Article ID: 947249 - Last Review: January 24, 2008 - Revision: 1.2 The recovery password for Windows BitLocker is not FIPS-compliant in Windows Vista and in Windows Server 2008
On This PageINTRODUCTIONIn Windows Vista and in Windows Server 2008, the recovery password for Windows BitLocker Drive Encryption is not Federal Information Processing Standards (FIPS)-compliant. Therefore, you may encounter the following issues when the System cryptography: Use FIPS compliant algorithms for encryption, hashing, and signing Group Policy setting is enabled. Issue 1When you manually add a recovery password at a command prompt, you receive the following error message:The numerical password was not added. The FIPS Group Policy setting on the computer prevents recovery password creation. Issue 2When you try to encrypt a drive on which BitLocker recovery passwords are required, you cannot encrypt the drive as expected. Additionally, you receive the following error message:Cannot Encrypt Disk. Policy requires a password which is not allowed with the current security policy about use of FIPS algorithms. Issue 3When you encrypt a drive, a recovery key is created, but no recovery password is created as a key protector.Issue 4A recovery password is not archived in the Active Directory directory service.MORE INFORMATIONA BitLocker recovery password has 48 digits. This password is not FIPS-compliant. Therefore, if you enable the System cryptography: Use FIPS compliant algorithms for encryption, hashing, and signing Group Policy setting, you cannot create or unlock a drive by using a recovery password. However, a BitLocker recovery key is FIPS-compliant because it has additional entropy. Therefore, a recovery key is not affected by this Group Policy setting. To disable the System cryptography: Use FIPS compliant algorithms for encryption, hashing, and signing Group Policy setting, follow these steps:
APPLIES TO
| Other Resources Other Support Sites
CommunityGet Help NowArticle Translations
|






Windows Live
Facebook
Twitter
Linkedin
Digg it
Yahoo
Delicious
StumbleUpon
Yammer
Reddit
Technorati
FriendFeed
Email
Back to the top
