you can be totally casual with me here since i dont know how to be a very formal Professor anyways.
Cheers ~!
Saturday, September 27, 2008
Configure BitLocker (Part 2) - Best Practice
we’ll take a look at BitLocker from an Active Directory point of view and look at BitLocker and TPM configuration using Group Policies and how to perform key recovery.
DisclaimerI think it is safe to say, that BitLocker in an Active Directory based environment will probably be the most used scenario. By using BitLocker in an Active Directory based environment, you get all the security benefits from BitLocker combined with all the security, availability and scalability that comes with Active Directory.
But, before we get started, you should be aware of a few disclaimers:
- Microsoft hasn’t released their BitLocker Deployment Kit yet, so unfortunately we’re unable to provide you with the official links or copies of the scripts used in this article
- Also, we haven’t seen the official BitLocker deployment material that will soon be released, but the scripts we are using are provided by Microsoft. Please note however, that the names and the number of scripts covered in this article, may change when the BitLocker Deployment Kit is released
- As soon as Microsoft releases the various scripts and white paper which we mention within this article, it will be updated with the respective links and so on, so that it corresponds with filenames etc. We will let you know when the article is updated through our blogs, so stay tuned!
Prerequisites
Before we get started, let us look at some prerequisites that should be satisfied, enabling you to control BitLocker from Active Directory.
- You will need to extend the schema in Active Directory
- If you want to control TPM recovery information from Active Directory, then you need to change the permission on the Computer class object in Active Directory
- BitLocker Active Directory schema extensions are only supported on domain controllers running Windows Server 2003 with SP1 or newer, Windows Server 2003 R2 and Windows Server “Longhorn”
- BitLocker is only supported to run on Windows Vista Enterprise, Windows Vista Ultimate, and Windows “Longhorn” Server
Note: While I’m writing this article, Service Pack 2 for Windows Server 2003 has hit RTM. SP2 will not include the BitLocker schema updates. You still have to the run the BitLocker schema extension script explained in this article, after you have installed SP2 on your Windows Server 2003 based setup.
Scripts that are needed
It’s time that we get started, so let us look at the files required to get BitLocker integrated with a Windows Server 2003 based Active Directory:
The following files are required so that your Windows Server 2003 based Active Directory is ready to support BitLocker.
- BitLockerTPMSchemaExtension.ldf
- Add-TPMSelfWriteACE.vbs
Use the files below to help verify your BitLocker configuration in Active Directory. We’ll use one of them in our example later on in this article.
- List-ACEs.vbs
- Get-BitLockerRecoveryInfo.vbs
- Get-TPMOwnerInfo.vbs
Extend the schema in Active Directory
After you have verified the prerequisites and verified the scripts, you’re ready to extend your Active Directory so that you can store your BitLocker and TPM recovery information in Active Directory.
The way it works, is that the BitLocker recovery information is stored in a sub-object of the Computer object in Active Directory, which means that the Computer object serves as the container for one or more BitLocker recovery objects associated with a particular Computer object. The reason why I say one or more BitLocker recovery objects is because it is possible to have more than one recovery password associated with a BitLocker-enabled computer, for example if you have encrypted more than one volume on the same computer.
The name of the BitLocker recovery object has a fixed length of 63 characters that consists of the following information:
This can be important to know, if you have more than one recovery key associated with a specific computer, and decide to remove some of the recovery keys for security purposes.
But it doesn’t end here. There’s more information stored with the Computer object. If you’re the lucky owner of a computer with a TPM chip (Trusted Platform module) version 1.2, then you’re also able to store the TPM recovery information in Active Directory. Please note however, that there is only one TPM owner password that can be assigned per computer. When the TPM is initialized or when you change the TPM password, then it gets stored as an attribute of the same Computer object used by BitLocker
Let us start by extending the schema with BitLocker and TPM objects and attributes.
- Make sure that you’re logged on a domain controller as a user that’s part of the “Schema Admins” group in Active Directory. (Normally the built-in Administrator account is a member of this group per default)
- Make sure that you can connect to the domain controller in your Active Directory that holds the Schema Master FSMO role
- For this article, I’m using an Active Directory domain called domain.local. With that info on hand, I run the following command (see figure 1):
ldifde -i -v -f BitLockerTPMSchemaExtension.ldf -c "DC=X" "dc=domain,dc=local" -k -j .
The use of the -k parameter suppresses the error message "Object Already Exists" if the portions of the schema already exist.
The use of the -j . parameters (yes, the dot is part of the parameter) saves an extended log file to the current working directory, which in our case is C:\LDIF.LOG
Figure 1
- Make sure that all the schema extensions are applied by checking the LDIF log file before you continue.
- The next thing we need to do is set the permissions on the BitLocker and TPM recovery information schema objects. This step will add an Access Control Entry (ACE) making it possible to back up TPM recovery information to Active Directory. Run the following command (see figure 2):
cscript Add-TPMSelfWriteACE.vbs
Figure 2
And that’s it. You have now extended the schema in Active Directory and prepared it for BitLocker and TPM support.
You’re now ready to modify the necessary Group Policy settings for both BitLocker and the TPM chip (if your computer supports this feature).
Note: For more information on configuring Windows Vista Group Policy Objects (GPO) on the domain please see the following article series from windowsecurity.com:
- http://www.windowsecurity.com/articles/Managing-Windows-Vista-Group-Policy-Part1.html
- http://www.windowsecurity.com/articles/Managing-Windows-Vista-Group-Policy-Part2.html
- http://www.windowsecurity.com/articles/Managing-Windows-Vista-Group-Policy-Part3.html
- From Vista you log on with a domain account that has the rights to modify Group Policies
- At the Vista Start | Search command prompt you type GPMC.MSC and press Enter
- There are several Group Policy settings you can configure as displayed in figure 3, but the one setting you definitely want to configure is the setting that will enabling backup of BitLocker recovery information to Active Directory:
- Navigate to Computer Configuration > Administrative Templates > Windows Components > BitLocker Drive Encryption
- Double-click Turn on BitLocker backup to Active Directory Domain Services
- Select the Enabled radio button
Figure 3
- If your client computers support a compliant TPM chip, then you want to enable a Group Policy setting that allows your clients to back up TPM recovery information to Active Directory (see figure 4):
- Navigate to Computer Configuration > Administrative Templates > System > Trusted Platform Module Services
- Double-click Turn on TPM backup to Active Directory Domain Services
- Select the Enabled radio button
Figure 4
Verifying key recovery in Active Directory
The last thing we’ll do is show you how to perform an encryption centrally, where we also make sure that we get a backup of the BitLocker recovery key used by a Vista client computer, which is stored in Active Directory. In our example we’ll use the BitLocker command line utility (manage-bde.wsf).
It should be noted that if you want to use the GUI interface when configuring BitLocker and the TPM chip, then key recovery will still be supported. As long as the Vista machine is a member of domain that satisfies the prerequisites mentioned earlier and the user doing the work is a domain administrator, then the key recovery will happen silently in the background without any user intervention.
BitLocker encryption with TPM support
- From the Vista Start Menu, locate the Command Prompt shortcut. Right-click the icon and select Run as administrator
- Enter the following command:
cscript manage-bde.wsf –on –recoverypassword C: - Follow the instructions on the screen to start the encryption process (see figure 5)
Figure 5
- While the volume is being encrypted, we can check whether the BitLocker recovery key has been backed up by typing the following command:
cscript GET-BitLockerRecoveryInfo.VBS
Notice that the recovery listed in figure 6 below matches the recovery key created in the previous step and listed in figure 5.
Figure 6
Friday, September 26, 2008
Configure BitLocker (Part 1) - Best Practice
BitLocker hardware and software requirements
With BitLocker you basically have two different ways to protect the crypto key (a.k.a. Volume Encryption Key).
- A TPM chip
- Using a clear key, which is simply a normal password protection method
The crypto key is used to encrypt a volume, but it is just as important that the crypto key is protected as well. If a malicious user deletes the crypto key or it is accidentally deleted, then you better have a good key recovery setup, assuming you want access to your data again (We’ll cover the key recovery part in more details in Part 2). On the positive side, deleting the crypto key on purpose, in a controlled environment, is a great way to decommission and quickly recycle a computer without having to worry about what was installed previously on the encrypted volume.
Before you can install and use BitLocker, you should ensure that the following requirements are met:
- TPM chip (Trusted Platform module) version 1.2 is available (only a requirement if you want to use BitLocker with a TPM chip)
- The system BIOS is TCG (Trusted Computing Group) version 1.2 compliant (again, this is only a requirement if you want to use BitLocker with a TPM chip)
- The system BIOS supports both reading and writing small files on a USB flash drive in the pre-operating system environment
- The computer must have a least two volumes, before BitLocker can be used:
- The first volume is the System Volume
This volume must be NTFS formatted and should differ from the Operating System Volume. The System Volume must not be encrypted, since it contains hardware-specific files that are needed to load Windows after pre-boot authentication. - The second volume is the Operating System (OS) Volume
This volume must be NTFS formatted and contains the Vista operating system and its support files. All data on the OS Volume is protected by BitLocker
- The first volume is the System Volume
- It should be noted that BitLocker is only included and supported in Windows Vista Enterprise, Windows Vista Ultimate, and Windows “Longhorn” Server
Let us configure BitLocker, by taking you through each of the requirements and spice it up with some useful tricks and hints on the way.
Prepare the system BIOS
A TPM chip is not required, but is highly recommended when using BitLocker. There are actually a couple of reasons for this:
- Since Microsoft is one of the big supporters of the Trusted Computing Platform initiative, they’ve build a lot of Vista security features (including BitLocker) around this chip, which can also be configured from an Active Directory based infrastructure using Group Policies.
- BitLocker is extremely weak when it comes to pre-boot authentication options, compared to 3rd party hard disk encryption tools. The best and most secure method when using BitLocker is a TPM + pin code enabled configuration.
A TPM chip is basically a smart card that is molded to the motherboard of the computer. The TPM chip is capable of performing cryptographic functions. It can create, store and manage keys and also perform digital signature operations, and best of all, protect itself against attacks.
Hopefully by now, you should be convinced that using BitLocker together with a TPM chip is a good thing. But before you can take advantage of your TPM chip in Vista, you need to make sure that it is TCG version 1.2 compliant. Most of the newer TPM chips can be firmware upgraded, so that they’re compatible with Vista. However this also means that your BIOS needs an upgrade. If you’re not sure whether your computer fulfills the TPM requirements, you should go visit your computer manufactures website for more information.
On most systems, all you need to do is enter the BIOS setup and enable the TPM chip (usually identified in the BIOS as a “Security Chip”). Once you have done that, you’re ready to move on to the next section.
Prepare the hard disk
If you have purchased a computer recently that is Vista Ready and/or has Vista pre-installed, then you’ll notice that the hard drive has at least two different volumes. Basically what it means is that the volumes on the computer have been prepared to support BitLocker, and you can simply move on to the next section.
If you don’t have the volumes prepared from your hardware vendor or simply want to re-install Vista and also prepare it for BitLocker, then you need to prepare the volumes required by BitLocker, mentioned earlier. This should be done during the Vista installation process.
This can be easily done using Windows PE 2.0 which is included with your Vista DVD and a small simple script which we have included in this article. This process is actually easier than you think. Here’s what you need to do:
Copy the following script to a USB key:
bde-part.txt (used to partition the hard disk):
select disk 0
clean
create partition primary size=1500
assign letter=S
active
format fs=ntfs quick
create partition primary
assign letter=C
format fs=ntfs quick
list volume
exit
Important: The “clean” command in the bde-part.txt script will wipe all your existing partitions on disk 0 (your primary drive) including the repair/installation partitions that may have been preconfigured by your computer manufacture, so use this command with care or omit it from the script. Instead of the clean command, you can use the diskpart select volume=<drive letter> and thereafter the diskpart delete volume if you want more granular control of which volumes you want to delete.
Once you have copied the script to a USB key, it is time to make use of it.
- Insert the USB key and start the computer from the Windows Vista product DVD
- In the initial Install Windows screen, choose your Installation language, Time and currency format, and Keyboard layout, and then click Next
- In the next Install Windows screen, click System Recovery Options, located in the lower left corner of the screen
- In the System Recovery Options dialog box, choose your keyboard layout, and then click Next
- In the next System Recovery Options dialog box, make sure no operating system is selected. To do this, click in the empty area of the Operating System list, below any listed entries. Then click Next
- In the next System Recovery Options dialog box, click Command Prompt (see figure 1)
Figure 1
- Allocate the drive letter assigned to your USB key by entering the following commands one-by-one:
diskpart
list volumes
exit
Make a note of the drive letter assigned to the USB key.
- Prepare the volumes by entering the following command:
diskpart /s>:\bde-part.txt
whereshould be replaced with the drive letter allocated to your USB key.
Once you have completed the above steps, you should exit the command prompt window and return to the installation program and complete the Vista installation.
Prepare the TPM chip
Before we can use the TPM chip, we need to prepare it. This means that we need to ensure the following:
- Ensure that the correct TPM driver is installed in Vista
- Initialize the TPM chip
- Take ownership of the TPM chip
Note: If you don’t want to use a TPM chip with BitLocker, then you can skip this section and move on to the next section.
There are several reasons why Microsoft depends on a TPM chip that is version 1.2 TCG compliant, but two of the primary reasons, besides added security features, are compatibility and stability. Microsoft delivers this through a generic TPM Vista driver. The rule of thumb is that you should only use Microsoft’s TPM driver if you want to use BitLocker with a TPM chip.
Verify that you are using the right driver for your TPM chip (assuming your computer supports it) by entering the Device Manager. In the category called Security Devices, you should see Microsoft’s TPM driver, called “Trusted Platform Module 1.2”. If you want to verify the driver version, simply right-click the Trusted Platform Module 1.2 device and select Properties and then click the Driver tab, as illustrated in Figure 2.
Figure 2
If for some reason or another, you’re using a different TPM driver, then you can upgrade the driver to the before-mentioned Microsoft TPM driver, which you’ll find on the Vista DVD.
Once you have verified that the right TPM driver is loaded, it’s time to initialize the TPM chip. This can be done in two different ways, either by using the TPM MMC (simply type tpm.mcs) or configure it from the command line. In this article we’ll show you how this is done from the command line using the command line utility manage-bde.wsf which is a WMI based script.
- From the Vista Start Menu, locate the Command Prompt shortcut. Right-click the icon and select Run as administrator
- Enter the following command:
cscript manage-bde.wsf –tpm –takeownership - where
should be replaced with your own choice of password
Treat this password as your TPM master password. - The TPM chip is now ready for use (see Figure 3).
Figure 3
Encrypt the volumes
Up until now, we have gone through all the preliminary steps that are needed, before we can actually start encrypting volumes. Some of the steps explained so far, may already have been prepared directly by the manufacture of your computer, or not applicable if your computer doesn’t have a version 1.2 TPM compliant chip. Let’s move on and encrypt some data. This can be done in two different ways, either by using the BitLocker Control Panel GUI or done from the command line. In this article we’ll show you how this is done from the command line for various reasons:
- The BitLocker Control Panel GUI is only supported on machines with a compliant TPM chip. This means that if you want to take advantage of BitLocker without using a TPM chip, then your only option is the BitLocker command line utility (manage-bde.wsf)
- Another reason is, that officially, BitLocker in Vista only supports encryption of the OS Volume (which is normally the C: drive). However with the command line utility, you have the option to encrypt data volumes as well, a feature that is only officially supported in Longhorn Server
- The command line utility can be used to centrally encrypt client computers in an Active Directory environment, which we’ll take a closer look at in Part 2 of this article series.
How the volumes can be encrypted
- From the Vista Start Menu, locate the Command Prompt shortcut. Right-click the icon and select Run as administrator
- Enter the following command: cscript manage-bde.wsf –on /?
- This will show you the different pre-boot authentication and key recovery options you have with BitLocker. In this article we’ll show you how to encrypt a volume with TPM support, a volume without TPM support and finally a volume other than the C: drive
BitLocker encryption with TPM support
- From the Vista Start Menu, locate the Command Prompt shortcut. Right-click the icon and select Run as administrator
- Enter the following command:
cscript manage-bde.wsf –on –recoverypassword C:
Figure 4
- Follow the instructions on the screen to start the encryption process (see figure 4)
BitLocker encryption without TPM support:
- From the Vista Start Menu, locate the Command Prompt shortcut. Right-click the icon and select Run as administrator
- Enter the following command:
cscript manage-bde.wsf –on –startupkey:-recoverypassword –recoverykey :
is the drive letter assigned to the USB key that is used instead of the TPM chip. Remember to include the colon with the drive letter
can be either a hard drive, a USB key or a network drive. Again, remember to include the colon with the drive letter
BitLocker encryption of data volumes
The procedure is the same as the two previous examples. Just replace the drive letter with the drive you want to encrypt. The feature does however come with a couple of caveats if you’re not careful.
- The first one is that this will only work if you have encrypted the OS Volume with the manage-bde command line utililty as well
- The second caveat is that after the data volume is encrypted, you will not be able to access the data after you reboot the computer, unless you automatically unlock the data volume. Here’s how you can avoid this problem:
- We’ll assume you have encrypted the Data Volume using one of our examples in this article or your own preferences
- Before you restart the computer, enter the following command:
cscript manage-bde.wsf –autounlock –enable :
is the drive letter assigned to the Data Volume. Remember to include the colon with the data drive letter
The above command will generate an external key protector on the data volume and store the crypto key on the OS Volume (normally the C: drive) which we encrypted earlier. That way the crypto key for the data volume is protected by the crypto key for the OS Volume, but still automatically loaded during the boot phase.