dislocker icon indicating copy to clipboard operation
dislocker copied to clipboard

dislocker works with password but fails with recovery key when FIPS is activated

Open romanoju opened this issue 6 years ago • 10 comments

Have a strange situation. A disk partition bitlocked in windows (10) can be unlocked in windows with either the passkey or the recovery-key. However in ubuntu (3., it can be unlocked with the passkey but NOT with the recovery key.

#:~$ lsb_release -a No LSB modules are available. Distributor ID: Ubuntu Description: Ubuntu 12.04.2 LTS Release: 12.04 Codename: precise

kernel: 3.16.7

Attached are the outputs (stdout) of both commands. One with a passkey (works) the other with the recovery-key (Fails). dislocker-pwd-falcon.log dislocker-recoverykey-falcon.log

Any ideas? Has anybody seen this?

romanoju avatar Apr 13 '18 20:04 romanoju

"Have a strange situation. A disk partition bitlocked in windows (10) can be unlocked in windows with either the passkey or the recovery-key. However in ubuntu (3., it can be unlocked with the passkey but NOT with the recovery key." I just found out that the user who encrypted the drive in WIndows 10 may have enabled FIPS. Not sure if this is the problem. Does dislocker support FIPS-enabled bitlocker drives? If so, what is the procedure to recover such drives?

romanoju avatar Apr 16 '18 22:04 romanoju

Yes. Ubuntu 12.04.2.LTS

From: superbonaci [mailto:[email protected]] Sent: Tuesday, April 17, 2018 1:57 AM To: Aorimn/dislocker Cc: Juan Romano; Author Subject: Re: [Aorimn/dislocker] dislocker works with password but fails with recovery key (#141)

Running ubuntu 2012?

— You are receiving this because you authored the thread. Reply to this email directly, view it on GitHubhttps://github.com/Aorimn/dislocker/issues/141#issuecomment-381907882, or mute the threadhttps://github.com/notifications/unsubscribe-auth/AklixT_Y1kCBMpx_-VV9eMx_63WeiFY-ks5tpa5DgaJpZM4TUWPV.

romanoju avatar Apr 17 '18 16:04 romanoju

I don't think I ever tested FIPS-enabled bitlocker drives, so I don't have any information about the support or not of this feature.

Aorimn avatar May 08 '18 17:05 Aorimn

Well, it may be Windows release version dependent... https://docs.microsoft.com/en-us/windows/security/information-protection/bitlocker/prepare-your-organization-for-bitlocker-planning-and-policies#bkmk-fipssupport

thinrope avatar May 16 '18 19:05 thinrope

That indeed confirms the issue, thanks @thinrope !

@romanoju: I've edited the issue's subject to reflect the real problem, I hope you don't mind. This is indeed a limitation in dislocker right now.

Aorimn avatar May 17 '18 06:05 Aorimn

That’s fine. Thanks.

From: Aorimn [mailto:[email protected]] Sent: Wednesday, May 16, 2018 11:38 PM To: Aorimn/dislocker Cc: Juan Romano; Mention Subject: Re: [Aorimn/dislocker] dislocker works with password but fails with recovery key when FIPS is activated (#141)

That indeed confirms the issue, thanks @thinropehttps://github.com/thinrope !

@romanojuhttps://github.com/romanoju: I've edited the issue's subject to reflect the real problem, I hope you don't mind. This is indeed a limitation in dislocker right now.

— You are receiving this because you were mentioned. Reply to this email directly, view it on GitHubhttps://github.com/Aorimn/dislocker/issues/141#issuecomment-389760789, or mute the threadhttps://github.com/notifications/unsubscribe-auth/AklixaKZxv6Ay1aeKmIlQKrjeL7j-qDNks5tzRrRgaJpZM4TUWPV.

romanoju avatar May 17 '18 16:05 romanoju

Son of a gun. This is the same problem I had. Any work towards supporting the FIPS enabled bitlocker?

See Unlocking via Recovery Key #108

eddiek2000 avatar Jul 26 '18 18:07 eddiek2000

There's no work done toward this goal right now.

Aorimn avatar Jul 28 '18 12:07 Aorimn

This would be very helpful for us - do we even know where to start on this?

opoplawski avatar Nov 14 '18 17:11 opoplawski

This still remains an issue, and I'd be willing to work on it. Any pointers where to start?

bf avatar Jun 04 '19 14:06 bf