Lenovo ThinkVantage Client Security Solution 8.3 Bedienungsanleitung Seite 79

  • Herunterladen
  • Zu meinen Handbüchern hinzufügen
  • Drucken
  • Seite
    / 86
  • Inhaltsverzeichnis
  • LESEZEICHEN
  • Bewertet. / 5. Basierend auf Kundenbewertungen
Seitenansicht 78
AppendixD.UsingtheTPMonThinkPadnotebookcomputers
ThemainusecasefortheTPMistheBitLockerfeaturethatisincludedwithcertainversionsoftheMicrosoft
WindowsVistaandWindows7operatingsystems.Thisappendixprovidesanswerstothefollowing
frequentlyaskedquestionswhendeployingBitLockerinWindowsenvironments.
“HowtodeployBitLockerremotely?”onpage73
“HowdoesTPMlockoutwork?”onpage73
HowtodeployBitLockerremotely?
UsingthestandardWindowstoolstoactivatetheTPM,suchasthemanage-bde.exeleortheTPMcontrol
panel,requiresacompleteshutdownofthecomputer.Then,whenyouturnonthecomputeragain,you
mustpressakeytoconrmtheaction.ThistypeofinteractionmakesitimpossibletodeployBitLockerina
remoteandunattendedway.
TherearetwodistinctstatustypesrelatedtotheTPM:EnabledandActivated.AnenabledTPMisnot
necessarilyactivated,justlikeanactivatedTPMisnotnecessarilyenabled.TheTPMmustbeenabledand
activatedbeforeusingBitLocker.ThinkPadnotebookcomputersarealwaysshippedwiththeTPMinthe
enabledanddeactivatedstatus.Therefore,youshouldsettheTPMstatustoactivatedtodeployBitLocker
successfully.
Since2008,ThinkPadnotebookcomputershaveprovidedWindowsManagementInstrumentation(WMI)to
changeanyBIOSsetting(includingtheactivatedstatusoftheTPM).WMIcanbescriptedandexecuted
remotely,anddoesnotrequireanyphysicalinteractionwiththecomputer.
TochangetheBIOSsetting,dothefollowing:
1.GototheWebsiteathttp://support.lenovo.com/en_US/detail.page?LegacyDocID=MIGR-68488.
2.ClickSampleScriptsforBIOSDeploymentGuidetodownloadthescript.ziple.Thenextractthe
ziple.
3.Typecscript.exeSetCong.vbsSecurityChipActiveintheCommandPromptwindowtoexecute
theSetCong.vbsle.IfyouareusingtheBIOSsupervisorpassword,typecscript.exe
SetCongPassword.vbsSecurityChipActiveintheCommandPromptwindowtoexecutethe
SetCongPassword.vbsleinstead.
4.Restartthecomputertwice.TherstrestartchangestheBIOSsetting,andthesecondrestartmakes
thenewBIOSsettingtakeeffect.
Note:TheaboveprocedureactivatesonlytheTPMoncomputerswheretheTPMalreadyisenabled(for
example,modelsinthefactorydefaultstatus).IfyouhavedisabledtheTPMbyusingWindowstools,
suchasthemanage-bde.exeleortheTPMcontrolpanel,youmustre-enabletheTPMrstbyusingthe
samemethodthatwasusedtodisableit.
HowdoesTPMlockoutwork?
OneofthecoresecurityfeaturesoftheTPMistoprevent“hammering,thatis,theattempttoguess
TPMpasswordsinanautomatedway.EachTPMimplementsananti-hammeringmethod,andwhenan
attackisdetected,theTPMenterslockoutmodewhichmeansthatfurtherpasswordguessesareignored
untilthelockoutmodeends.However,theTrustedComputingGroup(theorganizationthatdenesTPM
behavior)failedtodeneastandardforTPMlockout,soeachTPMmanufacturerhasdevelopeditsown
implementationforlockout.LenovohasusedTPMsfromthefollowingfourdifferentvendors:
©CopyrightLenovo2008,2011
73
Seitenansicht 78
1 2 ... 74 75 76 77 78 79 80 81 82 83 84 85 86

Kommentare zu diesen Handbüchern

Keine Kommentare