Yubico Forum

...visit our web-store at store.yubico.com
It is currently Tue Jan 30, 2018 11:11 am

All times are UTC + 1 hour




Post new topic Reply to topic  [ 3 posts ] 
Author Message
PostPosted: Thu Feb 09, 2017 1:28 pm 
Offline

Joined: Thu Feb 09, 2017 1:03 pm
Posts: 2
Hi!

I am trying to set up disk encryption in Windows 10 Pro using BitLocker and self-signed x509 certificate.
To achieve that I was following this tutorial: http://www.securearchitectures.com/2015 ... rd-to.html . I had set SelfSignedCertificates to 1 in registry and allowed running BitLocker without tpm. I also shared certificate as instructed in https://technet.microsoft.com/en-us/lib ... 30(v=ws.10).aspx .

Unfortunately when I try to enable encryption I am not offered SmartCard option -- only password and usb keyfile.

Can anyone tell me what I am missing?

Best regards,
grunai.


Top
 Profile  
Reply with quote  

Share On:

Share on Facebook FacebookShare on Twitter TwitterShare on Tumblr TumblrShare on Google+ Google+

PostPosted: Sun Feb 12, 2017 7:11 pm 
Offline

Joined: Sun Feb 12, 2017 6:56 pm
Posts: 1
Hi,

I've used the same tutorial. You may have not noticed but there is a typo in this line:

Quote:
Sign the certificate with the internal CA
.\openssl.exe x509 -req -days 36500 -sha512 -in 'C:\Users\dlohin\Documents\bit\bitlockercsr.pem' -CA C:\Users\dlohin\Documents\bit\cacert.pem -CAkey C:\Users\dlohin\Documents\bit\cakey.pem -CAcreateserial -out C:\Users\dlohin\Documents\bit\bitlockercer.pub


The default days should be 365000 not 36500.

If it still not fixes it, share your openssl.cnf file, in case you've modified it.

Regards,

Bekir


Top
 Profile  
Reply with quote  
PostPosted: Mon Feb 13, 2017 8:54 pm 
Offline

Joined: Thu Feb 09, 2017 1:03 pm
Posts: 2
Thank you for your response.

I had to use smaller value for availability period because of 2038 year bug in openssl.
Here is my openssl.cnf file: http://pastebin.com/2WiCEuBD

I appreciate your help.

Best regards,
grunai.


Top
 Profile  
Reply with quote  
Display posts from previous:  Sort by  
Post new topic Reply to topic  [ 3 posts ] 

All times are UTC + 1 hour


Who is online

Users browsing this forum: Google [Bot] and 3 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for:
Jump to:  
Powered by phpBB® Forum Software © phpBB Group