• Some users have recently had their accounts hijacked. It seems that the now defunct EVGA forums might have compromised your password there and seems many are using the same PW here. We would suggest you UPDATE YOUR PASSWORD and TURN ON 2FA for your account here to further secure it. None of the compromised accounts had 2FA turned on.
    Once you have enabled 2FA, your account will be updated soon to show a badge, letting other members know that you use 2FA to protect your account. This should be beneficial for everyone that uses FSFT.

eDrive encryption

AMD T-type

Supreme [H]ardness
Joined
Aug 26, 2002
Messages
4,590
Is it just me, or is this a very difficult thing to get set up?

I got the wife a new laptop (Latitude E5440) and bought a 256GB Crucial MX100 which is touted to be one of the only drives which "Meets Microsoft eDrive, IEEE-1667, and TCG Opal 2.0 standards of encryption".
Also to point out, I just bought it because it was cheap.
I'm not looking to encrypt my super secret secrets from the governments, but being a laptop and that my wife will be using it for many financial things, I just thought it would be nice to enable eDrive which sounds like a nice feature, especially the no performance hit and lower power consumption points.

There are countless articles touting eDrive and SSD's that support it, but I can't seem to find any easy way to turn this thing on without standing on one foot, patting my head, and doing a backflip.


From what I've been able to find, the following requirements must be met:

BitLocker only supports TPM version 1.2 and 2.0 (or newer). In addition, you must use a Microsoft-provided TPM driver (Please note, BitLocker can also work without a TPM, but it will need a USB flash drive to set the password instead)
• The system needs to support UEFI 2.3.1
• Make sure UEFI boot is enabled and you have a UEFI enabled Windows 8 installed
• The computer must boot natively from UEFI.
• The boot order must be set to start first from the SSD (not the USB or CD drives)
• Dynamic discs are not supported by BitLocker
• The SSD must have two partitions (drives with Windows installed generally do anyway) and the main partition to be encrypted must be NTFS
• Ensure ATA Security features, for example Secure Boot, are disabled in the BIOS. The M500 supports either ATA Security or TCG Opal (which is needed for SED) but not both.
• The system needs to support Opal 2.0 The Opal 2.0 standard is not backwards compatible; Crucial SEDs are not compatible with Opal 1.0
• The computer must have the Compatibility Support Module (CSM) disabled in UEFI.

Also apparently the drive must be in an uninitiated state according to Microsoft. dafuq? How are you supposed to do this without installing Windows first?
It's on disk hardware encryption, is it really this fucking hard? aka. I hope I'm just doing this wrong.
 
never used it... but what error are you getting when you try to encrypt your drive?
 
never used it... but what error are you getting when you try to encrypt your drive?

No error, I just can't get it to encrypt instantly, it keeps wanting to encrypt the entire drive, as in "it's going to take 24 minutes" instead of "10 seconds later, its encrypted"
 
hmmm are you sure that you have everything set correctly?

especially uefi?

see below urls.

http://technet.microsoft.com/en-us/library/ee449438(v=ws.10).aspx#BKMK_LongEncrypt

Approximately how long will initial encryption take when BitLocker is turned on?
BitLocker encryption occurs in the background while you continue to work, and the system remains usable, but encryption times vary depending on the type of drive that is being encrypted, the size of the drive, and the speed of the drive. If you are encrypting very large drives, you may want to set encryption to occur during times when you will not be using the drive.

http://www.anandtech.com/show/6891/...ndows-8-edrive-investigated-with-crucial-m500

With all of your ducks in a row, all you need to do is enable BitLocker at this point. If everything is eDrive compliant you won’t be asked whether or you want to encrypt all or part of the drive, after you go through the initial setup BitLocker will just be enabled. There’s no extra encryption stage (since the data is already encrypted on your SSD). If you’ve done something wrong, or some part of your system isn’t eDrive compliant, you’ll get a progress indicator and a somewhat lengthy software encryption process.

For example, with 107GB in use my test 240GB M500 was fully encrypted with BitLocker enabled after a couple of seconds. Just a pause, then boom, BitLocker was enabled. My 256GB Samsung SSD 840 Pro on the other hand took about 21 minutes to encrypt the very same data using software encryption.

The gallery below shows all of the steps I went through to enable BitLocker/eDrive support on my Intel DX79SI motherboard with Crucial’s M500.
 
Still not having much luck.

I found this post specifically dealing with the actual series laptop I'm trying to do this on:
http://community.spiceworks.com/top...-1-edrive-crucial-m550-hardware-bitlocker-ftw

Dell Latitude 5000 + Crucial M550 SSD + Microsoft Windows 8.1 Pro eDrive
BIOS
 General > Boot Sequence > UEFI
 System Configuration > SATA Operation > AHCI
 Security > Admins Password > Set Password
Install
 Boot off install Media
 At Install screen, press Shift+F10
o Diskpart (enter twice)
o Select disk system
o Clean
o Exit
o Reboot
 Boot off install Media again
 Do Custom Install
 Install OS
BitLocker
 Control Panel > BitLocker
 Turn on BitLocker
 Save Key to USB
 Eject USB, click Next
 Uncheck Run Bitlocker system check
 If you’re prompted to encrypt all or part of the disk, it is not setup properly.
Driver Installs
 Follow Dell Install Order for drivers
 DO NOT INSTALL Intel Rapid Restore Technology Driver (Intel RRT)

However after diskparting the drive and installing win 8.1 pro it reboots and gives me an error of "no bootable device"

At this point I don't even want to use it, but this is [H] and I will not be defeated..........
 
are you sure your setup with uefi? I would just blow away all partitions on your hd and make it one whole drive and reinstall windows 8.

if it still says it can't boot then something else is not set correctly...
 
Yes,, using UEFI for sure, and installing under UEFI boot option for the usb drive as well.

If I enable legacy boot options and install via regular usb option, it starts booting windows fine, but with uefi options after its finished installing windows it reboots and no bootable device found.

Spent a few hours on it the other night, still got nowhere.
 
hmmm well i'm all out of suggestions brah...

you could also check to see if you got the latest bios/uefi from dell...

sorry couldn't be any more of help...
 
Fixed one issue, seems you need to have the BIOS set to RAID instead of AHCI. with AHCI set after installing Windows in UEFI mode it fails to find a boot device. With RAID set it loads perfectly.
About to test eDrive...
 
Well with RAID set, eDrive looks like its enabled according to the tool I ran from the lenovo thread, but I can't actually get the drive to instantly encrypt it keeps wanting to take 20 minutes, so back to square one problem i was having originally

Seems MS really dropped the ball with this.
 
Last edited:
Finally got it working. I can only assume the new BIOS update that was released yesterday for my laptop (Latitude 14 5000 series, E5440) helped in this regard. I was on A04, and yesterdays release was A07.

In case it helps anyone else, here are the important BIOS settings I had to use.
SATA operation = AHCI (not RAID)
TPM = on and enabled
SecureBoot = disabled
When installing Win 8.1 Pro I used Shift+F10 to run a diskpart and clean command.
UEFI boot only (legacy mode disabled)

Also in case it helps, in the lenovo thread there is a tool that checks the status of eDrive. It doesnt seem to work for Latitudes, as it was reporting no eDrive found, but when i turned on BitLocker, it encrypted instantly, with no progress bar and no asking if I wanted a certain partition or the whole disk.
 
Back
Top