<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en-gb">
<link rel="self" type="application/atom+xml" href="https://forum.yubico.com/feed.php?f=26&amp;t=2321" />

<title>Yubico Forum</title>
<subtitle>...visit our web-store at</subtitle>
<link href="https://forum.yubico.com/index.php" />
<updated>2016-12-14T05:15:50+01:00</updated>

<author><name><![CDATA[Yubico Forum]]></name></author>
<id>https://forum.yubico.com/feed.php?f=26&amp;t=2321</id>
<entry>
<author><name><![CDATA[rsrinivasan]]></name></author>
<updated>2016-12-14T05:15:50+01:00</updated>
<published>2016-12-14T05:15:50+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=2321&amp;p=9218#p9218</id>
<link href="https://forum.yubico.com/viewtopic.php?t=2321&amp;p=9218#p9218"/>
<title type="html"><![CDATA[Re: [Solved] Smartcard for Bitlocker in Windows 10]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=2321&amp;p=9218#p9218"><![CDATA[
I tried following this process (self signing certificate) - but when I use the Microsoft Technet instructions it says to insert the smart card (which of course you can't write to directly from Windows). I'm presuming you have to generate certificate manually and then import it (using the Yubikey PIV manager tool). How do I create the certificate manually on the Windows 10 PC such that it works for Bitlocker?<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=4578">rsrinivasan</a> — Wed Dec 14, 2016 5:15 am</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[velosol]]></name></author>
<updated>2016-07-08T00:25:57+01:00</updated>
<published>2016-07-08T00:25:57+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=2321&amp;p=8775#p8775</id>
<link href="https://forum.yubico.com/viewtopic.php?t=2321&amp;p=8775#p8775"/>
<title type="html"><![CDATA[Re: [Solved] Smartcard for Bitlocker in Windows 10]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=2321&amp;p=8775#p8775"><![CDATA[
The key to be 'just create[d]' is the HKLM\Software\Policies\Microsoft\FVE registry key.  The link provided originally has the full set of instructions but says to make an adjustment to a registry key.  In this case the key does not exist and must be created and set as in the instructions.  Always be careful playing around in the registry, it can be a real pain to recover from mistakes there!<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=4225">velosol</a> — Fri Jul 08, 2016 12:25 am</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[werto]]></name></author>
<updated>2016-06-12T22:27:11+01:00</updated>
<published>2016-06-12T22:27:11+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=2321&amp;p=8708#p8708</id>
<link href="https://forum.yubico.com/viewtopic.php?t=2321&amp;p=8708#p8708"/>
<title type="html"><![CDATA[Re: [Question] Smartcard for Bitlocker in Windows 10]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=2321&amp;p=8708#p8708"><![CDATA[
<div class="quotetitle">PleasingSpringbok wrote:</div><div class="quotecontent"><br />I'm a little embarrassed to say this, but the solution was to just create the key and add the entry anyway. It really is that simple. Thanks to the people over at the TechNet forums for their help.<br /></div><br />Could anyone point me in the right direction here..?<br />I am completely lost <img src="https://forum.yubico.com/images/smilies/icon_redface.gif" alt=":oops:" title="Embarrassed" /><p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=4362">werto</a> — Sun Jun 12, 2016 10:27 pm</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[PleasingSpringbok]]></name></author>
<updated>2016-05-31T10:04:27+01:00</updated>
<published>2016-05-31T10:04:27+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=2321&amp;p=8660#p8660</id>
<link href="https://forum.yubico.com/viewtopic.php?t=2321&amp;p=8660#p8660"/>
<title type="html"><![CDATA[Re: [Question] Smartcard for Bitlocker in Windows 10]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=2321&amp;p=8660#p8660"><![CDATA[
I'm a little embarrassed to say this, but the solution was to just create the key and add the entry anyway. It really is that simple. Thanks to the people over at the TechNet forums for their help.<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=4344">PleasingSpringbok</a> — Tue May 31, 2016 10:04 am</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[PleasingSpringbok]]></name></author>
<updated>2016-05-31T10:04:45+01:00</updated>
<published>2016-05-29T00:41:19+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=2321&amp;p=8656#p8656</id>
<link href="https://forum.yubico.com/viewtopic.php?t=2321&amp;p=8656#p8656"/>
<title type="html"><![CDATA[[Solved] Smartcard for Bitlocker in Windows 10]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=2321&amp;p=8656#p8656"><![CDATA[
I'm trying to use my Yubikey NEO's PIV Smartcard capabilities to unlock Bitlocker drives in Windows 10. The main problem seems to be that all of the information on the internet for this is intended for Windows 7. I've tried following a few different guides but the outcome is the same: When I try to add a smart card as an unlock method, I get a popup telling me that &quot;A certificate suitable for bitlocker can't be found on your smart card.&quot;<br /><br />I tried using Microsoft's instructions on &quot;Creating a self-signed certificate for use with Bitlocker&quot;, available <a href="https://technet.microsoft.com/en-us/library/dd875530(v=ws.10).aspx" class="postlink">here</a>. I think the main issue is that I can't edit the registry to enable self-signed certificates, since HKLM\Software\Policies\Microsoft\FVE does not exist in Windows 10. I also tried the instructions under &quot;Sharing an EFS certificate with BitLocker&quot; on the same page, but it lead to the same error. In either case there was no issue in actually loading the certificate onto the Yubikey (thank you for the GUI tool!)<br /><br />Does this registry entry have an equivalent in Windows 10? It seems to be the bit that I'm missing.<br /><br />The certificate request file I'm using is:<br /><div class="codetitle"><b>Code:</b></div><div class="codecontent">&#91;NewRequest&#93;<br />Subject = &quot;CN=BitLocker&quot;<br />KeyLength = 2048<br />HashAlgorithm = Sha256<br />Exportable = TRUE<br />KeySpec = &quot;AT_KEYEXCHANGE&quot;<br />KeyUsage = &quot;CERT_KEY_ENCIPHERMENT_KEY_USAGE&quot;<br />KeyUsageProperty = &quot;NCRYPT_ALLOW_DECRYPT_FLAG&quot;<br />RequestType = Cert<br />SMIME = FALSE<br />ValidityPeriodUnits = 99<br />ValidityPeriod = Years<br /><br />&#91;EnhancedKeyUsageExtension&#93;<br />OID=1.3.6.1.4.1.311.67.1.1<br /></div><p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=4344">PleasingSpringbok</a> — Sun May 29, 2016 12:41 am</p><hr />
]]></content>
</entry>
</feed>